<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Motiondivision on GitHub Actions Marketplace News</title><link>https://devops-actions.github.io/github-actions-marketplace-news/tags/motiondivision/</link><description>Recent content in Motiondivision on GitHub Actions Marketplace News</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Fri, 24 Jul 2026 14:01:17 +0000</lastBuildDate><atom:link href="https://devops-actions.github.io/github-actions-marketplace-news/tags/motiondivision/index.xml" rel="self" type="application/rss+xml"/><item><title>vulngate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/vulngate/</link><pubDate>Sat, 25 Jul 2026 00:43:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/vulngate/</guid><description>Version updated for https://github.com/cisoventures/vulngate to version v1.5.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary vulngate is an agent-neutral security check tool that scans code repositories for vulnerabilities using SAST, secrets scanning, and dependency auditing. It provides a unified interface for running these checks and offers structured findings with plain English explanations and fix hints. The core of vulngate orchestrates deterministic scanners and normalizes their output, ensuring minimal overhead and cost while providing valuable security insights to developers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/cisoventures/vulngate">https://github.com/cisoventures/vulngate</a></strong> to version <strong>v1.5.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vulngate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>vulngate is an agent-neutral security check tool that scans code repositories for vulnerabilities using SAST, secrets scanning, and dependency auditing. It provides a unified interface for running these checks and offers structured findings with plain English explanations and fix hints. The core of vulngate orchestrates deterministic scanners and normalizes their output, ensuring minimal overhead and cost while providing valuable security insights to developers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Follow-up to v1.5.1. That release probed <code>/code-scanning/alerts</code> and treated <strong>404</strong> as &ldquo;code scanning unavailable&rdquo; — but a <strong>public</strong> repo that simply hasn&rsquo;t uploaded an analysis yet <em>also</em> returns 404 (<code>no analysis found</code>). Result: the very first SARIF upload would be skipped, permanently, on exactly the repos where code scanning works.</p>
<p><strong>Fix:</strong> read repository metadata instead of probing for analyses. Upload when the repo is <strong>public</strong> (code scanning is free there) or when <strong>Advanced Security is enabled</strong> on a private repo.</p>
<p>Verified against all three real cases: private-without-Advanced-Security → skip cleanly; public → upload.</p>
<p>The v1.5.1 guarantee still holds: a scan that passes never produces a failing build.</p>
]]></content:encoded></item><item><title>Yarn 2 Bump Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/yarn-2-bump-action/</link><pubDate>Sat, 25 Jul 2026 00:42:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/yarn-2-bump-action/</guid><description>Version updated for https://github.com/cometkim/yarn-plugin-bump to version v0.0.5.
This action is used across all versions by 5 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a Yarn 2 plugin designed to simplify dependency upgrades in projects using the Plug’n’Play (PnP) mode. It automates the process of upgrading packages by running yarn up with specific filtering options, such as excluding certain packages or focusing on development or production dependencies. The action also supports specifying range updates for individual packages. The plugin is particularly useful for teams that rely on Yarn 2 and need a straightforward way to manage dependency upgrades without manual intervention.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/cometkim/yarn-plugin-bump">https://github.com/cometkim/yarn-plugin-bump</a></strong> to version <strong>v0.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/yarn-2-bump-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a Yarn 2 plugin designed to simplify dependency upgrades in projects using the Plug&rsquo;n&rsquo;Play (PnP) mode. It automates the process of upgrading packages by running <code>yarn up</code> with specific filtering options, such as excluding certain packages or focusing on development or production dependencies. The action also supports specifying range updates for individual packages. The plugin is particularly useful for teams that rely on Yarn 2 and need a straightforward way to manage dependency upgrades without manual intervention.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>v0.0.5 (fde50fd)</li>
<li>Update README (ae1cd0e)</li>
<li>Add more features (0059210)</li>
<li>Bump-up dependencies (#7) (ee96e21)</li>
<li>Fix action entry (d872385)</li>
<li>Upload artifact even release creation was failed (a2983e6)</li>
<li>Remove unused dependency (6d2524f)</li>
<li>Fix bump action (382d27e)</li>
<li>Add publish action (0d0779c)</li>
<li>Add bumping trigger (0134e22)</li>
</ul>
]]></content:encoded></item><item><title>Mutineer Ruby</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/mutineer-ruby/</link><pubDate>Sat, 25 Jul 2026 00:41:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/mutineer-ruby/</guid><description>Version updated for https://github.com/davidteren/mutineer to version v0.11.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Mutineer is a clean-room mutation-testing tool for Ruby that automates the process of identifying gaps in test coverage by mutating code and checking if tests fail to catch these mutations. It supports various options for customization, such as specifying test files, operators to use, and threshold settings. The action ensures thorough testing by running mutants against test suites and provides clear reports on gaps in test coverage.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/davidteren/mutineer">https://github.com/davidteren/mutineer</a></strong> to version <strong>v0.11.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mutineer-ruby">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Mutineer is a clean-room mutation-testing tool for Ruby that automates the process of identifying gaps in test coverage by mutating code and checking if tests fail to catch these mutations. It supports various options for customization, such as specifying test files, operators to use, and threshold settings. The action ensures thorough testing by running mutants against test suites and provides clear reports on gaps in test coverage.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong><code>--test-command</code> under version managers</strong> — scrub Mutineer&rsquo;s rbenv/asdf
version bins and bundler/gem env from the child so the suite can resolve the
app&rsquo;s Ruby via shims / <code>.ruby-version</code>. Smoke check prints a targeted hint on
<code>Bundler::RubyVersionMismatch</code> instead of only blaming DB/migrations. Docs
cover a wrapper recipe for stubborn setups (#32).</li>
</ul>
]]></content:encoded></item><item><title>Setup Elide</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/setup-elide/</link><pubDate>Sat, 25 Jul 2026 00:40:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/setup-elide/</guid><description>Version updated for https://github.com/elide-dev/setup-elide to version v4.2.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 4 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up the Elide runtime, a modern web framework for building APIs and microservices. It automates installation of Elide by default or through various installer methods like archive, shell, apt, etc., allowing users to choose their preferred installation method and customize the setup process. The action also supports caching for faster installations and anonymous error telemetry for better debugging support.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/elide-dev/setup-elide">https://github.com/elide-dev/setup-elide</a></strong> to version <strong>v4.2.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>4</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-elide">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up the Elide runtime, a modern web framework for building APIs and microservices. It automates installation of Elide by default or through various installer methods like <code>archive</code>, <code>shell</code>, <code>apt</code>, etc., allowing users to choose their preferred installation method and customize the setup process. The action also supports caching for faster installations and anonymous error telemetry for better debugging support.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: version matching and tool cache keys for build-metadata tags by @melodicore in <a href="https://github.com/elide-dev/setup-elide/pull/255">https://github.com/elide-dev/setup-elide/pull/255</a></li>
<li>chore: bump js-yaml by @darvld in <a href="https://github.com/elide-dev/setup-elide/pull/256">https://github.com/elide-dev/setup-elide/pull/256</a></li>
<li>chore: update dist by @darvld in <a href="https://github.com/elide-dev/setup-elide/pull/257">https://github.com/elide-dev/setup-elide/pull/257</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@melodicore made their first contribution in <a href="https://github.com/elide-dev/setup-elide/pull/255">https://github.com/elide-dev/setup-elide/pull/255</a></li>
<li>@darvld made their first contribution in <a href="https://github.com/elide-dev/setup-elide/pull/256">https://github.com/elide-dev/setup-elide/pull/256</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/elide-dev/setup-elide/compare/v4.1.0...v4.2.0">https://github.com/elide-dev/setup-elide/compare/v4.1.0...v4.2.0</a></p>
]]></content:encoded></item><item><title>Codex Code Review &amp; Actor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/codex-code-review-actor/</link><pubDate>Sat, 25 Jul 2026 00:38:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/codex-code-review-actor/</guid><description>Version updated for https://github.com/gersmann/codex-review-action to version v1.8.4.
This action is used across all versions by 8 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Codex Review Action automates the process of reviewing and editing pull requests using OpenAI’s GPT models. It posts inline review comments and a PR-level summary, and can apply focused edits on demand when trusted users comment /codex. The action supports both review and act modes, allowing for minimal or detailed edits based on the specified reasoning effort.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/gersmann/codex-review-action">https://github.com/gersmann/codex-review-action</a></strong> to version <strong>v1.8.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/codex-code-review-actor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Codex Review Action automates the process of reviewing and editing pull requests using OpenAI&rsquo;s GPT models. It posts inline review comments and a PR-level summary, and can apply focused edits on demand when trusted users comment <code>/codex</code>. The action supports both review and act modes, allowing for minimal or detailed edits based on the specified reasoning effort.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: update codex-python to 1.145.0 by @gersmann in <a href="https://github.com/gersmann/codex-review-action/pull/25">https://github.com/gersmann/codex-review-action/pull/25</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/gersmann/codex-review-action/compare/v1...v1.8.4">https://github.com/gersmann/codex-review-action/compare/v1...v1.8.4</a></p>
]]></content:encoded></item><item><title>action-ecr-publish</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/action-ecr-publish/</link><pubDate>Sat, 25 Jul 2026 00:37:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/action-ecr-publish/</guid><description>Version updated for https://github.com/heronlabs/action-ecr-publish to version v6.0.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action builds, lints, and optionally pushes a Docker image to an AWS ECR repository. It leverages GitHub Actions, OIDC authentication, and IAM roles for secure access to the ECR. The action can handle both push-to-main and release workflows and supports linting and building with optional private npm package dependencies.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/heronlabs/action-ecr-publish">https://github.com/heronlabs/action-ecr-publish</a></strong> to version <strong>v6.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/action-ecr-publish">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action builds, lints, and optionally pushes a Docker image to an AWS ECR repository. It leverages GitHub Actions, OIDC authentication, and IAM roles for secure access to the ECR. The action can handle both push-to-main and release workflows and supports linting and building with optional private npm package dependencies.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>[skip ci] bump v6.0.4 (dfe428d)</li>
<li>build(deps): update action-tag-release-build and AWS actions to latest versions (dfa633b)</li>
<li>[skip ci] bump v6.0.3 (1f89ae4)</li>
<li>build(deps): bump the actions group with 2 updates (#27) (1af0aef)</li>
<li>[skip ci] bump v6.0.2 (43d9c12)</li>
<li>chore: migrate supera.json to 2.x schema (#28) (2a5ab83)</li>
<li>[skip ci] bump v6.0.1 (35506d7)</li>
<li>chore: update bats-core action to use version 4.0.0 (200cf9e)</li>
<li>[skip ci] bump v6.0.0 (08a376d)</li>
<li>[skip ci] bump v5.0.7 (b34355d)</li>
</ul>
]]></content:encoded></item><item><title>action-tag-release-build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/action-tag-release-build/</link><pubDate>Sat, 25 Jul 2026 00:36:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/action-tag-release-build/</guid><description>Version updated for https://github.com/heronlabs/action-tag-release-build to version v7.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of bumping a version number, tagging a commit, creating a release with a CHANGELOG, and optionally updating package.json or Claude Code plugin files. It uses semantic versions to determine the bump type based on merge/HEAD commit messages or defaults to patch. The action can be triggered via a GitHub workflow dispatch event, and it exposes outputs for later use in subsequent steps.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/heronlabs/action-tag-release-build">https://github.com/heronlabs/action-tag-release-build</a></strong> to version <strong>v7.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/action-tag-release-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of bumping a version number, tagging a commit, creating a release with a CHANGELOG, and optionally updating package.json or Claude Code plugin files. It uses semantic versions to determine the bump type based on merge/HEAD commit messages or defaults to <code>patch</code>. The action can be triggered via a GitHub workflow dispatch event, and it exposes outputs for later use in subsequent steps.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="-breaking-changes">⚠ BREAKING CHANGES</h3>
<ul>
<li>feat!: scaffold environment sync command and plan (#48) (23b4ee7177744fbda42d4ebbd2cd43879e0fc1a6)</li>
</ul>
<h3 id="features">Features</h3>
<ul>
<li>feat!: scaffold environment sync command and plan (#48) (23b4ee7177744fbda42d4ebbd2cd43879e0fc1a6)</li>
</ul>
]]></content:encoded></item><item><title>NTN-in-a-Box</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/ntn-in-a-box/</link><pubDate>Sat, 25 Jul 2026 00:35:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/ntn-in-a-box/</guid><description>Version updated for https://github.com/hyavari/ntn-in-a-box to version v0.1.5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NTN-in-a-Box is a self-hostable open-source platform that simulates the conditions of satellite passes, allowing developers to test and build applications under realistic NTN (Non-Terrestrial Network) conditions. It provides a condition engine for shaping real network traffic like a satellite pass and a pluggable module system for building capabilities such as messaging and emergency services.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hyavari/ntn-in-a-box">https://github.com/hyavari/ntn-in-a-box</a></strong> to version <strong>v0.1.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ntn-in-a-box">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>NTN-in-a-Box is a self-hostable open-source platform that simulates the conditions of satellite passes, allowing developers to test and build applications under realistic NTN (Non-Terrestrial Network) conditions. It provides a condition engine for shaping real network traffic like a satellite pass and a pluggable module system for building capabilities such as messaging and emergency services.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hyavari/ntn-in-a-box/compare/v0.1.4...v0.1.5">https://github.com/hyavari/ntn-in-a-box/compare/v0.1.4...v0.1.5</a></p>
]]></content:encoded></item><item><title>Jamf Recovery Lock Rotation</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/jamf-recovery-lock-rotation/</link><pubDate>Sat, 25 Jul 2026 00:33:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/jamf-recovery-lock-rotation/</guid><description>Version updated for https://github.com/Inetum-Poland/jamf-recovery-lock-rotation to version v1.0.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the rotation of Recovery Lock passphrases on Jamf Pro-managed Apple Silicon Mac computers. It uses OAuth client credentials and retrieves device Management IDs from Jamf Pro inventory, with optional scoping via a Smart Computer Group. The action issues the SET_RECOVERY_LOCK MDM command, exposing outputs for downstream workflow steps or reporting. It supports dry-run workflows to validate roles and group scoping before executing MDM commands.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Inetum-Poland/jamf-recovery-lock-rotation">https://github.com/Inetum-Poland/jamf-recovery-lock-rotation</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jamf-recovery-lock-rotation">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the rotation of Recovery Lock passphrases on Jamf Pro-managed Apple Silicon Mac computers. It uses OAuth client credentials and retrieves device Management IDs from Jamf Pro inventory, with optional scoping via a Smart Computer Group. The action issues the <code>SET_RECOVERY_LOCK</code> MDM command, exposing outputs for downstream workflow steps or reporting. It supports dry-run workflows to validate roles and group scoping before executing MDM commands.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="jamf-recovery-lock-rotation">Jamf Recovery Lock Rotation</h2>
<p>This is a version of <strong>Inetum-Poland/jamf-recovery-lock-rotation</strong> released by GitHub Actions.</p>
<hr>
<h2 id="changes-since-v100">Changes since <a href="https://github.com/Inetum-Poland/jamf-recovery-lock-rotation/releases/tag/v1.0.0">v1.0.0</a></h2>
<ul>
<li><a href="http://github.com/Inetum-Poland/jamf-recovery-lock-rotation/commit/4d11d22ff6cc927adf199021ae9a200840a88df0">4d11d22</a> - feat(repo): add release attestation and improve CLI passphrase generation (#6)</li>
<li><a href="http://github.com/Inetum-Poland/jamf-recovery-lock-rotation/commit/f4834673442723e7c6e8ff18337419a4d382f658">f483467</a> - docs(action): refine marketplace description (#5)</li>
</ul>
<h4 id="full-changelog-v100">Full Changelog: <a href="https://github.com/Inetum-Poland/jamf-recovery-lock-rotation/compare/v1.0.0...v1.0.2">v1.0.0&hellip;v1.0.2</a></h4>
<p><sup>Contributed by @bsojka</sup></p>
]]></content:encoded></item><item><title>Official Junie GitHub Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/official-junie-github-action/</link><pubDate>Sat, 25 Jul 2026 00:32:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/official-junie-github-action/</guid><description>Version updated for https://github.com/JetBrains/junie-github-action to version v1.6.1.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 38 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action Junie automates the integration of JetBrains’ AI coding agent into GitHub workflows to resolve issues, manage PRs, and provide inline code reviews. It responds to mentions in comments, issues, and PRs, automatically implements fixes and suggestions, and integrates with Jira and YouTrack for project management.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/JetBrains/junie-github-action">https://github.com/JetBrains/junie-github-action</a></strong> to version <strong>v1.6.1</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>38</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/official-junie-github-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action Junie automates the integration of JetBrains&rsquo; AI coding agent into GitHub workflows to resolve issues, manage PRs, and provide inline code reviews. It responds to mentions in comments, issues, and PRs, automatically implements fixes and suggestions, and integrates with Jira and YouTrack for project management.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>[Junie]: Update Junie CLI Version to 2383.10 in Files by @mashan555 in <a href="https://github.com/JetBrains/junie-github-action/pull/184">https://github.com/JetBrains/junie-github-action/pull/184</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/JetBrains/junie-github-action/compare/v1...v1.6.1">https://github.com/JetBrains/junie-github-action/compare/v1...v1.6.1</a></p>
]]></content:encoded></item><item><title>Codex Review Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/codex-review-gate/</link><pubDate>Sat, 25 Jul 2026 00:31:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/codex-review-gate/</guid><description>Version updated for https://github.com/JoeyTeng/codex-review-gate-action to version v1.3.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Codex Review Gate GitHub Action is a reusable tool designed for repositories that want a required status check to stay pending or failing until Codex review output for the current PR head is clean. It automates the process of requesting and evaluating Codex AI-generated reviews, ensuring reliability and control over the review state machine. The action handles different states of Codex findings, including outdated but unresolved threads, and provides clear disclosure about any generated comments from Codex.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/JoeyTeng/codex-review-gate-action">https://github.com/JoeyTeng/codex-review-gate-action</a></strong> to version <strong>v1.3.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/codex-review-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Codex Review Gate GitHub Action is a reusable tool designed for repositories that want a required status check to stay pending or failing until Codex review output for the current PR head is clean. It automates the process of requesting and evaluating Codex AI-generated reviews, ensuring reliability and control over the review state machine. The action handles different states of Codex findings, including outdated but unresolved threads, and provides clear disclosure about any generated comments from Codex.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="fixed">Fixed</h2>
<ul>
<li>Accept every exact official clean-result tagline observed during the <code>@v1</code> consumer rollout.</li>
<li>Preserve the closed clean grammar: arbitrary prose, punctuation near misses, and finding-formatted content still fail closed.</li>
<li>Exercise the live <code>Another round soon, please!</code> form through the full state machine, including reasserting success over stale status history without requesting another review.</li>
</ul>
<h2 id="release-identity">Release identity</h2>
<ul>
<li>Action commit: <code>11d400902175edd773340dc9ec00f8dd421feff7</code></li>
<li>Canonical source PR: <code>JoeyTeng/codex-review-gate#21</code></li>
<li>Canonical source merge: <code>f8a6b84eb39459dd5aa6c7a20487f444ae387df3</code></li>
</ul>
<p>The signed <code>v1.3.2</code>, <code>v1.3</code>, and <code>v1</code> tags all peel to the same tested action commit.</p>
]]></content:encoded></item><item><title>Register Jolter release</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/register-jolter-release/</link><pubDate>Sat, 25 Jul 2026 00:30:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/register-jolter-release/</guid><description>Version updated for https://github.com/jolterjs/register-release-action to version v1.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Register Jolter Release Action is a GitHub Action designed to register a published plugin release with the Jolter registry. It submits release metadata and the repository-scoped GitHub token, while keeping the plugin artifacts hosted in the GitHub Release. The action automates the process of registering releases for plugins, handling semantic versioning, and ensuring safe re-runs when versions are already registered.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jolterjs/register-release-action">https://github.com/jolterjs/register-release-action</a></strong> to version <strong>v1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/register-jolter-release">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Register Jolter Release Action is a GitHub Action designed to register a published plugin release with the Jolter registry. It submits release metadata and the repository-scoped GitHub token, while keeping the plugin artifacts hosted in the GitHub Release. The action automates the process of registering releases for plugins, handling semantic versioning, and ensuring safe re-runs when versions are already registered.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="breaking-change">Breaking change</h2>
<blockquote>
<p>With this release we are upgrading the typescript version from v6 to v7 for building the project. This does not affect how the action works, it only affects the development workflow of this action.</p>
</blockquote>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>deps: bump actions/setup-node from 6 to 7 in the github-actions group by @dependabot[bot] in <a href="https://github.com/jolterjs/register-release-action/pull/6">https://github.com/jolterjs/register-release-action/pull/6</a></li>
<li>deps: bump typescript from 6.0.3 to 7.0.2 by @dependabot[bot] in <a href="https://github.com/jolterjs/register-release-action/pull/5">https://github.com/jolterjs/register-release-action/pull/5</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jolterjs/register-release-action/compare/v1...v1.1">https://github.com/jolterjs/register-release-action/compare/v1...v1.1</a></p>
]]></content:encoded></item><item><title>datamodel-code-generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/datamodel-code-generator/</link><pubDate>Sat, 25 Jul 2026 00:29:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/datamodel-code-generator/</guid><description>Version updated for https://github.com/koxudaxi/datamodel-code-generator to version 0.71.0.
This action is used across all versions by 3,362 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The datamodel-code-generator GitHub Action generates Python data models from various schema definitions including OpenAPI 3, AsyncAPI, JSON Schema, Apache Avro, XML Schema, Protocol Buffers/gRPC, GraphQL, and MCP tool schemas. It can also convert existing Python types like Pydantic, dataclass, and TypedDict into different output types such as Pydantic v2, Pydantic v2 dataclass, dataclasses, TypedDict, or msgspec. The action handles complex schemas with features like $ref, allOf, oneOf, anyOf, enums, and nested types to produce type-safe, validated code ready for IDEs and type checkers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/koxudaxi/datamodel-code-generator">https://github.com/koxudaxi/datamodel-code-generator</a></strong> to version <strong>0.71.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3,362</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/datamodel-code-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>datamodel-code-generator</code> GitHub Action generates Python data models from various schema definitions including OpenAPI 3, AsyncAPI, JSON Schema, Apache Avro, XML Schema, Protocol Buffers/gRPC, GraphQL, and MCP tool schemas. It can also convert existing Python types like Pydantic, dataclass, and TypedDict into different output types such as Pydantic v2, Pydantic v2 dataclass, dataclasses, TypedDict, or msgspec. The action handles complex schemas with features like $ref, allOf, oneOf, anyOf, enums, and nested types to produce type-safe, validated code ready for IDEs and type checkers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="breaking-changes">Breaking Changes</h2>
<h3 id="default-behavior-changes">Default Behavior Changes</h3>
<ul>
<li>New warning emitted by default for unresolved local <code>$ref</code> pointers - By default, an unresolved local <code>$ref</code> JSON pointer now emits a new <code>DanglingRefWarning</code> and generates a fallback <code>Any</code> model. Previously such refs resolved to a silent fallback, and some cases (e.g., out-of-range JSON pointer array indices) raised a hard error. Schemas that previously generated cleanly can now produce warnings, which breaks workflows that treat warnings as errors (e.g., <code>python -W error</code>). Use <code>--strict-refs</code> to fail on unresolved pointers instead, or <code>--disable-warnings</code> to silence them (#3639)</li>
</ul>
<h3 id="error-handling-changes">Error Handling Changes</h3>
<ul>
<li><code>$ref</code> to a non-dict file now raises <code>InvalidFileFormatError</code> instead of <code>TypeError</code> - Resolving a <code>$ref</code> to a JSON/YAML file whose top-level value is not a mapping (e.g., a list) now raises <code>datamodel_code_generator.InvalidFileFormatError</code> (a subclass of <code>Error</code>/<code>Exception</code>) rather than the built-in <code>TypeError</code>. Programmatic callers that catch <code>TypeError</code> around <code>generate()</code> must catch <code>InvalidFileFormatError</code> (or <code>Error</code>) instead (#3639)</li>
<li>Malformed-input diagnostics reworded - Malformed inputs that previously surfaced an uncaught traceback now emit a concise message such as <code>Invalid file format for &lt;type&gt; at &lt;source&gt;: ...</code>, and the missing-file message changed from <code>File not found</code> to <code>File not found: &lt;path&gt;</code>. Tooling that matches on the exact previous strings needs updating (#3639)</li>
<li>Generation now aborts when output paths would overwrite inputs or collide - A new path-conflict validation runs before generation in both the <code>generate()</code> Python API and the CLI. Invocations that previously succeeded now raise an <code>Error</code> (CLI exits with an error code) in these cases: the output path resolves to an existing input file, the <code>--emit-model-metadata</code> path resolves to an existing input file, or the output and model-metadata paths resolve to the same file. Symlinks and hardlinks are resolved before the comparison. Workflows that intentionally wrote output over an input path, or that pointed the model-metadata artifact at the same path as the output, will now fail with one of:</li>
</ul>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-text" data-lang="text"><span style="display:flex;"><span>Output path must not overwrite an input path: &lt;path&gt;
</span></span><span style="display:flex;"><span>Model metadata path must not overwrite an input path: &lt;path&gt;
</span></span><span style="display:flex;"><span>Output and model metadata paths must be different: &lt;path&gt;
</span></span></code></pre></div><p>(#3647)</p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Update CHANGELOG for 0.70.0 by @dcg-generated-docs[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3619">https://github.com/koxudaxi/datamodel-code-generator/pull/3619</a></li>
<li>Decouple RootModel dependency ordering by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3620">https://github.com/koxudaxi/datamodel-code-generator/pull/3620</a></li>
<li>Improve README and docs homepage links by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3624">https://github.com/koxudaxi/datamodel-code-generator/pull/3624</a></li>
<li>Update release benchmark data by @dcg-generated-docs[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3625">https://github.com/koxudaxi/datamodel-code-generator/pull/3625</a></li>
<li>Move discriminator policies to output models by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3621">https://github.com/koxudaxi/datamodel-code-generator/pull/3621</a></li>
<li>Invalidate generation facts for every list mutation by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3622">https://github.com/koxudaxi/datamodel-code-generator/pull/3622</a></li>
<li>Document package manager installation options by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3629">https://github.com/koxudaxi/datamodel-code-generator/pull/3629</a></li>
<li>Move dict-key dependency policy to output models by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3626">https://github.com/koxudaxi/datamodel-code-generator/pull/3626</a></li>
<li>Decouple parser model behavior helpers by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3632">https://github.com/koxudaxi/datamodel-code-generator/pull/3632</a></li>
<li>Share model constraints across output backends by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3630">https://github.com/koxudaxi/datamodel-code-generator/pull/3630</a></li>
<li>Move Pydantic type rendering to backend by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3627">https://github.com/koxudaxi/datamodel-code-generator/pull/3627</a></li>
<li>Move dataclass ordering policies to output models by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3628">https://github.com/koxudaxi/datamodel-code-generator/pull/3628</a></li>
<li>Move template reference metadata to output models by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3631">https://github.com/koxudaxi/datamodel-code-generator/pull/3631</a></li>
<li>Declare output model construction capabilities by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3623">https://github.com/koxudaxi/datamodel-code-generator/pull/3623</a></li>
<li>Fix payload runtime validation exclusions by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3635">https://github.com/koxudaxi/datamodel-code-generator/pull/3635</a></li>
<li>Cover output backends across input formats by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3636">https://github.com/koxudaxi/datamodel-code-generator/pull/3636</a></li>
<li>Track large schema memory by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3637">https://github.com/koxudaxi/datamodel-code-generator/pull/3637</a></li>
<li>Reuse remote schema connections by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3638">https://github.com/koxudaxi/datamodel-code-generator/pull/3638</a></li>
<li>Improve malformed input diagnostics by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3639">https://github.com/koxudaxi/datamodel-code-generator/pull/3639</a></li>
<li>Bump setuptools from 82.0.1 to 83.0.0 by @dependabot[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3633">https://github.com/koxudaxi/datamodel-code-generator/pull/3633</a></li>
<li>Update project usage examples by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3641">https://github.com/koxudaxi/datamodel-code-generator/pull/3641</a></li>
<li>Fix vLLM usage link by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3642">https://github.com/koxudaxi/datamodel-code-generator/pull/3642</a></li>
<li>Refresh custom template paths by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3640">https://github.com/koxudaxi/datamodel-code-generator/pull/3640</a></li>
<li>List project maintainers by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3643">https://github.com/koxudaxi/datamodel-code-generator/pull/3643</a></li>
<li>Preserve Unicode line separators by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3644">https://github.com/koxudaxi/datamodel-code-generator/pull/3644</a></li>
<li>Fix TypedDict unique item sets by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3645">https://github.com/koxudaxi/datamodel-code-generator/pull/3645</a></li>
<li>Defer msgspec forward references by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3646">https://github.com/koxudaxi/datamodel-code-generator/pull/3646</a></li>
<li>Validate generation path conflicts by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3647">https://github.com/koxudaxi/datamodel-code-generator/pull/3647</a></li>
<li>Enforce dynamic model cache size by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3648">https://github.com/koxudaxi/datamodel-code-generator/pull/3648</a></li>
<li>Filter imported dynamic model classes by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3649">https://github.com/koxudaxi/datamodel-code-generator/pull/3649</a></li>
<li>Defer nested model default factories by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3650">https://github.com/koxudaxi/datamodel-code-generator/pull/3650</a></li>
<li>Isolate generation state by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3652">https://github.com/koxudaxi/datamodel-code-generator/pull/3652</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/koxudaxi/datamodel-code-generator/compare/0.70.0...0.71.0">https://github.com/koxudaxi/datamodel-code-generator/compare/0.70.0...0.71.0</a></p>
]]></content:encoded></item><item><title>OctoSTS</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/octosts/</link><pubDate>Sat, 25 Jul 2026 00:28:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/octosts/</guid><description>Version updated for https://github.com/launchdarkly/octosts-action to version v1.4.1.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 1 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action exchanges the workflow’s identity token for a GitHub token from the OctoSTS service, using a configured trust policy. It automates tasks such as federating tokens and configuring Git authentication based on the provided trust policy. The key capabilities include setting up federated authentication and handling default configurations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/launchdarkly/octosts-action">https://github.com/launchdarkly/octosts-action</a></strong> to version <strong>v1.4.1</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>1</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/octosts">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action exchanges the workflow&rsquo;s identity token for a GitHub token from the OctoSTS service, using a configured trust policy. It automates tasks such as federating tokens and configuring Git authentication based on the provided trust policy. The key capabilities include setting up federated authentication and handling default configurations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: Restore host-wide configure-git credential by @jsonbailey in <a href="https://github.com/launchdarkly/octosts-action/pull/20">https://github.com/launchdarkly/octosts-action/pull/20</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@jsonbailey made their first contribution in <a href="https://github.com/launchdarkly/octosts-action/pull/20">https://github.com/launchdarkly/octosts-action/pull/20</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/launchdarkly/octosts-action/compare/v1...v1.4.1">https://github.com/launchdarkly/octosts-action/compare/v1...v1.4.1</a></p>
]]></content:encoded></item><item><title>Setup Fortran Compilers</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/setup-fortran-compilers/</link><pubDate>Sat, 25 Jul 2026 00:28:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/setup-fortran-compilers/</guid><description>Version updated for https://github.com/minhqdao/setup-fortran to version v1.7.0.
This action is used across all versions by 4 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
The setup-fortran GitHub Action automates the installation and configuration of Fortran compilers across Linux, macOS, and Windows runners. It supports various compilers such as GNU Fortran (gfortran), Intel Fortran (ifort), and NVIDIA Fortran (nvfortran). The action allows users to specify which compiler they want to install and its version, and provides options for MSYS2 subsystem configuration and disk space cleanup for certain compilers like NVFortran.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/minhqdao/setup-fortran">https://github.com/minhqdao/setup-fortran</a></strong> to version <strong>v1.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-fortran-compilers">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>The <code>setup-fortran</code> GitHub Action automates the installation and configuration of Fortran compilers across Linux, macOS, and Windows runners. It supports various compilers such as GNU Fortran (<code>gfortran</code>), Intel Fortran (<code>ifort</code>), and NVIDIA Fortran (<code>nvfortran</code>). The action allows users to specify which compiler they want to install and its version, and provides options for MSYS2 subsystem configuration and disk space cleanup for certain compilers like NVFortran.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li><input checked="" disabled="" type="checkbox"> Add support for <code>lfortran</code> 0.64.0.</li>
<li><input checked="" disabled="" type="checkbox"> Robustness improvements.</li>
</ul>
]]></content:encoded></item><item><title>latexbuild</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/latexbuild/</link><pubDate>Sat, 25 Jul 2026 00:26:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/latexbuild/</guid><description>Version updated for https://github.com/MrzAhmadi/latexbuild to version v0.0.6.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The latexbuild GitHub Action automates the compilation of LaTeX documents by using a Docker container with a full TeX Live distribution. It simplifies the process of compiling .tex files locally without requiring any installation, making it easy to automate build processes or live preview PDFs as you edit your source files.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MrzAhmadi/latexbuild">https://github.com/MrzAhmadi/latexbuild</a></strong> to version <strong>v0.0.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/latexbuild">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The latexbuild GitHub Action automates the compilation of LaTeX documents by using a Docker container with a full TeX Live distribution. It simplifies the process of compiling <code>.tex</code> files locally without requiring any installation, making it easy to automate build processes or live preview PDFs as you edit your source files.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/MrzAhmadi/latexbuild/compare/v0.0.5...v0.0.6">https://github.com/MrzAhmadi/latexbuild/compare/v0.0.5...v0.0.6</a></p>
]]></content:encoded></item><item><title>Test Adequacy Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/test-adequacy-guard/</link><pubDate>Sat, 25 Jul 2026 00:24:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/test-adequacy-guard/</guid><description>Version updated for https://github.com/Ostico/test-guard to version v1.10.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Test-Guard automates the task of ensuring that code changes are adequately covered by tests. It uses diff coverage, heuristic matching across multiple languages, and AI-powered evaluation to ensure that every modified file has corresponding tests or is trivially untestable. The action provides a single pass/fail verdict based on these evaluations, helping developers quickly identify whether their PR has sufficient testing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Ostico/test-guard">https://github.com/Ostico/test-guard</a></strong> to version <strong>v1.10.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/test-adequacy-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Test-Guard automates the task of ensuring that code changes are adequately covered by tests. It uses diff coverage, heuristic matching across multiple languages, and AI-powered evaluation to ensure that every modified file has corresponding tests or is trivially untestable. The action provides a single pass/fail verdict based on these evaluations, helping developers quickly identify whether their PR has sufficient testing.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Patch release. <strong>If you use a jest/istanbul <code>clover.xml</code>, v1.10.0 did not deliver its own fix — upgrade to this.</strong></p>
<h2 id="the-bug">The bug</h2>
<p>v1.10.0 taught Test-Guard to read the coverage report directly, so a file with no <em>executable</em> changed lines (type declarations, interface members, doc comments) would pass instead of failing with <strong>&ldquo;not in coverage report.&rdquo;</strong> For jest reports, that check still failed.</p>
<p>Clover reporters disagree about which attribute holds the qualified path:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-xml" data-lang="xml"><span style="display:flex;"><span><span style="color:#75715e">&lt;!-- jest / istanbul --&gt;</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">&lt;file</span> <span style="color:#a6e22e">name=</span><span style="color:#e6db74">&#34;types.ts&#34;</span> <span style="color:#a6e22e">path=</span><span style="color:#e6db74">&#34;/home/runner/work/app/app/src/bruno/types.ts&#34;</span><span style="color:#f92672">&gt;</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e">&lt;!-- PHPUnit --&gt;</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">&lt;file</span> <span style="color:#a6e22e">name=</span><span style="color:#e6db74">&#34;/var/www/app/lib/AuthCookie.php&#34;</span><span style="color:#f92672">&gt;</span>
</span></span></code></pre></div><p>The presence check read <code>name=</code>, which is right for PHPUnit but yields a bare basename under jest. <code>is_in_report()</code> then refused to match it — deliberately, since a bare basename would otherwise match a same-named file in an unrelated directory. Net effect: a file sitting in the report at <strong>100%</strong> was still reported as un-instrumented.</p>
<h2 id="the-fix">The fix</h2>
<p>The Clover presence extractor now reads <strong>both</strong> <code>name=</code> and <code>path=</code> from every <code>&lt;file&gt;</code> and lets <code>is_in_report()</code> pick whichever is qualified. Path-prefix detection and Clover rewriting are untouched, so nothing else changes.</p>
<p>Diagnosed and verified against a real failing CI artifact, not a synthetic fixture: <code>is_in_report(&quot;src/bruno/types.ts&quot;)</code> returns <code>True</code>, Layer 1 returns PASS and short-circuits, and Layer 3&rsquo;s shortcut returns SKIP where it previously returned FAIL. A path genuinely absent from the report still fails, so real instrumentation gaps are still caught.</p>
<p>Regression tests now pin both reporter shapes.</p>
<h2 id="upgrading">Upgrading</h2>
<p>No configuration changes. Users on <code>@v1</code> get this automatically on the next run. If you added an exclude entry to work around a declaration-only file, you can drop it.</p>
<p><strong>Full changelog:</strong> <a href="https://github.com/Ostico/test-guard/compare/v1.10.0...v1.10.1">https://github.com/Ostico/test-guard/compare/v1.10.0...v1.10.1</a></p>
]]></content:encoded></item><item><title>WordPress Playground Link</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/wordpress-playground-link/</link><pubDate>Sat, 25 Jul 2026 00:23:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/wordpress-playground-link/</guid><description>Version updated for https://github.com/pattonwebz/wordpress-playground-action to version v0.1.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action converts an uploaded plugin zip artifact into a publicly accessible WordPress Playground link, allowing developers to easily test and deploy their plugins. It automatically handles private-repo artifacts by failing the action if the repository is private. The action supports various optional configurations such as activating themes and plugins upon installation, and provides options to post the link as a sticky comment on pull requests or in GitHub comments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pattonwebz/wordpress-playground-action">https://github.com/pattonwebz/wordpress-playground-action</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wordpress-playground-link">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action converts an uploaded plugin zip artifact into a publicly accessible WordPress Playground link, allowing developers to easily test and deploy their plugins. It automatically handles private-repo artifacts by failing the action if the repository is private. The action supports various optional configurations such as activating themes and plugins upon installation, and provides options to post the link as a sticky comment on pull requests or in GitHub comments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release.</p>
<p><strong>WordPress Playground Link</strong> turns a plugin zip you&rsquo;ve already uploaded as a GitHub Actions artifact into a one-click <a href="https://playground.wordpress.net/">WordPress Playground</a> link — install, activate, and land straight on the page you want reviewers to see, no manual setup.</p>
<h3 id="what-it-does">What it does</h3>
<ul>
<li>Resolves your artifact to a public URL via <a href="https://nightly.link">nightly.link</a> and builds a Playground blueprint around it</li>
<li>Installs and (optionally) activates the plugin, with configurable landing page, WP/PHP version, and multisite</li>
<li>Can install extra plugins or a theme alongside it</li>
<li>Optionally posts/updates a sticky PR comment with the generated link</li>
<li>Verifies the artifact actually exists before building a link, if you pass a token — fails loudly in CI instead of shipping a dead link</li>
</ul>
<h3 id="three-ways-to-trigger-it">Three ways to trigger it</h3>
<p>Manual (<code>workflow_dispatch</code>), automatic on every PR push, or label-triggered on demand — all three have complete, ready-to-copy example workflows in the <a href="https://github.com/pattonwebz/wordpress-playground-action#trigger-modes">README</a>.</p>
<h3 id="requirements">Requirements</h3>
<p>Your repository and artifact must be public — nightly.link can&rsquo;t proxy private-repo artifacts.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pattonwebz/wordpress-playground-action/commits/v0.1.0">https://github.com/pattonwebz/wordpress-playground-action/commits/v0.1.0</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Workspace Bootstrap</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/postman-onboarding-workspace-bootstrap/</link><pubDate>Sat, 25 Jul 2026 00:22:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/postman-onboarding-workspace-bootstrap/</guid><description>Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.10.20.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman Onboarding: Workspace Bootstrap action automates the creation of a Postman workspace from an OpenAPI specification. It generates baseline, smoke, and contract collections with executable tests, covering various protocols including gRPC, SOAP, GraphQL, AsyncAPI, and MCP lanes. The action handles spec imports securely through access tokens and supports both public HTTPS URLs and local file paths for the OpenAPI document.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-bootstrap-action">https://github.com/postman-cs/postman-bootstrap-action</a></strong> to version <strong>v2.10.20</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-workspace-bootstrap">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman Onboarding: Workspace Bootstrap action automates the creation of a Postman workspace from an OpenAPI specification. It generates baseline, smoke, and contract collections with executable tests, covering various protocols including gRPC, SOAP, GraphQL, AsyncAPI, and MCP lanes. The action handles spec imports securely through access tokens and supports both public HTTPS URLs and local file paths for the OpenAPI document.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Omit converter-only options from Spec Hub links by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/143">https://github.com/postman-cs/postman-bootstrap-action/pull/143</a></li>
<li>Release v2.10.20 by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/144">https://github.com/postman-cs/postman-bootstrap-action/pull/144</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.10.20">https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.10.20</a></p>
]]></content:encoded></item><item><title>ReleasePilot Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/releasepilot-guard/</link><pubDate>Sat, 25 Jul 2026 00:21:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/releasepilot-guard/</guid><description>Version updated for https://github.com/releasepilot/releasepilot-guard to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ReleasePilot Guard is a GitHub Action designed to assess the release impact of pull requests in Expo projects. It evaluates changes and provides a safety classification (OTA_safe, native_build_required, etc.) based on Git history and project configurations. This helps ensure that only safe updates are merged, reducing potential risks associated with dynamic or unverified code changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/releasepilot/releasepilot-guard">https://github.com/releasepilot/releasepilot-guard</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/releasepilot-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>ReleasePilot Guard</strong> is a GitHub Action designed to assess the release impact of pull requests in Expo projects. It evaluates changes and provides a safety classification (OTA_safe, native_build_required, etc.) based on Git history and project configurations. This helps ensure that only safe updates are merged, reducing potential risks associated with dynamic or unverified code changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="first-public-release">First public release</h2>
<p>ReleasePilot Guard is a conservative release-impact checker for Expo applications.</p>
<p>It analyzes a pull-request Git range and classifies the safest release route as:</p>
<ul>
<li>OTA safe</li>
<li>Native build required</li>
<li>Backend or configuration dependency</li>
<li>Store metadata only</li>
<li>No app release required</li>
<li>Manual review</li>
</ul>
<h3 id="included">Included</h3>
<ul>
<li>Reusable composite GitHub Action</li>
<li>Real Git-range analysis</li>
<li>Nested Expo monorepo support</li>
<li>Dependency and lockfile detection</li>
<li>Static Expo and EAS configuration comparison</li>
<li>Machine-readable evidence report</li>
<li>Conservative handling of unknown changes</li>
</ul>
<h3 id="validation">Validation</h3>
<p>Tested against 25 pinned commit ranges from five public Expo repositories:</p>
<ul>
<li>22/25 automatically classified</li>
<li>6/6 reviewed OTA-safe classifications correct</li>
<li>Zero unsafe changes labeled OTA-safe</li>
</ul>
<p>ReleasePilot is advisory by default and does not deploy applications or execute untrusted pull-request code.</p>
]]></content:encoded></item><item><title>Remyx Outrider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/remyx-outrider/</link><pubDate>Sat, 25 Jul 2026 00:20:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/remyx-outrider/</guid><description>Version updated for https://github.com/remyxai/outrider to version v1.7.40.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Outrider is a GitHub Action that automates the process of evaluating new methods against an existing codebase. It helps teams validate and compare new implementations by scheduling or dispatching evaluations on demand, using Anthropic Opus or z.ai GLM-5.2 as model backends for cost-effective evaluation. The action provides draft PRs with self-reviews, issues when preflight, validators, or self-review routes the paper to discussion, a branch-only mode, and ensures no duplicate work by not re-recommending papers once referenced.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remyxai/outrider">https://github.com/remyxai/outrider</a></strong> to version <strong>v1.7.40</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/remyx-outrider">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Outrider is a GitHub Action that automates the process of evaluating new methods against an existing codebase. It helps teams validate and compare new implementations by scheduling or dispatching evaluations on demand, using Anthropic Opus or z.ai GLM-5.2 as model backends for cost-effective evaluation. The action provides draft PRs with self-reviews, issues when preflight, validators, or self-review routes the paper to discussion, a branch-only mode, and ensures no duplicate work by not re-recommending papers once referenced.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Adds first-class support for <code>REVIEW.md</code> — a per-repo review-conventions file that Outrider threads into the drafter, fidelity audit, and convention pass on dispatch.</p>
<h2 id="changes">Changes</h2>
<ul>
<li>New <code>REVIEW.md</code> at repo root documenting this repo&rsquo;s own review conventions (#107)</li>
<li>Reader + orientation-block threading: <code>_orient_review_conventions()</code> reads <code>REVIEW.md</code> (root wins over <code>.github/</code>) and inserts it as the highest-precedence signal in the orientation block, ahead of contributor guides (#108)</li>
<li>Fidelity audit + convention patch prompts cross-check against <code>REVIEW.md</code>&rsquo;s scope-stance and anti-pattern sections when present (#108)</li>
<li><code>docs/REVIEW-template.md</code> — starter template maintainers can copy into their repos (#108)</li>
<li>8 tests covering discovery, precedence, empty-file, truncation, orientation-block inclusion/omission (#108)</li>
</ul>
<p>Silent info-level fallback when <code>REVIEW.md</code> is absent; no failure. Existing repos without a <code>REVIEW.md</code> see unchanged behavior.</p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/bernstein-multi-agent-orchestration/</link><pubDate>Sat, 25 Jul 2026 00:19:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.9.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bernstein is a deterministic orchestrator that automates CLI coding tasks using various adapters. It provides reproducible runs by scheduling them in plain Python and ensures checkable results through an always-on lineage spine and replay journal. The action supports multiple agents, including Claude Code, Codex, Gemini CLI, and 40+ more, with options for local and air-gap installations and auditing receipts offline.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Bernstein is a deterministic orchestrator that automates CLI coding tasks using various adapters. It provides reproducible runs by scheduling them in plain Python and ensures checkable results through an always-on lineage spine and replay journal. The action supports multiple agents, including Claude Code, Codex, Gemini CLI, and 40+ more, with options for local and air-gap installations and auditing receipts offline.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>A feature release. This wave widens the verifiability surface: the run journal, lineage spine, and HMAC audit chain gain new first-class receipts across identity and delegation, outbound payments, non-coding artifacts, evaluation, and cross-agent interop, and a hardening pass runs through the event, admission, MCP-audit, cost, and process-reap surfaces. No existing public API changes; upgrade in place, but read the behaviour-change note below first. The exhaustive index is <code>docs/reference/FEATURE_MATRIX.md</code>.</p>
<h2 id="behaviour-changes-read-before-upgrading">Behaviour changes (read before upgrading)</h2>
<ul>
<li>
<p><strong>A halted mission phase no longer halts the whole mission, and is no longer
reported as the active phase (#2683).</strong> Phases already run under isolated
budget envelopes at dispatch, so exhausting one phase&rsquo;s envelope never gated a
sibling&rsquo;s spend. The status <em>projection</em> had not caught up: it reported a
halted phase as the active phase and folded any halt into an overall
<code>halted</code> mission, so one exhausted envelope masked a runnable sibling. The
projection now skips halted (and passed) phases when selecting the active
phase, and reports the mission <code>halted</code> only when no phase remains runnable.
A halted phase beside a runnable one now leaves the mission active with the
runnable phase reported active.</p>
<p>The active phase and the overall mission state are both hashed into
<code>mission_status_hash</code>, so this correction deliberately moves that hash for any
ledger carrying a halt, and for every ledger it moves the schema-version
field alone. <code>MISSION_STATUS_SCHEMA_VERSION</code> is therefore bumped from 1 to 2.
That field is how a verifier tells &ldquo;folded under newer projection rules&rdquo; apart
from &ldquo;tampered with&rdquo;: an archived ledger stays reproducible because
<code>project_mission</code> (and <code>project_mission_from_ledger</code>) accept an explicit
<code>schema_version</code>, and projecting an archived ledger under <code>schema_version=1</code>
reproduces its original status hash byte for byte. The pinned v1 goldens
assert exactly that reproduction.</p>
<p>Halt semantics are unchanged and stay chain-anchored: a halted phase still
seals its halt receipt onto the work ledger and mirrors it onto the HMAC audit
chain. Isolation means a sibling phase continues, not that a halt is weakened.
The mission daily-progress digest embeds <code>mission_status_hash</code>, so its
<code>digest_hash</code> and <code>receipt_id</code> move with the projection even though the digest
document schema itself is unchanged.</p>
</li>
</ul>
<h2 id="identity-and-delegation">Identity and delegation</h2>
<ul>
<li>Attenuated delegation capability tokens: each hop is a detached-JWS token over a JCS-canonical body whose caveats can only narrow (permissions, task-id allowlist, path prefixes, expiry, uses, depth), verifiable offline from the token bytes with the registry unavailable, and minted as a chain-anchored event (#2901).</li>
<li>The install-identity signature on outbound agent-facing requests now binds the request body (an RFC 9530 Content-Digest folded into the RFC 9421 covered set), and the per-hop delegation ledger serialises its read-modify-write under a cross-process lock so concurrent writers can no longer fork the chain (#2935).</li>
<li>A2A server surface: a signed capability card served at both well-known paths, <code>message/send</code> + <code>tasks/get</code> over JSON-RPC with SSE, auth declared in the card, and every inbound task returning a chain-anchored lineage receipt an external caller can verify offline; clients without streaming or artifacts still work through polling (#2911).</li>
<li>AGNTCY ADS publication: <code>bernstein a2a publish --surface agntcy-ads</code> emits an OASF capability descriptor that is a deterministic projection of the signed card, carrying a provenance attestation signed by a trust root distinct from the card key; republishing an unchanged node is byte-identical (#2943).</li>
</ul>
<h2 id="payments-and-cost-governance">Payments and cost governance</h2>
<ul>
<li>Signed payment mandates with chain-anchored receipts: a <code>SpendMandate</code> is an Ed25519-signed, content-addressed authorization bounding amount, currency, recipient, and expiry in a <code>human_present</code> or <code>delegated</code> presence mode; every attempt is a <code>TransactionReceipt</code> (a refusal is a first-class receipt with a closed reason), amounts are string-encoded integer nano-units with no float in a signed payload, and cumulative spend is aggregated under a lock so concurrent workers sharing a mandate cannot exceed the cap (#2902). The mandate and consent-receipt surfaces were then hardened (#2936).</li>
<li>x402 settlement hook: metered MCP gateway calls settle through the mandate framework, binding the signed intent, the authorized calls, and the settlement reference into one chain-anchored consent receipt (#2937).</li>
</ul>
<h2 id="non-coding-artifacts-and-evaluation">Non-coding artifacts and evaluation</h2>
<ul>
<li>Typed artifact contract (slice 1): an <code>ArtifactKind</code> / <code>ArtifactSpec</code> threaded onto <code>Task</code> (defaulting to <code>code_diff</code>), widened lineage artefact kinds, per-kind canonical serialisers over one shared core, three new completion signals (<code>schema_valid</code> / <code>criteria_match</code> / <code>hash_stable</code>), and <code>bernstein artifact verify</code> — so a report, dataset, or action log is a signed, content-addressed lineage record rather than a blob (#2903).</li>
<li>Figure grounding for report artifacts: every material number in a report must trace to an anchored source (attachment, artifact, or query receipt) or the task does not complete; the figures sidecar is inside the artifact&rsquo;s own content hash, and <code>bernstein artifact verify</code> renders per-figure provenance (#2912).</li>
<li>Content-addressed query receipts: a read-only SQL result set an agent consumed is canonicalised and its hash bound into a signed lineage entry; <code>bernstein datasource verify</code> proves it offline and <code>--re-execute</code> reports MATCH or DRIFT, and DML/DDL is refused (#2909).</li>
<li>Deterministic replay-debugging surface: <code>bernstein replay debug</code> walks the Merkle step chain to name the exact diverging step and field, emits a byte-identical two-run path-diff, forks from a step, and produces an offline-verifiable debug receipt (#2900).</li>
</ul>
<h2 id="cluster-and-lifecycle">Cluster and lifecycle</h2>
<ul>
<li>Leaderless MESH claim journal (phases 1-2): a signed, append-only, hash-chained claim journal with a pure <code>project_claims</code> fold that two nodes reduce to byte-identical state, and a deterministic lowest-entry-hash supersede rule; the SQLite ledger becomes a projection of the journal on the opt-in path while STAR behaviour is unchanged (#2907).</li>
<li>Mission phase isolation is described in the behaviour-change note above (#2683).</li>
</ul>
<h2 id="integrations">Integrations</h2>
<ul>
<li>Generic OData v4 system-of-record integration: a watermark/delta trigger source with a deterministic, chain-anchored poll cursor, and receipt-anchored write-backs (GET-before-PATCH with <code>If-Match</code>, typed 412/428 conflicts, draft-activate) where every write-back is a signed audit event verifiable by <code>bernstein audit verify</code> (#2908).</li>
<li>Self-hosted OpenAI-compatible endpoint certification: <code>bernstein endpoints certify --base-url</code> produces the existing signed certification record for an arbitrary endpoint, with a docs page covering the certify → verify loop and the exercised endpoint families (#2913).</li>
</ul>
<h2 id="hardening-and-security">Hardening and security</h2>
<ul>
<li>Bounded hardening passes through the event feed, triggers, webhooks, and receipts (#2890); the pool/lease admission engine, ledger, tags, and verifier (#2891); MCP stateless/gateway/client audit ordering (#2892); provider-state mutation capture (#2893); cost-scheduling receipts and the price table (#2894); and process reap, platform compat, and worktree isolation (#2895).</li>
<li><code>bernstein audit verify</code> is now total over an undecodable chain segment: a non-UTF-8 segment is reported as a named verification failure at the exact byte offset instead of raising out of <code>verify()</code> (#2880).</li>
<li><code>bernstein lineage verify</code> fails closed with a distinct exit code when the audit key is missing, instead of misreporting a setup problem as tamper (#2882).</li>
<li>The SLA-receipt log sink escapes caller-supplied paths so a CR/LF path can no longer forge log lines (#2881); adapter capability-profile selection is recorded at spawn so replay detects drift (#2883).</li>
<li>The CI weekly-digest and skills-publish workflows were hardened, along with skills packaging (#2945, #2946).</li>
</ul>
<h2 id="observability">Observability</h2>
<ul>
<li>The OpenTelemetry GenAI-semconv gaps in the signed OTLP span projection were closed (#2896).</li>
</ul>
<h2 id="cli-and-documentation">CLI and documentation</h2>
<ul>
<li>Operator-surface follow-ups from the 3.8.2 sweep: an honest dashboard capacity denominator, <code>stop --force</code> process-group reaping, a live-scan <code>ps</code> cross-check, and a <code>bernstein cluster status</code> node view (#2897).</li>
<li>The README now front-loads the four differentiators as a scannable at-a-glance ahead of the full capability list (#2938); the feature matrix was refreshed for currency across the verifiability, identity, payments, and provenance surfaces shipped since the last pass (#2941); the agent-doc mirrors gained currency guards so the generated views cannot silently drift (#2906).</li>
<li>A decision record measures the cost of enabling the HMAC audit chain by default and defines the migration path, without flipping the default (#2905).</li>
</ul>
<h2 id="thanks">Thanks</h2>
<p>Thanks to @Maqbool61 for documenting and helping certify the self-hosted OpenAI-compatible endpoint path (#2913).</p>
<hr>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install --upgrade bernstein<span style="color:#f92672">==</span>3.9.0
</span></span></code></pre></div>]]></content:encoded></item><item><title>GitGalaxy Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/gitgalaxy-scanner/</link><pubDate>Sat, 25 Jul 2026 00:18:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/gitgalaxy-scanner/</guid><description>Version updated for https://github.com/squid-protocol/gitgalaxy to version v2.4.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GitGalaxy automates security and architecture assessments for repositories, offering a deterministic audit tool that can scan multiple languages and detect risk exposures in full repos, providing actionable fixes to lower those risks. It uses a custom regex/lexical structural-analysis engine to identify code patterns relevant to security and architecture, generating normalized 0–100 risk scores and exporting the results in various formats for further analysis.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/squid-protocol/gitgalaxy">https://github.com/squid-protocol/gitgalaxy</a></strong> to version <strong>v2.4.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gitgalaxy-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>GitGalaxy automates security and architecture assessments for repositories, offering a deterministic audit tool that can scan multiple languages and detect risk exposures in full repos, providing actionable fixes to lower those risks. It uses a custom regex/lexical structural-analysis engine to identify code patterns relevant to security and architecture, generating normalized 0–100 risk scores and exporting the results in various formats for further analysis.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="gitgalaxy-v245-the-correctness-release">GitGalaxy v2.4.5: The Correctness Release</h1>
<p>This is a dense one. Where v2.4.0 was about getting GitGalaxy&rsquo;s findings <em>in front of</em> more people (SARIF everywhere, every CI platform), v2.4.5 is about making sure the findings underneath are actually true. It closes two long-running epics, fixes a critical bug that had silently disabled a core engine for every one of GitGalaxy&rsquo;s 58 supported languages, patches a disclosed CVE, and knocks out ~20 smaller data-integrity fixes along the way.</p>
<h2 id="critical-fix-the-commentcode-separation-engine-was-broken-for-every-language-386-390">Critical Fix: The Comment/Code Separation Engine Was Broken for Every Language (#386, #390)</h2>
<p><strong>What we found:</strong> My previous workflow resulted in Gemini based bug patterns of consumer producer mismatches of keys between files. Explicitly revealed with <code>prism.py</code>, the module responsible for stripping comments from source before analysis, was looking up its per-language delimiter rules under config keys (<code>mechanical_families</code>, <code>recursive_c_style</code>, <code>column_sensitive</code>, <code>single_line_only</code>, <code>c_style_comment</code>) that no producer in the codebase had ever written. The real config used a different taxonomy entirely. Every lookup silently fell through to defaults, meaning comment stripping had been non-functional — or working by pure coincidence — across all 58 supported languages since the feature was introduced.</p>
<p><strong>Why nothing caught it:</strong> <code>test_prism.py</code>&rsquo;s test fixtures were hand-built mocks that mirrored the <em>wrong</em> key names, so they were internally consistent with the bug and passed cleanly for hundreds of runs. Real production config and test config had quietly diverged.</p>
<p><strong>What we did:</strong> Renamed the lookups to match the real taxonomy (<code>lexical_families</code>, <code>recursive_block</code>, <code>positional_anchored</code>, <code>line_exclusive</code>, <code>standard_block</code>), replaced the mocks with tests that exercise the actual <code>LANGUAGE_DEFINITIONS</code>/<code>LEXICAL_FAMILY_HEURISTICS</code> config, and — in a follow-up (#390) found while double-checking the first fix — caught and fixed one more missed reference in <code>_strip_nested_comments()</code> that had been masked by a fallback value that coincidentally matched the correct data. The new regression test uses non-default delimiters specifically so that kind of coincidence can&rsquo;t hide a bug again.</p>
<p><strong>Known limitations, documented and deferred on purpose:</strong> a 9-delimiter gap in <code>standard_block</code> affects 5 non-C-style languages, and <code>golden_master.json</code> was not regenerated as part of this fix. Both are scoped as explicit follow-ups rather than folded in here.</p>
<h2 id="new-the-dead-key-auditor-and-the-closure-of-epic-325">New: The Dead Key Auditor, and the Closure of Epic #325</h2>
<p>Epic #325 tracked a recurring failure pattern across the codebase: a consumer reads <code>data[&quot;some_key&quot;]</code>, but no producer anywhere ever writes <code>&quot;some_key&quot;</code> — a silent, type-checker-invisible class of bug.</p>
<ul>
<li><strong>Built <code>tests/dead_key_audit.py</code>:</strong> an AST-based static analyzer that walks the codebase, cross-references every dict-key read against every dict-key write (including f-string prefix patterns like <code>f&quot;sec_{key}&quot;</code>), and reports the gaps.</li>
<li><strong>Wired it into CI</strong> (<code>dead-key-audit.yml</code>) as a baseline-gated required check — new dead keys fail the build, but the tool doesn&rsquo;t demand the whole codebase be clean on day one.</li>
<li><strong>Ran it, and fixed all 15 findings it surfaced</strong>, filed and closed individually (#364–#378):
<ul>
<li>Every recorder read <code>&quot;AI Threat Score&quot;</code>; the producer wrote <code>&quot;AI Threat Confidence&quot;</code> (#364)</li>
<li><code>AIAppSecSensor</code>&rsquo;s Over-Permissioned Agent rule was reading a dead <code>ai_tools</code> signal instead of <code>llm_orchestrator</code> (#365)</li>
<li>Four dead security-flag SQLite columns in <code>record_keeper.py</code> (#366–#369)</li>
<li><code>repo_z_score</code> and <code>typosquat_hits</code> were computed but never backfilled into the summary, in both the main and Delta Mode pipelines (#370, #371, #376)</li>
<li><code>max_big_o</code> was written onto the graph node but never copied back onto the file dict (#372)</li>
<li><code>has_tests</code> was a dead read; wired to real <code>test_coverage_map</code> (#373)</li>
<li><code>aperture_reason</code> vs. <code>reason</code> key mismatch across <code>signal_processor.py</code>/<code>audit_recorder.py</code> (#374)</li>
<li>Missing <code>TYPOSQUAT_WHITELIST</code> in <code>APERTURE_CONFIG</code> (#375)</li>
<li>Missing cross-referenced <code>disqualifiers</code> for <code>matlab</code> and <code>objective-c</code> language definitions (#377)</li>
<li>The <code>mechanical_families</code> investigation above, which escalated into #386 (#378)</li>
</ul>
</li>
</ul>
<p>The baseline file is now empty — every finding the tool surfaced this cycle has been resolved.</p>
<h2 id="epic-102--348-spatial-correlation-phase-23">Epic #102 / #348: Spatial Correlation, Phase 2–3</h2>
<p>Continued work on satellite-aware, post-hoc spatial correlation of security signals:</p>
<ul>
<li><strong>Persisted a satellite-aware spatial ledger</strong> for post-hoc correlation across scans (#348)</li>
<li><strong>Scoped dampener correlation to real function boundaries</strong> instead of naive proximity (#346, phase 1)</li>
<li><strong>Implemented the Spatial Radar for DB injection funnels</strong> (#105)</li>
<li><strong>Spatially verified Metaprogramming Hallucination Risk</strong> in the Dev Agent Firewall (#106)</li>
<li><strong>Scoped the Exfiltration Distance Check</strong> to real function boundaries (#102)</li>
<li>Fixed <code>detector.py</code>&rsquo;s dead RCE-taint corroboration and a <code>sec_</code> merge overwrite bug that had been silently dropping signals (#344)</li>
</ul>
<h2 id="config-resolver-phase-01">Config Resolver: Phase 0–1</h2>
<p>Started consolidating GitGalaxy&rsquo;s config precedence rules (CLI flags, YAML, env, defaults) into a single, testable merge point:</p>
<ul>
<li>Added <code>config_resolver.py</code> with a single <code>ResolvedConfig</code> merge point (Phase 1)</li>
<li>Migrated <code>galaxyscope.py</code>&rsquo;s <code>main()</code> and 7 direct <code>gitgalaxy_config.py</code> importers off scattered module-level constants</li>
</ul>
<h2 id="security">Security</h2>
<ul>
<li><strong>Patched a disclosed CVE</strong> (GHSA-9xwg-3r6f-jcx2 / CVE-2026-61632, path traversal in <code>pymdown-extensions</code>&rsquo;s <code>b64</code> extension) by bumping to <code>11.0.1</code></li>
<li>Fixed churn risk silently scoring zero for docs and critical-secret-leak files (#245)</li>
<li>Fixed a CLI/YAML sentinel-collision bug in the pipeline-flag interceptor that could cause flags to be silently ignored (#247)</li>
<li>Made Aperture&rsquo;s file-size gate tiered and intent-aware instead of a single blunt cutoff (#343)</li>
</ul>
<h2 id="precision--data-integrity-fixes">Precision &amp; Data-Integrity Fixes</h2>
<p>A long tail of quieter correctness fixes, several with real blast radius:</p>
<ul>
<li><code>IGNORED_DIRECTORIES</code> case-mismatch was silently disabling 9 ignore rules (#306); GuideStar wasn&rsquo;t even pointed at the shared set (#319)</li>
<li>Case-insensitive matching for shadow-API file extensions (#320) and SBOM malware-scan candidates (#321)</li>
<li>Confidence/exposure scores that could exceed their intended 0–100 or 0–1 scale now clamp correctly (#310, #318, #331)</li>
<li>Removed several dead reads that had been silently no-op&rsquo;d for a while: <code>func_empty</code>/<code>keyword_debt</code> in tech-debt scoring (#308), <code>ai_tools</code>/<code>ai_memory</code>/<code>ai_logic_loop</code> from <code>SIGNAL_SCHEMA</code> (#323)</li>
<li>Fixed <code>zero_dependency_mode</code> under-reporting during incremental scans (#307)</li>
<li><code>AIAppSecSensor</code> was reading its 8 inputs from a phantom telemetry namespace that nothing wrote to (#326)</li>
<li><code>duplicate_logic</code> count wasn&rsquo;t being aggregated into equations the way <code>orphaned_logic</code> was (#327)</li>
<li>Wired opt-in network-centrality risk weighting into the firewall (#304), and the supply chain firewall into <code>SignalProcessor</code>&rsquo;s risk vector (#302)</li>
<li>Fixed a file-miscounting bug for files sharing the same name (#261/#273)</li>
<li>Fixed docstring harvesting running past a stand-alone closing delimiter (#279)</li>
</ul>
<h2 id="type-safety">Type Safety</h2>
<p>Closed out a focused mypy-hardening pass: fixed indexing and type-spoofing errors across <code>state_rehydrator.py</code>, <code>cobol_jcl_auditor.py</code>, <code>llm_recorder.py</code>, <code>galaxyscope.py</code>, and <code>FunctionNode</code>&rsquo;s <code>TypedDict</code> schema (#293–#301), plus a mass annotation cleanup.</p>
<h2 id="supply-chain--sbom">Supply Chain / SBOM</h2>
<ul>
<li>Unified manifest-filename registries, fixing mixed-ecosystem SBOM starvation (#285)</li>
<li>Added a dependency audit cache and entry-point priority audit ordering (#283, #284)</li>
<li>Consolidated manifest parsing into <code>manifest_parser.py</code></li>
</ul>
<h2 id="docs--ci">Docs &amp; CI</h2>
<ul>
<li>Corrected docs/CI-template accuracy repo-wide (&ldquo;Honest READMEs&rdquo;) and added a GitHub Actions reporting stage (#264)</li>
<li>Fixed the LLM architectural brief bot&rsquo;s identity and its workflow (it now opens a PR via a forked <code>create-pull-request</code> action instead of pushing directly to protected <code>main</code>)</li>
<li>Pinned <code>galaxyscope --output</code> to a file, not a folder, to match downstream SARIF/SBOM/LLM paths (#265)</li>
<li>Bumped Muninn (our CI security scanner) to v0.3.5 and then v0.3.6</li>
</ul>
<hr>
<p><strong>Full changelog:</strong> <a href="https://github.com/squid-protocol/gitgalaxy/compare/v2.4.0...v2.4.5"><code>v2.4.0...v2.4.5</code></a></p>
]]></content:encoded></item><item><title>Run Ternary Bonsai 27B Locally</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/run-ternary-bonsai-27b-locally/</link><pubDate>Sat, 25 Jul 2026 00:17:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/run-ternary-bonsai-27b-locally/</guid><description>Version updated for https://github.com/theabbie/ternary-bonsai-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action downloads and runs Ternary Bonsai 27B locally on a GitHub Actions runner, allowing inference without sending prompts or responses to Hugging Face. It caches the model and runtime for subsequent runs, supports local CPU inference, and provides options for prompting through text or file inputs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/theabbie/ternary-bonsai-action">https://github.com/theabbie/ternary-bonsai-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-ternary-bonsai-27b-locally">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action downloads and runs Ternary Bonsai 27B locally on a GitHub Actions runner, allowing inference without sending prompts or responses to Hugging Face. It caches the model and runtime for subsequent runs, supports local CPU inference, and provides options for prompting through text or file inputs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial local inference release</p>
<ul>
<li>Download and verify the pinned 7.17 GB Ternary Bonsai 27B Q2_0 GGUF on the runner.</li>
<li>Cache the model and pinned PrismML llama.cpp runtime.</li>
<li>Run inference through a loopback-only local llama-server.</li>
<li>Return the final answer, reasoning, timings, model path, and response file.</li>
</ul>
]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/rustscript-action/</link><pubDate>Sat, 25 Jul 2026 00:15:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.2.12.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RustScript is a Rust runtime that interprets and executes Rust scripts without compiling them to machine code. It provides a way to run small Rust programs directly from the command line or as part of CI/CD pipelines. This allows developers to quickly test snippets or automate tasks without waiting for a full compile.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.2.12</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>RustScript is a Rust runtime that interprets and executes Rust scripts without compiling them to machine code. It provides a way to run small Rust programs directly from the command line or as part of CI/CD pipelines. This allows developers to quickly test snippets or automate tasks without waiting for a full compile.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.2...v0.2.12">https://github.com/VladasZ/rustscript/compare/v0.2...v0.2.12</a></p>
]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/cowork-harness/</link><pubDate>Sat, 25 Jul 2026 00:14:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/25/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.9.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action automates the testing of Claude Cowork skills in a headless, scriptable, and CI-friendly environment. It reproduces the observable runtime contract closely enough to test skills across various scenarios without relying on the locked Desktop app. The main purpose is to reduce the cost and complexity of skill development by allowing for automated testing with limited or no access to the Desktop app itself.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v1.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action automates the testing of Claude Cowork skills in a headless, scriptable, and CI-friendly environment. It reproduces the observable runtime contract closely enough to test skills across various scenarios without relying on the locked Desktop app. The main purpose is to reduce the cost and complexity of skill development by allowing for automated testing with limited or no access to the Desktop app itself.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong><code>schema/critique-report.json</code></strong> — a descriptive, test-pinned schema for <code>critique</code>&rsquo;s JSON report /
<code>critique-report.json</code> artifact, so automation consumers (budget pacers gating on <code>costUsd.complete</code>,
harvesters) parse field names/shapes from a schema instead of prose. Deliberately <strong>not</strong> a SPEC
§12-frozen surface (unlike <code>doctor.json</code>) — critique is EXPERIMENTAL and additive field changes are
expected; the schema says so in its own description, and a two-way sync test pins it against the
actual report builder on every branch (findings / infraFailure / evaluatorError).</li>
<li><strong><code>gradedSkill</code> in the critique report</strong> (text header + JSON): the resolved <code>skills/&lt;name&gt;</code> the
packager graded under <code>--skill</code>/auto-selection. Load-bearing for multi-skill plugins:
<code>gradedSkillHash</code> keys the whole mounted plugin, so pairing by hash alone cross-pairs critiques of
<em>different</em> skills — pair by <code>(gradedSkillHash, gradedSkill)</code>. Docs updated accordingly.</li>
</ul>
<h3 id="docs">Docs</h3>
<ul>
<li>Truncation→DROPPED mechanics: a finding whose <code>evidence</code> quotes SKILL.md text past the packaging cap
fails citation-resolution and lands in DROPPED (the check runs against the <em>cut</em> copy) — documented
next to <code>skillMdTruncated</code> so a back-half DROPPED skew on an oversized skill has its cause named.</li>
<li><code>findingFingerprint</code> direction-of-inference: high-precision, LOW-RECALL — a match proves
reproduction; a mismatch does NOT prove non-reproduction (the same finding reworded fingerprints
differently). The Reproduction section says so before anyone concludes &ldquo;didn&rsquo;t reproduce&rdquo;.</li>
<li>Evaluator cost share: the two evaluator passes were ~3/4 of a measured e2e total — the
calibrate-then-<code>--evaluator-model</code> strategy is now in the cost section and <code>critique --help</code>, with
the armor-verification-is-default-evaluator-only caveat.</li>
<li>SPEC §12 now names the critique report explicitly under <strong>NOT covered</strong>: <code>schema/critique-report.json</code>
is descriptive (parse against it, not prose) but not the compatibility contract while critique is
EXPERIMENTAL — its surface-baseline presence is for change visibility, and it is the promotion
candidate on the <code>doctor.json</code> template once critique stabilizes. README, llms.txt, and the shipped
skill point at the schema and the <code>(gradedSkillHash, gradedSkill)</code> pairing rule.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>critique&rsquo;s &ldquo;Attached inputs&rdquo; evidence no longer reports <code>(none)</code> when <code>mounts.json</code> is corrupt.</strong>
<code>listAttachedInputs</code> derived connected-folder names from <code>loadVmPathContext</code>, which returns <code>null</code> for
BOTH an absent <code>mounts.json</code> (legitimately no mounts) and a present-but-unparseable one (the folder map
is UNKNOWN). Uploads already distinguished these (the ENOENT-vs-read-fault split), but folders — which
have no fixed-layout fallback — silently collapsed to <code>[]</code>, so a corrupt <code>mounts.json</code> rendered <code>(none)</code>,
telling the evaluator &ldquo;the agent correctly saw no connected folder&rdquo; when the truth was unknown. It now
surfaces a corrupt <code>mounts.json</code> as an explicit UNKNOWN note, completing the same
confabulation-vs-correct guard the uploads path already applies.</li>
<li><strong><code>diff</code> no longer treats two tool inputs that differ only past the ~2000-char cap as the same call.</strong>
<code>canonicalizeInput</code> truncated a tool input&rsquo;s canonical JSON to a 2000-char cap and used that truncated
string as the tool-sequence equality key, so two <code>Write</code>/<code>Bash</code> calls sharing a long identical prefix
but differing only in the dropped tail compared as <code>op: &quot;same&quot;</code> in <code>diffToolSequence</code> — a false &ldquo;no
change&rdquo; that could flip the advisory <code>diff</code> exit code to 0. A truncated key now folds in a
<code>#&lt;len&gt;·&lt;sha16&gt;</code> hash of the full canonical string, so the key depends on the entire content while the
visible prefix stays readable in the hunk; both diff sides canonicalize identically, so the comparison
stays consistent.</li>
<li><strong><code>COWORK_VM_GATEWAY</code> is now validated as a canonical IPv4 literal.</strong> The L2-microVM gateway override was
interpolated verbatim into a root-run guest <code>iptables -A OUTPUT -d &lt;gateway&gt;</code> command (via <code>sh -c</code>), so a
malformed or hostile value could inject shell syntax into privileged provisioning — or, more mundanely,
leave the firewall in an unknown state. <code>vmGatewayIp()</code> now rejects anything that isn&rsquo;t a canonical IPv4
literal (digits-and-dots only, octets 0–255, no leading zeros), failing loud instead of reaching the
shell. Operator-set env var, so this is defense-in-depth; no valid gateway value is affected.</li>
<li><strong>The <code>agent.stderr.log</code> sink is now flushed before the teardown secret-scrub reads it.</strong> The stderr sink
was piped fire-and-forget and never awaited, so bytes still buffered when <code>scrubRawRunLogs</code> read the file
could land raw <em>afterwards</em> — a persisted-secret leak in a narrow teardown window. <code>LiveAgentSession</code> now
pipes it with <code>{ end: false }</code> and ends+awaits it in the same session-teardown drain that already flushes
<code>events.jsonl</code> / <code>control-out.jsonl</code>, so the session generator resolves only after the sink is fully
flushed — the scrub always sees the complete log.</li>
<li><strong><code>critique</code> no longer prints raw host paths in its report or diagnostics.</strong> The text report&rsquo;s <code>run dir:</code>
line, the <code>inspect &lt;dir&gt;</code> hints, the write-failure diagnostics, and the echoed skill-folder path all
printed absolute <code>$HOME</code>-rooted paths, so a shared report or screenshot leaked the username + filesystem
layout (it landed in a video frame). critique was the one rendering path in the CLI that never called
<code>tildeify</code>, while <code>skill</code>/<code>run</code> scrub unconditionally. Every human-facing path is now collapsed to <code>~</code>;
the JSON report and persisted-artifact paths stay raw (machine data a consumer feeds back to a tool). The
<code>--demo</code> rejection is unchanged — it was never the fix — but its reason now notes the report already
collapses paths.</li>
<li><strong><code>critique</code> fails fast on a missing or non-directory skill folder.</strong> A typo&rsquo;d/absent positional folder
previously minted a session and spawned the task turn before infra-failing (exit 2), leaving a stray run
dir behind. <code>resolveCritiquedSkillDir</code> now <code>existsSync</code>/<code>isDirectory</code>-checks the folder up front — before
any session is minted or spawned — so a bad path exits 2 immediately with nothing left on disk. A
present-but-<code>SKILL.md</code>-less folder still defers to the packager&rsquo;s degraded flow, unchanged.</li>
<li><strong><code>critique</code>&rsquo;s report header and stderr diagnostics now say <code>critique:</code> (were <code>skill-critique:</code>).</strong> A
leftover label from the <code>scripts/skill-critique.ts</code> instrument; the invoked command is <code>critique</code>.
Cosmetic, no schema change.</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>release: 1.9.0 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/74">https://github.com/yaniv-golan/cowork-harness/pull/74</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.9.0">https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.9.0</a></p>
]]></content:encoded></item><item><title>rs-cargo</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/rs-cargo/</link><pubDate>Fri, 24 Jul 2026 19:25:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/rs-cargo/</guid><description>Version updated for https://github.com/clechasseur/rs-cargo to version v5.0.7.
This action is used across all versions by 303 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action runs specified cargo commands on a Rust project. It automates the execution of common tasks such as building and testing, and provides transparent support for cross-compilation through optional tools like cross or cargo-hack.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/clechasseur/rs-cargo">https://github.com/clechasseur/rs-cargo</a></strong> to version <strong>v5.0.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>303</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rs-cargo">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action runs specified <code>cargo</code> commands on a Rust project. It automates the execution of common tasks such as building and testing, and provides transparent support for cross-compilation through optional tools like <code>cross</code> or <code>cargo-hack</code>.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Patch release with updates to vulnerable dependencies.</p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): bump fast-xml-parser from 5.9.3 to 5.10.1 in the npm_and_yarn group across 1 directory by @dependabot[bot] in <a href="https://github.com/clechasseur/rs-cargo/pull/427">https://github.com/clechasseur/rs-cargo/pull/427</a></li>
<li>fix: update <code>@clechasseur/rs-actions-core</code> to 8.0.3, run <code>npm update</code> to get vulnerability fixes by @clechasseur in <a href="https://github.com/clechasseur/rs-cargo/pull/429">https://github.com/clechasseur/rs-cargo/pull/429</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/clechasseur/rs-cargo/compare/v5.0.6...v5.0.7">https://github.com/clechasseur/rs-cargo/compare/v5.0.6...v5.0.7</a></p>
]]></content:encoded></item><item><title>check-version-before-release</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/check-version-before-release/</link><pubDate>Fri, 24 Jul 2026 19:24:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/check-version-before-release/</guid><description>Version updated for https://github.com/digicatapult/check-version to version v1.5.94.
This action is used across all versions by 35 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action compares versions in project manifests and checks they are higher than the latest published tag, supporting npm, Cargo, and Poetry package managers. It uses GitHub API tokens to access tags and supports filtering tags with a regular expression. If the local version matches the latest published tag, it can either fail or return a boolean indicating if it’s a new version.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/digicatapult/check-version">https://github.com/digicatapult/check-version</a></strong> to version <strong>v1.5.94</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>35</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/check-version-before-release">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action compares versions in project manifests and checks they are higher than the latest published tag, supporting npm, Cargo, and Poetry package managers. It uses GitHub API tokens to access tags and supports filtering tags with a regular expression. If the local version matches the latest published tag, it can either fail or return a boolean indicating if it&rsquo;s a new version.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changes">Changes</h2>
<p><strong><a href="https://github.com/digicatapult/check-version/pull/549">chore(deps): update npm - all minor and patch updates</a></strong></p>
]]></content:encoded></item><item><title>Pull request bot synchronizes two services GitHub, Moodle. Script 1</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/pull-request-bot-synchronizes-two-services-github-moodle.-script-1/</link><pubDate>Fri, 24 Jul 2026 19:23:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/pull-request-bot-synchronizes-two-services-github-moodle.-script-1/</guid><description>Version updated for https://github.com/Dmitriy129/moodle-github-sync-1 to version test.0.1.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The moodle-github-sync-1 GitHub Action automates the synchronization of Moodle themes and plugins with their corresponding files on GitHub. It solves the problem of maintaining and updating Moodle resources by allowing developers to push changes from local repositories directly to the remote repository, ensuring consistency across different development environments and platforms.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Dmitriy129/moodle-github-sync-1">https://github.com/Dmitriy129/moodle-github-sync-1</a></strong> to version <strong>test.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pull-request-bot-synchronizes-two-services-github-moodle-script-1">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>moodle-github-sync-1</code> GitHub Action automates the synchronization of Moodle themes and plugins with their corresponding files on GitHub. It solves the problem of maintaining and updating Moodle resources by allowing developers to push changes from local repositories directly to the remote repository, ensuring consistency across different development environments and platforms.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update action.yml (dac9fb3)</li>
<li>fix (4dfa764)</li>
<li>fix (e87bf87)</li>
<li>fix (e724dd2)</li>
<li>fix (d7578cc)</li>
<li>fix (2fd3a3b)</li>
<li>fix (ed97de6)</li>
<li>Update README.md (0aa4988)</li>
<li>fix (c97812f)</li>
<li>fix (e3035b7)</li>
</ul>
]]></content:encoded></item><item><title>sealed-build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/sealed-build/</link><pubDate>Fri, 24 Jul 2026 19:23:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/sealed-build/</guid><description>Version updated for https://github.com/EngineerSamet/sealed-build to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action builds a container image and produces an SBOM, refuses to push it if it fails a vulnerability threshold, and signs the result with keyless attestation using pinned commit hashes, ensuring security by maintaining immutable evidence. It addresses trust issues in the supply chain by preventing malicious pushes through mutable tags.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/EngineerSamet/sealed-build">https://github.com/EngineerSamet/sealed-build</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sealed-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action builds a container image and produces an SBOM, refuses to push it if it fails a vulnerability threshold, and signs the result with keyless attestation using pinned commit hashes, ensuring security by maintaining immutable evidence. It addresses trust issues in the supply chain by preventing malicious pushes through mutable tags.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Shortens the <code>action.yml</code> description below the GitHub Marketplace limit of 125 characters. No behavioural change from v0.1.0.</p>
<p>Released as a new version rather than by re-pointing the <code>v0.1.0</code> tag. Moving a published tag is exactly the mutability this Action exists to argue against — on 19 March 2026 an attacker force-pushed malware over 76 of 77 release tags of <code>aquasecurity/trivy-action</code> — and the argument does not get an exemption for being inconvenient to its own author.</p>
<p>The floating <code>v0</code> tag does move, which is the documented Marketplace convention; pin to <code>v0.1.1</code> if you want the guarantee.</p>
]]></content:encoded></item><item><title>Plumber Score</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/plumber-score/</link><pubDate>Fri, 24 Jul 2026 19:22:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/plumber-score/</guid><description>Version updated for https://github.com/getplumber/plumber to version v0.4.16.
This action is used across all versions by 44 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Plumber is an open-source CI/CD security scanner that uses a Rego policy engine to scan .gitlab-ci.yml and .github/workflows/*.{yml,yaml} files. It helps identify risky patterns and security gaps in CI/CD pipelines, providing comprehensive reports in various formats such as terminal, JSON, SARIF, GitLab SAST, PBOM, and CycloneDX.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/getplumber/plumber">https://github.com/getplumber/plumber</a></strong> to version <strong>v0.4.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>44</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/plumber-score">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Plumber is an open-source CI/CD security scanner that uses a Rego policy engine to scan <code>.gitlab-ci.yml</code> and <code>.github/workflows/*.{yml,yaml}</code> files. It helps identify risky patterns and security gaps in CI/CD pipelines, providing comprehensive reports in various formats such as terminal, JSON, SARIF, GitLab SAST, PBOM, and CycloneDX.</p>
<p>Plumber automates security scanning for GitLab CI and GitHub Actions, offering a one-command solution to ensure secure and compliant pipelines. The tool is designed to work with the latest versions of GitLab and GitHub, providing real-time feedback on potential vulnerabilities in your workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="0416-2026-07-24"><a href="https://github.com/getplumber/plumber/compare/v0.4.15...v0.4.16">0.4.16</a> (2026-07-24)</h2>
<h3 id="-features">✨ Features</h3>
<ul>
<li><strong>output:</strong> restructure control output into clear Passed/Skipped/Failed sections (<a href="https://github.com/getplumber/plumber/commit/78b576f8451f2af02381f4f1c7efbdca559682fb">78b576f</a>)</li>
</ul>
<h3 id="-cicd">👷 CI/CD</h3>
<ul>
<li><strong>release:</strong> pin v0.4.15 refs [skip ci] (<a href="https://github.com/getplumber/plumber/commit/5ad6b5472460107be9975c155930f86bbc2adbd3">5ad6b54</a>)</li>
</ul>
]]></content:encoded></item><item><title>Supply Chain Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/supply-chain-guard/</link><pubDate>Fri, 24 Jul 2026 19:20:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/supply-chain-guard/</guid><description>Version updated for https://github.com/homeofe/supply-chain-guard to version v5.17.8.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Supply-chain Guard is an open-source tool designed to scan and analyze dependency chains across various package managers and ecosystems, including npm, Pypi, Cargo, Go, RubyGems, Composer, NuGet, Docker, Terraform, VS Code extensions, GitHub Actions, and repositories. It detects malware campaigns (e.g., GlassWorm, Vidar), fake AI tool repos, account takeovers, and numerous threat indicators across multiple lockfile formats. The action generates CycloneDX SBOMs, validates SLSA provenance, and correlates findings into attack-chain incidents for enhanced security awareness and remediation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/homeofe/supply-chain-guard">https://github.com/homeofe/supply-chain-guard</a></strong> to version <strong>v5.17.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/supply-chain-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Supply-chain Guard is an open-source tool designed to scan and analyze dependency chains across various package managers and ecosystems, including npm, Pypi, Cargo, Go, RubyGems, Composer, NuGet, Docker, Terraform, VS Code extensions, GitHub Actions, and repositories. It detects malware campaigns (e.g., GlassWorm, Vidar), fake AI tool repos, account takeovers, and numerous threat indicators across multiple lockfile formats. The action generates CycloneDX SBOMs, validates SLSA provenance, and correlates findings into attack-chain incidents for enhanced security awareness and remediation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="5178---2026-07-24">[5.17.8] - 2026-07-24</h2>
<p><strong>Threat intel: jscrambler npm compromise, cPanel/WHM GitHub Actions abuse, and the Apex macOS infostealer</strong></p>
<p>Added detection for three developer-targeted supply-chain campaigns whose concrete
indicators were sourced from primary vendor write-ups (Socket, The Hacker News, OX
Security, StepSecurity, safedep, Rescana) after the daily news scan surfaced them
by name only.</p>
<ul>
<li><strong>jscrambler npm compromise</strong> (2026-07-11). The <code>jscrambler</code> package (~15,800
weekly downloads) and four companion build plugins were hijacked and republished
with a native Rust infostealer: a malicious <code>preinstall</code> hook in 8.14.0-8.17.0,
then a self-executing dropper in <code>dist/index.js</code> and <code>dist/bin/jscrambler.js</code>
from 8.18.0. The payload harvests AWS, GCP and Azure credentials, crypto wallets,
browser data and AI-tool configs on Windows, macOS and Linux. Last clean release
is 8.13.0, fixed in 8.22.0. The previous partial entry (8.14.0 only) is extended
to the full malicious set.</li>
<li><strong>cPanel/WHM GitHub Actions abuse</strong> (2026-07-23). A legitimate developer&rsquo;s ten
Packagist packages had malicious <code>dev-main</code> versions injected with dozens of
GitHub Actions workflow files that spin up runners, pull an architecture-specific
Linux payload from <code>43[.]228[.]157[.]68</code>, and scan for cPanel/WHM servers
vulnerable to CVE-2026-41940 to harvest credentials, SSH material and cloud keys.
Only the network and file indicators are ingested: the maintainer is a victim, so
neither the account nor the bare package names are flagged.</li>
<li><strong>Apex macOS infostealer</strong> (2026-07-22). A postinstall dropper installs an
AMOS-family macOS infostealer while installing a working forked coding agent as
cover. npm removed <code>@apexfdn/apex</code>; the operator re-published the same payload as
<code>@copilot-mcp/apex</code> about eleven hours later and churned twenty-plus versions in
eight hours, so the packages are blocked by name rather than version.</li>
</ul>
<h3 id="added">Added</h3>
<ul>
<li>Version-pinned <code>jscrambler</code> (8.14.0/8.16.0/8.17.0/8.18.0/8.20.0),
<code>jscrambler-webpack-plugin</code> 8.6.2, <code>gulp-jscrambler</code> 8.6.2, <code>grunt-jscrambler</code>
8.5.2 and <code>jscrambler-metro-plugin</code> 9.0.2 in <code>KNOWN_BAD_NPM_VERSIONS</code>
(src/ioc-blocklist.ts) and <code>BUNDLED_FEED</code> (src/threat-intel.ts), plus five
SHA-256 payload hashes.</li>
<li><code>43[.]228[.]157[.]68</code> in <code>KNOWN_C2_IPS</code>, the DNS-callback subdomain
<code>f5b0b742-240a-4811-8a5b-b0ba6060685d[.]dnshook[.]site</code> in <code>KNOWN_C2_DOMAINS</code>,
and the Linux exploit payload SHA-256 in <code>KNOWN_MALICIOUS_HASHES</code> for the
cPanel/WHM campaign, mirrored as <code>BUNDLED_FEED</code> entries.</li>
<li><code>^(@apexfdn\/apex|@copilot-mcp\/apex)$</code> to <code>MALICIOUS_PACKAGE_PATTERNS</code>
(src/patterns.ts) plus bare-name <code>BUNDLED_FEED</code> entries for both packages.</li>
<li>Campaign test coverage in <code>src/__tests__/campaigns.test.ts</code> for all three
campaigns, including negative tests for the clean jscrambler 8.13.0 release.</li>
</ul>
]]></content:encoded></item><item><title>Redflag Secret Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/redflag-secret-scanner/</link><pubDate>Fri, 24 Jul 2026 19:19:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/redflag-secret-scanner/</guid><description>Version updated for https://github.com/iammerus/redflag to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Redflag is a cross-platform CLI that scans source files and Git history for secrets using regular-expression rules and heuristic Shannon entropy checks. It helps automate the detection of sensitive information, such as passwords and API keys, in both codebases and version control systems. The action integrates with GitHub Actions to perform secret scanning in CI pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/iammerus/redflag">https://github.com/iammerus/redflag</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/redflag-secret-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Redflag is a cross-platform CLI that scans source files and Git history for secrets using regular-expression rules and heuristic Shannon entropy checks. It helps automate the detection of sensitive information, such as passwords and API keys, in both codebases and version control systems. The action integrates with GitHub Actions to perform secret scanning in CI pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="what-changed">What changed</h2>
<ul>
<li>Renamed the Action to <code>Redflag Secret Scanner</code> to satisfy the GitHub Marketplace unique-name requirement.</li>
<li>Published the reusable Action at <code>iammerus/redflag@v0.1.1</code>.</li>
<li>Updated the package version and README examples to <code>0.1.1</code>.</li>
<li>Kept scanner behaviour unchanged from <code>v0.1.0</code>.</li>
</ul>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fetch-depth</span>: <span style="color:#ae81ff">0</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">iammerus/redflag@v0.1.1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">git-history</span>: <span style="color:#e6db74">&#34;true&#34;</span>
</span></span></code></pre></div><p><strong>Full changelog:</strong> <a href="https://github.com/iammerus/redflag/compare/v0.1.0...v0.1.1">https://github.com/iammerus/redflag/compare/v0.1.0...v0.1.1</a></p>
]]></content:encoded></item><item><title>MCP Trust Checker — MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/mcp-trust-checker-mcp-security-scan/</link><pubDate>Fri, 24 Jul 2026 19:18:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/mcp-trust-checker-mcp-security-scan/</guid><description>Version updated for https://github.com/illiahaidar/mcptrustchecker to version 1.10.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary MCP Trust Checker is a deterministic security scanner that assesses Model Context Protocol servers to ensure they are safe before connecting them to data. It uses the Capability-Flow Trust Model, an original algorithm, to evaluate servers based on their roles and behavior, identifying threats such as untrusted input ingress, sensitive data sources, and exfiltration paths, ensuring they do not pose a risk.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/illiahaidar/mcptrustchecker">https://github.com/illiahaidar/mcptrustchecker</a></strong> to version <strong>1.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcp-trust-checker-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>MCP Trust Checker is a deterministic security scanner that assesses Model Context Protocol servers to ensure they are safe before connecting them to data. It uses the Capability-Flow Trust Model, an original algorithm, to evaluate servers based on their roles and behavior, identifying threats such as untrusted input ingress, sensitive data sources, and exfiltration paths, ensuring they do not pose a risk.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Methodology <code>mcptrustchecker-1.9</code> — <strong>unchanged</strong>. No weight, rule, gate or grade
band moved, so <strong>every grade this release produces is identical to 1.9.0</strong>.</p>
<h2 id="added--a-github-repository-is-now-a-scan-target">Added — a GitHub repository is now a scan target</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>mcptrustchecker scan upstash/context7
</span></span><span style="display:flex;"><span>mcptrustchecker scan https://github.com/modelcontextprotocol/servers
</span></span><span style="display:flex;"><span>mcptrustchecker scan owner/repo@v1.2.3
</span></span></code></pre></div><ul>
<li>Accepts <code>owner/repo</code>, <code>owner/repo@ref</code>, https/ssh github.com URLs, <code>.git</code>
suffixes and <code>/tree/&lt;ref&gt;</code> links. Every other target shape is untouched — a
scoped package, a path and a live URL still take their own branch, pinned by a
regression test.</li>
<li><strong>Nothing is cloned, written to disk or executed.</strong> The archive is fetched over
https from GitHub&rsquo;s pinned hosts and unpacked <strong>in memory</strong> by the same bounded
reader used for npm/PyPI artifacts: same size cap, same redirect re-validation,
same zip-slip-safe entry paths, same unpacked-bytes ceiling. No git binary runs,
so no hook can fire.</li>
<li>A repository is <strong>not</strong> a released artifact and the scan says so: the surface is
marked <code>repo</code>, verification is the <code>repo</code> tier (never <code>source</code> or <code>vendor</code>,
which require publish provenance), and the archive&rsquo;s own SHA-256 is recorded —
&ldquo;the default branch&rdquo; is only reproducible against the bytes actually read.</li>
<li><code>GITHUB_TOKEN</code> or <code>--github-token</code> lifts GitHub&rsquo;s anonymous rate limit; it is
sent to <code>api.github.com</code> only and never survives a redirect.</li>
</ul>
<h2 id="fixed--dns-rebinding-could-walk-past-the-ssrf-guard">Fixed — DNS rebinding could walk past the SSRF guard</h2>
<p><code>isBlockedHost()</code> compared the hostname as a <strong>string</strong>, so a public name whose
<code>A</code> record points at loopback sailed through. That mattered most in <strong>OAuth</strong>,
where discovery, registration and token endpoints are chosen by the target
server&rsquo;s own metadata.</p>
<ul>
<li>New <code>isBlockedHostResolved()</code> resolves the name and blocks it when <strong>any</strong>
returned address is non-routable — a multi-record name is only as safe as its
worst answer. Applied at the <code>acquireHttp</code> entry and on <strong>every</strong> fetch hop, so
it covers redirects and every OAuth host.</li>
<li>Private-range coverage widened: CGNAT (<code>100.64/10</code>), multicast (<code>224/4</code>) and
reserved space (<code>240/4</code>). <code>100.63.x</code> and <code>100.128.x</code> stay routable.</li>
<li><code>--allowed-hosts</code> now <strong>overrides</strong> the private-host guard, which previously
refused a host you had explicitly allowed — <code>100.64/10</code> is Tailscale&rsquo;s range.</li>
<li>The guard&rsquo;s DNS lookup is time-boxed to 3s; <code>dns.lookup</code> takes no timeout.</li>
</ul>
<p>Deliberate limits: an unresolvable name is not treated as blocked, and a sub-TTL
rebind between lookup and connect still needs a custom dispatcher to close.</p>
<h2 id="install">Install</h2>
<pre tabindex="0"><code>npm i -g mcptrustchecker@1.10.0
mcptrustchecker --version     # 1.10.0 (methodology mcptrustchecker-1.9)
</code></pre><p>415 tests pass, including new ones pinning the repository parser and the resolved
host guard.</p>
<p>Also live: the free online scanner — <strong><a href="https://mcptrustchecker.com/scan">https://mcptrustchecker.com/scan</a></strong></p>
<p><strong>Full changelog:</strong> <a href="https://github.com/illiahaidar/mcptrustchecker/blob/main/CHANGELOG.md">https://github.com/illiahaidar/mcptrustchecker/blob/main/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>droast — Dockerfile linter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/droast-dockerfile-linter/</link><pubDate>Fri, 24 Jul 2026 19:17:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/droast-dockerfile-linter/</guid><description>Version updated for https://github.com/immanuwell/dockerfile-roast to version 1.4.10.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary droast is an opinionated Dockerfile linter that catches bad practices and reports them in a blunt manner. It supports various features such as parsing heredocs, handling parser directives, shell forms, BuildKit flags, Windows paths, and PowerShell, and provides real-time feedback with inline squiggles in VS Code and lint-on-save for Neovim users.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/immanuwell/dockerfile-roast">https://github.com/immanuwell/dockerfile-roast</a></strong> to version <strong>1.4.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/droast-dockerfile-linter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>droast is an opinionated Dockerfile linter that catches bad practices and reports them in a blunt manner. It supports various features such as parsing heredocs, handling parser directives, shell forms, BuildKit flags, Windows paths, and PowerShell, and provides real-time feedback with inline squiggles in VS Code and lint-on-save for Neovim users.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>chore: release version 1.4.10 (6e9b82c)</li>
<li>fix: handle dynamic images and modern Dockerfile syntax (cd2c37e)</li>
<li>chore: release version 1.4.9 (a6b3c09)</li>
<li>fix: resume interrupted release preparation (0759a95)</li>
<li>fix: honor pip cache environment and synchronize release integrations (fa83565)</li>
<li>fix: skip DF023 for final unnamed stage (266abe8)</li>
<li>ci: skip VS Code publish without Marketplace token (bf12b21)</li>
<li>chore: automate release preparation and tagging (3e686f6)</li>
<li>chore: release version 1.4.8 (2b5b6bb)</li>
<li>fix: detect unprotected RUN pipelines after set options (65b5c43)</li>
</ul>
]]></content:encoded></item><item><title>Aeroflare CI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/aeroflare-ci/</link><pubDate>Fri, 24 Jul 2026 19:16:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/aeroflare-ci/</guid><description>Version updated for https://github.com/ItzEmoji/aeroflare to version v1.13.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: The GitHub Action ItzEmoji/aeroflare@v1 automates the process of building and pushing Nix packages to an OCI cache, providing a stateless, zero-infrastructure binary substituter. It supports pushing builds directly from CI without requiring additional tooling on the host machine. The action can build all outputs or specific ones based on changes or specified patterns, making it suitable for continuous integration workflows where Nix is used for packaging and caching dependencies.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ItzEmoji/aeroflare">https://github.com/ItzEmoji/aeroflare</a></strong> to version <strong>v1.13.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aeroflare-ci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary</strong>: The GitHub Action <code>ItzEmoji/aeroflare@v1</code> automates the process of building and pushing Nix packages to an OCI cache, providing a stateless, zero-infrastructure binary substituter. It supports pushing builds directly from CI without requiring additional tooling on the host machine. The action can build all outputs or specific ones based on changes or specified patterns, making it suitable for continuous integration workflows where Nix is used for packaging and caching dependencies.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1130-2026-07-24"><a href="https://github.com/ItzEmoji/aeroflare/compare/v1.12.0...v1.13.0">1.13.0</a> (2026-07-24)</h2>
<h3 id="features">Features</h3>
<ul>
<li>changed builds sentinel (<a href="https://github.com/ItzEmoji/aeroflare/commit/06ff04d438a0eb881ca08185eb2d2ef9a9087a5a">06ff04d</a>)</li>
<li><strong>ci:</strong> add a <code>changed</code> builds sentinel that diffs derivations (<a href="https://github.com/ItzEmoji/aeroflare/commit/2af89ef7547df586ba19bb723920c3e77a7d12fc">2af89ef</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>ci:</strong> attribute the NUR commit to the app&rsquo;s own bot (<a href="https://github.com/ItzEmoji/aeroflare/commit/15ec767e07d069334462e5a9633278b3e9801958">15ec767</a>)</li>
<li><strong>ci:</strong> diff <code>changed</code> against the nearest evaluatable ancestor (<a href="https://github.com/ItzEmoji/aeroflare/commit/25cd1c37800defb7a5a62c039ebcc1cc7dfaefd5">25cd1c3</a>)</li>
</ul>
]]></content:encoded></item><item><title>stackit-cli tools installer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/stackit-cli-tools-installer/</link><pubDate>Fri, 24 Jul 2026 19:14:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/stackit-cli-tools-installer/</guid><description>Version updated for https://github.com/jkroepke/setup-stackit-cli to version v1.2.92.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action installs a specific version of the stackit-cli tool on a runner, allowing developers to automate the setup and use of stackit-cli in their workflows. It supports fetching either the latest stable release or any specified semantic version, making it easy to integrate stackit-cli into CI/CD pipelines for deployment and management tasks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jkroepke/setup-stackit-cli">https://github.com/jkroepke/setup-stackit-cli</a></strong> to version <strong>v1.2.92</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/stackit-cli-tools-installer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action installs a specific version of the stackit-cli tool on a runner, allowing developers to automate the setup and use of stackit-cli in their workflows. It supports fetching either the latest stable release or any specified semantic version, making it easy to integrate stackit-cli into CI/CD pipelines for deployment and management tasks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at v1.2.92 -->
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="-dependencies">🛠️ Dependencies</h3>
<ul>
<li>chore(deps): update dependency undici to v8.9.0 by @renovate[bot] in <a href="https://github.com/jkroepke/setup-stackit-cli/pull/294">https://github.com/jkroepke/setup-stackit-cli/pull/294</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jkroepke/setup-stackit-cli/compare/v1.2.91...v1.2.92">https://github.com/jkroepke/setup-stackit-cli/compare/v1.2.91...v1.2.92</a></p>
]]></content:encoded></item><item><title>Kusari Ingest</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/kusari-ingest/</link><pubDate>Fri, 24 Jul 2026 19:14:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/kusari-ingest/</guid><description>Version updated for https://github.com/kusaridev/kusari-ingest to version v4.9.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of uploading SBOMs, SLSA attestations, and other artifacts to the Kusari Platform from a GitHub workflow. It simplifies integration by handling authentication credentials and provides options to generate SBOMs automatically or manually. Key features include capturing ingestion results for machine-readable IDs and ensuring components are mapped if needed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kusaridev/kusari-ingest">https://github.com/kusaridev/kusari-ingest</a></strong> to version <strong>v4.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kusari-ingest">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of uploading SBOMs, SLSA attestations, and other artifacts to the Kusari Platform from a GitHub workflow. It simplifies integration by handling authentication credentials and provides options to generate SBOMs automatically or manually. Key features include capturing ingestion results for machine-readable IDs and ensuring components are mapped if needed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Update kusari-cli to v2.9.1 by @karlyanelson in <a href="https://github.com/kusaridev/kusari-ingest/pull/42">https://github.com/kusaridev/kusari-ingest/pull/42</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/kusaridev/kusari-ingest/compare/v4.8.0...v4.9.0">https://github.com/kusaridev/kusari-ingest/compare/v4.8.0...v4.9.0</a></p>
]]></content:encoded></item><item><title>Lingo.Dev AI Localization</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/lingo.dev-ai-localization/</link><pubDate>Fri, 24 Jul 2026 19:13:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/lingo.dev-ai-localization/</guid><description>Version updated for https://github.com/lingodotdev/lingo.dev to version lingo.dev@0.138.3.
This action is used across all versions by 107 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action is designed to automate the continuous localization process within a repository using the Lingo.dev platform. It helps teams manage translations efficiently and ensure consistency across multiple locales, reducing errors by leveraging AI-assisted tools and connecting directly to translation APIs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lingodotdev/lingo.dev">https://github.com/lingodotdev/lingo.dev</a></strong> to version <strong><a href="mailto:lingo.dev@0.138.3">lingo.dev@0.138.3</a></strong>.</p>
<ul>
<li>This action is used across all versions by <strong>107</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lingo-dev-ai-localization">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action is designed to automate the continuous localization process within a repository using the Lingo.dev platform. It helps teams manage translations efficiently and ensure consistency across multiple locales, reducing errors by leveraging AI-assisted tools and connecting directly to translation APIs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="patch-changes">Patch Changes</h3>
<ul>
<li>Updated dependencies [<a href="https://github.com/lingodotdev/lingo.dev/commit/8c0393a084204affb58e789ae434e147f2338a61"><code>8c0393a</code></a>]:
<ul>
<li>@lingo.dev/_<a href="mailto:sdk@0.17.3">sdk@0.17.3</a></li>
</ul>
</li>
</ul>
]]></content:encoded></item><item><title>lgtmaybe</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/lgtmaybe/</link><pubDate>Fri, 24 Jul 2026 19:11:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/lgtmaybe/</guid><description>Version updated for https://github.com/MattJColes/lgtmaybe to version lgtmaybe-v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary lgtmaybe is a GitHub Action that reviews pull requests by analyzing code changes and security vulnerabilities, providing inline comments and summaries on GitHub. It uses an OpenAI-compatible model to generate feedback without checking out or running the code, focusing on logic errors, security risks, tests, documentation updates, performance issues, complexity, intent, and unnecessary complexity. The action can run in different presets for varying levels of thoroughness, including default fast mode and full audit mode for release branches.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MattJColes/lgtmaybe">https://github.com/MattJColes/lgtmaybe</a></strong> to version <strong>lgtmaybe-v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lgtmaybe">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>lgtmaybe is a GitHub Action that reviews pull requests by analyzing code changes and security vulnerabilities, providing inline comments and summaries on GitHub. It uses an OpenAI-compatible model to generate feedback without checking out or running the code, focusing on logic errors, security risks, tests, documentation updates, performance issues, complexity, intent, and unnecessary complexity. The action can run in different presets for varying levels of thoroughness, including default fast mode and full audit mode for release branches.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="110-2026-07-24"><a href="https://github.com/MattJColes/lgtmaybe/compare/lgtmaybe-v1.0.0...lgtmaybe-v1.1.0">1.1.0</a> (2026-07-24)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>diff:</strong> skip generated llms.txt/llms-full.txt files in review (<a href="https://github.com/MattJColes/lgtmaybe/issues/202">#202</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/b06086c23279bfd256b9e7de1ab3500f11c45474">b06086c</a>)</li>
<li>enable diagrams in starter workflows (<a href="https://github.com/MattJColes/lgtmaybe/issues/204">#204</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/157c47dfdca040529b08bc48591be7fbdfe00ff5">157c47d</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>align action with v1 release (<a href="https://github.com/MattJColes/lgtmaybe/issues/209">#209</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/46e94b518d46a31c969ba5e0623c84e32bb593d1">46e94b5</a>)</li>
<li>bound default review runtime (<a href="https://github.com/MattJColes/lgtmaybe/issues/208">#208</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/d21e4e8f262b809fbf75bbd4469178aaa8312519">d21e4e8</a>)</li>
</ul>
<h3 id="documentation">Documentation</h3>
<ul>
<li>add Google Search Console verification file (<a href="https://github.com/MattJColes/lgtmaybe/issues/201">#201</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/d20b6d31b308dd924e8b2f117e826f2f0ed94d46">d20b6d3</a>)</li>
<li>clarify Marketplace provider setup (<a href="https://github.com/MattJColes/lgtmaybe/issues/206">#206</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/089e74ff209e4043f1b7c394b191eccbb190dcdf">089e74f</a>)</li>
<li>improve homepage feature showcase (<a href="https://github.com/MattJColes/lgtmaybe/issues/207">#207</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/ab9984f9ae3f4651425f9d769f3717f8e6716cb4">ab9984f</a>)</li>
<li>show change diagram on homepage (<a href="https://github.com/MattJColes/lgtmaybe/issues/205">#205</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/64f58f7d5fdebdf2ff7b9e6ab8096d38128a7064">64f58f7</a>)</li>
</ul>
]]></content:encoded></item><item><title>vuln.mlab.sh SBOM scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/vuln.mlab.sh-sbom-scan/</link><pubDate>Fri, 24 Jul 2026 19:10:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/vuln.mlab.sh-sbom-scan/</guid><description>Version updated for https://github.com/mlab-sh/vuln-scan-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the scanning of dependency lockfiles in a repository for known CVEs using vuln.mlab.sh. It automatically detects common lockfile types and checks each package against OSV and Sonatype OSS Index, providing detailed vulnerability reports in the job summary. The action can fail the build based on a specified severity threshold or report vulnerabilities without failing, with outputs for total vulnerabilities, vulnerable packages, and failure status.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mlab-sh/vuln-scan-action">https://github.com/mlab-sh/vuln-scan-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vuln-mlab-sh-sbom-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the scanning of dependency lockfiles in a repository for known CVEs using vuln.mlab.sh. It automatically detects common lockfile types and checks each package against OSV and Sonatype OSS Index, providing detailed vulnerability reports in the job summary. The action can fail the build based on a specified severity threshold or report vulnerabilities without failing, with outputs for total vulnerabilities, vulnerable packages, and failure status.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release. 🎉</p>
<p>Scan your lockfiles for known CVEs in CI/CD, powered by <a href="https://vuln.mlab.sh">vuln.mlab.sh</a>.</p>
<h3 id="features">Features</h3>
<ul>
<li>Auto-detects lockfiles: <code>Cargo.lock</code>, <code>package-lock.json</code>, <code>npm-shrinkwrap.json</code>, <code>composer.lock</code>, <code>Gemfile.lock</code>, <code>go.sum</code>, <code>requirements.txt</code>, <code>mise.lock</code>.</li>
<li>Server-side parsing + scan against OSV &amp; Sonatype OSS Index — no local install, no database.</li>
<li>Severity threshold with <code>fail-on</code> (<code>any</code> · <code>critical</code> · <code>high</code> · <code>medium</code> · <code>low</code> · <code>none</code>).</li>
<li><code>soft-fail</code> mode to report without failing the build.</li>
<li>Job summary table + inline annotations on vulnerable dependencies.</li>
<li>Outputs: <code>total</code>, <code>vulnerable-packages</code>, <code>failed</code>.</li>
<li>Optional API token (<code>token:</code>) for 25 scans/hour (vs 8/hour anonymous).</li>
</ul>
<h3 id="usage">Usage</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">mlab-sh/vuln-scan-action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">token</span>: <span style="color:#ae81ff">${{ secrets.VULN_MLAB_TOKEN }}</span>
</span></span></code></pre></div><p>See the <a href="https://github.com/mlab-sh/vuln-scan-action">README</a> for all inputs.</p>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/go-proxy-cache-updater/</link><pubDate>Fri, 24 Jul 2026 19:09:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.32.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically updates a specific Go module proxy cache when new tags are created, ensuring that the latest module versions are immediately available and documentation is updated on platforms like pkg.go.dev. It supports both standard and submodule version tags and allows customization of the proxy configuration, import path, and Go version used for building the module.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.32</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically updates a specific Go module proxy cache when new tags are created, ensuring that the latest module versions are immediately available and documentation is updated on platforms like pkg.go.dev. It supports both standard and submodule version tags and allows customization of the proxy configuration, import path, and Go version used for building the module.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1132-2026-07-24"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.31...v1.1.32">1.1.32</a> (2026-07-24)</h2>
]]></content:encoded></item><item><title>Run AER Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/run-aer-tests/</link><pubDate>Fri, 24 Jul 2026 19:08:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/run-aer-tests/</guid><description>Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.24.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The aer action automates running Apex tests locally, providing a fast feedback loop without using an org or deploy. It supports running unit tests with code coverage and executing anonymous Apex, as well as debugging Apex in interactive mode through VS Code or IntelliJ. The action can be installed via Homebrew, the Salesforce CLI, or manually downloaded and added to the PATH.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/octoberswimmer/aer-dist">https://github.com/octoberswimmer/aer-dist</a></strong> to version <strong>v1.2.24</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-aer-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The aer action automates running Apex tests locally, providing a fast feedback loop without using an org or deploy. It supports running unit tests with code coverage and executing anonymous Apex, as well as debugging Apex in interactive mode through VS Code or IntelliJ. The action can be installed via Homebrew, the Salesforce CLI, or manually downloaded and added to the PATH.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Version v1.2.24</p>
<ul>
<li>
<p>Fix Generic And Array Class-literal Type Names</p>
</li>
<li>
<p>Persist CartTestUtil.createCart Records And Widen ProcessException.AttachedToId</p>
</li>
<li>
<p>Fix Infinite Recursion Resolving Methods When A Class Extends Its Own Inner Class</p>
</li>
<li>
<p>Maintain WebCart Summary Totals As Platform Roll-Ups</p>
</li>
<li>
<p>Support The Id.valueOf(String, Boolean) Restore-Casing Overload</p>
</li>
<li>
<p>Accept Already-Qualified Class Names In Two-Argument Type.forName</p>
</li>
<li>
<p>Correct Content SObject Describe Metadata</p>
</li>
<li>
<p>Truncate Auto-Generated User CommunityNickname To The Field Length</p>
</li>
<li>
<p>Replace Unknown-Typed Standard-Field Stubs When Feature Schemas Merge</p>
</li>
<li>
<p>Support ConnectApi Output Representation Field Inheritance</p>
</li>
<li>
<p>Gate Field-Name Auto-Feature Detection On An SObject Target</p>
</li>
<li>
<p>Resolve Instance Calls To Inherited Instance Method Over Static Shadow</p>
</li>
<li>
<p>Import Fields Declared Inline In An object-meta.xml File</p>
</li>
<li>
<p>Fix Flow Formula Datetime And Merge-Field String Conversion</p>
</li>
<li>
<p>Parse Custom Labels Through force-md To Accept Undeclared HTML Entities</p>
</li>
<li>
<p>Report RelationshipOrder For Builtin Master-Detail Fields</p>
</li>
<li>
<p>Guard Batch-update Audit-field Stamping On Field Existence</p>
</li>
<li>
<p>Derive ContentVersion.Title From PathOnClient When Omitted On Insert</p>
</li>
</ul>
]]></content:encoded></item><item><title>Automatic Semantic Releases</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/automatic-semantic-releases/</link><pubDate>Fri, 24 Jul 2026 19:07:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/automatic-semantic-releases/</guid><description>Version updated for https://github.com/oliversalzburg/action-automatic-semantic-releases to version v3.3.1.
This action is used across all versions by 16 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, designed by oliversalzburg, automates the creation of semantic releases. It helps maintain consistency in version numbers and release processes across projects. The action supports both tagged builds and automatic releases on pushes or schedules, ensuring that versions are managed correctly without manual intervention.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/oliversalzburg/action-automatic-semantic-releases">https://github.com/oliversalzburg/action-automatic-semantic-releases</a></strong> to version <strong>v3.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>16</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/automatic-semantic-releases">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, designed by oliversalzburg, automates the creation of semantic releases. It helps maintain consistency in version numbers and release processes across projects. The action supports both tagged builds and automatic releases on pushes or schedules, ensuring that versions are managed correctly without manual intervention.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="chores-2">Chores (2)</h2>
<ul>
<li>Rebuild entrypoint (<a href="https://github.com/oliversalzburg/action-automatic-semantic-releases/commit/cdfa9a9b07350ca82c76832db4796a5d59d9b081">Oliver Salzburg</a>)</li>
<li>Version bump 3.3.1 (<a href="https://github.com/oliversalzburg/action-automatic-semantic-releases/commit/f6b4b9413c3f2ef1659ead1b684609c4aa895eef">Oliver Salzburg</a>)</li>
</ul>
<h2 id="features-1">Features (1)</h2>
<ul>
<li>Don&rsquo;t set content-length header (<a href="https://github.com/oliversalzburg/action-automatic-semantic-releases/commit/ad11beffc1a359fbb7ea0cbcda83e6d646fb104e">Oliver Salzburg</a>)</li>
</ul>
]]></content:encoded></item><item><title>Directory Listing Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/directory-listing-generator/</link><pubDate>Fri, 24 Jul 2026 19:06:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/directory-listing-generator/</guid><description>Version updated for https://github.com/pranabdas/directory-listing to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates directory listings for a repository’s files and directories and automates their automatic deployment to a specified branch, either within the same repository or an external repository using personal access tokens. The action is useful for creating static websites directly from a GitHub repository without additional setup, and it supports various configuration options such as excluding certain files, setting custom site URLs, and managing publishing directories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pranabdas/directory-listing">https://github.com/pranabdas/directory-listing</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/directory-listing-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates directory listings for a repository&rsquo;s files and directories and automates their automatic deployment to a specified branch, either within the same repository or an external repository using personal access tokens. The action is useful for creating static websites directly from a GitHub repository without additional setup, and it supports various configuration options such as excluding certain files, setting custom site URLs, and managing publishing directories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: improve styling by @pranabdas in <a href="https://github.com/pranabdas/directory-listing/pull/2">https://github.com/pranabdas/directory-listing/pull/2</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pranabdas/directory-listing/compare/v1...v1.0.1">https://github.com/pranabdas/directory-listing/compare/v1...v1.0.1</a></p>
]]></content:encoded></item><item><title>Prowler Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/prowler-security-scan/</link><pubDate>Fri, 24 Jul 2026 19:05:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/prowler-security-scan/</guid><description>Version updated for https://github.com/prowler-cloud/prowler to version 5.36.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action described in the README facilitates automated security assessments within cloud environments using Prowler, an Open-Source Cloud Security Platform. It simplifies the process of conducting real-time monitoring and customizable vulnerability scans, ensuring organizations can maintain a secure and compliant state across multiple cloud platforms.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/prowler-cloud/prowler">https://github.com/prowler-cloud/prowler</a></strong> to version <strong>5.36.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/prowler-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action described in the README facilitates automated security assessments within cloud environments using Prowler, an Open-Source Cloud Security Platform. It simplifies the process of conducting real-time monitoring and customizable vulnerability scans, ensuring organizations can maintain a secure and compliant state across multiple cloud platforms.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="-new-features-to-highlight-in-this-version">✨ New features to highlight in this version</h1>
<p>Enjoy them all now for free at <a href="https://cloud.prowler.com">https://cloud.prowler.com</a></p>
<h2 id="-grouped-jira-workflows">🎫 Grouped Jira workflows</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Private Cloud</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>Selected Findings, Finding Groups, and mixed selections can now be sent to Jira. When you select multiple findings, choose between one grouped issue or separate issues. Generated issues keep their Prowler context with deep links and filter details, while the UI provides clear dispatch and failure feedback.</p>
<img width="4596" height="2614" alt="image" src="https://github.com/user-attachments/assets/00220926-aae1-480d-96a0-437e0d91763f" />
<p>Read more in our <a href="https://docs.prowler.com/user-guide/tutorials/prowler-app-jira-integration">Jira integration documentation</a>.</p>
<h2 id="-cleaner-attack-paths-results">🕸️ Cleaner Attack Paths results</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Private Cloud</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>Prowler Cloud now records which built-in Attack Paths queries returned data at the end of each scan. The query selector hides confirmed-empty queries for the selected scan, so you can focus on paths that exist without opening blank graph views. Errored, unknown, and parameterized queries remain available when they still require investigation or input.</p>
<p>All Attack Paths queries are now published on <a href="https://hub.prowler.com">Prowler Hub</a>, where you can browse the full catalog.</p>
<img width="4406" height="2260" alt="image" src="https://github.com/user-attachments/assets/a4f3de04-6499-4f5d-9398-8f8469220065" />
<p>Read more in our <a href="https://docs.prowler.com/user-guide/tutorials/prowler-app-attack-paths">Attack Paths documentation</a>.</p>
<h2 id="-new-tutorials-connect-your-ai-agents-to-prowler-cloud">🧑‍🏫 New Tutorials: Connect Your AI Agents to Prowler Cloud</h2>
<blockquote>
<p>[!NOTE]
For this feature you need a Prowler Cloud API key so this is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Private Cloud</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>New tutorials walk you through connecting your own AI agents to Prowler Cloud, so they can query your security posture and act on it programmatically.</p>
<p>Read more in our <a href="https://docs.prowler.com/user-guide/ai-agents/index">AI agents documentation</a>.</p>
<h2 id="-simpler-oci-provider-setup">☁️ Simpler OCI provider setup</h2>
<p>OCI provider credentials no longer require a region. Existing clients can still send the legacy <code>region</code> field for compatibility, but the API ignores it before storing credentials or starting a scan. This removes an unnecessary step from OCI onboarding.</p>
<p>Read more in our <a href="https://docs.prowler.com/user-guide/providers/oci/getting-started-oci">OCI documentation</a>.</p>
<h2 id="-checks">🔍 Checks</h2>
<h3 id="aws">AWS</h3>
<ul>
<li><code>sagemaker_notebook_instance_no_secrets</code> scans the <code>OnCreate</code> and <code>OnStart</code> lifecycle scripts of SageMaker notebook instances for hardcoded API keys, passwords, tokens, connection strings, and other secrets. Thanks to @kiranrajsg!</li>
</ul>
<p>Read more in our <a href="https://docs.prowler.com/user-guide/providers/aws/getting-started-aws">AWS documentation</a>.</p>
<p>Explore all AWS checks at <a href="https://hub.prowler.com/check?provider=aws">Prowler Hub</a>.</p>
<h2 id="-security">🔐 Security</h2>
<ul>
<li>Integration responses and operations now respect provider visibility, preventing hidden-provider disclosure and blocking unauthorized attachment, connection checks, Jira dispatches, edits, and deletion.</li>
<li>Next.js was updated from 16.2.9 to 16.2.11, patching four high-severity and five medium-severity vulnerabilities.</li>
<li>The unused <code>npm</code> CLI was removed from the UI container image, eliminating the bundled <code>node-tar</code> CVE-2026-59873 and reducing exposure to future bundled npm vulnerabilities.</li>
<li>Vitest and its browser packages were updated from 4.1.8 to 4.1.10, resolving the critical <code>@vitest/browser</code> file-access permission bypass. These are development dependencies and have no runtime impact.</li>
<li>Kubernetes kubeconfig validation now blocks <code>legacy auth-provider.config.cmd-path</code> command authentication, closing a command-execution bypass.</li>
<li><code>next-auth</code> was updated from 5.0.0-beta.30 to 5.0.0-beta.32, patching two critical Auth.js advisories: existence-based authorization checks that could fail open when a provider is misconfigured, and a homoglyph <code>@</code> bypass in email address normalization. The bump also pulls in the patched <code>@auth/core</code> 0.41.3 transitively.</li>
</ul>
<h2 id="-external-contributors">🙌 External Contributors</h2>
<p>Thank you to our community contributors for this release!</p>
<ul>
<li>@kiranrajsg: AWS <code>sagemaker_notebook_instance_no_secrets</code> check (#11843)</li>
<li>@owenchenxy: Alibaba Cloud SSH and RDP security group checks now handle capitalized <code>Policy=&quot;Accept&quot;</code> values correctly (#12049)</li>
<li>@rsaladra: S3 bucket name validation no longer raises an invalid escape sequence <code>SyntaxWarning</code> at startup (#12041)</li>
<li>@SujayKulkarni-2211 - Updated the AWS check count in the README (#12011)</li>
</ul>
<hr>
<h2 id="ui">UI</h2>
<h3 id="-added">🚀 Added</h3>
<ul>
<li>Finding Groups and grouped selections can be sent to Jira in Cloud with deep links, filter chip display, and Jira feedback toasts <a href="https://github.com/prowler-cloud/prowler/pull/12001">(#12001)</a></li>
<li>In Prowler Cloud, the Attack Paths query selector now lists only queries that returned data for the selected scan, hiding empty ones <a href="https://github.com/prowler-cloud/prowler/pull/12010">(#12010)</a></li>
<li>Overview banner linking to the AI agents documentation, shown next to the Lighthouse AI banner in Cloud and full width on self-hosted deployments <a href="https://github.com/prowler-cloud/prowler/pull/12074">(#12074)</a></li>
</ul>
<h3 id="-fixed">🐞 Fixed</h3>
<ul>
<li>Findings Severity Over Time chart Y-axis labels no longer overflow for large findings counts <a href="https://github.com/prowler-cloud/prowler/pull/11545">(#11545)</a></li>
<li>UI Sentry alerts now suppress non-actionable warnings and expected API/control-flow noise while preserving actionable runtime failures <a href="https://github.com/prowler-cloud/prowler/pull/11665">(#11665)</a></li>
<li>OCI provider E2E tests no longer require or submit a region when adding or updating credentials <a href="https://github.com/prowler-cloud/prowler/pull/11741">(#11741)</a></li>
<li>Billing navigation is hidden when Cloud billing is disabled, including Enterprise deployments <a href="https://github.com/prowler-cloud/prowler/pull/12047">(#12047)</a></li>
<li>AWS Organizations setup modal now shows the &ldquo;Enter a valid Organizational Unit or Root ID&rdquo; hint in the error color, clarifying why the deployment button is disabled <a href="https://github.com/prowler-cloud/prowler/pull/12063">(#12063)</a></li>
<li>Sidebar logo top spacing in the main app sidebar <a href="https://github.com/prowler-cloud/prowler/pull/12066">(#12066)</a></li>
<li>Contextual Cloud upgrade modal content remains stable throughout the closing animation <a href="https://github.com/prowler-cloud/prowler/pull/12067">(#12067)</a></li>
<li>Tenant switches now refresh session user permissions for the selected tenant <a href="https://github.com/prowler-cloud/prowler/pull/12087">(#12087)</a></li>
</ul>
<h3 id="-security-1">🔐 Security</h3>
<ul>
<li>Removed the unused <code>npm</code> CLI from the UI container image, eliminating the bundled <code>node-tar</code> <code>CVE-2026-59873</code> (and future bundled-npm CVEs); the image builds with <code>pnpm</code> via <code>corepack</code> and does not use <code>npm</code> <a href="https://github.com/prowler-cloud/prowler/pull/12065">(#12065)</a></li>
<li>Bumped <code>vitest</code> and <code>@vitest/browser</code>, <code>@vitest/browser-playwright</code>, <code>@vitest/coverage-v8</code> from <code>4.1.8</code> to <code>4.1.10</code>, resolving the critical <code>@vitest/browser</code> Browser Mode file-access permission bypass (<code>GHSA-p63j-vcc4-9vmv</code>) flagged by <code>pnpm audit</code>; dev dependencies only, no runtime impact <a href="https://github.com/prowler-cloud/prowler/pull/12077">(#12077)</a></li>
<li>Kubernetes credential forms now reject kubeconfig files using legacy <code>auth-provider.config.cmd-path</code> command authentication <a href="https://github.com/prowler-cloud/prowler/pull/12091">(#12091)</a></li>
<li>Next.js from 16.2.9 to 16.2.11, patching 4 high- and 5 medium-severity vulnerabilities <a href="https://github.com/prowler-cloud/prowler/pull/12093">(#12093)</a></li>
<li>next-auth from 5.0.0-beta.30 to 5.0.0-beta.32, patching 2 critical Auth.js advisories (GHSA-8fpg-xm3f-6cx3 fail-open auth checks, GHSA-7rqj-j65f-68wh email homoglyph bypass) <a href="https://github.com/prowler-cloud/prowler/pull/12108">(#12108)</a></li>
</ul>
<h2 id="api">API</h2>
<h3 id="-changed">🔄 Changed</h3>
<ul>
<li>OCI provider secrets no longer require <code>region</code>; legacy <code>region</code> input is accepted for backwards compatibility but ignored before storing or scanning <a href="https://github.com/prowler-cloud/prowler/pull/11741">(#11741)</a></li>
<li>Compliance overview ingest now runs in a single transaction per scan with a configurable <code>COPY</code> batch size (<code>DJANGO_COMPLIANCE_COPY_BATCH_SIZE</code>, default 2000), reducing write pressure on the database <a href="https://github.com/prowler-cloud/prowler/pull/11875">(#11875)</a></li>
</ul>
<h3 id="-fixed-1">🐞 Fixed</h3>
<ul>
<li>Scan findings now recover resources missing from the in-memory cache after resource pre-resolution, preventing valid findings from being skipped <a href="https://github.com/prowler-cloud/prowler/pull/12002">(#12002)</a></li>
<li>Tenant-wide integrations that are not attached to any provider, such as Jira, are now visible and manageable by roles with <code>manage_integrations</code> and without unlimited visibility <a href="https://github.com/prowler-cloud/prowler/pull/12060">(#12060)</a></li>
<li>Output generation now removes the scan&rsquo;s temporary output directory before writing, so a re-run of the task for the same scan (e.g. broker redelivery after a worker is killed mid-run) no longer appends to the previous run&rsquo;s files and duplicates finding rows in the exported CSV and other outputs <a href="https://github.com/prowler-cloud/prowler/pull/12097">(#12097)</a></li>
</ul>
<h3 id="-security-2">🔐 Security</h3>
<ul>
<li>Integration responses no longer disclose providers outside the visibility of the role, including the resources sideloaded through <code>?include=providers</code> <a href="https://github.com/prowler-cloud/prowler/pull/12060">(#12060)</a></li>
<li>Integration connection checks, Jira issue type lookups and Jira dispatches now resolve the integration through the provider visibility of the role instead of the whole tenant <a href="https://github.com/prowler-cloud/prowler/pull/12060">(#12060)</a></li>
<li>Roles without unlimited visibility can no longer attach an integration to providers they cannot see, nor edit or delete an integration bound to them <a href="https://github.com/prowler-cloud/prowler/pull/12060">(#12060)</a></li>
<li>Kubernetes kubeconfig validation now rejects legacy <code>auth-provider.config.cmd-path</code> command authentication in Prowler Cloud/API <a href="https://github.com/prowler-cloud/prowler/pull/12091">(#12091)</a></li>
</ul>
<h2 id="sdk">SDK</h2>
<h3 id="-added-1">🚀 Added</h3>
<ul>
<li><code>sagemaker_notebook_instance_no_secrets</code> check for AWS provider, scanning SageMaker notebook instance lifecycle configuration scripts (<code>OnCreate</code> and <code>OnStart</code>) for hardcoded secrets such as API keys, passwords, tokens, and connection strings <a href="https://github.com/prowler-cloud/prowler/pull/11843">(#11843)</a></li>
</ul>
<h3 id="-changed-1">🔄 Changed</h3>
<ul>
<li>Jira output rendering supports grouped Finding Group issues with caller-provided links and capped or uncapped finding copy <a href="https://github.com/prowler-cloud/prowler/pull/12035">(#12035)</a></li>
</ul>
<h3 id="-fixed-2">🐞 Fixed</h3>
<ul>
<li>Fix invalid escape sequence <code>SyntaxWarning</code> raised on startup by the S3 bucket name validation regex <a href="https://github.com/prowler-cloud/prowler/pull/12041">(#12041)</a></li>
<li>Alibaba Cloud SSH and RDP security group checks no longer produce false negatives when allowed rules use capitalized <code>Policy=&quot;Accept&quot;</code> values <a href="https://github.com/prowler-cloud/prowler/pull/12049">(#12049)</a></li>
</ul>
]]></content:encoded></item><item><title>ECS Exec</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/ecs-exec/</link><pubDate>Fri, 24 Jul 2026 19:03:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/ecs-exec/</guid><description>Version updated for https://github.com/risk3sixty/ecs-exec to version v2.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action allows developers to execute a command in the specified ECS Fargate Service. It automates database migrations by running scripts directly within the service containers, reducing the need for manual intervention and improving efficiency. The action handles multiple container services by requiring a specific container name when necessary, ensuring consistent execution across all tasks within the service.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/risk3sixty/ecs-exec">https://github.com/risk3sixty/ecs-exec</a></strong> to version <strong>v2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ecs-exec">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action allows developers to execute a command in the specified ECS Fargate Service. It automates database migrations by running scripts directly within the service containers, reducing the need for manual intervention and improving efficiency. The action handles multiple container services by requiring a specific container name when necessary, ensuring consistent execution across all tasks within the service.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>container_name input (optional) → passed to ExecuteCommandCommand.container. Backward-compatible; omitting it keeps today&rsquo;s behavior.</p>
<p>desiredStatus: RUNNING filter on ListTasks + explicit error if no running task (previously could grab a stopped/undefined task).</p>
<p>Exit-code detection — wraps the command so it echoes <strong>ECS_EXEC_EXIT</strong>=$? and scans the streamed output; the step now fails on a non-zero exit or a dropped session. This closes the silent-failure hole the raw CLI approach also had.</p>
]]></content:encoded></item><item><title>SFDT for Salesforce</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/sfdt-for-salesforce/</link><pubDate>Fri, 24 Jul 2026 19:03:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/sfdt-for-salesforce/</guid><description>Version updated for https://github.com/scoobydrew83/sfdt to version v0.19.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the deployment, testing, and release management of Salesforce projects using the @sfdt/cli tool. It simplifies the process by providing features such as interactive workflows with preflight validation, automated release manifests, parallel Apex test execution, AI-powered fix plans for code and tests, and CI/CD pipeline templates for GitHub, GitLab, Azure, and Bitbucket. The action also supports multi-package projects and provides a local web dashboard for monitoring and comparing org states.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/scoobydrew83/sfdt">https://github.com/scoobydrew83/sfdt</a></strong> to version <strong>v0.19.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sfdt-for-salesforce">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action automates the deployment, testing, and release management of Salesforce projects using the <code>@sfdt/cli</code> tool. It simplifies the process by providing features such as interactive workflows with preflight validation, automated release manifests, parallel Apex test execution, AI-powered fix plans for code and tests, and CI/CD pipeline templates for GitHub, GitLab, Azure, and Bitbucket. The action also supports multi-package projects and provides a local web dashboard for monitoring and comparing org states.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: promote develop → main (extension v0.8.1) by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/268">https://github.com/scoobydrew83/sfdt/pull/268</a></li>
<li>chore: promote develop → main — CLI v0.19.0 + extension v0.9.0 by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/269">https://github.com/scoobydrew83/sfdt/pull/269</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/scoobydrew83/sfdt/compare/v0.18.2...v0.19.0">https://github.com/scoobydrew83/sfdt/compare/v0.18.2...v0.19.0</a></p>
]]></content:encoded></item><item><title>Reelier replay</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/reelier-replay/</link><pubDate>Fri, 24 Jul 2026 19:02:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/reelier-replay/</guid><description>Version updated for https://github.com/seldonframe/reelier to version v1.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Reelier automates the verification of AI agent tool-call workflows against new dependencies, ensuring consistency and reliability in software development processes. By replaying recorded runs at zero LLM cost and diffing them, Reelier helps identify any drift between the original run and the updated environment, providing clear receipts for audits and approvals before merging changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/seldonframe/reelier">https://github.com/seldonframe/reelier</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/reelier-replay">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Reelier automates the verification of AI agent tool-call workflows against new dependencies, ensuring consistency and reliability in software development processes. By replaying recorded runs at zero LLM cost and diffing them, Reelier helps identify any drift between the original run and the updated environment, providing clear receipts for audits and approvals before merging changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Adds a Dependabot/Renovate bump-safety check: replay your recorded agent tool-call skills live against a bumped dependency at 0 LLM tokens, and fail the PR check on the exact step that drifted.</p>
<ul>
<li>New <code>wrap</code> input to front your own MCP server / tool process (the case that exercises a bumped SDK your tool code imports).</li>
<li>Copy-paste recipe: <code>.github/workflows/reelier-bump-check.yml</code>.</li>
<li>Honest scope: at <code>max-level 0</code> the replay never calls an LLM, so it verifies dependency / MCP-tool-call behavior, not model upgrades.</li>
</ul>
<p>Also works unscoped from bump PRs, as a scheduled drift check or a plain &ldquo;replay this skill on every PR&rdquo; gate. See the README.</p>
]]></content:encoded></item><item><title>Argus PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/argus-pr-review/</link><pubDate>Fri, 24 Jul 2026 19:01:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/argus-pr-review/</guid><description>Version updated for https://github.com/sibinms/argus to version v1.2.28.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Argus is an AI code review tool that optimizes recall to find more real bugs while keeping false positives manageable. It runs multiple specialized AI reviewers in parallel and uses an evidence-based curator to verify findings before posting review comments on GitHub pull requests. The planner briefs every reviewer up front, lenses focus on specific problem domains, and the curator merges duplicates and only dismisses issues with cited quotes from the diff.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sibinms/argus">https://github.com/sibinms/argus</a></strong> to version <strong>v1.2.28</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/argus-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Argus is an AI code review tool that optimizes recall to find more real bugs while keeping false positives manageable. It runs multiple specialized AI reviewers in parallel and uses an evidence-based curator to verify findings before posting review comments on GitHub pull requests. The planner briefs every reviewer up front, lenses focus on specific problem domains, and the curator merges duplicates and only dismisses issues with cited quotes from the diff.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Isolate lens failures and size context per model by @sibinms in <a href="https://github.com/sibinms/argus/pull/46">https://github.com/sibinms/argus/pull/46</a></li>
<li>Bump version to 1.2.28 by @sibinms in <a href="https://github.com/sibinms/argus/pull/47">https://github.com/sibinms/argus/pull/47</a></li>
<li>Release v1.2.28 by @sibinms in <a href="https://github.com/sibinms/argus/pull/48">https://github.com/sibinms/argus/pull/48</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sibinms/argus/compare/v1.2.27...v1.2.28">https://github.com/sibinms/argus/compare/v1.2.27...v1.2.28</a></p>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/ssg-static-site-generator/</link><pubDate>Fri, 24 Jul 2026 18:59:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.13.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: SSG is a fast Go-based static site generator that converts Markdown with YAML frontmatter into a complete website. It supports various features such as built-in themes, templates engines, SEO metadata, image processing, and deployment to multiple platforms like GitHub Pages, Netlify, Vercel, and more. The action automates content generation, rendering, and deployment processes, making it ideal for blog creation, documentation, and other static site needs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.13</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong> SSG is a fast Go-based static site generator that converts Markdown with YAML frontmatter into a complete website. It supports various features such as built-in themes, templates engines, SEO metadata, image processing, and deployment to multiple platforms like GitHub Pages, Netlify, Vercel, and more. The action automates content generation, rendering, and deployment processes, making it ideal for blog creation, documentation, and other static site needs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>1.8.13 — workers: plural workers, cookie-consent, comments, republish-trigger, config includes by @spagu in <a href="https://github.com/spagu/ssg/pull/50">https://github.com/spagu/ssg/pull/50</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.12...v1.8.13">https://github.com/spagu/ssg/compare/v1.8.12...v1.8.13</a></p>
]]></content:encoded></item><item><title>KCD Pak</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/kcd-pak/</link><pubDate>Fri, 24 Jul 2026 18:58:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/kcd-pak/</guid><description>Version updated for https://github.com/tkhquang/kcd-pak-action to version v1.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action packages a Kingdom Come: Deliverance loose-file mod into game-ready .pak files and a release .zip. It solves the problem of loading mods by ensuring that the paks do not have unnecessary modification-time metadata, which 7-Zip / WinRAR / WinZip add. The action supports both compression methods (deflate or store) and provides outputs for the mod ID and version, allowing users to manage their releases from the mod.manifest file.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tkhquang/kcd-pak-action">https://github.com/tkhquang/kcd-pak-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kcd-pak">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action packages a Kingdom Come: Deliverance loose-file mod into game-ready <code>.pak</code> files and a release <code>.zip</code>. It solves the problem of loading mods by ensuring that the paks do not have unnecessary modification-time metadata, which 7-Zip / WinRAR / WinZip add. The action supports both compression methods (deflate or store) and provides outputs for the mod ID and version, allowing users to manage their releases from the <code>mod.manifest</code> file.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Package a Kingdom Come: Deliverance (KCD1/KCD2) loose-file mod into game-ready <code>.pak</code> files and a release <code>.zip</code>. Runs as a GitHub Action or as a local Python tool.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>CryPak-safe paks</strong>: writes ZIPs with zero per-file modification-time extra fields (NTFS <code>0x000A</code> / extended-timestamp <code>0x5455</code>), the metadata that makes a plain renamed 7-Zip/WinRAR archive fail to load in KCD2.</li>
<li><strong>Correct pak layout</strong>: <code>Data/**</code> except <code>Data/Levels/**</code> -&gt; <code>Data/&lt;modid&gt;.pak</code>; <code>Localization/&lt;Lang&gt;/**</code> -&gt; <code>Localization/&lt;Lang&gt;.pak</code>; <code>Data/Levels/&lt;level&gt;/**</code> -&gt; <code>Data/Levels/&lt;level&gt;/&lt;modid&gt;.pak</code>; <code>mod.manifest</code> and <code>mod.cfg</code> are kept loose.</li>
<li><strong>Compression</strong>: <code>deflate</code> (default) or <code>store</code>.</li>
<li><strong>Outputs</strong>: <code>archive</code>, <code>deploy-dir</code>, <code>modid</code>, <code>version</code> (read from <code>mod.manifest</code>).</li>
</ul>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v7</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">tkhquang/kcd-pak-action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">mod-dir</span>: <span style="color:#ae81ff">src       </span> <span style="color:#75715e"># folder containing mod.manifest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">compress</span>: <span style="color:#ae81ff">deflate  </span> <span style="color:#75715e"># or &#39;store&#39;</span>
</span></span></code></pre></div><p>See the README for both the tag-triggered and manifest-driven release workflows.</p>
<h2 id="requirements">Requirements</h2>
<ul>
<li>Python 3.8+ on the runner (present on GitHub-hosted runners). Also runs locally: <code>python scripts/pak_kcd_mod.py &lt;mod-src-dir&gt;</code>.</li>
</ul>
<h2 id="license">License</h2>
<p>0BSD.</p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/neurolink-ai/</link><pubDate>Fri, 24 Jul 2026 14:11:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v10.5.2.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is the universal AI integration platform that simplifies integrating 30+ AI providers and models into applications. It provides a TypeScript-first interface that supports various functionalities such as text streaming from LLM providers, handling different output modes (avatar and music), and deploying with enterprise features like Redis memory and failover. The action automates these tasks and streamlines the integration process for developers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v10.5.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>NeuroLink is the universal AI integration platform that simplifies integrating 30+ AI providers and models into applications. It provides a TypeScript-first interface that supports various functionalities such as text streaming from LLM providers, handling different output modes (avatar and music), and deploying with enterprise features like Redis memory and failover. The action automates these tasks and streamlines the integration process for developers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1052-2026-07-24"><a href="https://github.com/juspay/neurolink/compare/v10.5.1...v10.5.2">10.5.2</a> (2026-07-24)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(core):</strong>  make supportsTools model-aware via the model registry (<a href="https://github.com/juspay/neurolink/commit/c4137f3784f8268eeda36cb57f5776f49939979e">c4137f3</a>)</li>
</ul>
]]></content:encoded></item><item><title>Agent Diff Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/agent-diff-guard/</link><pubDate>Fri, 24 Jul 2026 14:10:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/agent-diff-guard/</guid><description>Version updated for https://github.com/jwa-wa/agent-diff-guard to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks AI agent configurations to catch risky changes such as safety instructions removal, dangerous tool permissions addition, and model tier swaps. It automates these checks before merging changes into a repository, providing detailed reports and alerts for sensitive configuration modifications. The action supports free and Pro tiers with varying features and reporting options, making it suitable for both casual users and organizations requiring more advanced observability.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jwa-wa/agent-diff-guard">https://github.com/jwa-wa/agent-diff-guard</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-diff-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks AI agent configurations to catch risky changes such as safety instructions removal, dangerous tool permissions addition, and model tier swaps. It automates these checks before merging changes into a repository, providing detailed reports and alerts for sensitive configuration modifications. The action supports free and Pro tiers with varying features and reporting options, making it suitable for both casual users and organizations requiring more advanced observability.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial release: git-native <code>check</code> command, GitHub Action, and Pro tier (Gumroad-verified license: full per-file detail, model cost-tier detection, SARIF output).</p>
]]></content:encoded></item><item><title>pr-sage AI Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/pr-sage-ai-review/</link><pubDate>Fri, 24 Jul 2026 14:09:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/pr-sage-ai-review/</guid><description>Version updated for https://github.com/Kyeom1997/pr-sage to version v0.8.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary pr-sage is an AI-powered pull request reviewer designed to minimize noise and follow team conventions. It reviews only the most recent changes since the last review, uses fingerprinting to eliminate duplicate comments, and can enforce severity levels and quality gates in PRs. The action supports multiple providers (Anthropic, OpenAI, Gemini) and can be used locally for pre-push reviews without needing a GitHub token.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Kyeom1997/pr-sage">https://github.com/Kyeom1997/pr-sage</a></strong> to version <strong>v0.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pr-sage-ai-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>pr-sage is an AI-powered pull request reviewer designed to minimize noise and follow team conventions. It reviews only the most recent changes since the last review, uses fingerprinting to eliminate duplicate comments, and can enforce severity levels and quality gates in PRs. The action supports multiple providers (Anthropic, OpenAI, Gemini) and can be used locally for pre-push reviews without needing a GitHub token.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Review safety, onboarding, and operations improvements.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Finding lifecycle</strong> — follow-up reviews report which earlier findings were fixed and which remain unresolved</li>
<li><strong>Coverage honesty</strong> — every summary reports what was actually reviewed; partial reviews never auto-approve, and <code>--fail-on-incomplete</code> turns incomplete coverage into a CI failure</li>
<li><strong>Verification controls</strong> — <code>--verify-provider</code> / <code>--verify-model</code> to cross-check findings with a different model, <code>--verify-failure abort|keep|drop</code></li>
<li><strong><code>pr-sage doctor</code></strong> — diagnose config, keys, and workflow wiring in one command</li>
<li><strong>GitHub Check Run annotations</strong> (<code>--check-run</code>)</li>
<li><strong>Hardened generated workflow</strong> — config loaded from the trusted base commit, concurrency cancellation, self-hosted runner + <code>openai-base-url</code> support for fully local reviews</li>
<li>Scheduled benchmark workflow</li>
</ul>
<h2 id="since-v050-v060">Since v0.5.0 (v0.6.0)</h2>
<p><code>pr-sage init</code> 30-second setup wizard, draft/WIP/skip-label skip rules, <code>maxTokensPerRun</code> cost guard, monorepo <code>paths</code> scoping, <code>locale: auto</code> detection, README demo GIF.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx pr-sage init   <span style="color:#75715e"># 30-second setup</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Linear Release</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/linear-release/</link><pubDate>Fri, 24 Jul 2026 14:07:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/linear-release/</guid><description>Version updated for https://github.com/linear/linear-release-action to version v0.14.6.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 90 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The @linear/release-action GitHub Action automates the synchronization of deployments with Linear releases by integrating CI/CD pipelines into Linear’s release management system. It scans commits for Linear issue identifiers and pull request references, creating or updating releases in Linear automatically. This action helps teams manage releases more efficiently by ensuring that all related issues are linked to the correct releases.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/linear/linear-release-action">https://github.com/linear/linear-release-action</a></strong> to version <strong>v0.14.6</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>90</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/linear-release">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The @linear/release-action GitHub Action automates the synchronization of deployments with Linear releases by integrating CI/CD pipelines into Linear&rsquo;s release management system. It scans commits for Linear issue identifiers and pull request references, creating or updating releases in Linear automatically. This action helps teams manage releases more efficiently by ensuring that all related issues are linked to the correct releases.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Fix release PR body wording for drifted CLI version by @RomainCscn in <a href="https://github.com/linear/linear-release-action/pull/53">https://github.com/linear/linear-release-action/pull/53</a></li>
<li>Release v0.14.6 by @RomainCscn in <a href="https://github.com/linear/linear-release-action/pull/54">https://github.com/linear/linear-release-action/pull/54</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/linear/linear-release-action/compare/v0.14.5...v0.14.6">https://github.com/linear/linear-release-action/compare/v0.14.5...v0.14.6</a></p>
]]></content:encoded></item><item><title>Git Velocity Analyser</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/git-velocity-analyser/</link><pubDate>Fri, 24 Jul 2026 14:06:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/git-velocity-analyser/</guid><description>Version updated for https://github.com/lukaszraczylo/git-velocity to version v1.0.13.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Git Velocity is a GitHub Action that analyzes your code contributions and generates a game-like dashboard to track developer velocity. It automates the process of analyzing repositories, calculating scores and achievements, and providing insights into team activity patterns. The action supports local Git analysis, caching, and authentication options, making it fast and flexible for developers to monitor their contribution velocity effectively.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lukaszraczylo/git-velocity">https://github.com/lukaszraczylo/git-velocity</a></strong> to version <strong>v1.0.13</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/git-velocity-analyser">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Git Velocity is a GitHub Action that analyzes your code contributions and generates a game-like dashboard to track developer velocity. It automates the process of analyzing repositories, calculating scores and achievements, and providing insights into team activity patterns. The action supports local Git analysis, caching, and authentication options, making it fast and flexible for developers to monitor their contribution velocity effectively.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
]]></content:encoded></item><item><title>GitHub Milestones → Jira Epics</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/github-milestones-jira-epics/</link><pubDate>Fri, 24 Jul 2026 14:05:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/github-milestones-jira-epics/</guid><description>Version updated for https://github.com/malparty/gh-milestones-to-jira-epics-action to version 1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action mirrors repository milestones into Jira epics, ensuring one-way synchronization. It maintains an idempotent and safe operation, handling both scheduled runs and manual triggers. The action updates the epic’s summary, description, due date, and labels as needed, while preserving existing manual edits in Jira.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/malparty/gh-milestones-to-jira-epics-action">https://github.com/malparty/gh-milestones-to-jira-epics-action</a></strong> to version <strong>1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-milestones-jira-epics">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action mirrors repository milestones into Jira epics, ensuring one-way synchronization. It maintains an idempotent and safe operation, handling both scheduled runs and manual triggers. The action updates the epic&rsquo;s summary, description, due date, and labels as needed, while preserving existing manual edits in Jira.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>GitHub Milestones → Jira Epics — v1.0.0</em></p>
<p>Mirror a repository&rsquo;s GitHub milestones into Jira Cloud epics — one-way, idempotent, safe to run on a schedule.</p>
<h2 id="core-sync-">Core sync ♻️</h2>
<ul>
<li>One epic per milestone, matched by a structural gh-ms-<number> label via exact JQL lookup — survives title edits and manual changes.</li>
<li>Idempotent upsert: creates epics for new milestones, updates existing ones, and performs zero writes when nothing changed.</li>
<li>Change detection: summary, description, and duedate are written only when they actually differ — no noisy Jira history or watcher spam.</li>
</ul>
<h2 id="field-mapping-">Field mapping 🔗</h2>
<ul>
<li>Summary = milestone title verbatim.</li>
<li>Rich ADF description: &ldquo;do not edit&rdquo; notice, a closed/total issues closed header, the milestone description, and Open/Closed issue lists
— with pull requests excluded from both counts and lists, sorted deterministically.</li>
<li>Due date set only when the milestone has one, and never cleared afterward.</li>
<li>Start date never touched — a manually set start date always survives.</li>
<li>Labels reconciled as a superset: adds gh-ms-<n> + your configured labels, never prunes labels a human added in Jira.</li>
<li>Status sync by status category (done/new) — closes/reopens epics with milestone state, respects a manually set In Progress, and works across renamed or non-English statuses.</li>
</ul>
<h2 id="configuration--safety-">Configuration &amp; safety 🔒</h2>
<ul>
<li>Fully repo-agnostic: everything (project key, epic type id, extra labels, tokens) is an action input — nothing hardcoded.</li>
<li>Dry-run mode to preview every create/update/transition without writing.</li>
<li>only input/flag to scope a run to a single milestone (near-real-time on milestone events).</li>
<li>Fail-fast auth preflight with an actionable message (including the classic-vs-scoped API-token pitfall), and Jira error responses surfaced in full — no opaque 400s.</li>
<li>Bounded retry/backoff on rate limits and transient 5xx.</li>
<li>Clear run summary and exit codes; outputs created / updated / unchanged / skipped.</li>
</ul>
]]></content:encoded></item><item><title>lgtmaybe</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/lgtmaybe/</link><pubDate>Fri, 24 Jul 2026 14:04:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/lgtmaybe/</guid><description>Version updated for https://github.com/MattJColes/lgtmaybe to version lgtmaybe-v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The lgtmaybe GitHub Action reviews PRs by analyzing code changes and surrounding lines to identify potential issues such as logic errors, security vulnerabilities, and missing tests. It provides inline review comments and a summary of findings, helping reviewers focus on the most critical changes in context. The action supports multiple review levels (info through critical) and can be configured to run different presets based on branch status.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MattJColes/lgtmaybe">https://github.com/MattJColes/lgtmaybe</a></strong> to version <strong>lgtmaybe-v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lgtmaybe">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The lgtmaybe GitHub Action reviews PRs by analyzing code changes and surrounding lines to identify potential issues such as logic errors, security vulnerabilities, and missing tests. It provides inline review comments and a summary of findings, helping reviewers focus on the most critical changes in context. The action supports multiple review levels (info through critical) and can be configured to run different presets based on branch status.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="100-2026-07-24"><a href="https://github.com/MattJColes/lgtmaybe/compare/lgtmaybe-v0.13.1...lgtmaybe-v1.0.0">1.0.0</a> (2026-07-24)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>action:</strong> post reviews as a GitHub App via app_id/app_private_key inputs (<a href="https://github.com/MattJColes/lgtmaybe/issues/197">#197</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/88ec1e4e03284a28c2e8e97ccd00f98447178a41">88ec1e4</a>)</li>
</ul>
<h3 id="documentation">Documentation</h3>
<ul>
<li>optimise the docs site for SEO and LLM crawlers (<a href="https://github.com/MattJColes/lgtmaybe/issues/200">#200</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/d46078f18ebd97eedfa33b6f01e0d45f4eed32f2">d46078f</a>)</li>
</ul>
]]></content:encoded></item><item><title>move-test-gen coverage check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/move-test-gen-coverage-check/</link><pubDate>Fri, 24 Jul 2026 14:03:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/move-test-gen-coverage-check/</guid><description>Version updated for https://github.com/mehvetero/move-test-gen to version v1.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The move-test-gen GitHub Action is an Agent Skill that automatically generates edge-case test suites for Sui Move functions. It focuses on covering various edge cases such as boundary values, arithmetic edges, access control issues, state machine problems, and economic concerns, providing a comprehensive set of tests to ensure robustness in Move smart contracts. The action can be used to generate tests based on user requests or automatically check the coverage of existing tests to identify potential gaps.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mehvetero/move-test-gen">https://github.com/mehvetero/move-test-gen</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/move-test-gen-coverage-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The move-test-gen GitHub Action is an Agent Skill that automatically generates edge-case test suites for Sui Move functions. It focuses on covering various edge cases such as boundary values, arithmetic edges, access control issues, state machine problems, and economic concerns, providing a comprehensive set of tests to ensure robustness in Move smart contracts. The action can be used to generate tests based on user requests or automatically check the coverage of existing tests to identify potential gaps.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new-in-v130">What&rsquo;s new in v1.3.0</h2>
<p>MOV-002 and MOV-004 now use a lightweight Move parser instead of line-level regex. The parser tracks variable types through declarations, casts, and destructuring — so it knows that <code>numerator1</code> declared as <code>liquidity_u256 &lt;&lt; RESOLUTION</code> is u256, not u64. This killed most of the false positives that required naming-convention heuristics in v1.2.0.</p>
<h3 id="mov-004-unsafe-downcast-new-rule">MOV-004: unsafe downcast (new rule)</h3>
<p>Flags <code>(expr as u64)</code> from u128/u256 without a preceding overflow assert. Move&rsquo;s <code>as</code> silently truncates — unlike arithmetic ops which abort. Found 3 true positives in Bucket Protocol (pending reward/debt calculations downcast mul_factor_u128 results without checking), which led to the fix PR below.</p>
<h3 id="parser-integration-mov-002">Parser integration (MOV-002)</h3>
<p>Turbos CLMM went from 14 findings to 3 after the parser was wired in. Variables cast to u256 on earlier lines are now tracked through the function body instead of relying on <code>_u256</code> suffix matching.</p>
<h3 id="bucket-protocol-fix-pr">Bucket Protocol fix PR</h3>
<p>MOV-002 flagged <code>collateral_raw_value * pow(10, decimal_diff)</code> in Bucket&rsquo;s value conversion functions — <code>mul_factor</code> promotes to u128 internally, the scaling multiplication right after undoes it. Submitted a fix: <a href="https://github.com/Bucket-Protocol/v1-core/pull/12">https://github.com/Bucket-Protocol/v1-core/pull/12</a></p>
<h3 id="validation">Validation</h3>
<table>
  <thead>
      <tr>
          <th>Protocol</th>
          <th>Files</th>
          <th>Findings</th>
          <th>Notes</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Kriya DEX</td>
          <td>3</td>
          <td>1</td>
          <td>MOV-001 update_pool (confirmed TP from our Issue #2)</td>
      </tr>
      <tr>
          <td>Scallop</td>
          <td>172</td>
          <td>2</td>
          <td>MOV-002 liquidation mul + MOV-004 loop counter</td>
      </tr>
      <tr>
          <td>Bucket</td>
          <td>22</td>
          <td>40</td>
          <td>25 MOV-001 permissionless DeFi (known FP pattern), rest legitimate</td>
      </tr>
      <tr>
          <td>Turbos</td>
          <td>24</td>
          <td>21</td>
          <td>math library downcasts + tick arithmetic</td>
      </tr>
  </tbody>
</table>
<h3 id="infrastructure">Infrastructure</h3>
<ul>
<li><code>scripts/move-parser.mjs</code> — function-level parser: signatures, params with types, variable declarations, cast tracking, assert locations</li>
<li>gate-selftest: 11/11 cases, MOV-004 pins added (unsafe flagged, assert skipped, library skipped, small field skipped, test skipped)</li>
<li>Rules: 4 (MOV-001 through MOV-004)</li>
</ul>
<p>Diff from v1.2.0: <a href="https://github.com/mehvetero/move-test-gen/compare/v1.2.0...v1.3.0">https://github.com/mehvetero/move-test-gen/compare/v1.2.0...v1.3.0</a></p>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/totem-shield/</link><pubDate>Fri, 24 Jul 2026 14:02:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.105.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Totem is a tool that keeps project lessons and rules in the repository itself, ensuring architectural integrity by preventing re-inventing standard patterns. It uses a file-based toolkit with plain markdown lessons, a queryable knowledge index derived from them, and compiled lint rules enforced by a local, deterministic zero-LLM linter. This approach reduces friction and improves code quality by preventing common architectural mistakes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.105.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Totem is a tool that keeps project lessons and rules in the repository itself, ensuring architectural integrity by preventing re-inventing standard patterns. It uses a file-based toolkit with plain markdown lessons, a queryable knowledge index derived from them, and compiled lint rules enforced by a local, deterministic zero-LLM linter. This approach reduces friction and improves code quality by preventing common architectural mistakes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>MotionScore Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/motionscore-guard/</link><pubDate>Fri, 24 Jul 2026 14:01:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/motionscore-guard/</guid><description>Version updated for https://github.com/motiondivision/motionscore-guard to version v1.0.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary MotionScore Guard automates animation performance auditing for pull requests by loading pages in a real browser on GitHub runners and grading them with S to F tiers. It supports free access for any repository but provides a paid plan with token-based gating that fails builds if page grades fall below specified thresholds. The action can audit specific paths and upload reports, making it easy to integrate into workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/motiondivision/motionscore-guard">https://github.com/motiondivision/motionscore-guard</a></strong> to version <strong>v1.0.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/motionscore-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>MotionScore Guard automates animation performance auditing for pull requests by loading pages in a real browser on GitHub runners and grading them with S to F tiers. It supports free access for any repository but provides a paid plan with token-based gating that fails builds if page grades fall below specified thresholds. The action can audit specific paths and upload reports, making it easy to integrate into workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Runs motionscore CLI 0.1.2.</p>
]]></content:encoded></item><item><title>repro-check runnability</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/repro-check-runnability/</link><pubDate>Fri, 24 Jul 2026 14:00:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/repro-check-runnability/</guid><description>Version updated for https://github.com/nelsonjordanme/repro-check to version v0.11.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The repro-check GitHub Action automates the process of running and troubleshooting old research code, helping to identify and fix issues such as missing files, outdated dependencies, and removed APIs. It provides a runnability scaffold for reproducing computational papers by finding scripts, attempting to run them, and applying known fixes until they either run successfully or provide detailed information on where they stopped and what needs to be done next.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nelsonjordanme/repro-check">https://github.com/nelsonjordanme/repro-check</a></strong> to version <strong>v0.11.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/repro-check-runnability">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The repro-check GitHub Action automates the process of running and troubleshooting old research code, helping to identify and fix issues such as missing files, outdated dependencies, and removed APIs. It provides a runnability scaffold for reproducing computational papers by finding scripts, attempting to run them, and applying known fixes until they either run successfully or provide detailed information on where they stopped and what needs to be done next.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><code>--ai-suggest</code> asks an LLM to draft a diagnosis + suggested fix on a hand-off, using YOUR OWN ANTHROPIC_API_KEY or OPENAI_API_KEY (your machine, your bill). Ships with no key of its own; no key set = feature off, no fallback. The suggestion is flagged, never auto-applied, and never counted as a fix. <code>pip install --upgrade repro-check</code> — <a href="https://pypi.org/project/repro-check/0.11.0/">https://pypi.org/project/repro-check/0.11.0/</a></p>
]]></content:encoded></item><item><title>LinkML (linkml-scala)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/linkml-linkml-scala/</link><pubDate>Fri, 24 Jul 2026 13:59:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/linkml-linkml-scala/</guid><description>Version updated for https://github.com/NeverBlink-OSS/linkml-scala-action to version v0.11.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, linkml-scala-action, automates the validation and generation of LinkML schemas in CI using Node.js. It leverages the @neverblink/linkml npm package to validate schemas by linting them or generating various output formats such as JSON Schema, SHACL, RDF/SDLC, and Scala classes. Key features include inline annotations for GitHub checks, fast execution times, and support for importing additional schema files. The action is designed to be lightweight and compatible with any Node.js runner environment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NeverBlink-OSS/linkml-scala-action">https://github.com/NeverBlink-OSS/linkml-scala-action</a></strong> to version <strong>v0.11.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/linkml-linkml-scala">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>linkml-scala-action</code>, automates the validation and generation of LinkML schemas in CI using Node.js. It leverages the <code>@neverblink/linkml</code> npm package to validate schemas by linting them or generating various output formats such as JSON Schema, SHACL, RDF/SDLC, and Scala classes. Key features include inline annotations for GitHub checks, fast execution times, and support for importing additional schema files. The action is designed to be lightweight and compatible with any Node.js runner environment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Tracks <a href="https://github.com/NeverBlink-OSS/linkml-scala/releases/tag/v0.11.1">linkml-scala v0.11.1</a>.</p>
<p>Bundles <code>@neverblink/linkml@0.11.1</code>.</p>
<ul>
<li>Pin <code>uses: NeverBlink-OSS/linkml-scala-action@v0.11.1</code> for reproducibility.</li>
<li>Pin <code>@v1</code> for automatic patch/minor updates.</li>
</ul>
]]></content:encoded></item><item><title>AI Harness Doctor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/ai-harness-doctor/</link><pubDate>Fri, 24 Jul 2026 13:57:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/ai-harness-doctor/</guid><description>Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v1.16.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Harness Doctor is a tool that audits AI harness files to ensure they are well-organized, up-to-date, and effective. It helps teams consolidate scattered guidance into a single AGENTS.md file while measuring improvements in agent answers, reducing latency, and optimizing costs. The action checks for inconsistencies, overlapping instructions, declaration-vs-code mismatches, and conflicts across various agent-config files.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NieZhuZhu/ai-harness-doctor">https://github.com/NieZhuZhu/ai-harness-doctor</a></strong> to version <strong>v1.16.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-harness-doctor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AI Harness Doctor is a tool that audits AI harness files to ensure they are well-organized, up-to-date, and effective. It helps teams consolidate scattered guidance into a single <code>AGENTS.md</code> file while measuring improvements in agent answers, reducing latency, and optimizing costs. The action checks for inconsistencies, overlapping instructions, declaration-vs-code mismatches, and conflicts across various agent-config files.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(drift): stop flagging GitHub Actions uses references as missing paths by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/332">https://github.com/NieZhuZhu/ai-harness-doctor/pull/332</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NieZhuZhu/ai-harness-doctor/compare/v1...v1.16.3">https://github.com/NieZhuZhu/ai-harness-doctor/compare/v1...v1.16.3</a></p>
]]></content:encoded></item><item><title>NetBird CLI Connect</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/netbird-cli-connect/</link><pubDate>Fri, 24 Jul 2026 13:56:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/netbird-cli-connect/</guid><description>Version updated for https://github.com/NomisCZ/netbird-cli-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of connecting to a NetBird network as an ephemeral peer, enabling access to internal services or databases over a secure WireGuard mesh. It allows users to configure various parameters such as setup keys, management URLs, and DNS settings to facilitate seamless connectivity. The action also provides an option to wait for the local NetBird DNS resolver to be ready before proceeding with subsequent steps, which is useful for ensuring proper resolution of private resources.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NomisCZ/netbird-cli-action">https://github.com/NomisCZ/netbird-cli-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/netbird-cli-connect">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of connecting to a NetBird network as an ephemeral peer, enabling access to internal services or databases over a secure WireGuard mesh. It allows users to configure various parameters such as setup keys, management URLs, and DNS settings to facilitate seamless connectivity. The action also provides an option to wait for the local NetBird DNS resolver to be ready before proceeding with subsequent steps, which is useful for ensuring proper resolution of private resources.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add <code>dns-hosts</code> so the action waits until listed hostnames resolve to <strong>private IPs only</strong> (NetBird CGNAT / RFC1918), avoiding public DNS wins that call APIs from outside the mesh (e.g. 403).</li>
<li>Clarify split-horizon DNS wait behavior in README and action inputs.</li>
<li>Simplify private-IP checks in <code>wait-for-dns.sh</code>.</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NomisCZ/netbird-cli-action/compare/v1.0.0...v1.1.0">https://github.com/NomisCZ/netbird-cli-action/compare/v1.0.0...v1.1.0</a></p>
]]></content:encoded></item><item><title>Directory Listing Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/directory-listing-generator/</link><pubDate>Fri, 24 Jul 2026 13:55:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/directory-listing-generator/</guid><description>Version updated for https://github.com/pranabdas/directory-listing to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action generates directory listings for GitHub Pages and automates the deployment process using GitHub Actions. It supports generating listings from a specified folder, excluding files or directories, and deploying them to either the same repository’s gh-pages branch or an external repository. The action can also customize various aspects such as site URL, base path, site name, footer text, and commit messages.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pranabdas/directory-listing">https://github.com/pranabdas/directory-listing</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/directory-listing-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action generates directory listings for GitHub Pages and automates the deployment process using GitHub Actions. It supports generating listings from a specified folder, excluding files or directories, and deploying them to either the same repository&rsquo;s <code>gh-pages</code> branch or an external repository. The action can also customize various aspects such as site URL, base path, site name, footer text, and commit messages.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>major refactoring by @pranabdas in <a href="https://github.com/pranabdas/directory-listing/pull/1">https://github.com/pranabdas/directory-listing/pull/1</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@pranabdas made their first contribution in <a href="https://github.com/pranabdas/directory-listing/pull/1">https://github.com/pranabdas/directory-listing/pull/1</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pranabdas/directory-listing/commits/v1.0.0">https://github.com/pranabdas/directory-listing/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>Wrangler Deploy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/wrangler-deploy/</link><pubDate>Fri, 24 Jul 2026 13:54:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/wrangler-deploy/</guid><description>Version updated for https://github.com/risu729/wrangler-deploy-action to version v1.1.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment of Cloudflare Workers through GitHub Actions, providing a consistent workflow for preview, dry-run, and production deployments. It leverages Wrangler to manage worker deployments and outputs relevant information about the deployment to the GitHub Actions job summary. The action handles authentication credentials and ensures that only qualified users can deploy production workers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/risu729/wrangler-deploy-action">https://github.com/risu729/wrangler-deploy-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wrangler-deploy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment of Cloudflare Workers through GitHub Actions, providing a consistent workflow for preview, dry-run, and production deployments. It leverages Wrangler to manage worker deployments and outputs relevant information about the deployment to the GitHub Actions job summary. The action handles authentication credentials and ensures that only qualified users can deploy production workers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="110-2026-07-21"><a href="https://github.com/risu729/wrangler-deploy-action/compare/v1.0.0...v1.1.0">1.1.0</a> (2026-07-21)</h1>
<h3 id="features">Features</h3>
<ul>
<li>support package-local Wrangler (<a href="https://github.com/risu729/wrangler-deploy-action/issues/5">#5</a>) (<a href="https://github.com/risu729/wrangler-deploy-action/commit/a282705ddae16c69574bfe62cdda8cef47f963cb">a282705</a>)</li>
</ul>
]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/rumdl-action/</link><pubDate>Fri, 24 Jul 2026 13:53:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.42.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
rumdl is a high-performance Markdown linter and formatter written in Rust. It offers over 77 lint rules, automatic formatting with the --fix option, and support for multiple Markdown flavors. The action provides detailed error reporting and is optimized for speed, making it suitable for use in CI/CD pipelines and editor integrations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.42</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>rumdl is a high-performance Markdown linter and formatter written in Rust. It offers over 77 lint rules, automatic formatting with the <code>--fix</code> option, and support for multiple Markdown flavors. The action provides detailed error reporting and is optimized for speed, making it suitable for use in CI/CD pipelines and editor integrations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>mojibake</strong>: new rule MD083 for mojibake detection (#753) (<a href="https://github.com/rvben/rumdl/commit/552842bc70abf9a58317e1b47737321ff9b44e4c">552842b</a>)</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>lint_context</strong>: prevent panic when HTML tag window splits a UTF-8 char (<a href="https://github.com/rvben/rumdl/commit/d14b252671ec96cf7a2beea148a9a0f8c3341d4b">d14b252</a>)</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.42-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.42-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.42-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.42-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-apple-darwin.tar.gz">rumdl-v0.2.42-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-apple-darwin.tar.gz">rumdl-v0.2.42-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-pc-windows-msvc.zip">rumdl-v0.2.42-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.42/rumdl-v0.2.42-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/bernstein-multi-agent-orchestration/</link><pubDate>Fri, 24 Jul 2026 13:52:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.8.4.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bernstein is a deterministic orchestrator for CLI coding agents that schedules tasks in plain Python and ensures reproducibility and auditability. It uses an always-on lineage spine to track changes and an HMAC-chained audit log to verify results offline, making it suitable for environments with strict requirements on transparency and repeatability.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.8.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Bernstein is a deterministic orchestrator for CLI coding agents that schedules tasks in plain Python and ensures reproducibility and auditability. It uses an always-on lineage spine to track changes and an HMAC-chained audit log to verify results offline, making it suitable for environments with strict requirements on transparency and repeatability.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>A bug-fix release. This wave closes the defects surfaced by running 3.8.2/3.8.3 end to end across cluster mode, the task lifecycle, and the verifiability core: multi-machine setups that could never complete a task, runs that declared success without a deliverable, and audit/lineage surfaces that verified less than they claimed. Nothing here changes a public API; upgrade in place.</p>
<h2 id="cluster-mode">Cluster mode</h2>
<ul>
<li>Worker registration works with a single credential: the raw cluster secret (or the operator API token) now clears both auth layers, which previously accepted disjoint credentials with no issuance surface for the inner one (#2805). The cluster secret is deliberately barred from operator-only admin endpoints.</li>
<li>A tokenless or misconfigured worker join now fails fast with an actionable message naming <code>--token</code>, <code>BERNSTEIN_AUTH_TOKEN</code>, and the auto-generated token path, instead of silently retrying a 401 every 5 seconds forever; the deployment docs document the real join flow (#2802).</li>
<li>Remote task completion is possible: the completion URL respects <code>BERNSTEIN_SERVER_URL</code> instead of hardcoding localhost, and the worker loop reports terminal state for every reaped process (#2808).</li>
<li>Dead workers are detected and their claimed tasks requeued: the node reaper now always runs, and each claim records the owning node (#2801).</li>
<li>Workers honor the task&rsquo;s model/adapter selection instead of discarding it and refusing non-Claude adapters; a <code>--model</code> flag plus adapter profiles resolve sensible defaults (#2804).</li>
</ul>
<h2 id="task-lifecycle-and-run-correctness">Task lifecycle and run correctness</h2>
<ul>
<li>A suspiciously fast clean agent exit is no longer auto-completed into &ldquo;done&rdquo; with an empty diff; it routes to retry and surfaces as <code>clean_exit_unverified</code> (#2810).</li>
<li>Retry storms are capped: backoff and fail-counts follow the retried task lineage, so a structurally dead spawn terminates within the cap instead of ballooning a 5-step plan into ~97 task records (#2806).</li>
<li>Resume after stop no longer declares a run complete while dropping open tasks: stopped sessions persist their open work and re-plan on resume (#2798).</li>
<li>A supervisor watching an agent stuck at spawn-time &ldquo;starting&rdquo; now escalates through SIGTERM/SIGKILL and requeues the task instead of rewriting the shutdown signal forever (#2796).</li>
<li>The CLI no longer opens a browser dashboard that will greet the operator with a 401; it probes first and prints the working alternatives (#2794).</li>
<li>A manager/planning spawn that would run unsandboxed in the operator checkout is refused up front, and writes that escape the worktree are contained at reap time instead of landing untracked in the operator&rsquo;s checkout (#2793).</li>
<li>An explicit <code>--sandbox</code> override that cannot be honored fails loudly instead of degrading to host execution (#2847).</li>
<li><code>--dry-run</code> validates the seed through the same parser as a real run and warns on unparseable backlog files (#2849).</li>
</ul>
<h2 id="audit-chain-lineage-and-replay">Audit chain, lineage, and replay</h2>
<ul>
<li>The task server and spawner now resolve the same audit HMAC key, and appends hold a cross-process lock, so a mixed-writer chain verifies instead of failing on key mismatch; concurrent writers serialize into one verifiable chain (#2791).</li>
<li>Ambient host <code>BAGGAGE</code>/<code>TRACEPARENT</code> env (foreign Sentry/OTEL ids) is no longer sealed into lineage hashes; only orchestrator-owned context is recorded (#2787).</li>
<li>A lineage chain that contains only the journal seal no longer passes verification silently: <code>bernstein lineage verify</code> reports SEAL ONLY and exits non-zero when no artifact provenance exists (#2789).</li>
<li>Deterministic replay refuses to run live: activating replay for a run with no recording aborts before any agent spawns instead of silently executing against the world (#2790).</li>
<li>Nightly adapter-canary receipts are anchored into the HMAC audit chain as documented (#2850), chronic skip verdicts escalate to issues, and a stale or absent last-green is surfaced (#2845).</li>
<li>Qwen CLI-adapter runs record real token usage in the cost ledger (#2851).</li>
</ul>
<h2 id="cloud-and-cloudflare-adapter-surfaces">Cloud and Cloudflare adapter surfaces</h2>
<ul>
<li>The <code>cloudflare</code> and <code>codex_cloudflare</code> adapters refuse fast with actionable errors instead of pretending: one had no worker-trigger path (every task timed out with zero artifacts), the other targeted a REST API that does not exist; both are marked experimental in docs (#2782, #2783).</li>
<li><code>bernstein cloud init</code> scaffolds a runnable free-tier worker, <code>cloud deploy</code> no longer points at a template the wheel does not ship, dead-endpoint errors are actionable instead of raw tracebacks, and the template declares no paid bindings (#2784).</li>
</ul>
<h2 id="cli-and-dashboard">CLI and dashboard</h2>
<ul>
<li>Operator-surface defects from 3.8.2 testing: no more <code>.claude/mcp.json</code> churn on every run, <code>--fresh</code> works on <code>run</code>, <code>stop --force</code> reports only confirmed-terminated processes, <code>ps</code> sees a live leaf process, dry-run previews are populated, and the dashboard stops mislabeling models (#2800).</li>
<li><code>worker --adapter</code> accepts every registered adapter (same registry as <code>run --cli</code>), <code>--idle</code> documents that it forces the mock backend internally, <code>start</code> appears in <code>--help</code>, and container worker health is documented (#2807). Remaining wiring-level items are tracked in #2874.</li>
</ul>
<h2 id="ci-and-maintenance">CI and maintenance</h2>
<ul>
<li>The post-CI dispatcher boots again: the auto-release call granted less than the callee requested and every dispatcher run since 2026-07-19 ended as a silent startup_failure — auto-release, auto-heal, CI-fix, and bisect were all dead (#2866). A regression test now asserts caller grants cover every callee job request (#2867).</li>
<li>Hosted SonarQube, GlitchTip, Dependency-Track, and the operator Telegram alert integrations are retired to simplify operations (#2859, #2863); the observability snapshot runs on manual dispatch only (#2856).</li>
</ul>
<h2 id="thanks">Thanks</h2>
<p>Thanks to the external contributors in this release:</p>
<ul>
<li>@AnayGarodia — centralized the artifact constants and typed the wire payloads so the task and adapter surfaces share one definition (#2838)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sipyourdrink-ltd/bernstein/compare/v3.8.3...v3.8.4">https://github.com/sipyourdrink-ltd/bernstein/compare/v3.8.3...v3.8.4</a></p>
]]></content:encoded></item><item><title>Setup UniRTM</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/setup-unirtm/</link><pubDate>Fri, 24 Jul 2026 13:51:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/setup-unirtm/</guid><description>Version updated for https://github.com/snowdreamtech/setup-unirtm to version v0.6.0.
This action is used across all versions by 36 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action setup-unirtm automates the installation and configuration of UniRTM, a runtime and tools manager. It intelligently detects the best install method based on available runtimes and supports multiple methods such as npm, pip, GitHub Releases, and go installs. The action also offers features like caching using Handlebars templates and supports GitHub proxy configurations for restricted networks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/snowdreamtech/setup-unirtm">https://github.com/snowdreamtech/setup-unirtm</a></strong> to version <strong>v0.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>36</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-unirtm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action setup-unirtm automates the installation and configuration of UniRTM, a runtime and tools manager. It intelligently detects the best install method based on available runtimes and supports multiple methods such as npm, pip, GitHub Releases, and go installs. The action also offers features like caching using Handlebars templates and supports GitHub proxy configurations for restricted networks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="060-2026-07-24"><a href="https://github.com/snowdreamtech/setup-unirtm/compare/v0.5.0...v0.6.0">0.6.0</a> (2026-07-24)</h2>
<h3 id="features">Features</h3>
<ul>
<li>add support for concurrent blob downloads in artifact caching (<a href="https://github.com/snowdreamtech/setup-unirtm/commit/9b9d1bb9323907dcc47782922d82f03471ab152a">9b9d1bb</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>correct pip package name and remove legacy Harden Runner (<a href="https://github.com/snowdreamtech/setup-unirtm/commit/190f867ac9f43edf7c7ebe2ea27926d3cab76871">190f867</a>)</li>
</ul>
]]></content:encoded></item><item><title>DLP Secret Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/dlp-secret-scan/</link><pubDate>Fri, 24 Jul 2026 13:50:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/dlp-secret-scan/</guid><description>Version updated for https://github.com/SpiderCob/dlp-scan-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses dlp-patterns to scan a codebase for secrets, PII, and sensitive data. It helps detect over 50 categories of sensitive information and provides detailed reports on findings, including the number and severity levels. The action can be configured to focus only on API keys and credentials or to scan everything, including PII. Users can set thresholds for severities to trigger different actions in CI/CD pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SpiderCob/dlp-scan-action">https://github.com/SpiderCob/dlp-scan-action</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/dlp-secret-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses dlp-patterns to scan a codebase for secrets, PII, and sensitive data. It helps detect over 50 categories of sensitive information and provides detailed reports on findings, including the number and severity levels. The action can be configured to focus only on API keys and credentials or to scan everything, including PII. Users can set thresholds for severities to trigger different actions in CI/CD pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Scan your codebase for secrets and PII in CI — zero configuration needed.</p>
<ul>
<li>Detects 50+ categories: AWS/GitHub/Stripe/Slack keys, JWTs, private keys, DB connection strings, SSNs, credit cards, and more</li>
<li>Entropy gating and Luhn validation to minimise false positives</li>
<li><code>secrets-only</code> mode for fast source code scanning</li>
<li>Configurable <code>fail-on</code> severity: critical, high, medium, low</li>
<li>Outputs <code>findings-count</code> and <code>highest-severity</code> for downstream steps</li>
</ul>
<p>Powered by <a href="https://github.com/SpiderCob/dlp-patterns">dlp-patterns</a> — Apache 2.0</p>
]]></content:encoded></item><item><title>Install bashunit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/install-bashunit/</link><pubDate>Fri, 24 Jul 2026 13:49:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/install-bashunit/</guid><description>Version updated for https://github.com/TypedDevs/bashunit to version 0.43.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action is a simple testing framework for Bash scripts that automates the process of writing and running tests. It focuses on providing developers with a lightweight, fast testing experience with over 70 assertions across various families, including equality, strings, exit codes, numeric checks, arrays, file/directory permissions, JSON assertions, date comparisons, duration checks, snapshots, and test doubles. The framework is designed to be user-friendly and developer-centric, offering interactive learning through the learn command and extensive documentation at bashunit.com.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TypedDevs/bashunit">https://github.com/TypedDevs/bashunit</a></strong> to version <strong>0.43.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-bashunit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action is a simple testing framework for Bash scripts that automates the process of writing and running tests. It focuses on providing developers with a lightweight, fast testing experience with over 70 assertions across various families, including equality, strings, exit codes, numeric checks, arrays, file/directory permissions, JSON assertions, date comparisons, duration checks, snapshots, and test doubles. The framework is designed to be user-friendly and developer-centric, offering interactive learning through the <code>learn</code> command and extensive documentation at bashunit.com.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-improvements">✨ Improvements</h2>
<ul>
<li>Branch coverage now reports loop constructs (<code>while</code>/<code>until</code>/<code>for</code>/<code>select</code>): the loop body is a single-arm branch, marked covered only when the loop ran at least once, so a never-entered zero-iteration loop surfaces as an uncovered branch (#855)</li>
</ul>
<h2 id="-changes">🛠️ Changes</h2>
<ul>
<li>Core string assertions (<code>assert_contains</code>/<code>assert_not_contains</code>, <code>assert_matches</code>/<code>assert_not_matches</code>, <code>assert_string_starts_with</code>/<code>assert_string_ends_with</code> and their negations) no longer fork a subshell per call to join their arguments; a fork-free join with identical behaviour replaces it (#844)</li>
<li>The array, date, duration, json, files and folders assertions now resolve their failure label through the fork-free slot helper instead of a per-call command substitution — same labels, fewer forks</li>
<li>Parallel test workers name their per-test result file by a per-suite ordinal instead of <code>mktemp</code> + <code>mv</code>, removing two forks per test (plus the <code>echo \| tr \| sed</code> arg sanitizing for data-provider tests) with identical result aggregation (#851)</li>
</ul>
<h2 id="-contributors">👥 Contributors</h2>
<ul>
<li>@Chemaclass</li>
</ul>
<h2 id="checksum">Checksum</h2>
<p>SHA256: <code>151f3647964d53d3f5a7065c141790fc1b66ea3039024c80ed09b3a9602064a2</code></p>
<p><strong>Full Changelog:</strong> <a href="https://github.com/TypedDevs/bashunit/compare/0.42.0...0.43.0">0.42.0&hellip;0.43.0</a></p>
]]></content:encoded></item><item><title>MCP Test Harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/mcp-test-harness/</link><pubDate>Fri, 24 Jul 2026 13:48:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/mcp-test-harness/</guid><description>Version updated for https://github.com/vaquarkhan/mcp-test-harness to version v3.0.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The MCP Test Harness is a CI tool that automates and tests the correctness of MCP servers. It helps teams ensure their AI server features do not break silently and provides evidence of compliance with standards like JUnit, SARIF, and HTML reports. By using this action, developers can quickly verify the reliability and performance of their MCP servers before they are deployed, reducing costs associated with quality assurance and improving overall trust in their codebase.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vaquarkhan/mcp-test-harness">https://github.com/vaquarkhan/mcp-test-harness</a></strong> to version <strong>v3.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcp-test-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The MCP Test Harness is a CI tool that automates and tests the correctness of MCP servers. It helps teams ensure their AI server features do not break silently and provides evidence of compliance with standards like JUnit, SARIF, and HTML reports. By using this action, developers can quickly verify the reliability and performance of their MCP servers before they are deployed, reducing costs associated with quality assurance and improving overall trust in their codebase.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="mcp-test-harness-309">mcp-test-harness 3.0.9</h2>
<p>CRA evidence packaging release: SBOM on publish, VDP security policy, optional <code>--cra-output</code> CRA reporter, and version alignment across core + 17 vendor shims.</p>
<h3 id="publish">Publish</h3>
<ul>
<li>Core + Docker: triggered by this tag</li>
<li>Vendor shims: <code>publish-packages</code> workflow_dispatch from main</li>
</ul>
]]></content:encoded></item><item><title>Symfony Security Auditor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/symfony-security-auditor/</link><pubDate>Fri, 24 Jul 2026 13:46:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/symfony-security-auditor/</guid><description>Version updated for https://github.com/vinceAmstoutz/symfony-security-auditor to version 1.17.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is an AI-powered security auditor for Symfony applications that automates the detection of application-level vulnerabilities missed by traditional SAST tools. It targets business logic flaws and multi-file attack chains, providing a comprehensive validation report in console, JSON, SARIF, HTML, or Markdown formats. The action uses adversarial “Attacker” and skeptical “Reviewer” agents to identify and cull false positives over three iterations, ensuring a validated report for security audits in Symfony projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vinceAmstoutz/symfony-security-auditor">https://github.com/vinceAmstoutz/symfony-security-auditor</a></strong> to version <strong>1.17.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/symfony-security-auditor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is an AI-powered security auditor for Symfony applications that automates the detection of application-level vulnerabilities missed by traditional SAST tools. It targets business logic flaws and multi-file attack chains, providing a comprehensive validation report in console, JSON, SARIF, HTML, or Markdown formats. The action uses adversarial &ldquo;Attacker&rdquo; and skeptical &ldquo;Reviewer&rdquo; agents to identify and cull false positives over three iterations, ensuring a validated report for security audits in Symfony projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci: add 7-day Dependabot cooldown by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/commit/696801b">https://github.com/vinceAmstoutz/symfony-security-auditor/commit/696801b</a></li>
<li>fix(standalone): windows download errors by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/192">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/192</a></li>
<li>feat(standalone): one liner installation by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/191">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/191</a></li>
<li>fix(standalone): resolve self-update binary path on macOS by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/194">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/194</a></li>
<li>test: relax fork/boot slow-test bound by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/195">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/195</a></li>
<li>feat(command): add scriptable options by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/193">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/193</a></li>
<li>feat(command): add a doctor preflight command by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/196">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/196</a></li>
<li>feat(standalone): notify when a newer release is available by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/197">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/197</a></li>
<li>fix(standalone): throttle failed update checks too by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/199">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/199</a></li>
<li>fix(standalone): skip update notice after update by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/200">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/200</a></li>
<li>fix(standalone): honor SSA_NO_UPDATE_CHECK=0 by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/206">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/206</a></li>
<li>fix(standalone): SSA_INIT fallback under POSIX sh by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/198">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/198</a></li>
<li>fix(standalone): fail fast on unsupported platforms by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/201">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/201</a></li>
<li>docs: correct Git Bash install guidance by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/203">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/203</a></li>
<li>feat(command): add init &ndash;force by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/204">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/204</a></li>
<li>docs: scope PHP/Symfony requirement to the bundle by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/208">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/208</a></li>
<li>docs: FAQ on auditing older Symfony and PHP by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/209">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/209</a></li>
<li>docs: correct init options adoption claim by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/207">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/207</a></li>
<li>fix(command): normalize provider slugs in init by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/202">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/202</a></li>
<li>fix(standalone): locate only executable binaries by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/205">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/205</a></li>
<li>chore: release 1.17.0 by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/210">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/210</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/compare/1.16.0...1.17.0">https://github.com/vinceAmstoutz/symfony-security-auditor/compare/1.16.0...1.17.0</a></p>
]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/rustscript-action/</link><pubDate>Fri, 24 Jul 2026 13:45:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.2.10.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RustScript is a tool that interprets and runs Rust scripts without compiling them fully. It allows users to execute Rust code directly from the command line, bypassing the need for Cargo or type checking. The action supports running scripts, validating them without execution, building native binaries, listing supported features, clearing caches, and updating releases.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.2.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>RustScript is a tool that interprets and runs Rust scripts without compiling them fully. It allows users to execute Rust code directly from the command line, bypassing the need for Cargo or type checking. The action supports running scripts, validating them without execution, building native binaries, listing supported features, clearing caches, and updating releases.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.2...v0.2.10">https://github.com/VladasZ/rustscript/compare/v0.2...v0.2.10</a></p>
]]></content:encoded></item><item><title>Legion Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/legion-runner/</link><pubDate>Fri, 24 Jul 2026 13:44:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/legion-runner/</guid><description>Version updated for https://github.com/Wraith-security/Legion_runner to version v1.0.43.
This action is used across all versions by 8 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Legion Runner is an open-source security tool that hardens GitHub Actions against supply chain attacks by monitoring outbound connections, blocking unauthorized destinations, and identifying processes behind them. It provides a comprehensive defense mechanism that runs on pure Node built-ins without dependencies and offers features like egress policy control, process attribution, and file integrity checks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Wraith-security/Legion_runner">https://github.com/Wraith-security/Legion_runner</a></strong> to version <strong>v1.0.43</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/legion-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Legion Runner is an open-source security tool that hardens GitHub Actions against supply chain attacks by monitoring outbound connections, blocking unauthorized destinations, and identifying processes behind them. It provides a comprehensive defense mechanism that runs on pure Node built-ins without dependencies and offers features like egress policy control, process attribution, and file integrity checks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>Curated egress presets (<code>allowed-presets</code>)</strong>: opt-in per-ecosystem allowlists
(npm, yarn, pnpm, pip, pypi, cargo, rust, go, maven, gradle, nuget, apt, debian,
docker) so block mode &ldquo;just works&rdquo; for common toolchains without hand-listing
endpoints. e.g. <code>allowed-presets: &quot;cargo, apt&quot;</code>. Unit-tested.</li>
<li><strong>Download integrity verification</strong>: the action verifies the <code>legionr-bpf</code> /
<code>legionr-fim</code> release binaries against a <code>.sha256</code> sidecar before running them
(the release now attaches the checksums), and <strong>fails closed</strong> — an
unverified/corrupted/tampered download is rejected and the action degrades
instead of executing it.</li>
<li><strong><code>learned-baseline</code> input</strong> (default <code>true</code>): in block mode, also allow
destinations previously learned into the Actions cache. Set <code>false</code> to enforce
ONLY the explicit allowlist (inline + policy-file + GitHub) with no cache
read/write — used by the enforce self-test for deterministic deny.</li>
<li><strong>File-integrity / tamper detection (Rust <code>legionr-fim</code> agent)</strong>: snapshots
high-value tamper targets at job start (credential/config files, <code>.git</code>
config + hooks, and checked-out source) and diffs them at job end, surfacing
anything overwritten, deleted, or chmod&rsquo;d in the summary. Only sha256 hashes
are stored — never contents. New inputs <code>file-integrity</code> (auto|off) and
<code>fim-extra-paths</code>. <code>file-integrity: auto</code> downloads the agent from the latest
release (plain stable Rust, no eBPF toolchain) and degrades to a silent skip
if unavailable. Logic lives in <code>legionr-core::fim</code> (unit-tested); the binary
is a release asset like <code>legionr-bpf</code>, built + attached by <code>release.yml</code>.</li>
<li><strong>Package repositories roll-up (<code>📦</code>)</strong>: the summary now classifies named
outbound destinations into their ecosystem/registry (npm, PyPI, crates.io,
apt, Docker, Go, NuGet, Maven, Gradle, RubyGems, Alpine, GitHub) and shows a
<strong>Package repositories reached</strong> table — registry, ecosystem, connections, and
the process that reached each. Supply-chain risk hides in <em>which</em> registries a
build talks to, so we surface them directly instead of leaving you to read
IPs. Bare IPs that never got a forward name get a coarse CDN/provider hint
(Fastly/Cloudflare/GitHub) via CIDR match — honest about ambiguity (a shared
CDN can&rsquo;t name a registry). Logic in <code>action/repos.js</code>, fully unit-tested.</li>
<li><strong>Combined cross-job egress report (one summary for the whole run)</strong>: GitHub
has no run-level summary, so each job emits its captured egress as a JSON
artifact (<code>node action/report.js emit</code>) and a final <code>egress-report</code> job merges
them into a SINGLE table — which job + process reached what — with a package
repositories roll-up and a per-job diagnostics block (<code>render</code>). Wired into CI;
<code>render</code> is pure and unit-tested. Pairs with <code>job-summary: false</code> so the run
shows one combined summary instead of one table per job.</li>
<li><strong><code>job-summary</code> input</strong> (default <code>true</code>): set <code>false</code> to keep monitoring and
enforcement fully active but suppress the connections table in the job summary.
Useful when many jobs in one workflow each run the action and you only want the
table once (our own CI uses it so a run shows one table, not one per job).</li>
<li><strong>Secure diagnostics line</strong> in the summary: reports which resolution path
actually fired (<code>forwarder on/off · captured DNS records N · getaddrinfo route … · named X/Y destinations</code>) so a run that comes back as bare IPs is triagable.
Secure by construction — only booleans, counts, and a fixed enum; never the
upstream resolver IP, file paths, captured hostnames, or env values.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>Block mode no longer hangs the runner at teardown.</strong> <code>applyEgressBlock</code>
installed a default-deny <code>LEGION_EGRESS</code> chain in <code>OUTPUT</code> and nothing ever
removed it, so the runner&rsquo;s own completion call (to rotating GitHub-backend IPs
not in the static seed) was dropped and the job spun until timeout. <code>post()</code>
now tears the firewall down (<code>removeEgressBlock</code>).</li>
<li><strong>Runner hang from leaked daemons.</strong> The post step left privileged background
processes alive — eBPF agent, DNS forwarder — and the <code>/proc</code> monitor could
wedge in a blocking <code>ss</code> subprocess. The monitor now reads <code>/proc/net/tcp</code>
directly (no subprocess); daemons are reliably reaped.</li>
<li><strong>No more spurious &ldquo;could not resolve&rdquo; annotations.</strong> Allowlist entries that
are wildcard parents with no A record of their own (e.g. <code>blob.core.windows.net</code>,
<code>actions.githubusercontent.com</code>) used to emit one CI <strong>warning annotation</strong>
each on every run. They are benign: the action skips them, and their subdomains
are still observed via PTR / DNS capture (and opened just-in-time in block
mode). They are now collected into a single plain-text log line instead.</li>
<li><strong>Docs/labels</strong>: the eBPF mechanism is a <strong>tracepoint on <code>sys_enter_connect</code></strong>
(not a &ldquo;kprobe on tcp_connect&rdquo;); the sampler is <code>/proc</code>-only (the &ldquo;ss&rdquo; fallback
was removed). Corrected the runtime log line, summary label, and README.</li>
<li><strong>Outbound connections showed as bare IPs when systemd-resolved owns
<code>getaddrinfo</code>.</strong> The <code>nsswitch</code> reroute didn&rsquo;t always stick, so package-repo
lookups bypassed the capture forwarder and were never named. The forwarder now
targets the <em>real</em> upstream (systemd-resolved&rsquo;s actual servers, not the
<code>127.0.0.53</code> stub), and when the bypass is detected but the nsswitch reroute
fails, Legion redirects systemd-resolved itself at the forwarder via a
<code>resolved.conf.d</code> drop-in — <strong>verify-or-revert</strong> and restored on teardown, so
it never breaks the job&rsquo;s DNS.</li>
<li><strong>IPv4-mapped IPv6 destinations rendered as long expanded addresses</strong>
(<code>0000:0000:0000:0000:0000:ffff:HHHH:HHHH</code>) in the summary. The <code>/proc</code> sampler
emitted the expanded form while <code>normalizeIp</code> only collapsed the compressed
<code>::ffff:</code> form. Both now collapse to dotted IPv4 (and the v4/v6 tables dedupe).
(Shipped in v1.0.35.)</li>
<li>Removed dead <code>action/baseline.js</code>; pinned <code>release.yml</code> checkout to v6.</li>
</ul>
<h3 id="reliability">Reliability</h3>
<ul>
<li><strong>Tests for the paths that kept breaking</strong>: the firewall rule builders
(<code>egressBlockRules</code>/<code>egressUnblockRules</code> — order, DNS-allow, DROP-last,
OUTPUT-jump-removed-first), the checksum parser, the curated presets, and a
<strong>full-stack PR gate</strong> that runs block + DNS-capture + eBPF and asserts the
job finalizes (catches any teardown-hang regression), plus the package-repo
classifier (host-suffix + CIDR matching). Action test count 19 → 37.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>Removed em-dashes from the job-summary output (headers, the unresolved-host
note, the enforce hint, and empty-cell placeholders) for plainer rendering.</li>
<li><strong>Name more destinations</strong>: route glibc <code>getaddrinfo</code> (curl/apt/cargo/git)
through the DNS-capture forwarder via an <code>nsswitch.conf</code> reroute, so hosts
resolved by systemd-resolved (which ignores <code>resolv.conf</code>) are now captured
and named — not just <code>resolv.conf</code>/c-ares callers. Health-checked and restored
on teardown. (A connection to a hard-coded IP with no PTR still shows the IP —
there is no name to resolve.)</li>
<li>More accurate &ldquo;unresolved destination&rdquo; note in the summary (a name may have
been resolved outside the capture path, vs. a genuine raw-IP connection).</li>
<li><strong>We dogfood our own action.</strong> Every real-work job in this repo (CI, release,
eBPF agent, FIM self-test) now runs Legion Runner as its first step (<code>@v1</code>,
audit) — our CI is hardened by the product it ships.</li>
<li><strong>Docs-only PRs skip the build/test matrix</strong> (and the release it gates) via
<code>paths-ignore</code>; a <code>docs-passthrough</code> workflow reports the same check names
green so required checks stay satisfied and README edits stay mergeable
without burning CI minutes.</li>
<li><strong>Our CI now captures names.</strong> The dogfooded harden steps run with
<code>dns-capture: true</code> (still <code>audit</code> — monitor, don&rsquo;t firewall), so job summaries
show real destination and package-repository names instead of bare IPs, and the
capture path is exercised on every run. Safe now that <code>@v1</code> (&gt;= 1.0.35) carries
the teardown + systemd-resolved fixes.</li>
</ul>
]]></content:encoded></item><item><title>vibecheck-ai-slop</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/vibecheck-ai-slop/</link><pubDate>Fri, 24 Jul 2026 13:43:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/vibecheck-ai-slop/</guid><description>Version updated for https://github.com/yuvrajangadsingh/vibecheck to version v1.13.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary vibecheck is a tool that automates the detection of AI-generated code smells by using ESLint rules to identify common issues such as hardcoded secrets, empty catch blocks, and SQL injection vulnerabilities. It runs locally without requiring any external dependencies or configuration files. The main purpose of vibecheck is to help developers quickly identify potential problems in their AI-generated codebases, ensuring better security, maintainability, and performance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yuvrajangadsingh/vibecheck">https://github.com/yuvrajangadsingh/vibecheck</a></strong> to version <strong>v1.13.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibecheck-ai-slop">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>vibecheck is a tool that automates the detection of AI-generated code smells by using ESLint rules to identify common issues such as hardcoded secrets, empty catch blocks, and SQL injection vulnerabilities. It runs locally without requiring any external dependencies or configuration files. The main purpose of vibecheck is to help developers quickly identify potential problems in their AI-generated codebases, ensuring better security, maintainability, and performance.</p>
]]></content:encoded></item><item><title>Devr Codeguard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/devr-codeguard/</link><pubDate>Fri, 24 Jul 2026 06:33:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/devr-codeguard/</guid><description>Version updated for https://github.com/devr-tools/codeguard to version v1.2.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary codeguard is a comprehensive tool that automates various repository checks across code quality, design boundaries, security, CI/CD hygiene, AI prompt governance, and repo-specific policy rules. It supports extensive capabilities such as repository exclusions, baselines, waivers, changed-lines diff scans, SARIF output, GitHub annotations, custom rule packs, natural-language custom rules through an optional AI runtime, policy profiles, scan caching, doctor checks, rule discovery from the CLI, native TypeScript/Python quality, design, and security heuristics, and language-specific command checks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/devr-tools/codeguard">https://github.com/devr-tools/codeguard</a></strong> to version <strong>v1.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/devr-codeguard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>codeguard</code> is a comprehensive tool that automates various repository checks across code quality, design boundaries, security, CI/CD hygiene, AI prompt governance, and repo-specific policy rules. It supports extensive capabilities such as repository exclusions, baselines, waivers, changed-lines diff scans, SARIF output, GitHub annotations, custom rule packs, natural-language custom rules through an optional AI runtime, policy profiles, scan caching, doctor checks, rule discovery from the CLI, native TypeScript/Python quality, design, and security heuristics, and language-specific command checks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="121-2026-07-23"><a href="https://github.com/devr-tools/codeguard/compare/v1.2.0...v1.2.1">1.2.1</a> (2026-07-23)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>bound TypeScript semantic analysis to scan corpus (<a href="https://github.com/devr-tools/codeguard/commit/f473e6eacc4329898e134f15c27d18b9a9bba00c">f473e6e</a>)</li>
<li>bound TypeScript semantic analysis to scan corpus (<a href="https://github.com/devr-tools/codeguard/issues/61">#61</a>) (<a href="https://github.com/devr-tools/codeguard/commit/685cf99f3a49b9502e6b814d86f32c16169b19db">685cf99</a>)</li>
</ul>
]]></content:encoded></item><item><title>check-version-before-release</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/check-version-before-release/</link><pubDate>Fri, 24 Jul 2026 06:32:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/check-version-before-release/</guid><description>Version updated for https://github.com/digicatapult/check-version to version v1.5.93.
This action is used across all versions by 35 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action compares the versions in package.json and package-lock.json with those of Cargo.toml and pyproject.toml, ensuring they are higher than the latest published tags for each manager. It also provides a way to set custom paths for these files and handle failed checks by setting a fail_on_same_version flag.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/digicatapult/check-version">https://github.com/digicatapult/check-version</a></strong> to version <strong>v1.5.93</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>35</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/check-version-before-release">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action compares the versions in package.json and package-lock.json with those of Cargo.toml and pyproject.toml, ensuring they are higher than the latest published tags for each manager. It also provides a way to set custom paths for these files and handle failed checks by setting a fail_on_same_version flag.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changes">Changes</h2>
<p><strong><a href="https://github.com/digicatapult/check-version/pull/549">chore(deps): update npm - all minor and patch updates</a></strong></p>
]]></content:encoded></item><item><title>easySFTP</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/easysftp/</link><pubDate>Fri, 24 Jul 2026 06:31:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/easysftp/</guid><description>Version updated for https://github.com/eiserv/easySFTP to version v3.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary easySFTP is a fast, secure, and user-friendly GitHub Action for deploying files to an SFTP server. It handles common deploy tasks with minimal configuration and can be expanded for more complex deployments using a config file. The action supports multiple deployment targets, various authentication methods, and advanced features like file skipping, deletion guards, and performance tuning.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/eiserv/easySFTP">https://github.com/eiserv/easySFTP</a></strong> to version <strong>v3.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/easysftp">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>easySFTP is a fast, secure, and user-friendly GitHub Action for deploying files to an SFTP server. It handles common deploy tasks with minimal configuration and can be expanded for more complex deployments using a config file. The action supports multiple deployment targets, various authentication methods, and advanced features like file skipping, deletion guards, and performance tuning.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="300-2026-07-23"><a href="https://github.com/eiserv/easySFTP/compare/v2.2.2...v3.0.0">3.0.0</a> (2026-07-23)</h2>
<h3 id="-breaking-changes">⚠ BREAKING CHANGES</h3>
<ul>
<li>server was renamed to host, uploads was replaced by source + target, strategy is now mode, ignore is now exclude, host-key-fingerprint is now host-key, config-file is now config.</li>
<li>Multiple upload mappings require a config file; inline mode supports exactly one deployment.</li>
<li>All advanced/tuning inputs (concurrency, retries, timeout, stall-timeout, sftp-request-concurrency, sync-fast-path, skip-unchanged, manifest-name, dir-mode, file-mode, preserve-times, max-deletes) moved into the config file.</li>
<li>All proxy/bastion connection inputs moved into the config file (connection.proxy); only the proxy credentials remain inputs.</li>
<li>The config file format changed: version: 3, connection settings live in the file, and targets became named deployments.</li>
<li>Host key verification is required. A run without host-key / known-hosts fails unless allow-any-host-key: true is set explicitly (v2 printed a warning and accepted any key).</li>
<li>build-mode was removed; the build mode is selected automatically from the action ref (release tags download the verified prebuilt binary, development refs build from source).</li>
<li>The default log no longer prints one line per file; per-file output moved to log-level: verbose (see <a href="https://eiserv.github.io/easySFTP/docs.html#migration-v3/logging-changes">Logging changes</a>).</li>
<li>The delete tombstone input from v1 was finally removed.</li>
</ul>
<h3 id="features">Features</h3>
<ul>
<li>v3 configuration model (inline vs config file, no mixed mode) (<a href="https://github.com/eiserv/easySFTP/issues/124">#124</a>) (<a href="https://github.com/eiserv/easySFTP/commit/2887530782498233207a4d54ec445ecc75b86e37">2887530</a>), closes <a href="https://github.com/eiserv/easySFTP/issues/123">#123</a></li>
</ul>
]]></content:encoded></item><item><title>Fallow - Codebase Intelligence</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/fallow-codebase-intelligence/</link><pubDate>Fri, 24 Jul 2026 06:30:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/fallow-codebase-intelligence/</guid><description>Version updated for https://github.com/fallow-rs/fallow to version v3.9.1.
This action is used across all versions by 349 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates static code analysis for TypeScript and JavaScript projects by identifying unused files, circular dependencies, duplication, complexity hotspots, boundary violations, and design-system styling drift. It provides deterministic findings with typed output contracts and can be integrated into CI workflows to ensure code quality before deployment. The action supports various formats and integrates with popular development tools like LSP servers for language-specific analysis.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/fallow-rs/fallow">https://github.com/fallow-rs/fallow</a></strong> to version <strong>v3.9.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>349</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/fallow-codebase-intelligence">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates static code analysis for TypeScript and JavaScript projects by identifying unused files, circular dependencies, duplication, complexity hotspots, boundary violations, and design-system styling drift. It provides deterministic findings with typed output contracts and can be integrated into CI workflows to ensure code quality before deployment. The action supports various formats and integrates with popular development tools like LSP servers for language-specific analysis.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="fallow-impact-in-your-status-line">Fallow Impact in your status line</h2>
<p><code>fallow impact statusline</code> gives agent and editor chrome one compact, path-free
line with the latest whole-project issue count, its trend, and findings cleared
while Impact was tracking. It reads local history only, never runs analysis,
migrates data, records telemetry, or prints normal CLI notices.</p>
<p>The Fallow plugin for Claude Code can compose this line with an existing status
line. Codex and other agents can use the same stable command through the bundled
Fallow skill.</p>
<h2 id="cloud-runtime-confidence">Cloud runtime confidence</h2>
<p>Cloud <code>never_called</code> evidence now keeps its provenance. Runtime-observed
functions can retain the existing high-confidence deletion recommendation,
while inventory-backed, missing, and future provenance remains conservative.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/fallow-rs/fallow/compare/v3.8.1...v3.9.1">https://github.com/fallow-rs/fallow/compare/v3.8.1...v3.9.1</a></p>
]]></content:encoded></item><item><title>opseclint detection-coverage</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/opseclint-detection-coverage/</link><pubDate>Fri, 24 Jul 2026 06:29:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/opseclint-detection-coverage/</guid><description>Version updated for https://github.com/Gerrrt/opseclint to version v0.1.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary opseclint is a detection-coverage analyzer that identifies and analyzes the detectability of command-line actions, scripts, or post-exploitation playbooks against various operating systems (Linux/Auditd, Windows/Sysmon, macOS/Endpoint Security) by resolving them to MITRE ATT&amp;amp;CK techniques, telemetry events, and expected detections. It helps developers understand how their actions would be detected if executed in a real-world environment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Gerrrt/opseclint">https://github.com/Gerrrt/opseclint</a></strong> to version <strong>v0.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/opseclint-detection-coverage">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>opseclint is a detection-coverage analyzer that identifies and analyzes the detectability of command-line actions, scripts, or post-exploitation playbooks against various operating systems (Linux/Auditd, Windows/Sysmon, macOS/Endpoint Security) by resolving them to MITRE ATT&amp;CK techniques, telemetry events, and expected detections. It helps developers understand how their actions would be detected if executed in a real-world environment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add Dockerfile + GHCR container image by @Gerrrt in <a href="https://github.com/Gerrrt/opseclint/pull/10">https://github.com/Gerrrt/opseclint/pull/10</a></li>
<li>Revamp README (Best-README-Template format + shields) by @Gerrrt in <a href="https://github.com/Gerrrt/opseclint/pull/11">https://github.com/Gerrrt/opseclint/pull/11</a></li>
<li>Bump version to 0.1.2 by @Gerrrt in <a href="https://github.com/Gerrrt/opseclint/pull/12">https://github.com/Gerrrt/opseclint/pull/12</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Gerrrt/opseclint/compare/v0.1.1...v0.1.2">https://github.com/Gerrrt/opseclint/compare/v0.1.1...v0.1.2</a></p>
<h2 id="whats-changed-2">What&rsquo;s Changed</h2>
<ul>
<li>Add Dockerfile + GHCR container image by @Gerrrt in <a href="https://github.com/Gerrrt/opseclint/pull/10">https://github.com/Gerrrt/opseclint/pull/10</a></li>
<li>Revamp README (Best-README-Template format + shields) by @Gerrrt in <a href="https://github.com/Gerrrt/opseclint/pull/11">https://github.com/Gerrrt/opseclint/pull/11</a></li>
<li>Bump version to 0.1.2 by @Gerrrt in <a href="https://github.com/Gerrrt/opseclint/pull/12">https://github.com/Gerrrt/opseclint/pull/12</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Gerrrt/opseclint/compare/v0.1.1...v0.1.2">https://github.com/Gerrrt/opseclint/compare/v0.1.1...v0.1.2</a></p>
<h2 id="whats-changed-3">What&rsquo;s Changed</h2>
<ul>
<li>Add Dockerfile + GHCR container image by @Gerrrt in <a href="https://github.com/Gerrrt/opseclint/pull/10">https://github.com/Gerrrt/opseclint/pull/10</a></li>
<li>Revamp README (Best-README-Template format + shields) by @Gerrrt in <a href="https://github.com/Gerrrt/opseclint/pull/11">https://github.com/Gerrrt/opseclint/pull/11</a></li>
<li>Bump version to 0.1.2 by @Gerrrt in <a href="https://github.com/Gerrrt/opseclint/pull/12">https://github.com/Gerrrt/opseclint/pull/12</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Gerrrt/opseclint/compare/v0.1.1...v0.1.2">https://github.com/Gerrrt/opseclint/compare/v0.1.1...v0.1.2</a></p>
<h2 id="whats-changed-4">What&rsquo;s Changed</h2>
<ul>
<li>Add Dockerfile + GHCR container image by @Gerrrt in <a href="https://github.com/Gerrrt/opseclint/pull/10">https://github.com/Gerrrt/opseclint/pull/10</a></li>
<li>Revamp README (Best-README-Template format + shields) by @Gerrrt in <a href="https://github.com/Gerrrt/opseclint/pull/11">https://github.com/Gerrrt/opseclint/pull/11</a></li>
<li>Bump version to 0.1.2 by @Gerrrt in <a href="https://github.com/Gerrrt/opseclint/pull/12">https://github.com/Gerrrt/opseclint/pull/12</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Gerrrt/opseclint/compare/v0.1.1...v0.1.2">https://github.com/Gerrrt/opseclint/compare/v0.1.1...v0.1.2</a></p>
]]></content:encoded></item><item><title>trigger-tree docs discoverability gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/trigger-tree-docs-discoverability-gate/</link><pubDate>Fri, 24 Jul 2026 06:27:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/trigger-tree-docs-discoverability-gate/</guid><description>Version updated for https://github.com/Hedde/trigger_tree to version v1.24.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary trigger-tree is a local tool that records discovery evidence to improve documentation quality by monitoring which AI coding assistants are accessing project documentation. It helps identify patterns, guardrails, and areas of improvement in the documentation process without relying on cloud analytics or model tokens. The action supports various platforms and provides insights into the health and effectiveness of documentation for teams.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Hedde/trigger_tree">https://github.com/Hedde/trigger_tree</a></strong> to version <strong>v1.24.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/trigger-tree-docs-discoverability-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>trigger-tree is a local tool that records discovery evidence to improve documentation quality by monitoring which AI coding assistants are accessing project documentation. It helps identify patterns, guardrails, and areas of improvement in the documentation process without relying on cloud analytics or model tokens. The action supports various platforms and provides insights into the health and effectiveness of documentation for teams.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Both findings below were reported by @BartWaardenburg — thank you.</p>
<ul>
<li>The structural inventory follows git&rsquo;s view of the repository (#16): a file
excluded by <code>.gitignore</code> can no longer surface as a router member, orphan,
or missing entry point in <code>tt-stats</code> or <code>tt gate</code>. The scope scanner and
the structure inventory now share one git-visible source of truth; the
filesystem walk remains the fallback outside git repositories.</li>
<li>Watched surfaces behind a directory symlink are named instead of silently
missing (#15): the stats payload gains <code>unfollowed_surfaces</code> (path, target,
reason), the health grade states its scope explicitly (evaluable docs), a
health driver counts unfollowed surfaces, and <code>tt doctor</code> warns with the
paths. Symlinks are still never followed — bytes outside the repository
stay out of the deterministic score by design; the boundary is documented
in the heat-model guide.</li>
</ul>
<hr>
<p><strong>Install (Claude Code)</strong></p>
<pre tabindex="0"><code>/plugin marketplace add Hedde/trigger_tree
/plugin install trigger-tree@trigger-tree
</code></pre><p><strong>Install (Codex, pinned to this release)</strong></p>
<pre tabindex="0"><code>codex plugin marketplace add Hedde/trigger_tree --ref v1.24.0
codex plugin add trigger-tree@trigger-tree
</code></pre><p><a href="https://hedde.github.io/trigger_tree/">Website</a> · <a href="https://github.com/Hedde/trigger_tree/tree/main/docs">Documentation</a> · <a href="https://github.com/Hedde/trigger_tree/blob/main/CHANGELOG.md">Changelog</a> · <a href="https://github.com/Hedde/trigger_tree/blob/main/PRIVACY.md">Privacy</a></p>
]]></content:encoded></item><item><title>Amino Email Deliverability Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/amino-email-deliverability-audit/</link><pubDate>Fri, 24 Jul 2026 06:26:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/amino-email-deliverability-audit/</guid><description>Version updated for https://github.com/hireamino/amino-audit-action to version v1.3.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action audits the email-authentication posture of sending domains to ensure they meet best practices, such as SPF, DKIM, and DMARC. It provides a detailed audit report in the job summary and allows users to set severity thresholds to fail builds on regressions. The action is read-only and runs on any runner OS.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hireamino/amino-audit-action">https://github.com/hireamino/amino-audit-action</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/amino-email-deliverability-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action audits the email-authentication posture of sending domains to ensure they meet best practices, such as SPF, DKIM, and DMARC. It provides a detailed audit report in the job summary and allows users to set severity thresholds to fail builds on regressions. The action is read-only and runs on any runner OS.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Major correctness + reliability release. The audit&rsquo;s email-auth verdicts are now governed by a shared conformance spec, verified identically across all three Amino surfaces (this Action, the web tool, and the skill).</p>
<p><strong>Still advisory-by-default</strong> — <code>fail-on: advisory</code> continues to never break the build; enforcement is opt-in.</p>
<h3 id="false-pass-fixes-a-security-gate-must-never-call-broken-config-healthy">False-pass fixes (a security gate must never call broken config healthy)</h3>
<ul>
<li><strong>DKIM</strong>: an empty <code>p=</code> (revoked selector) and a malformed Ed25519 key no longer read as healthy; real RSA modulus bit-length is read from the key DER (weak = any RSA &lt; 2048).</li>
<li><strong>DMARC</strong>: <code>p=</code> must be <code>none|quarantine|reject</code> (<code>p=banana</code> is no longer &ldquo;enforced&rdquo;); tags parsed case-insensitively; <strong>RFC 9989 tree walk</strong> so a subdomain inherits the org policy instead of a false &ldquo;No DMARC&rdquo;; eTLD+1 org-domain (so <code>good.co.uk</code>≠<code>evil.co.uk</code> for report authorization).</li>
<li><strong>SPF</strong>: <code>-ALL</code> handled case-insensitively (no contradictory &ldquo;no all mechanism&rdquo;).</li>
<li><strong>MTA-STS</strong>: wildcard matches exactly one label (RFC 8461); <code>enforce</code> requires <code>version: STSv1</code> + valid mode + integer <code>max_age</code> + ≥1 <code>mx:</code>; policy fetch requires HTTP 200 + <code>text/plain</code>.</li>
<li><strong>DANE/DNSSEC</strong>: DANE requires a <strong>DNSSEC-validated</strong> (AD-bit) TLSA (RFC 7672); DNSSEC uses the AD bit, which respects the zone cut.</li>
</ul>
<h3 id="reliability--new-io">Reliability / new I/O</h3>
<ul>
<li>New input <code>continue-on-audit-error</code> (default <code>true</code>) and output <code>audit-complete</code>. Empty/invalid <code>domains</code> input now exits non-zero; a transient DNS failure (SERVFAIL/REFUSED) on a critical lookup marks the audit inconclusive (<code>audit-complete=false</code>, <code>passed=false</code>) rather than a silent green — failing the build only when <code>continue-on-audit-error=false</code>.</li>
</ul>
<h3 id="engineering">Engineering</h3>
<ul>
<li>Zero runtime dependencies preserved. A fixtures-driven conformance runner gates every surface in CI. 69 local tests + 15 shared conformance cases green.</li>
</ul>
<p>Full plan and per-invariant detail: hireamino/amino-skills#1.</p>
]]></content:encoded></item><item><title>stackit-cli tools installer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/stackit-cli-tools-installer/</link><pubDate>Fri, 24 Jul 2026 06:25:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/stackit-cli-tools-installer/</guid><description>Version updated for https://github.com/jkroepke/setup-stackit-cli to version v1.2.90.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the installation of the stackit-cli binary on GitHub Actions runners, allowing users to specify a version (latest or a specific semantic version) and cache the installed binary for future use. The action also prepends the cached binary path to the PATH environment variable, making it accessible in subsequent steps of the workflow.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jkroepke/setup-stackit-cli">https://github.com/jkroepke/setup-stackit-cli</a></strong> to version <strong>v1.2.90</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/stackit-cli-tools-installer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the installation of the stackit-cli binary on GitHub Actions runners, allowing users to specify a version (latest or a specific semantic version) and cache the installed binary for future use. The action also prepends the cached binary path to the PATH environment variable, making it accessible in subsequent steps of the workflow.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at v1.2.90 -->
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="-dependencies">🛠️ Dependencies</h3>
<ul>
<li>chore(deps): update dependencies by @renovate[bot] in <a href="https://github.com/jkroepke/setup-stackit-cli/pull/290">https://github.com/jkroepke/setup-stackit-cli/pull/290</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jkroepke/setup-stackit-cli/compare/v1.2.89...v1.2.90">https://github.com/jkroepke/setup-stackit-cli/compare/v1.2.89...v1.2.90</a></p>
]]></content:encoded></item><item><title>Codex Review Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/codex-review-gate/</link><pubDate>Fri, 24 Jul 2026 06:24:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/codex-review-gate/</guid><description>Version updated for https://github.com/JoeyTeng/codex-review-gate-action to version v1.3.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Codex Review Gate GitHub Action ensures that a PR head has clean Codex review output before passing as a required status check, using Codex’s generative AI capabilities to review pull requests. It maintains a thin workflow in .github/workflows/codex-review-gate.yml and coordinates with GitHub comments, reviews, reactions, and commit statuses for reliable checks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/JoeyTeng/codex-review-gate-action">https://github.com/JoeyTeng/codex-review-gate-action</a></strong> to version <strong>v1.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/codex-review-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Codex Review Gate GitHub Action ensures that a PR head has clean Codex review output before passing as a required status check, using Codex&rsquo;s generative AI capabilities to review pull requests. It maintains a thin workflow in <code>.github/workflows/codex-review-gate.yml</code> and coordinates with GitHub comments, reviews, reactions, and commit statuses for reliable checks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s changed</h2>
<ul>
<li>Reconcile official <code>COMMENTED</code> review wrappers with their inline findings instead of treating the wrapper as a second standalone finding.</li>
<li>Keep incomplete REST/GraphQL snapshots fail-closed until bounded reloads produce a complete, mutually reconciled snapshot.</li>
<li>Preserve unresolved inline findings as failures while allowing resolved inline findings to stop blocking a later current-head clean result.</li>
<li>Add regressions for partial snapshots, orphaned parent/child evidence, unknown wrapper grammar, and transient thread retrieval errors.</li>
</ul>
<h2 id="compatibility">Compatibility</h2>
<ul>
<li>Existing action inputs remain compatible.</li>
<li><code>completion-signal-buffer-seconds</code> and <code>failed-findings-recovery-mode</code> remain accepted as deprecated legacy inputs.</li>
</ul>
<p>All release tags (<code>v1.3.1</code>, <code>v1.3</code>, and <code>v1</code>) are signed and resolve to action commit <code>ef41b938a6c57a8a1adde44baaabd29eb8ee4df6</code>.</p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/neurolink-ai/</link><pubDate>Fri, 24 Jul 2026 06:24:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v10.5.1.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is the AI integration platform that provides a single, consistent API for 30+ AI providers and 100+ models. It enables developers to integrate AI into any application with a TypeScript-first approach. Key features include multi-provider failover, intelligent routing, and built-in tools. Users can switch providers with a single parameter change.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v10.5.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>NeuroLink is the AI integration platform that provides a single, consistent API for 30+ AI providers and 100+ models. It enables developers to integrate AI into any application with a TypeScript-first approach. Key features include multi-provider failover, intelligent routing, and built-in tools. Users can switch providers with a single parameter change.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1051-2026-07-23"><a href="https://github.com/juspay/neurolink/compare/v10.5.0...v10.5.1">10.5.1</a> (2026-07-23)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(proxy):</strong>  retry subscription beta-rejection 400s on the next account (<a href="https://github.com/juspay/neurolink/commit/4b67bd1e93391967694d6a00e0db3742851128f1">4b67bd1</a>)</li>
</ul>
]]></content:encoded></item><item><title>agent-bom Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/agent-bom-scan/</link><pubDate>Fri, 24 Jul 2026 06:23:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/agent-bom-scan/</guid><description>Version updated for https://github.com/msaad00/agent-bom to version v0.97.5.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the scan and reporting of security vulnerabilities across AI, cloud infrastructure, and tools. It helps centralize evidence and enforce runtime calls, providing a single Finding with a UnifiedGraph model accessible from CLI, API, UI, and MCP. The action supports scanning from CLI, CI, Docker, or cloud connections on a custom control plane, allowing for comprehensive visibility into security risks across various environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/msaad00/agent-bom">https://github.com/msaad00/agent-bom</a></strong> to version <strong>v0.97.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-bom-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action automates the scan and reporting of security vulnerabilities across AI, cloud infrastructure, and tools. It helps centralize evidence and enforce runtime calls, providing a single Finding with a UnifiedGraph model accessible from CLI, API, UI, and MCP. The action supports scanning from CLI, CI, Docker, or cloud connections on a custom control plane, allowing for comprehensive visibility into security risks across various environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(deploy): preserve legacy demo overlay before pull by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4409">https://github.com/msaad00/agent-bom/pull/4409</a></li>
<li>chore: drop public co-author deny-list and harden release README by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4410">https://github.com/msaad00/agent-bom/pull/4410</a></li>
<li>fix(deploy): use shipped driver for postgres migrations by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4411">https://github.com/msaad00/agent-bom/pull/4411</a></li>
<li>feat(ui): make context and investigation graphs the canvas hero by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4412">https://github.com/msaad00/agent-bom/pull/4412</a></li>
<li>feat(ui): punchier graph captures and skill capability contracts by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4414">https://github.com/msaad00/agent-bom/pull/4414</a></li>
<li>chore(ops): fail closed on missing UI Hub tag and fix pilot compose by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4413">https://github.com/msaad00/agent-bom/pull/4413</a></li>
<li>feat(ui): distinct graph proof shots and labeled relationships by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4415">https://github.com/msaad00/agent-bom/pull/4415</a></li>
<li>chore(deps): bump aws-actions/configure-aws-credentials from 6.2.2 to 6.2.3 by @dependabot[bot] in <a href="https://github.com/msaad00/agent-bom/pull/4416">https://github.com/msaad00/agent-bom/pull/4416</a></li>
<li>chore(deps): bump lucide-react from 1.25.0 to 1.26.0 in /ui by @dependabot[bot] in <a href="https://github.com/msaad00/agent-bom/pull/4417">https://github.com/msaad00/agent-bom/pull/4417</a></li>
<li>fix(deps): bump postcss to 8.5.12 for CVE-2026-45623 by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4420">https://github.com/msaad00/agent-bom/pull/4420</a></li>
<li>fix(deploy): harden EKS reference install path by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4421">https://github.com/msaad00/agent-bom/pull/4421</a></li>
<li>docs(arch): Python-primary runtime; optional Go sidecar later by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4423">https://github.com/msaad00/agent-bom/pull/4423</a></li>
<li>chore(release): 0.97.5 by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4422">https://github.com/msaad00/agent-bom/pull/4422</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/msaad00/agent-bom/compare/v0.97.4...v0.97.5">https://github.com/msaad00/agent-bom/compare/v0.97.4...v0.97.5</a></p>
]]></content:encoded></item><item><title>Lambda MicroVM GitHub Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/lambda-microvm-github-runner/</link><pubDate>Fri, 24 Jul 2026 06:21:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/lambda-microvm-github-runner/</guid><description>Version updated for https://github.com/neebs12/lambda-microvm-github-runner to version v1.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Lambda MicroVM GitHub Runner is an action designed to run GitHub Actions jobs on AWS Lambda using MicroVMs, providing a way to extend Lambda’s 8-hour execution time by utilizing the lightweight nature of MicroVMs. This tool automates the setup and teardown of AWS resources required for running these actions, including creating IAM users, roles, and logs. It also supports configuring containerized workflows inside the runner, making it suitable for multi-container applications.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/neebs12/lambda-microvm-github-runner">https://github.com/neebs12/lambda-microvm-github-runner</a></strong> to version <strong>v1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lambda-microvm-github-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Lambda MicroVM GitHub Runner is an action designed to run GitHub Actions jobs on AWS Lambda using MicroVMs, providing a way to extend Lambda&rsquo;s 8-hour execution time by utilizing the lightweight nature of MicroVMs. This tool automates the setup and teardown of AWS resources required for running these actions, including creating IAM users, roles, and logs. It also supports configuring containerized workflows inside the runner, making it suitable for multi-container applications.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add suspended warm server pools by @neebs12 in <a href="https://github.com/neebs12/lambda-microvm-github-runner/pull/14">https://github.com/neebs12/lambda-microvm-github-runner/pull/14</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/neebs12/lambda-microvm-github-runner/compare/v1...v1.1">https://github.com/neebs12/lambda-microvm-github-runner/compare/v1...v1.1</a></p>
]]></content:encoded></item><item><title>Project Vault Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/project-vault-action/</link><pubDate>Fri, 24 Jul 2026 06:20:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/project-vault-action/</guid><description>Version updated for https://github.com/nestormata/vault-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action retrieves secrets from Project Vault and exports them as masked environment variables in a workflow. It automates the retrieval of secrets scoped to specific projects using machine-user API keys, ensuring that each secrets input refers to the same project, and provides options for handling errors gracefully. The action does not implement its own HTTP client or token exchange logic.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nestormata/vault-action">https://github.com/nestormata/vault-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/project-vault-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action retrieves secrets from Project Vault and exports them as masked environment variables in a workflow. It automates the retrieval of secrets scoped to specific projects using machine-user API keys, ensuring that each <code>secrets</code> input refers to the same project, and provides options for handling errors gracefully. The action does not implement its own HTTP client or token exchange logic.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Retrieve secrets from <a href="https://github.com/nestormata/project-vault">Project Vault</a> and export them as masked environment variables in your GitHub Actions workflow — no custom HTTP calls, no plaintext secrets in logs.</p>
<h3 id="usage">Usage</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">nestormata/vault-action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">vault-url</span>: <span style="color:#ae81ff">https://vault.example.com</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.VAULT_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">secrets</span>: |<span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">      &lt;PROJECT_ID&gt;/&lt;CREDENTIAL_NAME&gt; as &lt;ENV_VAR_NAME&gt;</span>
</span></span></code></pre></div><p>See the <a href="https://github.com/nestormata/vault-action#readme">README</a> for full setup (machine-user + API key creation), multi-secret syntax, <code>continue-on-error</code> semantics, and SHA-pinning guidance.</p>
<h3 id="highlights">Highlights</h3>
<ul>
<li>Machine-user API key auth, scoped to one project per step</li>
<li>Automatic masking of every retrieved value</li>
<li>10-second network timeout per credential, so an unreachable vault fails fast instead of stalling your job</li>
<li><code>continue-on-error</code> input to soften only &ldquo;vault unreachable&rdquo; failures — application-level errors (bad key, missing credential, wrong scope) always fail the step</li>
<li>Runs on Node 24</li>
</ul>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/go-proxy-cache-updater/</link><pubDate>Fri, 24 Jul 2026 06:19:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.31.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically pulls new versions of Go modules when tags are created, ensuring that your module is immediately available and up-to-date on platforms like pkg.go.dev. It supports both standard and submodule version tags and allows customization of proxy configuration, import paths, and Go versions. The action is triggered by release events and uses the actions/setup-go toolchain for setup.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.31</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically pulls new versions of Go modules when tags are created, ensuring that your module is immediately available and up-to-date on platforms like pkg.go.dev. It supports both standard and submodule version tags and allows customization of proxy configuration, import paths, and Go versions. The action is triggered by release events and uses the actions/setup-go toolchain for setup.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1131-2026-07-23"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.30...v1.1.31">1.1.31</a> (2026-07-23)</h2>
]]></content:encoded></item><item><title>pirafrank/notion-to-jekyll</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/pirafrank/notion-to-jekyll/</link><pubDate>Fri, 24 Jul 2026 06:18:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/pirafrank/notion-to-jekyll/</guid><description>Version updated for https://github.com/pirafrank/notion-to-jekyll to version v2.
This action is used across all versions by 3 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action converts Notion pages to Jekyll markdown files, extracting properties such as category and tags. It also downloads block assets like images and files from Notion, ensuring SEO compatibility by adding necessary front matter to posts. The action is designed to be run in a GitHub Actions workflow and can be customized via environment variables for different configurations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pirafrank/notion-to-jekyll">https://github.com/pirafrank/notion-to-jekyll</a></strong> to version <strong>v2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pirafrank-notion-to-jekyll">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action converts Notion pages to Jekyll markdown files, extracting properties such as category and tags. It also downloads block assets like images and files from Notion, ensuring SEO compatibility by adding necessary front matter to posts. The action is designed to be run in a GitHub Actions workflow and can be customized via environment variables for different configurations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>date range support by @pirafrank in <a href="https://github.com/pirafrank/notion-to-jekyll/pull/2">https://github.com/pirafrank/notion-to-jekyll/pull/2</a></li>
<li>dry run</li>
<li>log improvements</li>
<li>enhancements and bug fixes</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pirafrank/notion-to-jekyll/compare/v1...v2">https://github.com/pirafrank/notion-to-jekyll/compare/v1...v2</a></p>
]]></content:encoded></item><item><title>Postman API Onboarding</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/postman-api-onboarding/</link><pubDate>Fri, 24 Jul 2026 06:17:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/postman-api-onboarding/</guid><description>Version updated for https://github.com/postman-cs/postman-api-onboarding-action to version v2.1.8.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of setting up a new API repository by bootstrapping a Postman workspace, uploading an OpenAPI specification, generating test collections, and syncing them with the repository. It also creates CI workflows to rerun tests on every push, pull request, and schedule. The action is designed to provide comprehensive, executable testing solutions for APIs in GitHub repositories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-api-onboarding-action">https://github.com/postman-cs/postman-api-onboarding-action</a></strong> to version <strong>v2.1.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-api-onboarding">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of setting up a new API repository by bootstrapping a Postman workspace, uploading an OpenAPI specification, generating test collections, and syncing them with the repository. It also creates CI workflows to rerun tests on every push, pull request, and schedule. The action is designed to provide comprehensive, executable testing solutions for APIs in GitHub repositories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Release v2.1.8 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/90">https://github.com/postman-cs/postman-api-onboarding-action/pull/90</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.1.7...v2.1.8">https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.1.7...v2.1.8</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Workspace Bootstrap</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/postman-onboarding-workspace-bootstrap/</link><pubDate>Fri, 24 Jul 2026 06:16:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/postman-onboarding-workspace-bootstrap/</guid><description>Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.10.19.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the creation of a Postman workspace from an OpenAPI specification, generating baseline, smoke, and contract collections. It also includes dynamic contract tests that cover various protocols such as gRPC, SOAP, GraphQL, AsyncAPI, and MCP. The action is part of the broader Postman API Onboarding suite and requires either a public HTTPS URL or a file path to the spec in the repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-bootstrap-action">https://github.com/postman-cs/postman-bootstrap-action</a></strong> to version <strong>v2.10.19</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-workspace-bootstrap">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the creation of a Postman workspace from an OpenAPI specification, generating baseline, smoke, and contract collections. It also includes dynamic contract tests that cover various protocols such as gRPC, SOAP, GraphQL, AsyncAPI, and MCP. The action is part of the broader Postman API Onboarding suite and requires either a public HTTPS URL or a file path to the spec in the repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Hydrate org reconciliation markers from collection export by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/140">https://github.com/postman-cs/postman-bootstrap-action/pull/140</a></li>
<li>Release v2.10.19 by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/141">https://github.com/postman-cs/postman-bootstrap-action/pull/141</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.10.19">https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.10.19</a></p>
]]></content:encoded></item><item><title>Postman Onboarding GCP Spec Discovery</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/postman-onboarding-gcp-spec-discovery/</link><pubDate>Fri, 24 Jul 2026 06:14:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/postman-onboarding-gcp-spec-discovery/</guid><description>Version updated for https://github.com/postman-cs/postman-gcp-spec-discovery-action to version v1.1.8.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Postman Onboarding: GCP Spec Discovery, automates the discovery and export of OpenAPI specifications from Google Cloud services such as GCP APIs and Apigee proxies. It can automatically resolve a specification based on repository context or labels if available, or explicitly specify an API ID for a known configuration. The action uses Application Default Credentials (ADC) or Workload Identity Federation for authentication and supports exporting every candidate specification to facilitate Postman onboarding processes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action">https://github.com/postman-cs/postman-gcp-spec-discovery-action</a></strong> to version <strong>v1.1.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-gcp-spec-discovery">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, Postman Onboarding: GCP Spec Discovery, automates the discovery and export of OpenAPI specifications from Google Cloud services such as GCP APIs and Apigee proxies. It can automatically resolve a specification based on repository context or labels if available, or explicitly specify an API ID for a known configuration. The action uses Application Default Credentials (ADC) or Workload Identity Federation for authentication and supports exporting every candidate specification to facilitate Postman onboarding processes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(test): select npm CLI on Windows by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/24">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/24</a></li>
<li>chore: prepare v1.1.8 release by @jaredboynton in <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/25">https://github.com/postman-cs/postman-gcp-spec-discovery-action/pull/25</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-gcp-spec-discovery-action/compare/v1.1...v1.1.8">https://github.com/postman-cs/postman-gcp-spec-discovery-action/compare/v1.1...v1.1.8</a></p>
]]></content:encoded></item><item><title>SFDT for Salesforce</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/sfdt-for-salesforce/</link><pubDate>Fri, 24 Jul 2026 06:13:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/sfdt-for-salesforce/</guid><description>Version updated for https://github.com/scoobydrew83/sfdt to version ext-v0.8.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the deployment, testing, and quality analysis of Salesforce changes using the @sfdt/cli tool. It provides features like interactive deployment workflows, automated release manifest generation, parallel Apex test execution, code quality analysis with AI-powered fix plans, pre-release validation checklist, and multi-package project support.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/scoobydrew83/sfdt">https://github.com/scoobydrew83/sfdt</a></strong> to version <strong>ext-v0.8.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sfdt-for-salesforce">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action automates the deployment, testing, and quality analysis of Salesforce changes using the <code>@sfdt/cli</code> tool. It provides features like interactive deployment workflows, automated release manifest generation, parallel Apex test execution, code quality analysis with AI-powered fix plans, pre-release validation checklist, and multi-package project support.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: promote develop → main (extension v0.8.1) by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/268">https://github.com/scoobydrew83/sfdt/pull/268</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/scoobydrew83/sfdt/compare/v0.18.2...ext-v0.8.1">https://github.com/scoobydrew83/sfdt/compare/v0.18.2...ext-v0.8.1</a></p>
]]></content:encoded></item><item><title>Shipi18n Auto Translate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/shipi18n-auto-translate/</link><pubDate>Fri, 24 Jul 2026 06:12:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/shipi18n-auto-translate/</guid><description>Version updated for https://github.com/Shipi18n/shipi18n-github-action to version v1.3.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically translates i18n locale files in a repository using the Shipi18n platform. It supports multiple languages, placeholder preservation, and incremental translation, automating the process of maintaining internationalized content. The action also generates pull requests for review and self-corrects failed translations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Shipi18n/shipi18n-github-action">https://github.com/Shipi18n/shipi18n-github-action</a></strong> to version <strong>v1.3.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/shipi18n-auto-translate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically translates i18n locale files in a repository using the Shipi18n platform. It supports multiple languages, placeholder preservation, and incremental translation, automating the process of maintaining internationalized content. The action also generates pull requests for review and self-corrects failed translations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Relicensed to Apache-2.0.</p>
]]></content:encoded></item><item><title>soroush-bench</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/soroush-bench/</link><pubDate>Fri, 24 Jul 2026 06:11:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/soroush-bench/</guid><description>Version updated for https://github.com/soroush-tech/bench-action to version v1.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The bench-action GitHub Action automates benchmarking of TypeScript files using the @soroush.tech/bench package in a Docker sandbox. It fails the CI build if any case drops below a specified minimum speed ratio compared to the baseline case, and posts results as a sticky PR comment using the bench bot if configured with the id-token: write permission. The action is easy to use as it doesn’t require installation or setup beyond selecting a release tag.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/soroush-tech/bench-action">https://github.com/soroush-tech/bench-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/soroush-bench">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>bench-action</code> GitHub Action automates benchmarking of TypeScript files using the <code>@soroush.tech/bench</code> package in a Docker sandbox. It fails the CI build if any case drops below a specified minimum speed ratio compared to the baseline case, and posts results as a sticky PR comment using the bench bot if configured with the <code>id-token: write</code> permission. The action is easy to use as it doesn&rsquo;t require installation or setup beyond selecting a release tag.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="bench-actionv1">bench-action@v1</h2>
<p>First public release of <strong>Bench Gate</strong> — a performance gate for pull requests.</p>
<p>It runs your repo&rsquo;s <a href="https://www.npmjs.com/package/@soroush.tech/bench"><code>@soroush.tech/bench</code></a> <code>*.bench.ts</code> suites inside a CPU/RAM-pinned Docker sandbox, compares every case against a baseline case, <strong>fails the job</strong> when any case drops below your minimum speed ratio, and posts the results as a single sticky PR comment that updates in place on every push.</p>
<p><strong>One <code>uses:</code> step, zero setup.</strong></p>
<h3 id="highlights">Highlights</h3>
<ul>
<li>
<p><strong>Pinned sandbox, stable numbers</strong><br>
Every suite runs in a Docker container pinned to a single CPU (<code>--cpuset-cpus</code>) with a hard CPU quota and a memory cap (swap disabled), so timings stay comparable run-to-run even on shared runners. <code>rounds: N</code> gates on the median of N runs for extra noise immunity.</p>
</li>
<li>
<p><strong>Ratio gate</strong><br>
Pick a <code>baseline-case</code> and a <code>min-ratio</code> (percent). Any case slower than the threshold fails its file; any failed file fails the job. Gate against your last published version by declaring it via npm&rsquo;s <code>latest</code> dist-tag directly inside the bench file.</p>
</li>
<li>
<p><strong>Zero-config results comment</strong><br>
<code>github-token</code> defaults to the workflow&rsquo;s automatic runtime token—no secrets to wire. Pass <code>''</code> to skip commenting entirely; the gate verdict is never affected by comment delivery.</p>
</li>
<li>
<p><strong>Branded comments (optional)</strong><br>
Install the <a href="https://github.com/apps/soroush-bench">bench GitHub App</a> and grant <code>id-token: write</code>. The comment is authored by the <strong>bench bot</strong> via an OIDC-verified relay, with automatic fallback to a direct GitHub comment if the relay is unavailable.</p>
</li>
<li>
<p><strong>Everything baked in</strong><br>
The bundled runner and vendored sandbox ship with the release tag. GitHub-hosted runners already provide Docker, so there&rsquo;s nothing to install, build, or download in your workflow.</p>
</li>
</ul>
<h3 id="getting-started">Getting Started</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">bench</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span> <span style="color:#75715e"># Required for the results comment</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">id-token</span>: <span style="color:#ae81ff">write</span> <span style="color:#75715e"># Optional, enables branded &#34;bench bot&#34; comments</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v5</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">soroush-tech/bench-action@v1</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">bench-dir</span>: <span style="color:#ae81ff">bench</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">baseline-case</span>: <span style="color:#ae81ff">previous</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">min-ratio</span>: <span style="color:#e6db74">&#34;80&#34;</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">rounds</span>: <span style="color:#e6db74">&#34;5&#34;</span>
</span></span></code></pre></div><h3 id="branded-comments">Branded Comments</h3>
<p>Branded comments are a <strong>one-time, secret-free setup</strong>:</p>
<ol>
<li>Install the <a href="https://github.com/apps/soroush-bench">bench GitHub App</a> on your repository.</li>
<li>Keep <code>id-token: write</code> in your workflow permissions.</li>
</ol>
<p>If you skip both, everything still works—the results comment is simply posted by <code>github-actions[bot]</code>.</p>
<h3 id="requirements">Requirements</h3>
<ul>
<li>A <strong>Linux</strong> runner with Docker (all GitHub-hosted Linux runners qualify).</li>
<li>The <strong>Node 24 Actions runtime</strong>. Any current GitHub-hosted runner works; self-hosted runners must be recent enough to include Node 24.</li>
<li>Pin a release (<code>@v1</code> or a version tag). <strong><code>@main</code> does not include build artifacts and will not run.</strong></li>
</ul>
]]></content:encoded></item><item><title>Sigbound</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/sigbound/</link><pubDate>Fri, 24 Jul 2026 06:10:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/sigbound/</guid><description>Version updated for https://github.com/surya-koritala/sigbound to version v1.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sigbound automates the process of merging code changes from multiple AI coding agents in parallel, resolving conflicts using a model and verifying merges before they land. It uses Git worktrees to handle each agent’s work independently and combines non-conflicting changes efficiently. The action is customizable with various commands for planning, running agents, resolving conflicts, verifying merges, and repairing failed builds, allowing users to harness their own AI models for effective collaboration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/surya-koritala/sigbound">https://github.com/surya-koritala/sigbound</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sigbound">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sigbound automates the process of merging code changes from multiple AI coding agents in parallel, resolving conflicts using a model and verifying merges before they land. It uses Git worktrees to handle each agent&rsquo;s work independently and combines non-conflicting changes efficiently. The action is customizable with various commands for planning, running agents, resolving conflicts, verifying merges, and repairing failed builds, allowing users to harness their own AI models for effective collaboration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>cbfd3b7ac0ba5d0f1689c06599f2a6cc243c898b docs: correct /ui auth prose to match the SPA-shell pattern</li>
<li>5cbcf58af0c98e3e91bb2bcb5301d35c0815a6cd fix: close bare &lsquo;<em>&rsquo; fail-open in -env-</em> allowlists (issue #56)</li>
<li>b41f5a535d184afcfb92118ee41f9af2e6f4a53e fix: don&rsquo;t count -verify-cache hits toward verify.invocations/wallMs</li>
<li>e6043c25b71cf264512d597781f4bfbec72cb8d8 fix: resolve singleton group heads to OIDs in IntegrateOCC</li>
<li>b894a53137a70bdeba7c22d4ea81b23e9db838c3 fix: serve /ui unauthenticated so the token field is reachable</li>
</ul>
]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/rustscript-action/</link><pubDate>Fri, 24 Jul 2026 06:09:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.2.7.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RustScript is a tool that allows running Rust scripts without compiling them. It supports a practical subset of the language and provides features like rust check to validate scripts without executing them. The interpreter does not implement a second type system, but it handles errors and panics as expected for compiled Rust code.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.2.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>RustScript is a tool that allows running Rust scripts without compiling them. It supports a practical subset of the language and provides features like <code>rust check</code> to validate scripts without executing them. The interpreter does not implement a second type system, but it handles errors and panics as expected for compiled Rust code.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.2...v0.2.7">https://github.com/VladasZ/rustscript/compare/v0.2...v0.2.7</a></p>
]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/cowork-harness/</link><pubDate>Fri, 24 Jul 2026 06:07:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.8.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary cowork-harness is a scriptable, CI-friendly test harness that accurately reproduces Claude Cowork’s observable runtime contract. It supports various testing scenarios and environments, including local skills and live tiers with multi-node setups and Docker containers. The tool helps developers automate their skill testing across different platforms and ensures consistent behavior with real Cowork runs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v1.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>cowork-harness is a scriptable, CI-friendly test harness that accurately reproduces Claude Cowork&rsquo;s observable runtime contract. It supports various testing scenarios and environments, including local skills and live tiers with multi-node setups and Docker containers. The tool helps developers automate their skill testing across different platforms and ensures consistent behavior with real Cowork runs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong><code>check:versions</code> closes the stale-pin gap a docs audit found.</strong> Three new enforcement surfaces:
every companion-skill <code>references/*.md</code> <code>(baseline desktop-X.Y.Z)</code> pin must match SKILL.md&rsquo;s
<code>tracks-harness</code> baseline; <code>task-recipes.md</code> now carries the same guarded
<code>Tracks `cowork-harness X.Y.Z`</code> stamp as the other references (and is a <code>bump-version</code> target);
DESIGN.md&rsquo;s one present-tense &ldquo;currently <strong>X</strong>, per <code>baselines/desktop-Y.json</code>&rdquo; sentence must name the
max committed baseline + its <code>agentVersion</code> (its dated verification-pass notes stay exempt). A new
docs-index sync test keeps README&rsquo;s Documentation table and docs/README.md&rsquo;s Guides table from
drifting apart (that drift is how <code>critique.md</code> went missing from the README table).</p>
</li>
<li>
<p><strong><code>doctor</code> warns when a <em>pulled</em> agent image is behind the published one.</strong> For the
<code>container</code>/<code>hostloop</code>/<code>cowork</code> tiers, a new advisory <code>image-freshness</code> check compares the local agent
image&rsquo;s registry digest against the current published <code>ghcr.io/yaniv-golan/cowork-agent-base:2</code> (or
<code>-full</code>) and warns — with a re-pull + retag remedy — when they diverge. Best-effort and never blocking:
a locally-built image (no registry digest), an offline host, <code>docker buildx</code> being unavailable, or a
custom <code>COWORK_AGENT_IMAGE</code> is a quiet skip, never a false &ldquo;stale&rdquo;; only a pulled image incurs a network
probe. The <code>doctor --output-format json</code> envelope gains an <code>image-freshness</code> entry (the open
<code>checks[].id</code> set — SPEC §12 — already permits this).</p>
</li>
<li>
<p><code>critique</code> now stamps <code>verdictProvenance</code> on every report (JSON key + text &ldquo;verdict scope&rdquo; line): the
verdict is an advisory self-run, not an independent attestation.</p>
</li>
<li>
<p><strong><code>critique --skill &lt;name&gt;</code> — plugin-aware grading.</strong> A multi-skill plugin root (<code>skills/&lt;name&gt;/SKILL.md</code>,
no root SKILL.md) previously graded a missing file, downgrading every coverage finding to &ldquo;not
adjudicable&rdquo;. <code>--skill</code> selects the invoked skill&rsquo;s folder for the packager (selection only — the
positional folder is still what both turns mount, and <code>fingerprint.skillHash</code> is unchanged: per-plugin,
not per-skill); a multi-skill root with no <code>--skill</code> is refused <strong>before any model spend</strong>, naming the
available skills; a single-skill plugin auto-selects with a notice. The evidence package now also
carries the invoked skill&rsquo;s <code>agents/&lt;name&gt;.md</code> body and bounded <code>references/*.md</code> <strong>content</strong> (not just
filenames), and the report carries an advisory <code>skillInvocationObserved</code> (false = the graded run&rsquo;s own
<code>skillActivity</code> never mentions the selected skill).</p>
</li>
<li>
<p><strong><code>critique</code> persists run-dir artifacts.</strong> Every critique writes <code>critique-report.json</code> (the
machine-readable report); when the evaluator ran, <code>critique-evidence-package.txt</code> (the exact armored
corpus it graded against — re-grade a disputed finding offline); on an instrument failure (exit 2),
<code>critique-salvage.json</code> (the self-report + each evaluator pass&rsquo;s RAW reply captured <strong>pre-parse</strong>).
New <code>--out &lt;path&gt;</code> also writes the selected-format report to a file. The two <code>not-built</code> limitations
these close (<code>evidence-not-persisted</code>, <code>report-stdout-only</code>) are removed from the registry.</p>
</li>
<li>
<p><strong>Per-critique cost across all four workloads.</strong> The report&rsquo;s <code>costUsd</code> sums the task turn, reflection
turn, and BOTH evaluator passes (whose usage the transport previously discarded), marked <code>INCOMPLETE</code>
whenever any workload is unpriced. The header also carries the pinned <code>fidelity</code> plus the graded turn&rsquo;s
recorded <code>gradedEffectiveFidelity</code>/<code>gradedBaseline</code>, and the graded run&rsquo;s resolved gate answers are
echoed as copy-pasteable <code>--answer</code> lines (JSON: <code>gateAnswers</code>).</p>
</li>
<li>
<p><strong><code>critique</code> evaluator parse is per-item tolerant.</strong> One malformed item in an <code>{&quot;items&quot;:[...]}</code> reply
previously discarded the whole document (&ldquo;no valid JSON found&rdquo;, a broken discovery run). Valid items now
survive; malformed ones are dropped AND counted (<code>droppedEvaluatorItems</code>, surfaced in both report
formats). The integrity canary is recognized by its <code>idea</code> alone (a mutated echo still proves
instruction-following) and stripped before dedup, so a full-document + canary-only-restatement reply no
longer trips the ambiguity throw. Fail-loud preserved: garbage, or all-malformed-with-no-canary, still
throws — now naming which field check failed.</p>
</li>
<li>
<p><strong>Sub-agent research is observable end-to-end.</strong> A sub-agent&rsquo;s WebSearch never enters the main
<code>toolCounts</code>/<code>webSearches[]</code>; its query + result are now captured from the child session transcript as
<code>subagents[].webSearches</code> (bounded, live/record lane only — absent on replay, and absence is never
evidence of no research), surfaced by the new <strong><code>trace --view subagent-research</code></strong>, and packaged into
critique&rsquo;s evidence as a &ldquo;Sub-agent research&rdquo; section so &ldquo;researched&rdquo; claims are groundable.</p>
</li>
<li>
<p>Each critique item now carries a <strong><code>findingFingerprint</code></strong> (sha16 over the normalized
idea + classification + recommendedAction, deliberately excluding the input-specific evidence excerpt) —
clusters the SAME finding across DIFFERENT inputs, complementing <code>skillHash</code> (same skill across fixes).
docs/critique.md gains a &ldquo;Reproduction&rdquo; section documenting the ≥2-run discipline.</p>
</li>
<li>
<p>SKILL.md truncation is now reported distinctly: a readable-but-oversized SKILL.md marks the report
<code>skillMdTruncated</code> (&ldquo;the evaluator graded a cut copy&rdquo;) instead of being indistinguishable from a fully
packaged one; only missing/unreadable still forces the mechanical &ldquo;already-covered&rdquo; downgrade — the
<code>--help</code>/docs limitation wording now says so.</p>
</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>Published agent images (<code>cowork-agent-base</code> / <code>cowork-agent-full</code>) now carry OCI metadata labels</strong>
(<code>org.opencontainers.image.{title,description,source,documentation,licenses}</code>), so their GHCR package
pages render a description, repo link, license, and the &ldquo;contains no Anthropic binary&rdquo; provenance note
instead of appearing bare. The <code>publish-image</code> workflow sets the <code>full</code> variant&rsquo;s title/description via
<code>--label</code> so its page isn&rsquo;t mislabeled by the base image&rsquo;s baked-in defaults.</li>
<li><code>critique</code> evidence caps raised: SKILL.md 16KB→64KB, transcript 16KB→32KB, overall package 48KB→144KB
(the overall cap sits above the worst-case per-section sum, agents/references/research sections included), so
a flagship-sized (~51KB) SKILL.md no longer grades permanently truncated. Increases per-critique evaluator
token cost on large skills (~2–2.5×).</li>
<li><code>sync</code>&rsquo;s two code-tripwire warnings (the <code>getMcpSkillSources</code> caller-count and MCP-skills-capability
checks) now carry a self-contained instruction — re-verify whether MCP servers can contribute skills and
whether the harness must model MCP-contributed skill sources — instead of pointing at a reference the
published repo does not carry.</li>
<li><strong>Pinned sessions stamp their fidelity tier on <code>session.json</code>, and a cross-tier <code>--resume</code> fails loud</strong>
(pre-spawn, with a &ldquo;re-run at <code>--fidelity &lt;stamped&gt;</code>&rdquo; remedy). The agent&rsquo;s native conversation store is
tier-LOCAL — container persists it under the work tree, hostloop under the host config dir — so resuming
a session at a different tier would hand the binary a <code>--resume</code> for a conversation its store has never
seen. Legacy stampless manifests (pre-dating the stamp) are let through with a warning; every manifest
written from now on carries the stamp. <code>readSessionManifest</code> gains a required <code>expectedFidelity</code>
argument.</li>
</ul>
<h3 id="docs">Docs</h3>
<ul>
<li>README documents that the agent images are <strong>published to GHCR</strong> and can be pulled + retagged instead of
built from scratch (<code>:2</code> floats to the latest release; <code>:2-&lt;version&gt;</code> pins an immutable per-release
build), and that the harness resolves the <em>local</em> tag — so a stale local image shadows the published one;
re-pull after upgrading. The <code>doctor</code> command row notes the new freshness warning.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>hostloop uploads bullet advertised a non-readable path.</strong> The dynamic &ldquo;## Shell access&rdquo; section
rendered the uploads mapping&rsquo;s file-tool side as <code>dirname(upload.hostPath)</code> — the user&rsquo;s original
source dir, which the path-containment gate does not allow — while the base prompt pointed at the
correct staged dir. An agent following the bullet got &ldquo;outside this session&rsquo;s connected folders&rdquo; and
worked around it via copy-into-outputs + <code>rm</code>, tripping a spurious <code>outputs-delete</code> fail. The bullet
now advertises the staged uploads dir — the SAME hoisted value the path gate allows, so the prompt and
the gate cannot disagree. (Live-verified: hostloop <code>--upload</code> + Read-tool read succeeds at the
advertised path.)</li>
<li>The task-turn timeout kill message now names <code>--timeout</code> and the 10-minute default; a &ldquo;missing&rdquo;
SKILL.md report note now points at <code>--skill</code> / the invoked skill&rsquo;s folder (the multi-skill-plugin-root
cause) instead of only stating the symptom.</li>
<li>Shipped-doc corrections that induced field misdiagnoses: the cowork-harness skill&rsquo;s gotcha #8 now states
that <strong>production enforces</strong> outputs delete-deny (EPERM + approval) and the harness gap is
detection-only; docs/critique.md documents that a WebSearch produces <strong>no search-host entries in the
container egress.log</strong> (an <code>api.anthropic.com</code>-only log is consistent with research working —
live-verified with a first-party capture) and that sub-agent searches don&rsquo;t increment the main
<code>toolCounts.WebSearch</code>; the shipped fidelity reference explains the hostloop Read-vs-bash path split
including uploads readability.</li>
<li><strong><code>critique</code> now runs at <code>--fidelity hostloop</code> as well as <code>container</code> — the container-tier pin is
lifted.</strong> The pin existed because the reflection turn <em>resumes</em> the task turn and resume-continuity was
only proven for the container Linux ELF; a live two-turn proof at hostloop&rsquo;s <strong>native</strong> agent binary
(<code>test/live-contract.test.ts</code>, &ldquo;resume-continuity proof at hostloop&rdquo;) cleared it, and a live
<code>critique --fidelity hostloop</code> e2e validates the full protocol there. <code>microvm</code>/<code>protocol</code>/<code>cowork</code> stay
refused, each with its own stated reason: the single <code>container-tier-only</code> limitation is replaced by
three tagged ones — <code>microvm-tier-refused</code> <code>[unverified]</code> (a resume-continuity proof at the microVM guest
would lift it), <code>protocol-tier-refused</code> <code>[not-built]</code> (protocol never plumbs a session id/<code>--resume</code>),
and <code>cowork-tier-refused</code> <code>[deliberate]</code> (the synced loop gate would make the graded tier
baseline-dependent, adding noise to skillHash-paired generation comparisons).</li>
<li><strong><code>skill</code> accepts <code>--allow-host-writes</code></strong> (and <code>critique</code> forwards it to BOTH turns) — the
hostloop writable-connected-folder consent that previously only <code>chat</code> (its own flag) and <code>run</code> (the
<code>allow_host_writes: true</code> scenario field) could grant; a plain <code>skill --fidelity hostloop --folder X</code>
was refused with no way to consent at all. Folder-less runs (skill dir + uploads) still need no consent —
uploads and skill/plugin mounts are read-only.</li>
<li><strong><code>critique</code>&rsquo;s spaced flag parser no longer silently grabs the next flag as a value.</strong> <code>critique &lt;folder&gt; --prompt --output-format json</code> (a forgotten <code>--prompt</code> value) swallowed <code>--output-format</code> as the
prompt AND dropped the real flag, then ran a four-workload critique on the wrong input. The spaced form
now fails loud and points at the equals escape hatch (<code>--prompt=&lt;value&gt;</code>) for a value that intentionally
starts with <code>-</code>.</li>
<li><strong><code>critique</code>&rsquo;s subprocess byte cap is now one combined stdout+stderr budget.</strong> <code>boundedSpawn</code> kept two
independent per-stream counters, so a looping or hostile child splitting output across both streams could
buffer ~2× the documented cap before either tripped. It now charges both streams against a single budget
and slices the terminal chunk to the remaining room, so captured output never exceeds the cap.</li>
<li><strong><code>critique</code>&rsquo;s verbatim citation-grounding is now case-sensitive.</strong> The mechanical check that drops any
finding whose cited evidence is not a verbatim excerpt normalized whitespace AND folded case — so a
case-altered (paraphrased) citation resolved as &ldquo;grounded,&rdquo; weakening the principal defense against
evaluator hallucination. It now matches case-exact; whitespace reflow stays tolerated (models reflow
spacing when quoting — they don&rsquo;t change case).</li>
<li><strong>critique&rsquo;s &ldquo;Attached inputs&rdquo; evidence no longer reports <code>(none)</code> when the uploads dir is unreadable.</strong>
<code>listAttachedInputs</code> caught every <code>readdirSync</code> failure identically, so an unreadable uploads dir
(<code>EACCES</code>/<code>ENOTDIR</code>/…) collapsed to the same <code>(none)</code> as a legitimately-absent one — telling the
evaluator &ldquo;the agent correctly saw no file&rdquo; when attachment presence was actually UNKNOWN. It now
distinguishes <code>ENOENT</code> (absent) from a genuine read fault and surfaces the uncertainty loudly.</li>
<li><strong>critique flags a partly-corrupt archived turn-1 transcript instead of grading it as clean.</strong>
<code>readTurn1Transcript</code> skipped malformed JSONL rows (resilient) but returned <code>degraded: false</code> on the
first valid transcript record regardless — so archive corruption vanished from evidence health and the
evaluator graded a silently-incomplete transcript as solid ground truth. It now scans the whole
(turn-1-only) archive and sets <code>turn1SliceDegraded</code> when a malformed row was skipped or the archive
doesn&rsquo;t hold exactly one transcript record; the transcript is still delivered, just flagged.</li>
<li><strong>critique flags a crashed task turn instead of grading evidence from it.</strong> <code>taskTurnInfraFailure</code> only
treated a <em>killed</em> (timed-out / byte-capped) task turn as an instrument failure — a task that exited
nonzero without ever printing a parseable result envelope (a crash after the early <code>[status]</code> line)
slipped through, and its <code>[status]</code>-recovered run dir was reflected on and graded as a legitimate task.
It now also flags a nonzero exit with no parseable envelope. Deliberately narrow: a completed run that
reported a failing verdict (<code>ok:false</code> / <code>result:&quot;error&quot;</code> with a valid envelope) stays gradeable.</li>
<li><strong>A nested unreadable output subtree no longer persists a partial file list as complete.</strong> The
<code>workspaceFiles</code> / <code>artifacts</code> list was recorded as UNAVAILABLE (<code>undefined</code>, the evidence-unavailable
convention) only when the workspace ROOT was unobservable; a nested <code>EACCES</code>/<code>EIO</code> subtree left the walk
partial (<code>walkComplete: false</code>) but still persisted the incompletely-enumerated list as if complete. An
authored file inside the unreadable subtree then vanished with no signal, so an absence-sensitive
consumer (<code>delivered_clean</code> / <code>ended_with_question</code>, the replay <code>diff</code>, <code>scaffold</code>, <code>file_exists</code>) could
read it as absent — a silent false-clean. All three RunResult producers (run, partial-salvage, chat) now
route through one shared <code>trustedWorkspaceFiles</code> gate that collapses a missing root OR any incomplete
walk to <code>undefined</code>, and the run lanes emit a <code>::warning::</code> naming the unreadable subtree.</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(security): fast-uri HIGH advisories + CodeQL URL-substring alert by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/64">https://github.com/yaniv-golan/cowork-harness/pull/64</a></li>
<li>chore(deps): Bump the actions group across 1 directory with 3 updates by @dependabot[bot] in <a href="https://github.com/yaniv-golan/cowork-harness/pull/63">https://github.com/yaniv-golan/cowork-harness/pull/63</a></li>
<li>feat(doctor): warn on stale pulled agent image; label GHCR images by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/65">https://github.com/yaniv-golan/cowork-harness/pull/65</a></li>
<li>fix(critique): reject a flag-looking value in the spaced form (no silent positional-grab) by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/66">https://github.com/yaniv-golan/cowork-harness/pull/66</a></li>
<li>fix(critique): one combined stdout+stderr byte cap in boundedSpawn (was 2 independent caps) by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/67">https://github.com/yaniv-golan/cowork-harness/pull/67</a></li>
<li>fix(critique): make verbatim citation-grounding case-sensitive (was case-folded) by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/68">https://github.com/yaniv-golan/cowork-harness/pull/68</a></li>
<li>fix(critique): don&rsquo;t report &ldquo;(none)&rdquo; attachments when the uploads dir is unreadable by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/69">https://github.com/yaniv-golan/cowork-harness/pull/69</a></li>
<li>fix(critique): degrade a partly-corrupt archived turn-1 transcript (was silently clean) by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/70">https://github.com/yaniv-golan/cowork-harness/pull/70</a></li>
<li>fix(critique): flag a crashed task turn instead of grading evidence from it by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/71">https://github.com/yaniv-golan/cowork-harness/pull/71</a></li>
<li>fix(run): record workspaceFiles/artifacts unavailable on an incomplete workspace walk (#54) by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/72">https://github.com/yaniv-golan/cowork-harness/pull/72</a></li>
<li>release: 1.8.0 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/73">https://github.com/yaniv-golan/cowork-harness/pull/73</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.8.0">https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.8.0</a></p>
]]></content:encoded></item><item><title>Agent Lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/agent-lint/</link><pubDate>Fri, 24 Jul 2026 06:06:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/agent-lint/</guid><description>Version updated for https://github.com/zhupanov/agent-lint to version v4.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Lint is a linter tool that validates configuration files and directories related to Claude, Cursor, Codex, and MCP agents. It checks for various rules such as plugin paths, hook paths, skill frontmatter, agent fields, prompt quality, and more. The action can be used via GitHub Actions or pre-commit hooks, with the option to run specific rules or suppress them based on a configuration file.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zhupanov/agent-lint">https://github.com/zhupanov/agent-lint</a></strong> to version <strong>v4.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Agent Lint is a linter tool that validates configuration files and directories related to Claude, Cursor, Codex, and MCP agents. It checks for various rules such as plugin paths, hook paths, skill frontmatter, agent fields, prompt quality, and more. The action can be used via GitHub Actions or pre-commit hooks, with the option to run specific rules or suppress them based on a configuration file.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Fix manual upgrade handoff by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/656">https://github.com/zhupanov/agent-lint/pull/656</a></li>
<li>Fix false positives from SRE pedantic scan by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/658">https://github.com/zhupanov/agent-lint/pull/658</a></li>
<li>Release v4.0.3 by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/659">https://github.com/zhupanov/agent-lint/pull/659</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/zhupanov/agent-lint/compare/v4...v4.0.3">https://github.com/zhupanov/agent-lint/compare/v4...v4.0.3</a></p>
]]></content:encoded></item><item><title>zizmor-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/zizmor-action/</link><pubDate>Fri, 24 Jul 2026 06:05:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/24/zizmor-action/</guid><description>Version updated for https://github.com/zizmorcore/zizmor-action to version v0.6.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action, zizmor-action, automates the execution of the zizmor security scanning tool in a GitHub workflow. It provides detailed analysis of code to identify potential vulnerabilities and helps developers triage issues more efficiently. The action supports both public and private repositories with various configurations like severity thresholds, token management, and output formats. Users can integrate it into their workflows for continuous security monitoring without relying on advanced security features.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zizmorcore/zizmor-action">https://github.com/zizmorcore/zizmor-action</a></strong> to version <strong>v0.6.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zizmor-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action, <code>zizmor-action</code>, automates the execution of the <code>zizmor</code> security scanning tool in a GitHub workflow. It provides detailed analysis of code to identify potential vulnerabilities and helps developers triage issues more efficiently. The action supports both public and private repositories with various configurations like severity thresholds, token management, and output formats. Users can integrate it into their workflows for continuous security monitoring without relying on advanced security features.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>zizmor 1.28.0 is now the default version used by the action.</p>
]]></content:encoded></item><item><title>slopscore-lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/slopscore-lint/</link><pubDate>Thu, 23 Jul 2026 15:22:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/slopscore-lint/</guid><description>Version updated for https://github.com/jman4162/slopscore to version v0.8.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary slopscore is a transparent linter that measures the density of formulaic, generic, low-specificity, and over-polished writing patterns in text. It reports per-dimension scores and evidence spans to help identify specific writing issues, encouraging clearer, more specific prose. The tool is designed as a prose linter rather than an AI detector for authorship, focusing on detecting common writing patterns that are characteristic of AI-generated or low-effort content.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jman4162/slopscore">https://github.com/jman4162/slopscore</a></strong> to version <strong>v0.8.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/slopscore-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>slopscore</code> is a transparent linter that measures the density of formulaic, generic, low-specificity, and over-polished writing patterns in text. It reports per-dimension scores and evidence spans to help identify specific writing issues, encouraging clearer, more specific prose. The tool is designed as a prose linter rather than an AI detector for authorship, focusing on detecting common writing patterns that are characteristic of AI-generated or low-effort content.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Adds a structural-metaphor tell to <code>insight_signaling</code> — a class a human reader caught that both linters (and a curated grep) missed.</p>
<h2 id="whats-new">What&rsquo;s new</h2>
<p><code>insight_signaling</code> now flags anatomical/structural metaphors for an organizing principle:</p>
<ul>
<li><strong>Noun-of-noun</strong> (&ldquo;the spine of the argument&rdquo;, &ldquo;the backbone of the piece&rdquo;) — <code>INSIGHT_STRUCTURAL_METAPHOR</code>.</li>
<li><strong>Copular</strong> (&ldquo;The spine is the same evidence&hellip;&rdquo;) — <code>INSIGHT_STRUCTURAL_COPULA</code>.</li>
</ul>
<p>Both are context-gated: the noun-of-noun form requires a prose/argument noun, and the copular form gates its complement to abstract nouns — so literal senses (lumbar spine, backbone network, construction/React scaffolding, book spine, &ldquo;a column of vertebrae&rdquo;, &ldquo;a fiber-optic link&rdquo;) do not fire. Bare &ldquo;through-line&rdquo; (legitimate in film/writing) is <code>--broad</code>-only.</p>
<p>Ships with literal-negative unit tests (the real guard for this rule class). The JSON report shape is unchanged; <code>SCHEMA_VERSION</code> stays 0.8.0.</p>
<p>Full changelog: <a href="https://github.com/jman4162/slopscore/blob/main/CHANGELOG.md">https://github.com/jman4162/slopscore/blob/main/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>Bulk GitHub Organization Settings Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/bulk-github-organization-settings-sync/</link><pubDate>Thu, 23 Jul 2026 15:21:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/bulk-github-organization-settings-sync/</guid><description>Version updated for https://github.com/joshjohanning/bulk-github-org-settings-sync-action to version v1.13.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the bulk configuration of various GitHub organization settings across multiple organizations using a declarative YAML configuration file. Key features include syncing custom property definitions, values, rulesets, issue types and fields, member privileges, repository policies, and .github repository files. The action supports dry-run mode for previewing changes and provides per-organization overrides via YAML configuration. It also offers rich job summaries with per-organization status tables for easy tracking of changes. The action is designed to support GitHub.com, GHES, and GHEC platforms.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/joshjohanning/bulk-github-org-settings-sync-action">https://github.com/joshjohanning/bulk-github-org-settings-sync-action</a></strong> to version <strong>v1.13.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bulk-github-organization-settings-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the bulk configuration of various GitHub organization settings across multiple organizations using a declarative YAML configuration file. Key features include syncing custom property definitions, values, rulesets, issue types and fields, member privileges, repository policies, and .github repository files. The action supports dry-run mode for previewing changes and provides per-organization overrides via YAML configuration. It also offers rich job summaries with per-organization status tables for easy tracking of changes. The action is designed to support GitHub.com, GHES, and GHEC platforms.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: add custom property value sync by @joshjohanning in <a href="https://github.com/joshjohanning/bulk-github-org-settings-sync-action/pull/72">https://github.com/joshjohanning/bulk-github-org-settings-sync-action/pull/72</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/joshjohanning/bulk-github-org-settings-sync-action/compare/v1.12.4...v1.13.0">https://github.com/joshjohanning/bulk-github-org-settings-sync-action/compare/v1.12.4...v1.13.0</a></p>
]]></content:encoded></item><item><title>datamodel-code-generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/datamodel-code-generator/</link><pubDate>Thu, 23 Jul 2026 15:20:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/datamodel-code-generator/</guid><description>Version updated for https://github.com/koxudaxi/datamodel-code-generator to version 0.70.0.
This action is used across all versions by 3,357 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of generating Python data models from various schema definitions, including OpenAPI 3, AsyncAPI, JSON Schema, Apache Avro, XML Schema, Protocol Buffers/gRPC, GraphQL, and MCP tool schemas. It supports converting raw data (JSON/YAML/CSV) into Python model output types, retargeting existing Pydantic, dataclass, or TypedDict classes, and outputs models in different styles like Pydantic v2, Pydantic v2 dataclass, dataclasses, TypedDict, or msgspec. The action handles complex schemas with $ref, allOf, oneOf, anyOf, enums, and nested types, producing type-safe, validated code that is ready for IDEs and type checkers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/koxudaxi/datamodel-code-generator">https://github.com/koxudaxi/datamodel-code-generator</a></strong> to version <strong>0.70.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3,357</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/datamodel-code-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of generating Python data models from various schema definitions, including OpenAPI 3, AsyncAPI, JSON Schema, Apache Avro, XML Schema, Protocol Buffers/gRPC, GraphQL, and MCP tool schemas. It supports converting raw data (JSON/YAML/CSV) into Python model output types, retargeting existing Pydantic, dataclass, or TypedDict classes, and outputs models in different styles like Pydantic v2, Pydantic v2 dataclass, dataclasses, TypedDict, or msgspec. The action handles complex schemas with <code>$ref</code>, <code>allOf</code>, <code>oneOf</code>, <code>anyOf</code>, enums, and nested types, producing type-safe, validated code that is ready for IDEs and type checkers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="breaking-changes">Breaking Changes</h2>
<ul>
<li>Preserved additionalProperties value constraints change generated output - JSON Schema <code>additionalProperties</code> (and <code>propertyNames</code>/mapping) value schemas that carry constraints (e.g. <code>minimum</code>/<code>maximum</code>, <code>minLength</code>/<code>maxLength</code>/<code>pattern</code>, array item constraints, <code>allOf</code>-merged primitives) now retain those constraints in the generated model instead of dropping them. This produces new <code>TypeAlias</code>/<code>RootModel</code>/<code>TypeAliasType</code> definitions and changes dict value type hints, so output differs for existing schemas. For example, a mapping value that previously generated <code>dict[str, Literal['fixed']]</code> now generates a dedicated alias preserving the constraints (#3616):</li>
</ul>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-python" data-lang="python"><span style="display:flex;"><span><span style="color:#75715e"># Before</span>
</span></span><span style="display:flex;"><span><span style="color:#66d9ef">class</span> <span style="color:#a6e22e">DictModel</span>(RootModel[dict[str, Literal[<span style="color:#e6db74">&#39;fixed&#39;</span>]]]):
</span></span><span style="display:flex;"><span>    root: dict[str, Literal[<span style="color:#e6db74">&#39;fixed&#39;</span>]]
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># After</span>
</span></span><span style="display:flex;"><span>DictModelAdditionalProperty <span style="color:#f92672">=</span> TypeAliasType(
</span></span><span style="display:flex;"><span>    <span style="color:#e6db74">&#34;DictModelAdditionalProperty&#34;</span>,
</span></span><span style="display:flex;"><span>    Annotated[Literal[<span style="color:#e6db74">&#39;fixed&#39;</span>], Field(max_length<span style="color:#f92672">=</span><span style="color:#ae81ff">100</span>, min_length<span style="color:#f92672">=</span><span style="color:#ae81ff">1</span>)],
</span></span><span style="display:flex;"><span>)
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#66d9ef">class</span> <span style="color:#a6e22e">DictModel</span>(RootModel[dict[str, DictModelAdditionalProperty]]):
</span></span><span style="display:flex;"><span>    root: dict[str, DictModelAdditionalProperty]
</span></span></code></pre></div><h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Update CHANGELOG for 0.69.0 by @dcg-generated-docs[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3613">https://github.com/koxudaxi/datamodel-code-generator/pull/3613</a></li>
<li>Update release benchmark data by @dcg-generated-docs[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3614">https://github.com/koxudaxi/datamodel-code-generator/pull/3614</a></li>
<li>[pre-commit.ci] pre-commit autoupdate by @pre-commit-ci[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3617">https://github.com/koxudaxi/datamodel-code-generator/pull/3617</a></li>
<li>Preserve additionalProperties value constraints by @chuenchen309 in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3616">https://github.com/koxudaxi/datamodel-code-generator/pull/3616</a></li>
<li>Rename a msgspec field named &ldquo;field&rdquo; to avoid shadowing the field import by @chuenchen309 in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3615">https://github.com/koxudaxi/datamodel-code-generator/pull/3615</a></li>
<li>Bump the github-actions group with 8 updates by @dependabot[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3618">https://github.com/koxudaxi/datamodel-code-generator/pull/3618</a></li>
<li>Update types-setuptools requirement from &lt;70,&gt;=67.6.0.5 to &gt;=67.6.0.5,&lt;84 by @dependabot[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3584">https://github.com/koxudaxi/datamodel-code-generator/pull/3584</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/koxudaxi/datamodel-code-generator/compare/0.69.0...0.70.0">https://github.com/koxudaxi/datamodel-code-generator/compare/0.69.0...0.70.0</a></p>
]]></content:encoded></item><item><title>agent-test-verifier</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/agent-test-verifier/</link><pubDate>Thu, 23 Jul 2026 15:19:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/agent-test-verifier/</guid><description>Version updated for https://github.com/LaterKidsXD/agent-test-verifier to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The agent-test-verifier (atv) is a static analysis tool that detects patterns commonly used by coding agents to bypass bug fixes and fool test suite verification. It scans diff files for changes that could lead to fake passing tests, such as force-pass hooks or assertion weakening. The tool can be used in CI pipelines to ensure that code changes actually fix bugs rather than just manipulate the test output.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/LaterKidsXD/agent-test-verifier">https://github.com/LaterKidsXD/agent-test-verifier</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-test-verifier">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The agent-test-verifier (atv) is a static analysis tool that detects patterns commonly used by coding agents to bypass bug fixes and fool test suite verification. It scans diff files for changes that could lead to fake passing tests, such as force-pass hooks or assertion weakening. The tool can be used in CI pipelines to ensure that code changes actually fix bugs rather than just manipulate the test output.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release of the <strong>agent-test-verifier</strong> GitHub Action: a static, deterministic check that catches the patterns coding agents use to fake a passing test suite — force-pass <code>conftest.py</code> hooks, neutered/trivialized assertions, newly skipped tests, and null tests that cannot fail.</p>
<h2 id="use-it">Use it</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">agent-test-verifier</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">on</span>: <span style="color:#ae81ff">pull_request</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">atv</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">fetch-depth</span>: <span style="color:#ae81ff">0</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">LaterKidsXD/agent-test-verifier@v1</span>
</span></span></code></pre></div><p>Findings show up as inline annotations on the PR diff, a findings table on the run&rsquo;s Summary page, and a red check when anything meets the <code>fail-on</code> bar. See the <a href="https://github.com/LaterKidsXD/agent-test-verifier/pull/2">permanently open demo PR</a> with every pattern planted.</p>
<h2 id="101">1.0.1</h2>
<ul>
<li>Marketplace branding metadata in <code>action.yml</code></li>
<li>README: live demo PR link</li>
<li>Fixed <code>atv.__version__</code> drift (<code>0.1.0</code> → in lockstep with the package version)</li>
</ul>
<h2 id="100">1.0.0</h2>
<ul>
<li><code>--format {text,json,github,markdown}</code> CLI (<code>--json</code> kept as alias)</li>
<li>Composite action: base-ref resolution, severity-gated annotations, step-summary table, honest exit codes (<code>0</code> clean / <code>1</code> findings / <code>2</code> usage error — never a silent false &ldquo;clean&rdquo;)</li>
<li>Self-check workflow dogfooding the action on this repo&rsquo;s own PRs</li>
</ul>
]]></content:encoded></item><item><title>jira-cve-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/jira-cve-action/</link><pubDate>Thu, 23 Jul 2026 15:18:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/jira-cve-action/</guid><description>Version updated for https://github.com/levigo/jira-cve-action to version v1.24.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action takes vulnerabilities from Trivy scans and creates Jira issues for each vulnerability. It automatically adds these issues as subtasks under a parent issue and can move them between states based on whether they have a fix version or not. The action also ensures that CVEs are shared across multiple projects in the same Jira instance, with project-specific versions marked on each issue.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/levigo/jira-cve-action">https://github.com/levigo/jira-cve-action</a></strong> to version <strong>v1.24</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jira-cve-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action takes vulnerabilities from Trivy scans and creates Jira issues for each vulnerability. It automatically adds these issues as subtasks under a parent issue and can move them between states based on whether they have a fix version or not. The action also ensures that CVEs are shared across multiple projects in the same Jira instance, with project-specific versions marked on each issue.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Merge pull request #17 from levigo/fix/NF-3145_CVE_Score (c4ee83e)</li>
<li>fix(NF-3145): Implement score selection analog with Trivys severity filter. (ce50175)</li>
<li>Merge pull request #16 from levigo/fix/NF-2994-link-to-cve-database-in-generated-cve-tickets-doesnt-work-404-error (81c9666)</li>
<li>fix(NF-2994): update URL resolution to return multiple references for CVE tickets (e3d857b)</li>
<li>Merge pull request #14 from levigo/fix/NF-2994-link-to-cve-database-in-generated-cve-tickets-doesnt-work-404-error (ada9e08)</li>
<li>fix(NF-2994): update URL resolution to return multiple references for CVE tickets (1cb2f2d)</li>
<li>fix(NF-2994): update URL resolution to return multiple references for CVE tickets (1e8feb2)</li>
<li>Merge pull request #13 from levigo/feature/esm (6130050)</li>
<li>fix(INF-346): json syntax error (2b9e63b)</li>
<li>Merge pull request #12 from levigo/feature/esm (a3852cf)</li>
</ul>
]]></content:encoded></item><item><title>lgtmaybe</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/lgtmaybe/</link><pubDate>Thu, 23 Jul 2026 15:18:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/lgtmaybe/</guid><description>Version updated for https://github.com/MattJColes/lgtmaybe to version lgtmaybe-v0.12.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: lgtmaybe is a provider-agnostic GitHub Action that automatically reviews pull requests by analyzing the diff. It provides a comprehensive review including logic and correctness bugs, security vulnerabilities, missing tests, outdated code, performance regressions, unnecessary complexity, intent misalignment, and potential ponytail (code redundancy) issues. The tool uses OpenAI models to generate inline comments and a summary of the PR’s changes, handling sensitive information securely and efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MattJColes/lgtmaybe">https://github.com/MattJColes/lgtmaybe</a></strong> to version <strong>lgtmaybe-v0.12.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lgtmaybe">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary</strong>: lgtmaybe is a provider-agnostic GitHub Action that automatically reviews pull requests by analyzing the diff. It provides a comprehensive review including logic and correctness bugs, security vulnerabilities, missing tests, outdated code, performance regressions, unnecessary complexity, intent misalignment, and potential ponytail (code redundancy) issues. The tool uses OpenAI models to generate inline comments and a summary of the PR&rsquo;s changes, handling sensitive information securely and efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="0122-2026-07-22"><a href="https://github.com/MattJColes/lgtmaybe/compare/lgtmaybe-v0.12.1...lgtmaybe-v0.12.2">0.12.2</a> (2026-07-22)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>homebrew:</strong> prefer wheels so litellm &gt;=1.92 sdist never builds in the sandbox (<a href="https://github.com/MattJColes/lgtmaybe/issues/189">#189</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/df6e7e1cc417bce46f8cb0823315b7af31df37b8">df6e7e1</a>)</li>
</ul>
<h3 id="dependencies">Dependencies</h3>
<ul>
<li>bump the python-dependencies group with 6 updates (<a href="https://github.com/MattJColes/lgtmaybe/issues/187">#187</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/5615a792c64c760e88cb230aef73aac4b5335197">5615a79</a>)</li>
</ul>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/totem-shield/</link><pubDate>Thu, 23 Jul 2026 15:17:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.104.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Totem is a tool that automates the process of creating and enforcing coding rules within repositories using Markdown lessons. It ensures that project-specific knowledge and lessons are stored alongside the code, preventing inconsistencies between sessions and reducing the need for constant re-explanations. By compiling lint rules from these lessons, Totem provides a deterministic, offline linter that helps maintain architectural integrity and velocity.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.104.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Totem is a tool that automates the process of creating and enforcing coding rules within repositories using Markdown lessons. It ensures that project-specific knowledge and lessons are stored alongside the code, preventing inconsistencies between sessions and reducing the need for constant re-explanations. By compiling lint rules from these lessons, Totem provides a deterministic, offline linter that helps maintain architectural integrity and velocity.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>Setup iso8583tool</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/setup-iso8583tool/</link><pubDate>Thu, 23 Jul 2026 15:16:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/setup-iso8583tool/</guid><description>Version updated for https://github.com/nao1215/setup-iso8583tool to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action installs the iso8583tool CLI, a tool for generating and parsing ISO 8583 messages, on your CI/CD pipelines. It downloads prebuilt binaries instead of building from source, ensuring fast execution times across Linux, macOS, and Windows platforms. The action allows you to specify a version to install and verify checksums or attestation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nao1215/setup-iso8583tool">https://github.com/nao1215/setup-iso8583tool</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-iso8583tool">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action installs the iso8583tool CLI, a tool for generating and parsing ISO 8583 messages, on your CI/CD pipelines. It downloads prebuilt binaries instead of building from source, ensuring fast execution times across Linux, macOS, and Windows platforms. The action allows you to specify a version to install and verify checksums or attestation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nao1215/setup-iso8583tool/commits/v0.1.0">https://github.com/nao1215/setup-iso8583tool/commits/v0.1.0</a></p>
]]></content:encoded></item><item><title>LinkML (linkml-scala)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/linkml-linkml-scala/</link><pubDate>Thu, 23 Jul 2026 15:15:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/linkml-linkml-scala/</guid><description>Version updated for https://github.com/NeverBlink-OSS/linkml-scala-action to version v0.11.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action linkml-scala-action automates the validation and generation of LinkML schemas using Node.js. It supports various commands like validate and generate, with options to specify schema files, strict mode, and output directories. The action can emit annotations to GitHub PRs, making it easier to track issues in schema definitions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NeverBlink-OSS/linkml-scala-action">https://github.com/NeverBlink-OSS/linkml-scala-action</a></strong> to version <strong>v0.11.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/linkml-linkml-scala">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>linkml-scala-action</code> automates the validation and generation of LinkML schemas using Node.js. It supports various commands like validate and generate, with options to specify schema files, strict mode, and output directories. The action can emit annotations to GitHub PRs, making it easier to track issues in schema definitions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Tracks <a href="https://github.com/NeverBlink-OSS/linkml-scala/releases/tag/v0.11.0">linkml-scala v0.11.0</a>.</p>
<p>Bundles <code>@neverblink/linkml@0.11.0</code>.</p>
<ul>
<li>Pin <code>uses: NeverBlink-OSS/linkml-scala-action@v0.11.0</code> for reproducibility.</li>
<li>Pin <code>@v1</code> for automatic patch/minor updates.</li>
</ul>
]]></content:encoded></item><item><title>AI Harness Doctor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/ai-harness-doctor/</link><pubDate>Thu, 23 Jul 2026 15:15:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/ai-harness-doctor/</guid><description>Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v1.16.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Harness Doctor automates the auditing of AI agent configurations across repositories to ensure consistency and accuracy in instruction sets. It helps consolidate scattered guidance into a single AGENTS.md file, improves agent answers by consolidating conflicting instructions, and measures improvements in latency and cost. The tool also detects issues such as overlapping files, mismatched declarations, and conflicts within the same scope.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NieZhuZhu/ai-harness-doctor">https://github.com/NieZhuZhu/ai-harness-doctor</a></strong> to version <strong>v1.16.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-harness-doctor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AI Harness Doctor automates the auditing of AI agent configurations across repositories to ensure consistency and accuracy in instruction sets. It helps consolidate scattered guidance into a single <code>AGENTS.md</code> file, improves agent answers by consolidating conflicting instructions, and measures improvements in latency and cost. The tool also detects issues such as overlapping files, mismatched declarations, and conflicts within the same scope.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(registry): recognize Warp, Firebase Studio, Goose, and Kiro agents by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/325">https://github.com/NieZhuZhu/ai-harness-doctor/pull/325</a></li>
<li>fix(scan): stop reading &ldquo;npm provenance&rdquo; release prose as npm package-manager usage by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/326">https://github.com/NieZhuZhu/ai-harness-doctor/pull/326</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NieZhuZhu/ai-harness-doctor/compare/v1.15.2...v1.16.0">https://github.com/NieZhuZhu/ai-harness-doctor/compare/v1.15.2...v1.16.0</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Workspace Bootstrap</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/postman-onboarding-workspace-bootstrap/</link><pubDate>Thu, 23 Jul 2026 15:14:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/postman-onboarding-workspace-bootstrap/</guid><description>Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.10.8.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the provisioning of a Postman workspace by generating baseline, smoke, and contract collections based on an OpenAPI specification. It includes dynamic contract tests that validate request/response schemas, security checks, and multi-protocol support. The action provides executable contract tests and logs the Postman CLI in for spec linting.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-bootstrap-action">https://github.com/postman-cs/postman-bootstrap-action</a></strong> to version <strong>v2.10.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-workspace-bootstrap">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the provisioning of a Postman workspace by generating baseline, smoke, and contract collections based on an OpenAPI specification. It includes dynamic contract tests that validate request/response schemas, security checks, and multi-protocol support. The action provides executable contract tests and logs the Postman CLI in for spec linting.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: converge concurrent generation ownership by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/110">https://github.com/postman-cs/postman-bootstrap-action/pull/110</a></li>
<li>fix(release): publish verified bootstrap artifacts by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/111">https://github.com/postman-cs/postman-bootstrap-action/pull/111</a></li>
<li>feat: parallelize bootstrap generation and harden SEA startup by @mmorales-post in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/100">https://github.com/postman-cs/postman-bootstrap-action/pull/100</a></li>
<li>test: rebind fanout evidence after squash by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/113">https://github.com/postman-cs/postman-bootstrap-action/pull/113</a></li>
<li>fix: wait for canonical fanout links by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/115">https://github.com/postman-cs/postman-bootstrap-action/pull/115</a></li>
<li>perf(ci): accelerate Windows parity gate by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/114">https://github.com/postman-cs/postman-bootstrap-action/pull/114</a></li>
<li>chore: prepare v2.10.8 by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/118">https://github.com/postman-cs/postman-bootstrap-action/pull/118</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.10.8">https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.10.8</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Insights Linking</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/postman-onboarding-insights-linking/</link><pubDate>Thu, 23 Jul 2026 15:13:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/postman-onboarding-insights-linking/</guid><description>Version updated for https://github.com/postman-cs/postman-insights-onboarding-action to version v2.1.6.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the linking of services discovered by Postman Insights to a Postman workspace and Git repository, ensuring they are linked with collections, repo links, and live telemetry. It requires human-user credentials and a specific region for the insights agent discovery mode. The action does not deploy the agent or perform other setup tasks but provides a link mechanism once the service is discovered.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-insights-onboarding-action">https://github.com/postman-cs/postman-insights-onboarding-action</a></strong> to version <strong>v2.1.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-insights-linking">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the linking of services discovered by Postman Insights to a Postman workspace and Git repository, ensuring they are linked with collections, repo links, and live telemetry. It requires human-user credentials and a specific region for the insights agent discovery mode. The action does not deploy the agent or perform other setup tasks but provides a link mechanism once the service is discovered.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: extract staged package identity cleanly by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/58">https://github.com/postman-cs/postman-insights-onboarding-action/pull/58</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-insights-onboarding-action/compare/v2.1.5...v2.1.6">https://github.com/postman-cs/postman-insights-onboarding-action/compare/v2.1.5...v2.1.6</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Repo Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/postman-onboarding-repo-sync/</link><pubDate>Thu, 23 Jul 2026 15:12:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/postman-onboarding-repo-sync/</guid><description>Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.1.13.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of exporting Postman collections and environments into a repository, setting up CI, mocking servers, and monitors around them. It solves the problem of managing API assets (collections, environments, mocks, monitors) in a centralized location within a Git repository. Key capabilities include:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-repo-sync-action">https://github.com/postman-cs/postman-repo-sync-action</a></strong> to version <strong>v2.1.13</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-repo-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of exporting Postman collections and environments into a repository, setting up CI, mocking servers, and monitors around them. It solves the problem of managing API assets (collections, environments, mocks, monitors) in a centralized location within a Git repository. Key capabilities include:</p>
<ul>
<li>Exporting Postman assets to <code>.postman</code> directory</li>
<li>Generating a CI workflow file based on selected assets</li>
<li>Setting up mock servers for test environments</li>
<li>Creating or updating monitors for asset health</li>
<li>Integrating with GitHub Actions for continuous integration</li>
<li>Using Postman API key or service token to authenticate operations</li>
</ul>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: configure registry for release install by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/97">https://github.com/postman-cs/postman-repo-sync-action/pull/97</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.12...v2.1.13">https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.12...v2.1.13</a></p>
]]></content:encoded></item><item><title>quantakrypto Quantum Readiness Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/quantakrypto-quantum-readiness-scan/</link><pubDate>Thu, 23 Jul 2026 15:11:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/quantakrypto-quantum-readiness-scan/</guid><description>Version updated for https://github.com/quantakrypto/pqc-tools to version v1.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of identifying quantum-vulnerable cryptographic vulnerabilities in codebases using qScan, a CLI tool that scans various programming languages for RSA, (EC)DH, ECDSA, and EdDSA implementations. The action uploads SARIF formatted reports to GitHub Checks and fails the build if any new quantum-vulnerable crypto is found, providing an integrated solution for post-quantum readiness testing in CI environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/quantakrypto/pqc-tools">https://github.com/quantakrypto/pqc-tools</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/quantakrypto-quantum-readiness-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of identifying quantum-vulnerable cryptographic vulnerabilities in codebases using <code>qScan</code>, a CLI tool that scans various programming languages for RSA, (EC)DH, ECDSA, and EdDSA implementations. The action uploads SARIF formatted reports to GitHub Checks and fails the build if any new quantum-vulnerable crypto is found, providing an integrated solution for post-quantum readiness testing in CI environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/quantakrypto/pqc-tools/compare/v0.5.0...v1">https://github.com/quantakrypto/pqc-tools/compare/v0.5.0...v1</a></p>
]]></content:encoded></item><item><title>UnityPackage Builder</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/unitypackage-builder/</link><pubDate>Thu, 23 Jul 2026 15:10:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/unitypackage-builder/</guid><description>Version updated for https://github.com/r74tech/create-unitypackage to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the creation of Unity .unitypackage files by downloading a precompiled native CLI, verifying its integrity, and executing it to package assets. It simplifies the process of bundling Unity projects into portable formats across different platforms. The action supports Linux, macOS, and Windows, with options for customizing the project directory, asset files, and output path.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/r74tech/create-unitypackage">https://github.com/r74tech/create-unitypackage</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/unitypackage-builder">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the creation of Unity <code>.unitypackage</code> files by downloading a precompiled native CLI, verifying its integrity, and executing it to package assets. It simplifies the process of bundling Unity projects into portable formats across different platforms. The action supports Linux, macOS, and Windows, with options for customizing the project directory, asset files, and output path.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="100-2026-07-23">1.0.0 (2026-07-23)</h2>
<h3 id="-features">🚀 Features</h3>
<ul>
<li>Generate deterministic <code>.unitypackage</code> archives on Linux, macOS, and Windows.</li>
<li>Download the native <code>unitypackage</code> CLI and verify it using SHA-256 checksums.</li>
<li>Support current inputs and compatibility aliases for existing workflows.</li>
<li>Run without shell interpolation or npm runtime dependencies.</li>
</ul>
]]></content:encoded></item><item><title>Redis Repo Memory</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/redis-repo-memory/</link><pubDate>Thu, 23 Jul 2026 15:10:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/redis-repo-memory/</guid><description>Version updated for https://github.com/redis-learn/redis-repo-memory to version v1.0.3.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Redis Repo Memory is a GitHub Action that automates the process of finding semantically related pull requests, issues, and commits from repository history. By using OpenAI’s text-embedding-3-small API to embed the context of each commit or PR, it searches a Redis vector index for similar prior work and posts the results as a comment on pull requests and a status update in push events. The action helps teams stay informed about what has been done before by providing insights into related content across their repository history.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/redis-learn/redis-repo-memory">https://github.com/redis-learn/redis-repo-memory</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/redis-repo-memory">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Redis Repo Memory is a GitHub Action that automates the process of finding semantically related pull requests, issues, and commits from repository history. By using OpenAI&rsquo;s text-embedding-3-small API to embed the context of each commit or PR, it searches a Redis vector index for similar prior work and posts the results as a comment on pull requests and a status update in push events. The action helps teams stay informed about what has been done before by providing insights into related content across their repository history.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Remove npm caching and bump node-version to <code>24</code></p>
]]></content:encoded></item><item><title>Project Health Score</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/project-health-score/</link><pubDate>Thu, 23 Jul 2026 15:09:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/project-health-score/</guid><description>Version updated for https://github.com/RohitS456/project-health-score to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of assessing project health by scanning for common best-practice files and calculating a health score. It identifies various checks such as existence of README, LICENSE, tests, CONTRIBUTING guide, code of conduct, GitHub Actions configuration, security policy, and Dependabot setup. The tool posts the results as a PR comment and job summary, allowing users to monitor and improve project health.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RohitS456/project-health-score">https://github.com/RohitS456/project-health-score</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/project-health-score">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of assessing project health by scanning for common best-practice files and calculating a health score. It identifies various checks such as existence of README, LICENSE, tests, CONTRIBUTING guide, code of conduct, GitHub Actions configuration, security policy, and Dependabot setup. The tool posts the results as a PR comment and job summary, allowing users to monitor and improve project health.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release of Project Health Score.</p>
<p>Checks: README, LICENSE, tests, CONTRIBUTING, Code of Conduct,
GitHub Actions config, Security Policy, Dependabot enabled.</p>
<ul>
<li>Posts a PR comment with the score, updates it on new commits</li>
<li>Writes a job summary</li>
<li>Outputs: score, passed-count, total-count</li>
</ul>
]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/rumdl-action/</link><pubDate>Thu, 23 Jul 2026 15:08:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.41.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
rumdl is a high-performance Markdown linter and formatter written in Rust that provides over 76 lint rules to ensure consistency and best practices in Markdown files. It offers built-in formatting capabilities, automatic fixes, multi-flavor support, and zero dependencies. With its focus on speed and user experience, rumdl is suitable for both developers and CI/CD pipelines, making it a versatile tool for Markdown quality assurance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.41</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>rumdl is a high-performance Markdown linter and formatter written in Rust that provides over 76 lint rules to ensure consistency and best practices in Markdown files. It offers built-in formatting capabilities, automatic fixes, multi-flavor support, and zero dependencies. With its focus on speed and user experience, rumdl is suitable for both developers and CI/CD pipelines, making it a versatile tool for Markdown quality assurance.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>flavor</strong>: add Hugo flavor and skip block attribute lists in blanks-around rules (<a href="https://github.com/rvben/rumdl/commit/e6bb033813121b898784003e1af73df1b464e097">e6bb033</a>)</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>md044</strong>: recognize indented HTML comments so links and code escape the rule (<a href="https://github.com/rvben/rumdl/commit/3d6191cb56366439bf7814e29463fcc157aaf5ac">3d6191c</a>)</li>
<li><strong>md013</strong>: keep an attr list whole inside a wrapped span (<a href="https://github.com/rvben/rumdl/commit/e06f03d515fc81054e3929b25d252020960a9c11">e06f03d</a>)</li>
<li><strong>md013</strong>: keep a reference-style link whole inside a wrapped span (<a href="https://github.com/rvben/rumdl/commit/de427094fece132be1dae78efcc0e524e7cad5cd">de42709</a>)</li>
<li><strong>md013</strong>: wrap an over-long span whose whole content is another span (<a href="https://github.com/rvben/rumdl/commit/f6c7c9c45ffe924c6ef429dd70197109a2a33296">f6c7c9c</a>)</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.41-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.41-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.41-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.41-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-apple-darwin.tar.gz">rumdl-v0.2.41-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-apple-darwin.tar.gz">rumdl-v0.2.41-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-pc-windows-msvc.zip">rumdl-v0.2.41-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.41/rumdl-v0.2.41-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/agentauditkit-mcp-security-scan/</link><pubDate>Thu, 23 Jul 2026 15:07:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.58.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentAuditKit is a security scanner specifically designed to audit AI agent pipelines. It automates the detection of misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across various 13 agent platforms. Unlike hosted scanners that rely on LLMs for judgment, AgentAuditKit runs fully offline and deterministically, ensuring that findings are consistent across re-runs and audits. It also produces auditor-ready compliance-evidence packs in SARIF format along with PDF reports mapped to 13 security frameworks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.58</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AgentAuditKit is a security scanner specifically designed to audit AI agent pipelines. It automates the detection of misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across various 13 agent platforms. Unlike hosted scanners that rely on LLMs for judgment, AgentAuditKit runs fully offline and deterministically, ensuring that findings are consistent across re-runs and audits. It also produces auditor-ready compliance-evidence packs in SARIF format along with PDF reports mapped to 13 security frameworks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.58
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.58
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.58</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.57...v0.3.58">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.57...v0.3.58</a></p>
]]></content:encoded></item><item><title>Argus PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/argus-pr-review/</link><pubDate>Thu, 23 Jul 2026 15:06:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/argus-pr-review/</guid><description>Version updated for https://github.com/sibinms/argus to version v1.2.25.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Argus is a GitHub Action that automates code review by running multiple specialized AI reviewers in parallel and using an evidence-based curator to verify findings before posting review comments on pull requests. It optimizes for recall instead of precision, ensuring more real bugs are caught while minimizing false positives. The action supports various LLMs and provides markdown-based custom lenses for tailored reviews.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sibinms/argus">https://github.com/sibinms/argus</a></strong> to version <strong>v1.2.25</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/argus-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Argus is a GitHub Action that automates code review by running multiple specialized AI reviewers in parallel and using an evidence-based curator to verify findings before posting review comments on pull requests. It optimizes for recall instead of precision, ensuring more real bugs are caught while minimizing false positives. The action supports various LLMs and provides markdown-based custom lenses for tailored reviews.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(config): replace deprecated Gemini model names by @sibinms in <a href="https://github.com/sibinms/argus/pull/37">https://github.com/sibinms/argus/pull/37</a></li>
<li>feat(posting): reply-aware re-curation, drop the rolling summary by @sibinms in <a href="https://github.com/sibinms/argus/pull/36">https://github.com/sibinms/argus/pull/36</a></li>
<li>Release v1.2.25 by @sibinms in <a href="https://github.com/sibinms/argus/pull/38">https://github.com/sibinms/argus/pull/38</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sibinms/argus/compare/v1.2.24...v1.2.25">https://github.com/sibinms/argus/compare/v1.2.24...v1.2.25</a></p>
]]></content:encoded></item><item><title>Socket Basics Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/socket-basics-security-scanner/</link><pubDate>Thu, 23 Jul 2026 15:05:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/socket-basics-security-scanner/</guid><description>Version updated for https://github.com/SocketDev/socket-basics to version v2.1.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 8 repositories.
Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Socket Basics automates comprehensive security scanning using SAST, secrets detection, container scanning, and more. It normalizes outputs into Socket’s standardized format and delivers consolidated results through notification channels. Users can configure policies in the Socket Dashboard, eliminating the need for GitHub Actions workflow changes. The action supports zero configuration, unified scanning across various technologies, PR comments, centralized management, and a comprehensive guide on installation methods.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SocketDev/socket-basics">https://github.com/SocketDev/socket-basics</a></strong> to version <strong>v2.1.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>8</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/socket-basics-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Socket Basics automates comprehensive security scanning using SAST, secrets detection, container scanning, and more. It normalizes outputs into Socket&rsquo;s standardized format and delivers consolidated results through notification channels. Users can configure policies in the Socket Dashboard, eliminating the need for GitHub Actions workflow changes. The action supports zero configuration, unified scanning across various technologies, PR comments, centralized management, and a comprehensive guide on installation methods.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at main -->
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="-new-features">🚀 New Features</h3>
<ul>
<li>feat: add diff-only scan scoping by @lelia in <a href="https://github.com/SocketDev/socket-basics/pull/77">https://github.com/SocketDev/socket-basics/pull/77</a></li>
</ul>
<h3 id="-dependencies">📦 Dependencies</h3>
<ul>
<li>chore(deps): bundle Dependabot updates + harden dependency review workflows by @lelia in <a href="https://github.com/SocketDev/socket-basics/pull/78">https://github.com/SocketDev/socket-basics/pull/78</a></li>
</ul>
<h3 id="-documentation">📚 Documentation</h3>
<ul>
<li>chore(license): add nonempty license (LICENSE.md) by @ammkrn in <a href="https://github.com/SocketDev/socket-basics/pull/79">https://github.com/SocketDev/socket-basics/pull/79</a></li>
</ul>
<h3 id="-other-changes">🔧 Other Changes</h3>
<ul>
<li>fix: warn users when <code>socket_org</code> is missing by @dc-larsen in <a href="https://github.com/SocketDev/socket-basics/pull/23">https://github.com/SocketDev/socket-basics/pull/23</a></li>
<li>feat: add local ignore overrides for rule IDs + filepaths by @lelia in <a href="https://github.com/SocketDev/socket-basics/pull/59">https://github.com/SocketDev/socket-basics/pull/59</a></li>
<li>fix: honor action &lsquo;ignore&rsquo; when generating notifications by @dc-larsen in <a href="https://github.com/SocketDev/socket-basics/pull/83">https://github.com/SocketDev/socket-basics/pull/83</a></li>
<li>fix: improve custom SAST rule activation, filtering semantics + config observability by @lelia in <a href="https://github.com/SocketDev/socket-basics/pull/61">https://github.com/SocketDev/socket-basics/pull/61</a></li>
<li>docs: document required API token scopes for Socket Basics by @dc-larsen in <a href="https://github.com/SocketDev/socket-basics/pull/68">https://github.com/SocketDev/socket-basics/pull/68</a></li>
<li>feat: add log statement indicating config source by @dc-larsen in <a href="https://github.com/SocketDev/socket-basics/pull/18">https://github.com/SocketDev/socket-basics/pull/18</a></li>
<li>fix: restore standard <code>LICENSE</code> filename (revert <code>.md</code> rename from #79) by @lelia in <a href="https://github.com/SocketDev/socket-basics/pull/88">https://github.com/SocketDev/socket-basics/pull/88</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@ammkrn made their first contribution in <a href="https://github.com/SocketDev/socket-basics/pull/79">https://github.com/SocketDev/socket-basics/pull/79</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/SocketDev/socket-basics/compare/v2.0.3...v2.1.0">https://github.com/SocketDev/socket-basics/compare/v2.0.3...v2.1.0</a></p>
]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/rustscript-action/</link><pubDate>Thu, 23 Jul 2026 15:04:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.2.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a RustScript interpreter that automates the process of running and validating Rust scripts without the need to compile them fully. It supports executing and checking Rust code directly from files or snippets, providing a practical way to prototype and test small scripts without waiting for full compilation times.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a RustScript interpreter that automates the process of running and validating Rust scripts without the need to compile them fully. It supports executing and checking Rust code directly from files or snippets, providing a practical way to prototype and test small scripts without waiting for full compilation times.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.2...v0.2.1">https://github.com/VladasZ/rustscript/compare/v0.2...v0.2.1</a></p>
]]></content:encoded></item><item><title>AI-Driven ADR Enforcer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/ai-driven-adr-enforcer/</link><pubDate>Thu, 23 Jul 2026 15:03:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/ai-driven-adr-enforcer/</guid><description>Version updated for https://github.com/y-matsuo081991/ai-adr-enforcer to version v1.1.7.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI-Driven ADR Enforcer automates the auditing of incoming Pull Requests against Architecture Decision Records (ADRs) by leveraging LLMs to ensure architectural compliance. It dynamically reads local ADR files, evaluates code diffs in real-time, and provides inline suggestions for fixing architectural violations, thus preventing drift and technical debt accumulation. The Action offers self-healing features, automated quality gates, and a safety risk assessment pipeline for small changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/y-matsuo081991/ai-adr-enforcer">https://github.com/y-matsuo081991/ai-adr-enforcer</a></strong> to version <strong>v1.1.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-driven-adr-enforcer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AI-Driven ADR Enforcer automates the auditing of incoming Pull Requests against Architecture Decision Records (ADRs) by leveraging LLMs to ensure architectural compliance. It dynamically reads local ADR files, evaluates code diffs in real-time, and provides inline suggestions for fixing architectural violations, thus preventing drift and technical debt accumulation. The Action offers self-healing features, automated quality gates, and a safety risk assessment pipeline for small changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/y-matsuo081991/ai-adr-enforcer/compare/v1.1.6...v1.1.7">https://github.com/y-matsuo081991/ai-adr-enforcer/compare/v1.1.6...v1.1.7</a></p>
]]></content:encoded></item><item><title>Capture Environment Variable Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/capture-environment-variable-checker/</link><pubDate>Thu, 23 Jul 2026 15:03:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/capture-environment-variable-checker/</guid><description>Version updated for https://github.com/YhaliWaizman/Capture to version v2.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a static analysis tool that identifies discrepancies between environment variables declared in .env files and their usage in various programming languages, Dockerfiles, and Docker Compose files. It helps detect potential security risks by identifying hardcoded secrets and cross-checks variables across different sources to ensure consistency. The action supports parallel scanning and incremental caching for efficient performance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YhaliWaizman/Capture">https://github.com/YhaliWaizman/Capture</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/capture-environment-variable-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a static analysis tool that identifies discrepancies between environment variables declared in <code>.env</code> files and their usage in various programming languages, Dockerfiles, and Docker Compose files. It helps detect potential security risks by identifying hardcoded secrets and cross-checks variables across different sources to ensure consistency. The action supports parallel scanning and incremental caching for efficient performance.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="capture-200">capture 2.0.0</h2>
<p>A static analysis CLI tool that identifies mismatches between environment variables declared in .env files, Dockerfiles, and source code.</p>
<h3 id="installation">Installation</h3>
<p>Download the appropriate binary for your platform below, or install via Go:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>go install github.com/yhaliwaizman/capture/cmd/capture@v2.0.0
</span></span></code></pre></div><h2 id="changelog">Changelog</h2>
<ul>
<li>5829a8b895e0b17f693cb8948233dd5840bfda71 feat(ci): add official GitHub Action for capture scan</li>
<li>66d296f23d4884c3dc8f74d74fb5a9312f89e658 chore(release): first major good release</li>
<li>d9aaf67a253c86b38f24a6e8c73f4c6d0c06a2c1 chore(main): release 2.0.0</li>
<li>703cd3644be4b421faa0ac483f170166c06a9719 Merge pull request #40 from YhaliWaizman/release-please&ndash;branches&ndash;main</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<p>See the <a href="https://github.com/yhaliwaizman/capture/blob/main/CHANGELOG.md">CHANGELOG</a> for details.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yhaliwaizman/capture/compare/v1.7.0...v2.0.0">https://github.com/yhaliwaizman/capture/compare/v1.7.0...v2.0.0</a></p>
]]></content:encoded></item><item><title>Pi Code Assist</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/pi-code-assist/</link><pubDate>Thu, 23 Jul 2026 15:02:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/pi-code-assist/</guid><description>Version updated for https://github.com/zeldrisho/pi-code-assist to version v2.0.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action runs the Pi coding agent as a small, composable tool, executing one non-interactive prompt and streaming the response to the job log while exposing it to later steps. It allows users to specify a prompt, API key, provider, model, and optional parameters like thinking level and tools.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zeldrisho/pi-code-assist">https://github.com/zeldrisho/pi-code-assist</a></strong> to version <strong>v2.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pi-code-assist">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action runs the Pi coding agent as a small, composable tool, executing one non-interactive prompt and streaming the response to the job log while exposing it to later steps. It allows users to specify a prompt, API key, provider, model, and optional parameters like thinking level and tools.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="201-2026-07-23"><a href="https://github.com/zeldrisho/pi-code-assist/compare/v2.0.0...v2.0.1">2.0.1</a> (2026-07-23)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>harden Pi setup and execution phases (<a href="https://github.com/zeldrisho/pi-code-assist/commit/92d7c144100907a3701c2acf32573eaf6eba5467">92d7c14</a>)</li>
</ul>
]]></content:encoded></item><item><title>Agent Lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/agent-lint/</link><pubDate>Thu, 23 Jul 2026 15:01:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/agent-lint/</guid><description>Version updated for https://github.com/zhupanov/agent-lint to version v4.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Lint is a Rust-based linter designed to validate various configuration files used by Claude Code, Cursor, Codex, and standalone MCP. It provides lint rules, two modes (Basic and Plugin), configurable suppression or downgrade of rules, focused execution, GitHub Action integration, cross-platform binaries, and CLI options for linting and diagnosing issues in agent configurations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zhupanov/agent-lint">https://github.com/zhupanov/agent-lint</a></strong> to version <strong>v4.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Agent Lint is a Rust-based linter designed to validate various configuration files used by Claude Code, Cursor, Codex, and standalone MCP. It provides lint rules, two modes (Basic and Plugin), configurable suppression or downgrade of rules, focused execution, GitHub Action integration, cross-platform binaries, and CLI options for linting and diagnosing issues in agent configurations.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Introduce a renderer-independent structured diagnostic model by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/206">https://github.com/zhupanov/agent-lint/pull/206</a></li>
<li>Restore documentation and consistency gates by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/207">https://github.com/zhupanov/agent-lint/pull/207</a></li>
<li>Add focused rule execution with &ndash;only by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/208">https://github.com/zhupanov/agent-lint/pull/208</a></li>
<li>Add versioned JSON diagnostic output by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/209">https://github.com/zhupanov/agent-lint/pull/209</a></li>
<li>Fix bare extension path classification by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/210">https://github.com/zhupanov/agent-lint/pull/210</a></li>
<li>Normalize live instruction prose across AGENTS.md and Cursor rules by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/211">https://github.com/zhupanov/agent-lint/pull/211</a></li>
<li>Refine Q002 safety prohibition handling by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/212">https://github.com/zhupanov/agent-lint/pull/212</a></li>
<li>Add end-to-end CLI conformance corpus by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/213">https://github.com/zhupanov/agent-lint/pull/213</a></li>
<li>Add agent stop-control warning by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/214">https://github.com/zhupanov/agent-lint/pull/214</a></li>
<li>Add Q005 unbounded retry prompt rule by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/215">https://github.com/zhupanov/agent-lint/pull/215</a></li>
<li>Add Q006 prompt-output-conflict rule (issue 204) by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/217">https://github.com/zhupanov/agent-lint/pull/217</a></li>
<li>Add overlap warnings for agent and skill routing descriptions by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/218">https://github.com/zhupanov/agent-lint/pull/218</a></li>
<li>Add Q005 CLI conformance coverage by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/224">https://github.com/zhupanov/agent-lint/pull/224</a></li>
<li>Fix overlap checks for invalid YAML descriptions by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/225">https://github.com/zhupanov/agent-lint/pull/225</a></li>
<li>Fix A029 example and descriptive controls by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/226">https://github.com/zhupanov/agent-lint/pull/226</a></li>
<li>Fix Q006 output-shape classification and conflict pairs by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/227">https://github.com/zhupanov/agent-lint/pull/227</a></li>
<li>Fix bare extension classification without a fixed allowlist by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/231">https://github.com/zhupanov/agent-lint/pull/231</a></li>
<li>Fix A029 parsed agent tool declarations by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/232">https://github.com/zhupanov/agent-lint/pull/232</a></li>
<li>Fix Q005 maxTurns YAML handoff by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/233">https://github.com/zhupanov/agent-lint/pull/233</a></li>
<li>Fix Q006 clause classification false positives by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/267">https://github.com/zhupanov/agent-lint/pull/267</a></li>
<li>Fix audit JSON and description overlap gaps by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/268">https://github.com/zhupanov/agent-lint/pull/268</a></li>
<li>Harden shared inline-path classification and probes by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/270">https://github.com/zhupanov/agent-lint/pull/270</a></li>
<li>fix: unify retry and stop-control recognition by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/269">https://github.com/zhupanov/agent-lint/pull/269</a></li>
<li>Fix prompt analysis on supported instruction surfaces by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/274">https://github.com/zhupanov/agent-lint/pull/274</a></li>
<li>Retire unsupported S012/S013 skill-name rules by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/281">https://github.com/zhupanov/agent-lint/pull/281</a></li>
<li>Fix canonical skill-name validation across surfaces by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/282">https://github.com/zhupanov/agent-lint/pull/282</a></li>
<li>Fix Claude MCP remote transport validation by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/298">https://github.com/zhupanov/agent-lint/pull/298</a></li>
<li>Align plugin manifest contract with Claude Code by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/299">https://github.com/zhupanov/agent-lint/pull/299</a></li>
<li>Narrow S033 vague names and retire S049 gerund enforcement by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/301">https://github.com/zhupanov/agent-lint/pull/301</a></li>
<li>Extend M012/M013 plugin component path coverage by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/313">https://github.com/zhupanov/agent-lint/pull/313</a></li>
<li>Fix manifest diagnostic precision by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/316">https://github.com/zhupanov/agent-lint/pull/316</a></li>
<li>Deep-validate marketplace plugin entries (M009/M019/M021) by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/317">https://github.com/zhupanov/agent-lint/pull/317</a></li>
<li>Make MCP discovery and P-rule dispatch platform-aware by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/323">https://github.com/zhupanov/agent-lint/pull/323</a></li>
<li>Fix MCP structural validation and rule independence by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/331">https://github.com/zhupanov/agent-lint/pull/331</a></li>
<li>Add structured metadata to MCP diagnostics by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/332">https://github.com/zhupanov/agent-lint/pull/332</a></li>
<li>Make P018/P019 secret and command analysis syntax-aware by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/338">https://github.com/zhupanov/agent-lint/pull/338</a></li>
<li>Fix hook command path extraction and Basic autofix by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/347">https://github.com/zhupanov/agent-lint/pull/347</a></li>
<li>Fix plugin hook configuration discovery by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/351">https://github.com/zhupanov/agent-lint/pull/351</a></li>
<li>Align userConfig validation with current Claude Code schema by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/349">https://github.com/zhupanov/agent-lint/pull/349</a></li>
<li>Split and harden E001 without exposing email values by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/363">https://github.com/zhupanov/agent-lint/pull/363</a></li>
<li>Remove repository-specific K001 Slack fallback policy by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/357">https://github.com/zhupanov/agent-lint/pull/357</a></li>
<li>Fix script reference integrity rules by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/365">https://github.com/zhupanov/agent-lint/pull/365</a></li>
<li>Fix S030/S036/S072/S073 skill structural precision by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/370">https://github.com/zhupanov/agent-lint/pull/370</a></li>
<li>Fix Q004 live prose overlap detection by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/371">https://github.com/zhupanov/agent-lint/pull/371</a></li>
<li>Extend S031/S032 to .agents/skills and .cursor/skills by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/372">https://github.com/zhupanov/agent-lint/pull/372</a></li>
<li>Fix canonical agent YAML field validation by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/373">https://github.com/zhupanov/agent-lint/pull/373</a></li>
<li>Broaden body recognizers for S041/S046/S047/S055 by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/380">https://github.com/zhupanov/agent-lint/pull/380</a></li>
<li>Fix Codex config schema validation by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/383">https://github.com/zhupanov/agent-lint/pull/383</a></li>
<li>Narrow I004 generic-only guidance and remove unsound I005 by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/379">https://github.com/zhupanov/agent-lint/pull/379</a></li>
<li>Fix canonical multiline skill descriptions by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/389">https://github.com/zhupanov/agent-lint/pull/389</a></li>
<li>Broaden G005 to GitHub-supported SECURITY.md locations by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/375">https://github.com/zhupanov/agent-lint/pull/375</a></li>
<li>Fix path-root classification before PWD autofix by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/364">https://github.com/zhupanov/agent-lint/pull/364</a></li>
<li>S055: recursively inspect shebang scripts and assign diagnostics to the offending file by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/395">https://github.com/zhupanov/agent-lint/pull/395</a></li>
<li>Align S015 with Claude Code listing cap by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/394">https://github.com/zhupanov/agent-lint/pull/394</a></li>
<li>I002: make AGENTS.md credential detection complete, source-aware, and non-leaking by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/393">https://github.com/zhupanov/agent-lint/pull/393</a></li>
<li>Model Q006 response scopes as an inherited heading tree by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/386">https://github.com/zhupanov/agent-lint/pull/386</a></li>
<li>Fix agent frontmatter field validation by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/406">https://github.com/zhupanov/agent-lint/pull/406</a></li>
<li>Recognize A029/Q005 operative gates through Markdown emphasis by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/407">https://github.com/zhupanov/agent-lint/pull/407</a></li>
<li>Escape control characters in human-readable diagnostic output by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/405">https://github.com/zhupanov/agent-lint/pull/405</a></li>
<li>Fix typed Codex MCP secret detection by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/408">https://github.com/zhupanov/agent-lint/pull/408</a></li>
<li>Fix S059 script flag validation by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/409">https://github.com/zhupanov/agent-lint/pull/409</a></li>
<li>Fix S016/S018/S054 description heuristic false positives by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/414">https://github.com/zhupanov/agent-lint/pull/414</a></li>
<li>Fix canonical frontmatter autofix scope by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/416">https://github.com/zhupanov/agent-lint/pull/416</a></li>
<li>Fix S022 backslash path detection and autofix by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/417">https://github.com/zhupanov/agent-lint/pull/417</a></li>
<li>Broaden H023 dangerous-command pattern coverage by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/418">https://github.com/zhupanov/agent-lint/pull/418</a></li>
<li>L006: validate actionable npm commands in shell fences by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/419">https://github.com/zhupanov/agent-lint/pull/419</a></li>
<li>S031: stop flagging/rewriting XML-namespace identifiers and reserved-name hosts; single shared checker/autofix classifier by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/420">https://github.com/zhupanov/agent-lint/pull/420</a></li>
<li>Fix nested Cursor rule discovery by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/421">https://github.com/zhupanov/agent-lint/pull/421</a></li>
<li>Fix markdown fence and XML structure parsing by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/426">https://github.com/zhupanov/agent-lint/pull/426</a></li>
<li>Improve S/X diagnostic precision for shared refs and frontmatter by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/427">https://github.com/zhupanov/agent-lint/pull/427</a></li>
<li>Narrow D003/G006/G007 to syntactic unfinished-work markers by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/429">https://github.com/zhupanov/agent-lint/pull/429</a></li>
<li>fix: align Cursor hooks validation contract by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/428">https://github.com/zhupanov/agent-lint/pull/428</a></li>
<li>T001/T002: validate rendered PR URLs and reject ignored repository channelsEnabled by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/430">https://github.com/zhupanov/agent-lint/pull/430</a></li>
<li>Fix A012/A013 canonical agent contracts by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/432">https://github.com/zhupanov/agent-lint/pull/432</a></li>
<li>S044: gate context words on word boundaries, not substrings by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/431">https://github.com/zhupanov/agent-lint/pull/431</a></li>
<li>Share operative/example scopes across Q001-Q003 and scope Q002 alternatives (#359) by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/433">https://github.com/zhupanov/agent-lint/pull/433</a></li>
<li>Fix M021 to match kebab-case against raw marketplace names by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/439">https://github.com/zhupanov/agent-lint/pull/439</a></li>
<li>Fix S032 source-positioned secret detection by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/438">https://github.com/zhupanov/agent-lint/pull/438</a></li>
<li>A005-A007: self-activate the larch template convention and parse Markdown semantics by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/442">https://github.com/zhupanov/agent-lint/pull/442</a></li>
<li>D004/L001-L004: build a complete, safe, source-relative instruction import graph by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/441">https://github.com/zhupanov/agent-lint/pull/441</a></li>
<li>Unify shared model/tool vocabularies (S063/A014, S040/A019/A020) by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/440">https://github.com/zhupanov/agent-lint/pull/440</a></li>
<li>U009: flag userConfig defaults that ship secrets (#412) by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/444">https://github.com/zhupanov/agent-lint/pull/444</a></li>
<li>S021 autofix: follow the shared consecutive-bash policy (#326) by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/445">https://github.com/zhupanov/agent-lint/pull/445</a></li>
<li>Fix S037 file reference recognition by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/446">https://github.com/zhupanov/agent-lint/pull/446</a></li>
<li>CX013: narrow Slack signature class to reject backslashes (#425) by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/448">https://github.com/zhupanov/agent-lint/pull/448</a></li>
<li>Fix Q006 hard-wrapped conditional routing (#399) by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/447">https://github.com/zhupanov/agent-lint/pull/447</a></li>
<li>Fix script reference extraction gaps by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/451">https://github.com/zhupanov/agent-lint/pull/451</a></li>
<li>Sync MCP P026/P027/P009/P017 with current Claude/Cursor contracts by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/449">https://github.com/zhupanov/agent-lint/pull/449</a></li>
<li>Validate marketplace component paths by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/452">https://github.com/zhupanov/agent-lint/pull/452</a></li>
<li>G008: make inline-body checks GitHub-command-aware and shell-aware by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/454">https://github.com/zhupanov/agent-lint/pull/454</a></li>
<li>Fix CU016 Cursor environment schema validation by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/456">https://github.com/zhupanov/agent-lint/pull/456</a></li>
<li>Fix masked prose validation rules by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/455">https://github.com/zhupanov/agent-lint/pull/455</a></li>
<li>Report malformed hook configurations by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/458">https://github.com/zhupanov/agent-lint/pull/458</a></li>
<li>Test Cursor frontmatter prompt recovery by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/457">https://github.com/zhupanov/agent-lint/pull/457</a></li>
<li>CU014: optional Cursor subagent fields and A030 Cursor namespace by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/459">https://github.com/zhupanov/agent-lint/pull/459</a></li>
<li>I003/D005/L005/S062: structured Markdown refs and safe path resolution by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/460">https://github.com/zhupanov/agent-lint/pull/460</a></li>
<li>Fix Cursor skill field compatibility and discovery by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/462">https://github.com/zhupanov/agent-lint/pull/462</a></li>
<li>Agent discovery: scan .claude/agents and plugin agents/ recursively (#321) by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/463">https://github.com/zhupanov/agent-lint/pull/463</a></li>
<li>CX046-CX063: rebuild Codex plugin manifest linting by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/461">https://github.com/zhupanov/agent-lint/pull/461</a></li>
<li>G009-G011: replace line regexes with sound shell and awk analysis by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/464">https://github.com/zhupanov/agent-lint/pull/464</a></li>
<li>S014/S034: enforce the Agent Skills description contract by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/465">https://github.com/zhupanov/agent-lint/pull/465</a></li>
<li>Fix Codex diagnostic metadata contract by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/467">https://github.com/zhupanov/agent-lint/pull/467</a></li>
<li>Make D001/D002 Always-mode with precise Markdown docs refs by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/468">https://github.com/zhupanov/agent-lint/pull/468</a></li>
<li>Honor plugin skill export surfaces by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/466">https://github.com/zhupanov/agent-lint/pull/466</a></li>
<li>CX060: parse YAML semantically across every Codex skill surface by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/469">https://github.com/zhupanov/agent-lint/pull/469</a></li>
<li>Fix Codex project-document discovery and budget rules by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/470">https://github.com/zhupanov/agent-lint/pull/470</a></li>
<li>O001-O006: align output-style linting with Claude runtime by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/471">https://github.com/zhupanov/agent-lint/pull/471</a></li>
<li>Fix Q005 retry bound association by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/473">https://github.com/zhupanov/agent-lint/pull/473</a></li>
<li>Fix S058 Skill invocation detection by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/474">https://github.com/zhupanov/agent-lint/pull/474</a></li>
<li>Fix S060/S061 fence shell-command precision by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/475">https://github.com/zhupanov/agent-lint/pull/475</a></li>
<li>A002/A003/A008-A011: use canonical agent YAML and re-severitize description heuristics by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/477">https://github.com/zhupanov/agent-lint/pull/477</a></li>
<li>Fix H023 Git option and shell wrapper detection by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/482">https://github.com/zhupanov/agent-lint/pull/482</a></li>
<li>M014-M017: share plugin-field validation across manifests and enforce current LSP/channel shapes by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/478">https://github.com/zhupanov/agent-lint/pull/478</a></li>
<li>Read skill field-type frontmatter through canonical YAML (#341) by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/480">https://github.com/zhupanov/agent-lint/pull/480</a></li>
<li>Extend P019 threat matrix for PowerShell prefixes, root globs, argv joining, and headersHelper by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/484">https://github.com/zhupanov/agent-lint/pull/484</a></li>
<li>CU002-CU008: model Cursor MDC frontmatter as four activation states by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/476">https://github.com/zhupanov/agent-lint/pull/476</a></li>
<li>Add M024 marketplace whitespace rule by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/483">https://github.com/zhupanov/agent-lint/pull/483</a></li>
<li>S028/S069: align argument-hint cross-checks with merged command-argument contract by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/472">https://github.com/zhupanov/agent-lint/pull/472</a></li>
<li>R001-R003: recursively validate Claude rules with runtime-compatible paths semantics by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/481">https://github.com/zhupanov/agent-lint/pull/481</a></li>
<li>S033: complete domainless denylist and attach name-field metadata by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/485">https://github.com/zhupanov/agent-lint/pull/485</a></li>
<li>A031 agent-name-duplicate: flag duplicate agent names in .claude/agents (identity collision) by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/486">https://github.com/zhupanov/agent-lint/pull/486</a></li>
<li>Fix S065 agent reference resolution by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/489">https://github.com/zhupanov/agent-lint/pull/489</a></li>
<li>G005: accept security-md-missing as a legacy alias (#411) by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/487">https://github.com/zhupanov/agent-lint/pull/487</a></li>
<li>Fix S068 inline injection overflow detection by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/488">https://github.com/zhupanov/agent-lint/pull/488</a></li>
<li>Fix recursive S030 and S048 skill coverage by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/490">https://github.com/zhupanov/agent-lint/pull/490</a></li>
<li>S040/S045/S067: honor documented allowed-tools/disallowed-tools forms; retire S045 by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/491">https://github.com/zhupanov/agent-lint/pull/491</a></li>
<li>test: pin retired rule identifiers by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/492">https://github.com/zhupanov/agent-lint/pull/492</a></li>
<li>CX026/CX030: validate nested approvals_reviewer and default_tools_approval_mode sites by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/493">https://github.com/zhupanov/agent-lint/pull/493</a></li>
<li>docs: record Cursor contract provenance by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/498">https://github.com/zhupanov/agent-lint/pull/498</a></li>
<li>Validate Codex profile configuration values by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/494">https://github.com/zhupanov/agent-lint/pull/494</a></li>
<li>O001-O006: lint plugin-shipped output styles (root output-styles/ and manifest outputStyles paths) in Plugin mode by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/495">https://github.com/zhupanov/agent-lint/pull/495</a></li>
<li>M010/M011: require usable enrichment values without parent cascades by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/499">https://github.com/zhupanov/agent-lint/pull/499</a></li>
<li>CHANGELOG: record landed manifest-rule campaign (M001-M021) by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/501">https://github.com/zhupanov/agent-lint/pull/501</a></li>
<li>Fix hook script invocation classification by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/497">https://github.com/zhupanov/agent-lint/pull/497</a></li>
<li>Fix manifest root and plugin name validation by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/500">https://github.com/zhupanov/agent-lint/pull/500</a></li>
<li>Fix P018 MCP credential reference coverage by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/505">https://github.com/zhupanov/agent-lint/pull/505</a></li>
<li>S041 (fork-no-task): read <code>context</code> through canonical YAML by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/504">https://github.com/zhupanov/agent-lint/pull/504</a></li>
<li>Reverify Cursor contracts against cursor.com/docs by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/507">https://github.com/zhupanov/agent-lint/pull/507</a></li>
<li>Fix #437: refresh Claude Code vocabularies by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/503">https://github.com/zhupanov/agent-lint/pull/503</a></li>
<li>Fix focused JSON output for retired rule selectors by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/564">https://github.com/zhupanov/agent-lint/pull/564</a></li>
<li>fix: close S032 command substitution bypass by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/565">https://github.com/zhupanov/agent-lint/pull/565</a></li>
<li>Fix S058 canonical YAML tool gate by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/566">https://github.com/zhupanov/agent-lint/pull/566</a></li>
<li>fix: balance R001 brace expansion so nested empties fail closed by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/567">https://github.com/zhupanov/agent-lint/pull/567</a></li>
<li>fix: stop Q rules from scanning unterminated and BOM frontmatter by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/568">https://github.com/zhupanov/agent-lint/pull/568</a></li>
<li>fix: cover hook command runtime boundaries by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/571">https://github.com/zhupanov/agent-lint/pull/571</a></li>
<li>Fix plugin and marketplace validation drift by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/569">https://github.com/zhupanov/agent-lint/pull/569</a></li>
<li>Fix P019 command argv boundaries by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/570">https://github.com/zhupanov/agent-lint/pull/570</a></li>
<li>fix: unify runtime skill discovery consumers by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/572">https://github.com/zhupanov/agent-lint/pull/572</a></li>
<li>Fix CommonMark Markdown tokenization and link decoding by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/575">https://github.com/zhupanov/agent-lint/pull/575</a></li>
<li>fix: assign npm and grep positional roles option-awarely by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/573">https://github.com/zhupanov/agent-lint/pull/573</a></li>
<li>fix: align instruction reference discovery for imports and package scopes by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/574">https://github.com/zhupanov/agent-lint/pull/574</a></li>
<li>fix: accept documented empty and templated Claude MCP URLs (P010/P017) by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/576">https://github.com/zhupanov/agent-lint/pull/576</a></li>
<li>Fix G008-G011 shell analysis dispatch and dynamic-flow gaps by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/577">https://github.com/zhupanov/agent-lint/pull/577</a></li>
<li>fix: tighten instruction classifier grammars by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/578">https://github.com/zhupanov/agent-lint/pull/578</a></li>
<li>fix: complete Codex plugin manifest validation contracts by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/579">https://github.com/zhupanov/agent-lint/pull/579</a></li>
<li>fix: keep Codex diagnostics secret-safe and budget-visible by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/581">https://github.com/zhupanov/agent-lint/pull/581</a></li>
<li>Fix JSON diagnostics losing duplicate, field, and array source locations by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/580">https://github.com/zhupanov/agent-lint/pull/580</a></li>
<li>fix: correct agent root, marker, name, and metadata classification by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/582">https://github.com/zhupanov/agent-lint/pull/582</a></li>
<li>Enforce parser-role and invalid-subtree contracts by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/584">https://github.com/zhupanov/agent-lint/pull/584</a></li>
<li>Append bug-mining architectural entries by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/588">https://github.com/zhupanov/agent-lint/pull/588</a></li>
<li>Unify executable and retired identifier contracts by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/590">https://github.com/zhupanov/agent-lint/pull/590</a></li>
<li>Add conformance coverage and source-policy guards by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/597">https://github.com/zhupanov/agent-lint/pull/597</a></li>
<li>test: enforce diagnostic safety corpus by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/599">https://github.com/zhupanov/agent-lint/pull/599</a></li>
<li>Add AST-backed validator purity and traversal lints by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/606">https://github.com/zhupanov/agent-lint/pull/606</a></li>
<li>Fix live rule registry accounting by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/607">https://github.com/zhupanov/agent-lint/pull/607</a></li>
<li>test: inventory validator peer dependencies by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/608">https://github.com/zhupanov/agent-lint/pull/608</a></li>
<li>Fix S059 modular Python CLI flag validation by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/611">https://github.com/zhupanov/agent-lint/pull/611</a></li>
<li>fix: S030 ignore cache artifacts and harness-owned fixtures by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/609">https://github.com/zhupanov/agent-lint/pull/609</a></li>
<li>fix: stop S032 flagging ordinary token identifiers by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/610">https://github.com/zhupanov/agent-lint/pull/610</a></li>
<li>Fix Markdown control scope classifiers by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/613">https://github.com/zhupanov/agent-lint/pull/613</a></li>
<li>Enforce CWD test guards and serialization by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/612">https://github.com/zhupanov/agent-lint/pull/612</a></li>
<li>docs: record architectural contracts by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/614">https://github.com/zhupanov/agent-lint/pull/614</a></li>
<li>Generalize contract matrix admission by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/617">https://github.com/zhupanov/agent-lint/pull/617</a></li>
<li>fix: keep UTF-8 scalars intact in clause splitting and sourcepos ranges by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/618">https://github.com/zhupanov/agent-lint/pull/618</a></li>
<li>fix: unify script reference classification across G002-G004 by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/619">https://github.com/zhupanov/agent-lint/pull/619</a></li>
<li>test: add text/JSON renderer parity invariant by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/620">https://github.com/zhupanov/agent-lint/pull/620</a></li>
<li>test: cover UTF-8 clause scanning regression by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/622">https://github.com/zhupanov/agent-lint/pull/622</a></li>
<li>Fix Comrak column semantics for Unicode prose by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/624">https://github.com/zhupanov/agent-lint/pull/624</a></li>
<li>test: enforce architecture and rule/autofix consistency by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/623">https://github.com/zhupanov/agent-lint/pull/623</a></li>
<li>Fix S059 literal Python registry dispatch by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/629">https://github.com/zhupanov/agent-lint/pull/629</a></li>
<li>fix: recognize S030 references ending in sentence punctuation by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/630">https://github.com/zhupanov/agent-lint/pull/630</a></li>
<li>fix: recognize Python-owned skill fixtures by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/632">https://github.com/zhupanov/agent-lint/pull/632</a></li>
<li>Fix G004 Python-composed script reachability by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/631">https://github.com/zhupanov/agent-lint/pull/631</a></li>
<li>fix: accept End and Schedule Q002 alternatives by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/637">https://github.com/zhupanov/agent-lint/pull/637</a></li>
<li>Fix G004 Python subprocess reachability by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/638">https://github.com/zhupanov/agent-lint/pull/638</a></li>
<li>Fix S030 Python fixture string ownership by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/645">https://github.com/zhupanov/agent-lint/pull/645</a></li>
<li>Fix S059 imported Python literal registries by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/647">https://github.com/zhupanov/agent-lint/pull/647</a></li>
<li>Fix Python hygiene command edges by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/649">https://github.com/zhupanov/agent-lint/pull/649</a></li>
<li>Fix G003 command-substitution interpreter classification by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/651">https://github.com/zhupanov/agent-lint/pull/651</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/zhupanov/agent-lint/compare/v3...v4.0.0">https://github.com/zhupanov/agent-lint/compare/v3...v4.0.0</a></p>
]]></content:encoded></item><item><title>Validate Syscribe Model</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/validate-syscribe-model/</link><pubDate>Thu, 23 Jul 2026 06:33:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/validate-syscribe-model/</guid><description>Version updated for https://github.com/sjames/syscribe to version v0.32.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Syscribe is a tool that converts SysMLv2 models into human-readable Markdown files with YAML frontmatter, making them version-controlled and traceable. It automates the process of generating requirements, test cases, architecture decision records, and safety analysis reports from natural language descriptions using large language models (LLMs). The action supports various element types and provides features for cross-repository composition, security analysis, and IEC 62443 zones &amp;amp; conduits.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sjames/syscribe">https://github.com/sjames/syscribe</a></strong> to version <strong>v0.32.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/validate-syscribe-model">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Syscribe is a tool that converts SysMLv2 models into human-readable Markdown files with YAML frontmatter, making them version-controlled and traceable. It automates the process of generating requirements, test cases, architecture decision records, and safety analysis reports from natural language descriptions using large language models (LLMs). The action supports various element types and provides features for cross-repository composition, security analysis, and IEC 62443 zones &amp; conduits.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sjames/syscribe/compare/v0...v0.32.0">https://github.com/sjames/syscribe/compare/v0...v0.32.0</a></p>
]]></content:encoded></item><item><title>Muninn Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/muninn-security-scanner/</link><pubDate>Thu, 23 Jul 2026 06:31:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/muninn-security-scanner/</guid><description>Version updated for https://github.com/skaldlab/muninn to version v0.3.6.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Muninn is an open-source security scanning tool designed to integrate with GitHub Actions workflows. It automates the process of identifying vulnerabilities across various tools, normalizes their output, and presents findings in a unified format as comments on pull requests, SARIF uploads, and structured JSON. Muninn uses eight popular vulnerability scanners to detect secrets, pipeline misconfigurations, syntax errors, supply chain risks, application SAST issues, dependency vulnerabilities, container image vulnerabilities, and infrastructure-as-code misconfigurations, providing a comprehensive security scan of GitHub Actions pipelines and self-hosted CI environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/skaldlab/muninn">https://github.com/skaldlab/muninn</a></strong> to version <strong>v0.3.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/muninn-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Muninn is an open-source security scanning tool designed to integrate with GitHub Actions workflows. It automates the process of identifying vulnerabilities across various tools, normalizes their output, and presents findings in a unified format as comments on pull requests, SARIF uploads, and structured JSON. Muninn uses eight popular vulnerability scanners to detect secrets, pipeline misconfigurations, syntax errors, supply chain risks, application SAST issues, dependency vulnerabilities, container image vulnerabilities, and infrastructure-as-code misconfigurations, providing a comprehensive security scan of GitHub Actions pipelines and self-hosted CI environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="changelog">Changelog</h1>
<h2 id="036---2026-07-22">[0.3.6] - 2026-07-22</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>Docker image scanner updates: zizmor 1.28.0 (replaces yanked 1.27.0);
GitPython floor raised to &gt;=3.1.52 for checkov-transitive GHSA highs
(checkov remains at 3.2.531 pending aiohttp cap lift).</li>
<li>Go toolchain bumped to 1.26.5.</li>
</ul>
<h2 id="035---2026-07-20">[0.3.5] - 2026-07-20</h2>
<h3 id="changed-1">Changed</h3>
<ul>
<li>Docker image scanner updates: semgrep 1.170.0, zizmor 1.27.0 (checkov
remains at 3.2.531 pending aiohttp cap lift).</li>
</ul>
<h2 id="034---2026-07-04">[0.3.4] - 2026-07-04</h2>
<h3 id="changed-2">Changed</h3>
<ul>
<li>Docker image scanner updates: osv-scanner 2.4.0, trivy 0.72.0, semgrep
1.168.0, zizmor 1.26.1 (checkov remains at 3.2.531 pending aiohttp cap lift).</li>
</ul>
<h2 id="033---2026-06-17">[0.3.3] - 2026-06-17</h2>
<h3 id="changed-3">Changed</h3>
<ul>
<li>Trivy default severity is now all levels (<code>UNKNOWN</code> through <code>CRITICAL</code>) instead
of <code>CRITICAL</code> and <code>HIGH</code> only. osv-scanner and trivy now overlap on
medium/low advisories by default so cross-scanner dedup and <code>Detected by</code>
work without extra config. Consumers can narrow the Trivy scan with
<code>scanners.trivy.severity</code>; <code>fail-on</code> still controls which findings fail the run.</li>
</ul>
<h2 id="032---2026-06-16">[0.3.2] - 2026-06-16</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Suppressions with <code>tool</code> and/or <code>rule-id</code> are now applied. Previously only <code>id</code>
(path substring) and <code>fingerprint</code> matchers worked; tool+rule-id entries
parsed from <code>muninn.yml</code> but silently no-op&rsquo;d.</li>
</ul>
<h2 id="031---2026-06-16">[0.3.1] - 2026-06-16</h2>
<h3 id="fixed-1">Fixed</h3>
<ul>
<li>Poutine v1.x JSON parsing: findings from poutine 1.1.6+ (<code>rule_id</code>, <code>meta</code>,
<code>rules</code>, <code>blobshas</code>) now populate title, rule, and file in PR comments instead
of empty shells (<code>File: :0</code>, `Rule: ``) (#41).</li>
<li>Actionlint PR comments: fall back to <code>kind</code> (e.g. <code>expression</code>) when
<code>rule.name</code> is absent; omit empty Rule lines.</li>
<li>Poutine injection findings: render <code>injection_sources</code> as formatted
<strong>Sources</strong> instead of plain <code>meta.details</code> text.</li>
</ul>
<h3 id="changed-4">Changed</h3>
<ul>
<li>PR comment layout: shared field helpers; non-dependency findings follow
File → Rule → optional extras → description; single-scanner dependency
findings use <strong>File</strong> instead of a redundant <strong>Source</strong> line.</li>
</ul>
<h2 id="030---2026-06-16">[0.3.0] - 2026-06-16</h2>
<h3 id="added">Added</h3>
<ul>
<li>Cross-scanner deduplication by advisory id: findings that report the same
CVE/GHSA for the same package from different scanners (e.g. OSV-Scanner from a
lockfile and Trivy from a container layer) are now collapsed into a single
finding. The contributing scanners are recorded in a new <code>detected_by</code> field
(surfaced in the JSON report, the PR comment&rsquo;s &ldquo;Detected by&rdquo; line, and a
<code>detectedBy</code> SARIF result property). A CVE is preferred over GHSA so the same
vulnerability converges on one id across scanners (#27).</li>
<li>Richer dependency finding rendering: aggregated dependency findings now appear
under a neutral <code>[dependency]</code> heading (instead of a single scanner&rsquo;s name)
with <code>Package</code>, <code>Advisory</code> (including the shared CVE), <code>Detected by</code>, and a
<code>Sources</code> list showing where each scanner observed it. A new <code>sources</code> field on
the finding (per-scanner <code>tool</code> + <code>file</code>) backs the JSON report (#27).</li>
</ul>
<h3 id="fixed-2">Fixed</h3>
<ul>
<li>PR comment rendering: scanner descriptions are flattened to a single line and
their Markdown (code fences, headings) neutralized, so an unbalanced ``` fence
can no longer swallow later findings and the footer into a code block.</li>
</ul>
<h2 id="020---2026-06-15">[0.2.0] - 2026-06-15</h2>
<p>Supply-chain hardening for the scanner image and signed, verifiable releases
(closes #30).</p>
<h3 id="added-1">Added</h3>
<ul>
<li>Pinned every bundled binary scanner to an exact version with SHA256 checksum
verification in the Docker image — gitleaks, zizmor, actionlint, poutine,
osv-scanner, trivy (#31)</li>
<li>Hash-locked the pip-installed scanners (semgrep, checkov, zizmor) via a fully
pinned, multi-arch <code>requirements-scanners.txt</code> installed with
<code>pip --require-hashes</code> (#33)</li>
<li>Renovate configuration to auto-PR scanner version bumps, with a CI job that
refreshes the pinned checksums (#32)</li>
<li>Keyless (OIDC) cosign signing of the published container image and of the
release binary checksums (Sigstore bundle <code>checksums.txt.sigstore.json</code>) (#34)</li>
<li>SBOM (SPDX) attached to every release and as an image attestation (#34)</li>
<li>Max-mode SLSA build provenance attestation on the container image (#34)</li>
<li>&ldquo;Verifying releases&rdquo; instructions in the README (#34)</li>
</ul>
<h3 id="changed-5">Changed</h3>
<ul>
<li>Pinned checkov to 3.2.531 (from 3.3.1) so its dependency tree resolves the
patched aiohttp 3.14.1 and drops the unfixable python-ecdsa Minerva
dependency that checkov 3.3.x introduced. Revisit when a newer checkov lifts
its <code>aiohttp&lt;3.14</code> cap (#33)</li>
</ul>
<h2 id="010---2026-06-14">[0.1.0] - 2026-06-14</h2>
<h3 id="added-2">Added</h3>
<ul>
<li>8 security scanners: gitleaks, zizmor, actionlint, poutine,
semgrep, osv-scanner, trivy, checkov</li>
<li>Unified Finding schema with fingerprinting</li>
<li>Three output formats: SARIF 2.1.0, JSON, GitHub PR comment</li>
<li>GitHub Action with outputs</li>
<li>Config-driven scanner behavior via muninn.yml</li>
<li>Suppression management with expiry dates</li>
<li>90%+ test coverage enforced in CI</li>
<li>Integration tests with real scanner binaries</li>
<li>Self-scan: Muninn scans itself on every PR</li>
</ul>
<p>Built by Skald Lab — skaldlab.dev</p>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/ssg-static-site-generator/</link><pubDate>Thu, 23 Jul 2026 06:30:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.12.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website, supporting various themes, template engines, SEO features, and deployment options. It automates the process of generating clean URLs, feeds, search indexes, and more, making it suitable for building blogs, documentation sites, and landing pages efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.12</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website, supporting various themes, template engines, SEO features, and deployment options. It automates the process of generating clean URLs, feeds, search indexes, and more, making it suitable for building blogs, documentation sites, and landing pages efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>1.8.12 — Mermaid diagrams + code line numbers by @spagu in <a href="https://github.com/spagu/ssg/pull/46">https://github.com/spagu/ssg/pull/46</a></li>
<li>fix(docs-site): readable code blocks — github-dark highlight style by @spagu in <a href="https://github.com/spagu/ssg/pull/48">https://github.com/spagu/ssg/pull/48</a></li>
<li>feat: strip_md_link_text — drop .md from link text at publish (GO-075) by @spagu in <a href="https://github.com/spagu/ssg/pull/49">https://github.com/spagu/ssg/pull/49</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.11...v1.8.12">https://github.com/spagu/ssg/compare/v1.8.11...v1.8.12</a></p>
]]></content:encoded></item><item><title>spek - OpenSpec Static Site</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/spek-openspec-static-site/</link><pubDate>Thu, 23 Jul 2026 06:29:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/spek-openspec-static-site/</guid><description>Version updated for https://github.com/spekhq/spek to version v1.9.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The spek GitHub Action provides a lightweight, read-only viewer for OpenSpec content, offering structured browsing with BDD syntax highlighting, task progress tracking, and full-text search. It automates the process of displaying and managing specs, changes, and tasks in a single interface, making it easier to collaborate and understand complex projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spekhq/spek">https://github.com/spekhq/spek</a></strong> to version <strong>v1.9.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spek-openspec-static-site">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The spek GitHub Action provides a lightweight, read-only viewer for OpenSpec content, offering structured browsing with BDD syntax highlighting, task progress tracking, and full-text search. It automates the process of displaying and managing specs, changes, and tasks in a single interface, making it easier to collaborate and understand complex projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li><strong>The IntelliJ plugin opens again on IDEs built on platform 2026.2.</strong> Opening the Tool Window threw an IDE Internal Error and left no viewer at all, so the plugin was unusable — 2026.2 moved JCEF into a bundled plugin whose classes the plugin could no longer see (<a href="https://github.com/spekhq/spek/issues/24">#24</a>, reported on WebStorm 2026.2 with plugin 1.9.0). The embedded webview is restored, and JCEF being unavailable for any reason now degrades to the external-browser fallback instead of crashing — which is what makes the next platform change of this kind an inconvenience rather than an outage.</li>
<li><strong>The timeline&rsquo;s &ldquo;group by topic&rdquo; works when worktree aggregation is on.</strong> Every change landed in the &ldquo;(no topic)&rdquo; lane, which read as though the repo had no spec relationships at all. Nothing looked broken — the chart rendered exactly as it does when the grouping is genuinely empty. Repos with a single worktree were unaffected (<a href="https://github.com/spekhq/spek/issues/25">#25</a>, reported by a downstream consumer of the <code>@spekjs/ui</code> package). Web and VS Code only; the IntelliJ plugin has no worktree aggregation, so it never hit this.</li>
</ul>
<p>Also released: <strong><code>@spekjs/ui@1.1.0</code></strong> — the same grouping fix for registry consumers, plus a new exported <code>changeNodeSlug(node)</code> helper for resolving graph change node ids. See <code>packages/ui/CHANGELOG.md</code>.</p>
]]></content:encoded></item><item><title>nix init</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/nix-init/</link><pubDate>Thu, 23 Jul 2026 06:28:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/nix-init/</guid><description>Version updated for https://github.com/spotdemo4/nix-init to version v1.60.0.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action initializes Nix-based repositories by automating common setup tasks such as creating a GitHub App Token, checking out the repository, setting up Git user information, configuring an optimal Nix environment, installing Nix, and setting the Nix configuration from a Flake. It also supports caching with niks3 for better performance on self-hosted runners. The action is designed to run efficiently (&amp;lt; 1 minute) and can be used with various runner types (GitHub Actions, Gitea, Forgejo).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spotdemo4/nix-init">https://github.com/spotdemo4/nix-init</a></strong> to version <strong>v1.60.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nix-init">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action initializes Nix-based repositories by automating common setup tasks such as creating a GitHub App Token, checking out the repository, setting up Git user information, configuring an optimal Nix environment, installing Nix, and setting the Nix configuration from a Flake. It also supports caching with <code>niks3</code> for better performance on self-hosted runners. The action is designed to run efficiently (&lt; 1 minute) and can be used with various runner types (GitHub Actions, Gitea, Forgejo).</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat(action): use node for nix develop env export (718723a4b53683c78e4dfcfa2f1da4a78264b171)</li>
<li>feat(action): use vendored nix-develop script (d24036e34bc83eaa5f2637ba61d089ff8f4edaf1)</li>
<li>feat: Update spotdemo4/better-checkout action to v0.14.0 (#168) (b28fd2c4d5f02afb7135720526d061c9794d4749)</li>
<li>fix(tests): check requested env vars only (092ab684bd4227911e870c62c5127a2f19e17c96)</li>
<li>fix(nix-develop): snapshot exported host vars for bash 3.2 (2740b4c10b72ee87614b33b6f9c6c43feeab6480)</li>
<li>fix(nix-develop): avoid nounset from unset indirections (b6c3c02f35216c601bffc33f872dc4fd6e767164)</li>
<li>bump: v1.59.0 -&gt; v1.60.0 (2fc360eefced0d01fc56eaf691ab9393a94a1c60)</li>
<li>chore: add top comment to shell setup (ec872f577e0291c8f52260f4ce4c283e187d9b3b)</li>
<li>test(ci): validate devShell environment exports (1d68c4040201627cbcc638e596acf959b7d16429)</li>
<li>chore(deps): update github actions to v7.0.1 (#167) (2d87c0572b541faad84eea63853d4175504d9c59)</li>
<li>chore(deps): lock file maintenance nix inputs (#166) (2738beb2e2d1be14ada7c74133fcf7861d5982da)</li>
<li>chore(deps): update github actions to v1.59.0 (#165) (57bf48f3b354214cd10358b4ee755e3d50f71a02)</li>
</ul>
]]></content:encoded></item><item><title>Sprocket CI/CD</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/sprocket-ci/cd/</link><pubDate>Thu, 23 Jul 2026 06:27:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/sprocket-ci/cd/</guid><description>Version updated for https://github.com/stjude-rust-labs/sprocket-action to version v0.28.0.
This action is used across all versions by 8 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates static analysis of WDL documents using Sprocket, a tool for validating and linting WDL files. It provides subcommands for check, lint, and validate, allowing users to enforce coding standards and detect potential issues in their workflows. The action can be configured with input parameters such as lint rules, ignore patterns, and deny options. It also supports formatting checks using a sprocket.toml configuration file.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stjude-rust-labs/sprocket-action">https://github.com/stjude-rust-labs/sprocket-action</a></strong> to version <strong>v0.28.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sprocket-ci-cd">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates static analysis of WDL documents using Sprocket, a tool for validating and linting WDL files. It provides subcommands for <code>check</code>, <code>lint</code>, and <code>validate</code>, allowing users to enforce coding standards and detect potential issues in their workflows. The action can be configured with input parameters such as lint rules, ignore patterns, and deny options. It also supports formatting checks using a <code>sprocket.toml</code> configuration file.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Bumps <code>sprocket</code> to <a href="https://github.com/stjude-rust-labs/sprocket/releases/tag/v0.28.0">v0.28.0</a>.</p>
]]></content:encoded></item><item><title>xilo-nix-cache</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/xilo-nix-cache/</link><pubDate>Thu, 23 Jul 2026 06:26:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/xilo-nix-cache/</guid><description>Version updated for https://github.com/stubbedev/xilo to version v1.0.10.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The xilo action is a self-hosted Nix binary cache written in Go. It offers single-tenant multi-user support, content-addressed chunk deduplication, and supports local or S3 storage backends. Key features include instant token revocation, no stalls on concurrent pushes, a cachix-style admin dashboard, and a 9 MB Docker image serving zstd pulls directly from stored frames.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stubbedev/xilo">https://github.com/stubbedev/xilo</a></strong> to version <strong>v1.0.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/xilo-nix-cache">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The xilo action is a self-hosted Nix binary cache written in Go. It offers single-tenant multi-user support, content-addressed chunk deduplication, and supports local or S3 storage backends. Key features include instant token revocation, no stalls on concurrent pushes, a cachix-style admin dashboard, and a 9 MB Docker image serving zstd pulls directly from stored frames.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(ci): bump actions/setup-go from 6 to 7 in the actions group by @dependabot[bot] in <a href="https://github.com/stubbedev/xilo/pull/10">https://github.com/stubbedev/xilo/pull/10</a></li>
<li>chore(deps): bump the go-deps group with 5 updates by @dependabot[bot] in <a href="https://github.com/stubbedev/xilo/pull/11">https://github.com/stubbedev/xilo/pull/11</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/stubbedev/xilo/compare/v1...v1.0.10">https://github.com/stubbedev/xilo/compare/v1...v1.0.10</a></p>
]]></content:encoded></item><item><title>Sudden Agent</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/sudden-agent/</link><pubDate>Thu, 23 Jul 2026 06:25:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/sudden-agent/</guid><description>Version updated for https://github.com/sudden-network/agent to version v1.14.1.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Sudden Agent automates tasks on GitHub workflows through programmable agents. It solves problems related to automating code reviews, issue triage, security audits, and version management by providing customizable prompts and session persistence across different actions in the workflow. The action supports various models and authentication methods for different agents.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sudden-network/agent">https://github.com/sudden-network/agent</a></strong> to version <strong>v1.14.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sudden-agent">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Sudden Agent automates tasks on GitHub workflows through programmable agents. It solves problems related to automating code reviews, issue triage, security audits, and version management by providing customizable prompts and session persistence across different actions in the workflow. The action supports various models and authentication methods for different agents.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Support GPT-5.6 Codex models by @etienne-martin in <a href="https://github.com/sudden-network/agent/pull/117">https://github.com/sudden-network/agent/pull/117</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sudden-network/agent/compare/v1.14.0...v1.14.1">https://github.com/sudden-network/agent/compare/v1.14.0...v1.14.1</a></p>
]]></content:encoded></item><item><title>Sigbound</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/sigbound/</link><pubDate>Thu, 23 Jul 2026 06:24:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/sigbound/</guid><description>Version updated for https://github.com/surya-koritala/sigbound to version v0.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sigbound automates the process of running multiple AI coding agents on one repository in parallel, merging their work automatically. It handles conflicts by using a model to resolve them and ensures that only changes that build and pass your tests are landed. The action is designed to be flexible, allowing users to bring their own model for planning, agent execution, conflict resolution, and merge repair.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/surya-koritala/sigbound">https://github.com/surya-koritala/sigbound</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sigbound">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sigbound automates the process of running multiple AI coding agents on one repository in parallel, merging their work automatically. It handles conflicts by using a model to resolve them and ensures that only changes that build and pass your tests are landed. The action is designed to be flexible, allowing users to bring their own model for planning, agent execution, conflict resolution, and merge repair.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Run AI coding agents in parallel on one git repo and auto-merge their verified work — nothing lands unless it builds and passes your tests.</p>
<p><strong>Highlights in 0.3.0</strong></p>
<ul>
<li><code>-verify-bisect</code> — when the combined tree fails verify, land the verified green subset instead of losing everything</li>
<li><code>-verify-cache</code> — skip re-verifying trees already proven green (keyed by tree OID)</li>
<li>Run manifest + <code>sig replay</code> — every landing is reproducible provenance</li>
<li><code>-resume</code> — pick up an interrupted run without re-running finished agents</li>
<li><code>-publish</code> — push the landed commit and open a PR/MR with your own tooling</li>
<li>This GitHub Action — install a released <code>sig</code>, run it from typed inputs, gate your job on the outcome</li>
</ul>
<p><strong>Use it</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">surya-koritala/sigbound@v0.3.0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">agent</span>: <span style="color:#e6db74">&#39;claude -p --permission-mode acceptEdits &#34;$SIGBOUND_TASK&#34;&#39;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">goal</span>: <span style="color:#e6db74">&#34;Add CSV export, due dates, and a summary command&#34;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">verify</span>: <span style="color:#e6db74">&#34;go build ./... &amp;&amp; go test ./...&#34;</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Folder Hash v2</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/folder-hash-v2/</link><pubDate>Thu, 23 Jul 2026 06:22:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/folder-hash-v2/</guid><description>Version updated for https://github.com/tankist/folder-hash to version v4.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action calculates the hash of specified folders and outputs the result, which can be used to generate cache keys or as a checksum for folder content. It supports caching multiple folders and uses glob patterns for file selection.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tankist/folder-hash">https://github.com/tankist/folder-hash</a></strong> to version <strong>v4.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/folder-hash-v2">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action calculates the hash of specified folders and outputs the result, which can be used to generate cache keys or as a checksum for folder content. It supports caching multiple folders and uses glob patterns for file selection.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="breaking-changes">Breaking changes</h2>
<ul>
<li>Folder hash values have changed. Regenerate any cache keys that depend on this action after upgrading.</li>
</ul>
<h2 id="changed">Changed</h2>
<ul>
<li>Upgraded the action and CI runtime to Node 24.</li>
<li>Migrated source and tests to ES modules and Node’s native test runner.</li>
<li>Replaced deprecated hashing and bundling dependencies.</li>
<li>Refreshed the bundled action output and documentation.</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/tankist/folder-hash/commits/v4.0.0">https://github.com/tankist/folder-hash/commits/v4.0.0</a></p>
]]></content:encoded></item><item><title>Tenzai Test</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/tenzai-test/</link><pubDate>Thu, 23 Jul 2026 06:22:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/tenzai-test/</guid><description>Version updated for https://github.com/TenzaiLtd/tenzai-github-action to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Tenzai Test GitHub Action automates AI-powered security testing of deployments directly from CI pipelines. It sends a commit-diff test against an existing Tenzai application and provides real-time feedback on vulnerabilities, automatically triggering a Tenzai Test check run in the tested commit. The action requires a production Tenzai service-account access key and app ID, validates configuration, and supports dry runs for testing purposes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TenzaiLtd/tenzai-github-action">https://github.com/TenzaiLtd/tenzai-github-action</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tenzai-test">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Tenzai Test GitHub Action automates AI-powered security testing of deployments directly from CI pipelines. It sends a commit-diff test against an existing Tenzai application and provides real-time feedback on vulnerabilities, automatically triggering a <code>Tenzai Test</code> check run in the tested commit. The action requires a production Tenzai service-account access key and app ID, validates configuration, and supports dry runs for testing purposes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>add baseurl override to action by @Dor256 in <a href="https://github.com/TenzaiLtd/tenzai-github-action/pull/9">https://github.com/TenzaiLtd/tenzai-github-action/pull/9</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/TenzaiLtd/tenzai-github-action/compare/v1.0.1...v1.0.2">https://github.com/TenzaiLtd/tenzai-github-action/compare/v1.0.1...v1.0.2</a></p>
]]></content:encoded></item><item><title>Soundcheck Security Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/soundcheck-security-review/</link><pubDate>Thu, 23 Jul 2026 06:21:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/soundcheck-security-review/</guid><description>Version updated for https://github.com/thejefflarson/soundcheck-action to version v1.0.39.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Soundcheck Security Review (v2) GitHub Action automates the execution of Soundcheck, an OWASP-focused static code analysis tool. It performs a security review on all changes in a pull request or a scheduled scan across the repository, providing a severity-ranked findings table and optional autofix capabilities that rewrite critical issues directly into the affected files.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/thejefflarson/soundcheck-action">https://github.com/thejefflarson/soundcheck-action</a></strong> to version <strong>v1.0.39</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/soundcheck-security-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Soundcheck Security Review (v2) GitHub Action automates the execution of Soundcheck, an OWASP-focused static code analysis tool. It performs a security review on all changes in a pull request or a scheduled scan across the repository, providing a severity-ranked findings table and optional autofix capabilities that rewrite critical issues directly into the affected files.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Bumps soundcheck to <a href="https://github.com/thejefflarson/soundcheck/releases/tag/v1.17.0">v1.17.0</a></strong> and the claude CLI pin to <code>2.1.214</code>.</p>
<p>The v1.17.0 changes on the soundcheck side:</p>
<ul>
<li><code>hotspot-mapping</code> now covers rendering/output sinks and dependency/config manifests (previously blindspots)</li>
<li><code>vulnerability-audit</code> is exhaustive per hotspot — picks every applicable skill, sweeps sibling code</li>
</ul>
<p>Benchmark against OWASP Juice Shop: reviews now produce ~2× more findings and lift strict recall from 33% → 67%, with zero hallucinations across residual findings.</p>
<p>No breaking changes to inputs, outputs, or workflow shape.</p>
]]></content:encoded></item><item><title>Translatize Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/translatize-sync/</link><pubDate>Thu, 23 Jul 2026 06:20:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/translatize-sync/</guid><description>Version updated for https://github.com/Translatize/sync-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Translatize Sync is a GitHub Action that automates the synchronization of source keys and translations between a local repository and a Translatize project. It simplifies the process by providing commands to push new source keys, pull completed translations, and gate pull requests based on missing or changed strings. The action uses a branch-bound API token for authentication and supports configuration via translatize.config.json.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Translatize/sync-action">https://github.com/Translatize/sync-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/translatize-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Translatize Sync is a GitHub Action that automates the synchronization of source keys and translations between a local repository and a Translatize project. It simplifies the process by providing commands to push new source keys, pull completed translations, and gate pull requests based on missing or changed strings. The action uses a branch-bound API token for authentication and supports configuration via <code>translatize.config.json</code>.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release of Translatize Sync.</p>
<p>Sync your app&rsquo;s translations with <a href="https://translatize.com">Translatize</a> from GitHub workflows:</p>
<ul>
<li><code>push</code> – upload new and changed source keys to a project branch</li>
<li><code>pull</code> – download completed translations into your locale files</li>
<li><code>status</code> – compare local files with the branch; gate PRs with <code>--fail-on-missing</code> / <code>--fail-on-diff</code></li>
</ul>
<p>Authenticates with a branch-bound Translatize API token (repo secret). Works with any repo layout via <code>translatize.config.json</code>.</p>
<p>Docs: <a href="https://translatize.com/docs/github-action">https://translatize.com/docs/github-action</a></p>
]]></content:encoded></item><item><title>repo-trust-scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/repo-trust-scan/</link><pubDate>Thu, 23 Jul 2026 06:19:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/repo-trust-scan/</guid><description>Version updated for https://github.com/Uky0Yang/repo-trust-scan to version v0.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary repo-trust-scan is a CLI and GitHub Action that statically scans repository-controlled execution surfaces, helping users identify and understand potential security risks before executing unfamiliar code. It checks tasks like automatic editor actions, agent hooks, MCP server configurations, devcontainer lifecycle commands, package install hooks, escaping symlinks, hidden Unicode in instructions, download-and-execute chains, and credential-transfer patterns. The action is useful for ensuring that repositories are secure and safe to work with, complementing existing security tools but not replacing them.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Uky0Yang/repo-trust-scan">https://github.com/Uky0Yang/repo-trust-scan</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/repo-trust-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>repo-trust-scan</code> is a CLI and GitHub Action that statically scans repository-controlled execution surfaces, helping users identify and understand potential security risks before executing unfamiliar code. It checks tasks like automatic editor actions, agent hooks, MCP server configurations, devcontainer lifecycle commands, package install hooks, escaping symlinks, hidden Unicode in instructions, download-and-execute chains, and credential-transfer patterns. The action is useful for ensuring that repositories are secure and safe to work with, complementing existing security tools but not replacing them.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Publishes repo-trust-scan as a reusable GitHub Action in the Security and Utilities categories.</li>
<li>Adds a 21-second terminal demo and a 1280×640 social preview asset.</li>
<li>Moves real scan output ahead of installation and adds clear comparisons with secret scanners, SAST, and runtime scanners.</li>
<li>Adds a copyable GitHub Actions workflow.</li>
<li>Updates pinned GitHub Actions dependencies.</li>
</ul>
<h2 id="validation">Validation</h2>
<ul>
<li>25 unit tests pass (2 Windows symlink tests skipped as expected).</li>
<li>Package build, action smoke test, compile check, and critical self-scan pass.</li>
<li>CI passes on Ubuntu, Windows, and macOS with Python 3.10 and 3.14.</li>
</ul>
]]></content:encoded></item><item><title>urldn-link-check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/urldn-link-check/</link><pubDate>Thu, 23 Jul 2026 06:18:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/urldn-link-check/</guid><description>Version updated for https://github.com/URLdn/link-check to version v1.0.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action scans Markdown and MDX files to find broken, redirected, insecure HTTP links, and excessively long URLs. It can be used as a CLI or as part of a continuous integration pipeline to ensure the integrity of documentation links.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/URLdn/link-check">https://github.com/URLdn/link-check</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/urldn-link-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action scans Markdown and MDX files to find broken, redirected, insecure HTTP links, and excessively long URLs. It can be used as a CLI or as part of a continuous integration pipeline to ensure the integrity of documentation links.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/URLdn/link-check/compare/v1.0.0...v1.0.1">https://github.com/URLdn/link-check/compare/v1.0.0...v1.0.1</a></p>
]]></content:encoded></item><item><title>difftrace</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/difftrace/</link><pubDate>Thu, 23 Jul 2026 06:16:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/difftrace/</guid><description>Version updated for https://github.com/vanandrew/difftrace to version v1.5.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action difftrace automates change detection in monorepos by analyzing the uv.lock file to build a dependency graph, mapping changes to packages, and identifying transitively affected packages. It identifies which packages are directly or indirectly impacted by code changes, optimizing CI pipelines to only process relevant packages.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vanandrew/difftrace">https://github.com/vanandrew/difftrace</a></strong> to version <strong>v1.5.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/difftrace">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <strong>difftrace</strong> automates change detection in monorepos by analyzing the <code>uv.lock</code> file to build a dependency graph, mapping changes to packages, and identifying transitively affected packages. It identifies which packages are directly or indirectly impacted by code changes, optimizing CI pipelines to only process relevant packages.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: key lock fingerprints per-name-set so multi-version deps aren&rsquo;t hidden by @vanandrew in <a href="https://github.com/vanandrew/difftrace/pull/13">https://github.com/vanandrew/difftrace/pull/13</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vanandrew/difftrace/compare/v1.5.0...v1.5.1">https://github.com/vanandrew/difftrace/compare/v1.5.0...v1.5.1</a></p>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/vibgrate-scan/</link><pubDate>Thu, 23 Jul 2026 06:15:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.722.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The @vibgrate/cli GitHub Action provides a comprehensive local codebase intelligence tool for AI coding agents. It automates several key tasks including generating a deterministic code graph, calculating drift scores to measure how far behind the codebase is in terms of runtime dependencies and library versions, and providing ranked upgrade priorities for maintaining up-to-date dependencies. The action runs entirely on your machine, ensuring no network calls or data leaves your repository unless explicitly pushed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.722.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>@vibgrate/cli</code> GitHub Action provides a comprehensive local codebase intelligence tool for AI coding agents. It automates several key tasks including generating a deterministic code graph, calculating drift scores to measure how far behind the codebase is in terms of runtime dependencies and library versions, and providing ranked upgrade priorities for maintaining up-to-date dependencies. The action runs entirely on your machine, ensuring no network calls or data leaves your repository unless explicitly pushed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20267222">Vibgrate CLI 2026.722.2</h1>
<p><em>Released 2026-07-22</em></p>
<p>This release introduces new commands for managing models in the vg CLI. Users can now access a live hosted model catalog and remove locally-installed models more easily.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="new">New</h3>
<ul>
<li><code>vg models catalog</code> provides a key-free, cached list of live hosted models from OpenRouter, with options for JSON output and offline caching.</li>
<li><code>vg models rm &lt;name&gt;</code> allows for the removal of locally-installed models, printing a plan by default and requiring <code>--yes</code> for confirmation.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.722.1, interleaved on one runner against the pinned corpus (176 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>19690 count</td>
          <td>19690 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>8682 count</td>
          <td>8682 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.98 ratio</td>
          <td>0.98 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>579.30 ms</td>
          <td>585.60 ms</td>
      </tr>
  </tbody>
</table>
<p>No regressions against the previous release.</p>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.722.2">https://vibgrate.com/changelog/cli/2026.722.2</a></p>
]]></content:encoded></item><item><title>Repo Settings as Code</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/repo-settings-as-code/</link><pubDate>Thu, 23 Jul 2026 06:14:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/repo-settings-as-code/</guid><description>Version updated for https://github.com/Vivswan/repo-settings-as-code to version v1.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Repo Settings as Code GitHub Action automates the application of declarative repository settings from a .github/settings.yml file to GitHub repositories. It provides a loud, stateless replacement for the Probot Settings app, which also handles rulesets (branch, tag, and push). The action ensures that every apply is visible and fails with API error messages, ensuring no silent failures occur. It supports setting up fine-grained Personal Access Tokens (PATs) as repository secrets, using them to manage permissions and settings declaratively in YAML format.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Vivswan/repo-settings-as-code">https://github.com/Vivswan/repo-settings-as-code</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/repo-settings-as-code">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Repo Settings as Code GitHub Action automates the application of declarative repository settings from a <code>.github/settings.yml</code> file to GitHub repositories. It provides a loud, stateless replacement for the Probot Settings app, which also handles rulesets (branch, tag, and push). The action ensures that every apply is visible and fails with API error messages, ensuring no silent failures occur. It supports setting up fine-grained Personal Access Tokens (PATs) as repository secrets, using them to manage permissions and settings declaratively in YAML format.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="repo-settings-as-code-first-release">Repo Settings as Code: First release.</h2>
<p>Apply declarative repository settings from <code>.github/settings.yml</code>: a stateless replacement for the Probot Settings app.</p>
<ul>
<li>Sections: repository fields, labels, rulesets, branch protection, environments, autolinks, Actions permissions, workflow state, Pages, code scanning default setup, collaborators, teams, and milestones.</li>
<li>Every apply is a visible workflow run; failures are loud.</li>
<li><code>mode: check</code> reports drift and writes nothing.</li>
<li>Apply reads first and writes only what differs: a converged repository gets zero writes, and a second apply is a no-op.</li>
<li>Multi-repo mode manages a whole fleet from one admin repository.</li>
</ul>
<p>Setup and the full section reference: <a href="https://github.com/Vivswan/repo-settings-as-code#readme">README</a>.</p>
<h2 id="100-2026-07-22">1.0.0 (2026-07-22)</h2>
<h3 id="features">Features</h3>
<ul>
<li>actionable errors, per-call debug tracing, and coverage docs (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/fe9c9c51b565f740a76324533e0eb3c34bd57a9f">fe9c9c5</a>)</li>
<li>add discovery filters for multi-repo &ldquo;*&rdquo; mode (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/1d6531f22b8d46a088b4e0f017eb1e67d080a1a2">1d6531f</a>)</li>
<li>adopt octokit, actions/core, and zod for transport, IO, and validation (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/ff89bb6d3500b6917c3adc0a4a6f4118d397ab39">ff89bb6</a>)</li>
<li>api-version input, self-updating pre-commit, bundle-freshness test (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/a83671815b3bce667f0784ff5befe950fd0c552d">a836718</a>)</li>
<li>apply own settings with the action at HEAD (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/4dac8fc756ec7bffb439896a92febbf6028a263a">4dac8fc</a>)</li>
<li>declarative section permissions and endpoint dictionaries (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/de2416411d32eda6f38c145890a8d8091ea3a5a2">de24164</a>)</li>
<li>five new settings surfaces, audit fixes, and structural refactors (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/30e2dd2e932776302d563536282a5e7f969aa62b">30e2dd2</a>)</li>
<li>forward-compatible key routing in the actions section (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/1818569cad66a37d174090dada741e058ee13307">1818569</a>)</li>
<li>full passthrough in every section plus coverage inventory (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/34f108a30e5f925e783e17279be8abeadbb42c4d">34f108a</a>)</li>
<li>initial settings-as-code action (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/6e4857f78bf37304a3e115b42f6c4b99a2018cf7">6e4857f</a>)</li>
<li>multi-repo mode with central files, remote settings, and a defaults layer (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/04b379e10e236e753eed740d27c3f809b526d2ed">04b379e</a>)</li>
<li>node24 runtime and husky pre-commit hook (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/ba04830806226425d9e8b3375ff2651a26d78e73">ba04830</a>)</li>
<li>preflight barrier makes strict applies all-or-nothing (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/a92173fe5ada43a5bbc3602ae332a9d30b1a4e6e">a92173f</a>)</li>
<li>publish generated settings.yml JSON Schema (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/b706fa9287569b0d9c7be7e4a073e28d4e0e3419">b706fa9</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>enforce read-only preflight probes and guard check-mode purity (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/009def97ad53a5ab84416cc4416a930a21c67ba9">009def9</a>)</li>
<li>environments PUT status and write-throttle scaling, found by the new e2e fuzz harness (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/b03202487bb0e0149b34304464cfe2ca08ea615a">b032024</a>)</li>
<li>escape backslashes before pipes in the summary table (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/668456951edcad3701955467d082a56f7f7928e0">6684569</a>)</li>
<li>format the e2e mock files that landed mid-refinement (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/89110689a6b2476c663fb3f0ea8a9a292139fe0f">8911068</a>)</li>
<li>make the unrecognized actions-key note mode-aware and name the enabled value (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/1d3bc0a4c78dd76854e7eb119438dd6a86e7c2c0">1d3bc0a</a>)</li>
<li>pin bun via .bun-version so CI rebuilds the bundle byte-identically (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/4e7f2bcf59d5d477e1bb6727ba5c3bf33dcadbdf">4e7f2bc</a>)</li>
<li>print the final result on stdout (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/76b258d05785ea3d5fbed0ca62329811ae4a5557">76b258d</a>)</li>
<li>rate-limit discovery advice, shared constants, docs pinned to code (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/cf8f291ca25222b28c8d6db1e28b14e387153714">cf8f291</a>)</li>
<li>reject duplicate ruleset and branch declarations before any API call (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/441ed4956f95272517bdf058286c78e5a2acdb50">441ed49</a>)</li>
<li>shape-check the fields section handlers dereference (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/c9a8585d16d8a18b790e71bef1704067d25fb991">c9a8585</a>)</li>
<li>teams org grading, nightly issue auto-assignment, and fuzz artifact hygiene (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/f0378f0c0e641978bf387c60bedf6471f4af652b">f0378f0</a>)</li>
<li>unique marketplace name and shorter description (<a href="https://github.com/Vivswan/repo-settings-as-code/commit/9508134821b3197a81476bc4033ebebd413bc239">9508134</a>)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Vivswan/repo-settings-as-code/commits/v1.0.0">https://github.com/Vivswan/repo-settings-as-code/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/rustscript-action/</link><pubDate>Thu, 23 Jul 2026 06:13:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.1.9.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates Rust script execution by interpreting a practical subset of the language without compiling the entire project. It supports running scripts directly as binaries or executing snippets in compiled form, validating without running, and providing a list of supported methods per receiver and engine. The action is particularly useful for small scripts that do not require compilation to run efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates Rust script execution by interpreting a practical subset of the language without compiling the entire project. It supports running scripts directly as binaries or executing snippets in compiled form, validating without running, and providing a list of supported methods per receiver and engine. The action is particularly useful for small scripts that do not require compilation to run efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.1...v0.1.9">https://github.com/VladasZ/rustscript/compare/v0.1...v0.1.9</a></p>
]]></content:encoded></item><item><title>Hurd-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/hurd-vm/</link><pubDate>Thu, 23 Jul 2026 06:12:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/hurd-vm/</guid><description>Version updated for https://github.com/vmactions/hurd-vm to version v1.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action vmactions/hurd-vm allows users to run CI tests in the Hurd operating system. It automates the setup and execution of CI scripts on Hurd, a Unix-like operating system derived from GNU/Hurd. This action provides features such as sharing code between the host and VM, using different synchronization methods like rsync, nfs, or scp, and NATting ports to allow for remote access to the VM.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/hurd-vm">https://github.com/vmactions/hurd-vm</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hurd-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>vmactions/hurd-vm</code> allows users to run CI tests in the Hurd operating system. It automates the setup and execution of CI scripts on Hurd, a Unix-like operating system derived from GNU/Hurd. This action provides features such as sharing code between the host and VM, using different synchronization methods like <code>rsync</code>, <code>nfs</code>, or <code>scp</code>, and NATting ports to allow for remote access to the VM.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>init</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/hurd-vm/commits/v1.0.0">https://github.com/vmactions/hurd-vm/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>Void Checkout</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/void-checkout/</link><pubDate>Thu, 23 Jul 2026 06:10:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/void-checkout/</guid><description>Version updated for https://github.com/void-musl/checkout to version v1.0.0-treeless.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action checkout checks out a repository in treeless mode, which includes only the files and directories specified in .gitattributes. This is useful for creating lightweight clones of repositories that do not include unnecessary binary or large files. The action automates the checkout process by using the default ref (github.ref) if not provided, and supports specifying the repository name and server URL as inputs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/void-musl/checkout">https://github.com/void-musl/checkout</a></strong> to version <strong>v1.0.0-treeless</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/void-checkout">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>checkout</code> checks out a repository in treeless mode, which includes only the files and directories specified in <code>.gitattributes</code>. This is useful for creating lightweight clones of repositories that do not include unnecessary binary or large files. The action automates the checkout process by using the default ref (<code>github.ref</code>) if not provided, and supports specifying the repository name and server URL as inputs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/void-musl/checkout/commits/v1.0.0-treeless">https://github.com/void-musl/checkout/commits/v1.0.0-treeless</a></p>
]]></content:encoded></item><item><title>Void Upload</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/void-upload/</link><pubDate>Thu, 23 Jul 2026 06:10:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/void-upload/</guid><description>Version updated for https://github.com/void-musl/upload-release to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of uploading files to a specific release on GitHub. It simplifies the task by requiring only essential inputs such as the tag, release name, file pattern, and GitHub token. The main functionality is to allow developers to easily publish build artifacts or binary files directly from their workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/void-musl/upload-release">https://github.com/void-musl/upload-release</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/void-upload">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of uploading files to a specific release on GitHub. It simplifies the task by requiring only essential inputs such as the tag, release name, file pattern, and GitHub token. The main functionality is to allow developers to easily publish build artifacts or binary files directly from their workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/void-musl/upload-release/compare/v1.0.1...v1.0.2">https://github.com/void-musl/upload-release/compare/v1.0.1...v1.0.2</a></p>
]]></content:encoded></item><item><title>wartzar-bee CI Cost Guardrail</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/wartzar-bee-ci-cost-guardrail/</link><pubDate>Thu, 23 Jul 2026 06:10:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/wartzar-bee-ci-cost-guardrail/</guid><description>Version updated for https://github.com/wartzar-bee/ci-guardrail to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action wartzar-bee/ci-guardrail calculates the cost difference between the base and head branches of a PR, posts a comment with the delta and top contributors, and can block the build if the token cost increases beyond a configured threshold. It uses @wartzar-bee/tokenscope to estimate token costs based on file size and complexity, providing insights into potential cost regressions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wartzar-bee/ci-guardrail">https://github.com/wartzar-bee/ci-guardrail</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wartzar-bee-ci-cost-guardrail">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>wartzar-bee/ci-guardrail</code> calculates the cost difference between the base and head branches of a PR, posts a comment with the delta and top contributors, and can block the build if the token cost increases beyond a configured threshold. It uses <code>@wartzar-bee/tokenscope</code> to estimate token costs based on file size and complexity, providing insights into potential cost regressions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v111--self-test-ci--tests-badge">v1.1.1 — self-test CI + tests badge</h2>
<p>Patch release. No change to the action&rsquo;s behavior (entrypoint.sh / action.yml untouched vs v1.1.0). Backward compatible — <code>uses: wartzar-bee/ci-guardrail@v1</code> picks it up when the <code>v1</code> tag is moved.</p>
<h3 id="added">Added</h3>
<ul>
<li><strong>Self-test CI.</strong> <code>.github/workflows/test.yml</code> runs the 50-test integration suite (<code>bash test/run-test.sh</code>) on every push to <code>main</code> and every pull_request. The suite mocks <code>tokenscope</code> and <code>git</code> on PATH, so it needs only bash + python3 (both preinstalled on ubuntu-latest) — no npm/tokenscope install.</li>
<li><strong>Tests badge</strong> in the README (above the Marketplace badge). For a GitHub Action, a visible green self-test is a direct trust/conversion signal for the repo visitors the dev.to announcement + Marketplace listing drive here.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>README hero-line overclaim (honesty fix).</strong> The top-of-README tagline claimed the action &ldquo;comments on the responsible lines&rdquo;. It does not — it comments on the responsible <strong>files</strong> (<code>tokenscope scan</code> emits file-level token data with no line-level attribution; the PR comment renders per-file delta tables). Corrected &ldquo;lines&rdquo;-&gt;&ldquo;files&rdquo; so the flagship&rsquo;s first-impression line matches action.yml&rsquo;s Marketplace description and the actual behavior. Brand HARD RULE: never claim a capability the product lacks.</li>
<li><strong>Publish allowlist gap.</strong> <code>.publish-include</code> now lists <code>.github/workflows/test.yml</code>. It previously did not, so the tests badge added in the prior tick would have pointed at a workflow that never shipped to the public repo — a broken (404) badge. Now the workflow ships, the badge runs, and it goes green after the first push.</li>
</ul>
<p>Tests: 50/50 pass. Pre-publish audit: CLEAN.</p>
]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/cowork-harness/</link><pubDate>Thu, 23 Jul 2026 06:08:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.7.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action creates a headless, scriptable, CI-ready test harness for testing Claude Cowork skills. It reproduces Claude Cowork’s observable runtime contract closely enough to test the skills you write across multiple scenarios and in CI environments, without using the locked Desktop app. The action supports various fidelity tiers including replay, lint, container, hostloop, and microvm, each requiring different prerequisites such as a running agent, a Claude token, and a Docker or Lima runtime.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v1.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action creates a headless, scriptable, CI-ready test harness for testing Claude Cowork skills. It reproduces Claude Cowork&rsquo;s observable runtime contract closely enough to test the skills you write across multiple scenarios and in CI environments, without using the locked Desktop app. The action supports various fidelity tiers including replay, lint, container, hostloop, and microvm, each requiring different prerequisites such as a running agent, a Claude token, and a Docker or Lima runtime.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong><code>migrate-run-dir</code> — convert pre-layout run dirs to the per-turn <code>turns/&lt;N&gt;/</code> layout, in place.</strong>
A run dir written before the per-turn layout keeps <code>result.json</code> / <code>run.jsonl</code> / <code>trace.json</code> /
<code>resources.jsonl</code> at its root. Once the legacy read layer is removed, those dirs become unreadable to
<code>verify-run</code> / <code>diff</code> / <code>inspect</code> / <code>stats</code>; this command converts them so the history survives the
change instead of having to be re-run.</p>
<p><strong>Dry-run by default</strong> — <code>--write</code> applies, and <code>--scenario &lt;name&gt;</code> scopes the run to a single
scenario so a rollout can be staged: migrate one, verify it, then do the rest. It renames rather than copies, so file mtimes (the recency
signal <code>stats</code> and <code>status --latest-for</code> rank by) survive untouched, and it restores directory mtimes
afterwards. An interrupted run records a journal outside the run dir and is finished by re-running the
command. Anything it cannot resolve unambiguously — a root artifact that is neither a duplicate nor
placeable, telemetry whose turn boundary cannot be dated or that spans more than two turns or whose
samples would land in a turn no transcript or result evidences, a dir with
no transcript at all — is <strong>refused and named</strong>. The one inference it makes is positional: an EMPTY file
has no content to attribute, so it follows its position to an EVIDENCED turn (its own, by name or by
rootArtifactTurn when a root transcript or result exists to move there) — never one it would mint. The
same never-mint rule holds on the content path: a stray <code>resources.turn-N.jsonl</code> cannot manufacture
<code>turns/N/</code> whether it is empty or carries samples, and a fully-archived dir&rsquo;s trailing telemetry cannot
manufacture the next turn out of arithmetic alone. Exit <code>1</code> when anything was refused, so a CI caller sees unfinished work.
After a <code>--write</code> that migrated or recovered anything, it prints a reminder to rebuild the index
(<code>cowork-harness stats --reindex</code>), since the index keys a row&rsquo;s timestamp off <code>result.json</code>&rsquo;s mtime and
the files have moved.</p>
</li>
<li>
<p><strong><code>prune</code> skips scenarios with a migration in flight.</strong> Between an interrupted migration and its
recovery a run dir&rsquo;s mtime reflects the migration, not the run — and <code>prune</code> ranks keep-slots by that
mtime, so it could evict a newer run in favour of a half-migrated older one. It now defers those
scenarios and says so.</p>
</li>
<li>
<p><strong><code>critique</code> surfaces the GRADED turn&rsquo;s <code>outcome</code> and <code>skillHash</code> in its own report</strong>
(<code>gradedOutcome</code> / <code>gradedSkillHash</code> in JSON, and in the text header), and writes the graded result
under the stable name <strong><code>result.graded.json</code></strong>. <code>critique</code> runs two turns into one run directory, so
after the resume <code>result.json</code> is the <em>reflection</em> turn&rsquo;s and the graded turn is archived as
<code>result.turn-1.json</code> — the correct file to read was the <em>lower</em> number, the opposite of every other
multi-run convention. A harvester reading <code>result.json</code> silently ingested the reflection turn&rsquo;s numbers:
valid-looking, wrong, and unsignalled. Reported by a consumer building exactly that harvester; a
documentation-only fix would have helped only readers who already knew to look.</p>
</li>
<li>
<p><strong><code>exec_infra_error</code> verdict signal (<code>WARN</code>)</strong> — a container <code>exec</code> that failed for infrastructure
reasons, as distinct from the fail-severity <code>infra_error</code> (a supervising process died). One failed
command no longer contaminates a whole run&rsquo;s evidence.</p>
</li>
<li>
<p><strong><code>RunResult.infraErrors[].source</code> is now an enum</strong> — <code>hostloop-sidecar</code> / <code>hostloop-exec</code> /
<code>egress-sidecar</code>. The origin is what drives severity, and it is carried through the frozen cassette so
replay reaches the same verdict as the live run.</p>
</li>
<li>
<p><strong>Capability use-scan health</strong> — an unreadable or partially unparseable <code>events.jsonl</code> is now reported
as a degraded scan instead of being indistinguishable from a complete scan that found nothing.</p>
</li>
<li>
<p><strong>Every <code>critique</code> limitation is now tagged with WHY it exists</strong>, not just what it is — <code>structural</code>
(permanent, architect around it), <code>unverified</code> (unproven, <strong>not</strong> known-impossible), <code>deliberate</code> (a
design choice), <code>not-built</code> (simply absent). The distinction a reader needs is rarely &ldquo;what can&rsquo;t it
do&rdquo; but &ldquo;should I design around this forever, or wait for it?&rdquo; <strong>Container-tier-only is <code>unverified</code></strong>:
the resume-continuity proof was run against the container tier&rsquo;s Linux ELF, and hostloop runs a
different (native) agent binary, so the proof does not transfer — nothing suggests hostloop would fail,
nobody has run it. <strong>Lifting the pin needs BOTH</strong> a live resume-continuity proof at hostloop against its
native binary AND the follow-on work that proof unblocks (unpinning three hard-coded container sites,
stamping the tier on the session manifest so a cross-tier resume fails loud, and plumbing host-write
consent) — evidence alone is not sufficient. A consumer read that pin as permanent and built a second
test lane around it. The tags appear in <code>critique --help</code> and <a href="./docs/critique.md">docs/critique.md</a>,
generated from one source.</p>
</li>
<li>
<p><strong><code>critique --help</code>&rsquo;s KNOWN LIMITATIONS block is generated</strong> from that source, and CI asserts the
shipped binary&rsquo;s output, the docs bullets, and their tags all agree.</p>
</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>
<p>⚠️ <strong>BREAKING: per-turn run-directory layout, single shape — the root-level <code>result.json</code> compatibility
copy is REMOVED.</strong> A run directory that holds several turns (any <code>--resume</code>, and every <code>critique</code>) writes
each turn&rsquo;s <code>result.json</code>, <code>run.jsonl</code>, <code>trace.json</code> and <code>resources.jsonl</code> into <strong><code>turns/&lt;N&gt;/</code></strong>, once,
under its final name — nothing is renamed or overwritten as later turns arrive. <code>chat</code> now goes through
the same layout too (always <code>turns/1/</code> — a <code>chat</code> session mints a fresh dir per invocation and never
resumes). <strong><code>&lt;outDir&gt;/result.json</code> no longer exists — there is no root compat copy of any per-turn
artifact, on ANY run dir.</strong> Read <code>turns/&lt;N&gt;/result.json</code> directly (<code>turns/1/</code> for a single-turn run), or
— for <code>critique</code> — the unchanged <code>result.graded.json</code> / <code>trace.graded.json</code> role aliases. Cumulative
streams (<code>events.jsonl</code>, <code>timeline.jsonl</code>) and session state are unchanged, so <code>critique</code>&rsquo;s byte-offset
turn-isolation proof and cassette capture are unaffected.</p>
<p><strong>Two prior shapes are now REFUSED, loudly, by name, instead of being silently misread:</strong></p>
<ul>
<li>a <strong>pre-layout</strong> run dir (written before <code>turns/&lt;N&gt;/</code> existed: root <code>result.json</code>/<code>run.jsonl</code>, or a
name-mangled <code>result.turn-&lt;N&gt;.json</code> archive, no <code>turns/</code>);</li>
<li>a <strong>mixed</strong> run dir (a pre-layout dir resumed under CURRENT code before this release — <code>turns/</code> present
<em>and</em> a stray root/archived file).</li>
</ul>
<p><code>verify-run</code>, <code>inspect</code>, <code>scaffold</code>, <code>diff</code>, <code>status --latest-for</code>, and a resumed <code>--session-id</code> all
refuse these with a message naming the shape found and pointing at <code>trace &lt;dir&gt;</code> — which still works
fully, since every one of its views derives from <code>events.jsonl</code>, which never moves. <code>stats --reindex</code>
counts them as skipped and names the remedy rather than dropping them from the index quietly.</p>
<p><strong>Migration: <code>cowork-harness migrate-run-dir</code></strong> converts a pre-layout dir in place (dry-run by default),
preserving the file timestamps <code>stats</code> and <code>status --latest-for</code> rank by. <code>diff</code> and
<code>status --latest-for</code> are called out because their pre-refusal behaviour was the dangerous kind: <code>diff</code>
reported two genuinely different runs as <code>identical</code> and exited 0, and <code>status --latest-for</code> could
select a <em>different</em> run than the newest and report its verdict — a CI script reading <code>.verdict.pass</code>
got a green light for a red run.</p>
<p>Previously the latest turn lived at the root while earlier ones were name-mangled archives, so a file&rsquo;s
name depended on whether a later turn ever happened; that shape produced a wrong-turn read, a destroyed
trace, and a dropped index row — this release&rsquo;s read-side (<code>turnArtifactPath</code> / <code>listTurns</code> in
<code>turn-layout.ts</code>, with the old <code>readTurnResult</code> deleted for having zero production callers) no longer has
a legacy-resolving branch at all, so that class of bug is now unrepresentable rather than merely fixed. The Python SDK&rsquo;s <code>_latest_run_jsonl</code> likewise now raises loudly
on a pre-layout dir instead of silently falling back to a root <code>run.jsonl</code> that (for any current-layout
dir) is a path to nowhere.</p>
</li>
<li>
<p><strong>Platform baseline synced to Desktop 1.24012.1</strong> (<code>baselines/desktop-1.24012.1.json</code>, now what
<code>baseline: latest</code> resolves to). The staged <strong>agent binary is <code>2.1.217</code></strong> (native app + VM ELF, new
sha256 for each). The baseline moved in two steps this release — an earlier sync to <strong>1.24012.0</strong> (agent
<code>2.1.215</code>), then to 1.24012.1 — with <strong>no prompt, spawn-env, or egress-allowlist drift across either</strong>:
<code>spawn.env</code> is byte-identical to 1.22209.3, the same 15-domain allowlist and <code>gvisor</code> mode carry over
(the effort map is the one spawn field that changed — see the sonnet-5 delta below), and the
<code>deriveSpawnEnv</code> / <code>checkSpawnContractFacts</code> oracles stay green against the live asar. The
substantive deltas all came from the 1.24012.0 step and carry forward unchanged: <code>claude-sonnet-5</code> joins
the per-model effort map (<code>low|medium|high|xhigh|max</code>, recommended <code>medium</code>, modes <code>auto</code>); the
<code>coworkRuntimeConfig</code> gate drops its <code>pluginsFullSyncStalenessMs</code> key (never modeled here, inert); and
the dormant <code>autoModeOverridesAlwaysAllow</code> sentinel fired — see below. 1.24012.1 itself adds only the
agent bump: the <code>2.1.217</code> binary can emit the VCS SDK events <code>code_change_published</code> /
<code>vcs_state_changed</code> (SDK floor <code>2.1.216</code>), which the harness surfaces as a <code>system_event</code> (its existing
graceful degradation of an unmodeled system event, unchanged), and the binary&rsquo;s native skill-discovery
enable predicate widened to three branches — still inert here, since real Cowork&rsquo;s model-visible surface
is the Desktop SDK-MCP discovery servers, not the native tools. The example cassettes'
<code>fingerprint.baseline</code> tracks the new baseline.</p>
</li>
<li>
<p><strong>The <code>autoModeOverridesAlwaysAllow</code> gate (<code>4200321681</code>) flipped absent → on</strong> (<code>source: force</code>) and was
revisited as its pin intended. It stays <strong>unmodeled, deliberately</strong>: binary-verified in 1.24012.0, both
call sites only override an <em>already-existing</em> always-allow decision — the session rule cache
(<code>approvedToolNames</code>) and scheduled-task auto-approval — each further gated on <code>permissionMode</code> and
<code>isDestructiveConnectorTool</code>. The harness persists neither, so it already prompts wherever the gate makes
Cowork prompt; enabling it moves real Cowork <em>toward</em> harness behavior rather than away. Revisit only if
the harness gains a persistent per-tool approval cache.</p>
</li>
<li>
<p><strong>The staged agent (<code>2.1.217</code>) enforces sub-agent fan-out caps, so <code>dispatch_count_max</code> is now framed as
a budget UNDER Cowork&rsquo;s cap, not a reproduction of it.</strong> Because the harness spawns the real binary, a
run that fans out past the agent&rsquo;s caps now errors from the binary itself: a <strong>concurrent</strong> cap
(<code>CLAUDE_CODE_MAX_CONCURRENT_SUBAGENTS</code>, default 20; error <code>subagent_concurrency_cap</code>, new in 2.1.217)
and a <strong>per-session</strong> cap (<code>CLAUDE_CODE_MAX_SUBAGENTS_PER_SESSION</code>, default 200; error
<code>subagent_count_cap</code>, present since ≤2.1.215). The scenario schema&rsquo;s <code>dispatch_count_max</code> description,
the <code>assert</code> over-budget message, and SPEC §10 no longer claim &ldquo;Cowork imposes no in-conversation
Task-dispatch cap&rdquo; — that claim was stale. The harness does not reproduce the caps; it inherits them by
running the binary.</p>
</li>
<li>
<p><strong>A host-loop <code>exec</code> infrastructure failure now WARNS instead of failing the run.</strong> ⚠️ <strong>Upgrade note:</strong>
a run that previously exited <code>1</code> because one <code>docker exec</code> failed will now exit <code>0</code>. A dead sidecar
still hard-fails. Known residual, documented in <code>docs/scenario.md</code>: if <em>every</em> exec failed the agent ran
nothing and the run still only warns — inspect <code>result.infraErrors</code> when a run looks suspiciously empty.</p>
</li>
<li>
<p><strong>A model-requested bash <code>timeout_ms</code> expiry is no longer classified as an infrastructure failure.</strong>
The model now receives its command&rsquo;s own partial output with <code>Command timed out after &lt;duration&gt;</code>
merged into stderr — matching real Cowork, verified against the staged agent binary — instead of an
opaque <code>[infrastructure error: see run log for details]</code>.</p>
</li>
<li>
<p><strong>The agent&rsquo;s spawn env now always carries a normalized IANA <code>TZ</code></strong> — matching Desktop, which injects
<code>Intl.DateTimeFormat().resolvedOptions().timeZone</code> unconditionally. Previously <code>TZ</code> was forwarded only
when the host shell exported it, and forwarded raw, so a host with no <code>TZ</code> set — or a legacy/non-IANA
export (<code>US/Eastern</code>, <code>EST5EDT</code>) — diverged from real Cowork&rsquo;s date/&ldquo;today&rdquo; rendering inside the agent.</p>
</li>
<li>
<p><strong>The <code>tool_available</code> assertion now names its evidence limit.</strong> It evaluates against the run&rsquo;s
<em>eagerly-loaded</em> tool set (the SDK init manifest in <code>result.json</code>); a factory-deferred tool — e.g. the
skill-discovery MCP tools, loaded on demand via a <code>ToolSearch</code> round-trip — can be genuinely available in
the run yet miss here, a false negative. The assertion still fails on a miss; the failure message now
states that eagerly-loaded scope rather than implying provable unavailability.</p>
</li>
<li>
<p><strong>An explicitly requested <code>--dotenv</code> file now fails loud.</strong> ⚠️ <strong>Upgrade note:</strong> an unreadable file, or
a path that is a directory, previously fell through to lower-precedence <code>.env</code> sources <em>while still
printing a success line</em> — so a typo&rsquo;d path silently ran against the wrong credentials. It is now a
usage error. Automatic <code>.env</code> discovery is unchanged (still best-effort).</p>
</li>
<li>
<p><strong><code>diff</code> no longer reports <code>identical</code> when only one side has an artifact manifest.</strong> ⚠️ <strong>Upgrade
note:</strong> such a comparison previously exited <code>0</code>; it now exits <code>1</code>, because unavailable evidence is not
evidence of equality. Both-sides-missing still does not veto identity. The <code>--output-format json</code>
envelope gained an <code>artifactsAvailability</code> key.</p>
</li>
<li>
<p><strong><code>stats --reindex</code> merges rows by per-completion identity</strong> (<code>outDir</code> + a new <code>turn</code> field) rather than
by <code>outDir</code> alone, and reports rejected symlinked run directories.</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong><code>verify-run</code> now REFUSES a multi-turn run directory</strong> instead of certifying the wrong turn. Root
<code>result.json</code> is the latest turn; on a <code>critique</code> directory that is the <em>reflection</em> turn while the
scenario describes the <em>graded</em> one. Previously the cumulative gate scan false-FAILED on the other
turn&rsquo;s gates — wrong, but loud. The refusal names <code>result.graded.json</code> / <code>turns/1/result.json</code> so the
caller can still reach the graded turn.</p>
</li>
<li>
<p><strong><code>trace</code> no longer mixes turn scopes.</strong> After timeline reads became turn-scoped, <code>--view tool-durations</code> showed the latest turn while the tools/questions/dispatches views still showed every
turn — two views of one run directory describing different scopes. All views are now the latest turn,
and a <code>::notice::</code> reports when earlier turns exist rather than hiding them. Its cache-read footer and
gate-provenance (<code>answeredBy</code>) views also now say when a result is not turn-addressable (a pre-layout
dir) instead of silently omitting the cache-read ratio / labels.</p>
</li>
<li>
<p><strong><code>prune</code> no longer demotes an unmigrated pre-layout run dir to the junk tier.</strong> Its real-run predicate
keyed on <code>hasTurnDirs || events.jsonl</code>, reasoning only about what current writers produce — but <code>prune</code>
ranks <em>history</em>, including the legacy dirs <code>migrate-run-dir</code> exists to preserve, so a legacy dir with no
<code>events.jsonl</code> could be evicted ahead of an empty scaffold. It now also counts a <code>legacy</code> / <code>mixed</code> shape
as a real run. (Distinct from the in-flight-migration deferral above — this is about which dirs count as
real at all.)</p>
</li>
<li>
<p><strong>A resumed turn was judged on the PRIOR turn&rsquo;s evidence — three wrong-verdict paths.</strong> <code>events.jsonl</code>
is append-only across turns with no per-turn marker, and three whole-file scanners decide a run&rsquo;s
outcome: <code>scanEvents</code> (outputs-delete / host-path-leak → fail signals, and an authored
<code>no_delete_in_outputs</code>), <code>findUngatedPathToolCalls</code> (→ a run-level <code>error</code> at hostloop), and
<code>detectCapabilityUse</code> (→ <code>missing_capability</code>, a fail signal, which fires on the default lean image).
So on any <code>--resume</code> — and every <code>critique</code> reflection turn — turn 1&rsquo;s delete, gated tool call, or
capability use FAILED turn 2. A turn-start marker now scopes all three to the current turn.
<code>resources.jsonl</code> had the same shape (turn 1&rsquo;s peak RSS judged against turn 2&rsquo;s <code>max_peak_rss_bytes</code>)
and is archived per turn. Single-turn runs write no marker, so their <code>events.jsonl</code> is byte-identical
and no cassette is affected. Missing marker ⇒ whole-file scan, i.e. fail-closed.</p>
</li>
<li>
<p><strong>A resumed turn&rsquo;s telemetry included the PRIOR turn&rsquo;s events, and could produce a false PASS.</strong>
<code>timeline.jsonl</code> is append-mode with a fresh header per turn, but <code>readTimeline</code> returned every line
after the first as an event — so on any <code>--resume</code> (and every <code>critique</code> reflection turn) the current
turn&rsquo;s <code>toolDurations</code>/<code>skillActivity</code>/<code>subagents</code> folded in the previous turn&rsquo;s tool calls. Because
the <strong><code>skill_tool_used</code> assertion</strong> evaluates against that same <code>skillActivity</code>, a turn-1 skill window
could satisfy a turn-2 assertion. The reader now returns only the current turn&rsquo;s segment. The file
stays one append-only stream, so <code>critique</code>&rsquo;s byte-offset turn-isolation proof is unaffected.</p>
</li>
<li>
<p><strong>A resumed turn destroyed the prior turn&rsquo;s <code>trace.json</code>.</strong> Because it is rebuilt and overwritten on
every completion, the earlier turn&rsquo;s trace was deleted rather than preserved, so a <code>critique</code> lost the
graded turn&rsquo;s trace entirely. Each turn now owns its own <code>turns/&lt;N&gt;/trace.json</code>, written once and never
overwritten, and <code>critique</code> additionally writes <strong><code>trace.graded.json</code></strong> beside <code>result.graded.json</code>.</p>
</li>
<li>
<p><strong><code>stats --reindex</code> dropped every non-latest turn when rebuilding from the runs tree.</strong> It read only the
root <code>result.json</code> per run directory, so a resumed session&rsquo;s earlier turns vanished — and on a
<code>critique</code> directory the root file is the <em>reflection</em> turn, so it was the <strong>graded</strong> rows that were
lost. Every turn under <code>turns/&lt;N&gt;/</code> is now indexed as its own completion; <code>result.graded.json</code> — a
root-level copy of the graded turn — is deliberately not matched, so it cannot double-count. A dir that
has not been migrated is counted as <code>skippedLegacy</code> and reported with the remedy, never dropped
silently.</p>
</li>
<li>
<p><strong>An ambient <code>GIT_DIR</code> silently computed the wrong skill file set.</strong> Git hooks export <code>GIT_DIR</code> (and
<code>GIT_INDEX_FILE</code>) into every child process, and with <code>GIT_DIR</code> set but no <code>GIT_WORK_TREE</code> git stops
inferring the work tree from <code>cwd</code> and treats <code>cwd</code> as the repo root. <code>gitTrackedSet</code>&rsquo;s
<code>rev-parse --show-toplevel</code> probe therefore still succeeded — so the not-a-repo raw-walk fallback never
fired — while <code>git ls-files -- .</code> returned the <strong>entire repo index as root-relative paths</strong> instead of
the directory-relative ones. Measured on this repo: 2 tracked files became 625 wrong ones. That set
feeds both <code>skillHash</code> and the mount-copy filter, so any run invoked from a git hook (or from CI that
exports <code>GIT_DIR</code>) got a wrong hash and a mount filter pointed at paths that do not exist under the
skill dir. The visible symptom was the repo&rsquo;s own pre-commit hook reporting committed example cassettes
as <code>[stale] skill files changed since record</code> on every parity sync. <code>skillCommit</code> had the same defect:
<code>git -C &lt;dir&gt;</code> is overridden by an ambient <code>GIT_DIR</code>, so every skill dir resolved to that foreign repo&rsquo;s
HEAD — recording a foreign commit as the skill&rsquo;s provenance and masking dirs that are genuinely in
different repos. Both call sites now spawn git with <code>GIT_DIR</code> / <code>GIT_WORK_TREE</code> / <code>GIT_INDEX_FILE</code>
stripped, via one shared helper so they cannot drift. <code>run-index</code>&rsquo;s <code>gitInfo</code> and <code>doctor</code>&rsquo;s worktree
probe deliberately keep inheriting — they are asking about the <em>ambient</em> repo.</p>
</li>
<li>
<p><strong><code>stats --reindex</code> destroyed multi-turn history.</strong> Every <code>--resume</code> turn — and <code>critique</code>&rsquo;s task +
reflection pair — writes to one <code>outDir</code>, so keying by directory collapsed N completions into one,
silently changing run counts, pass rates and costs.</p>
</li>
<li>
<p><strong>Host-loop sidecar failures never reached the verdict.</strong> They were appended straight to <code>events.jsonl</code>,
which no live drive re-reads, so a dying sidecar left the run green; a signal-only termination (OOM,
<code>SIGKILL</code>) was recorded nowhere at all.</p>
</li>
<li>
<p><strong><code>result.json</code> was written non-atomically</strong> at all three producers, so an interrupted write could leave
the canonical record truncated.</p>
</li>
<li>
<p><strong>Corrupt index rows were blind-cast</strong>, letting one malformed row crash <code>stats</code> or fabricate a
pass/cost value; <code>reindex</code> also followed symlinks out of the runs root.</p>
</li>
<li>
<p><strong><code>scaffold</code> turned unavailable artifact evidence into &ldquo;no artifacts&rdquo;</strong>, permanently encoding a false
&ldquo;this run produced nothing&rdquo; claim into a generated scenario.</p>
</li>
<li>
<p><strong><code>critique</code> treated a vanished turn-1 evidence file as genuinely empty evidence</strong> rather than an
integrity failure. A stream that was legitimately zero bytes at capture is still reported clean.</p>
</li>
<li>
<p><strong><code>critique</code>&rsquo;s exit-code table omitted <code>1</code>.</strong> Exit <code>1</code> is reachable on operator interrupt
(SIGINT/SIGTERM); a sweep wrapper treating it as impossible misreads a cancelled run as a crash.</p>
</li>
<li>
<p>Documented that after critique&rsquo;s resume, <code>result.json</code> is the <strong>reflection</strong> turn&rsquo;s result — the graded
turn is archived as <code>result.turn-1.json</code>. Reading the wrong one yields a valid-looking wrong number.</p>
</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>release: 1.7.0 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/61">https://github.com/yaniv-golan/cowork-harness/pull/61</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v1.6.0...v1.7.0">https://github.com/yaniv-golan/cowork-harness/compare/v1.6.0...v1.7.0</a></p>
]]></content:encoded></item><item><title>AGENTS.md Lint (Schliff)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/agents.md-lint-schliff/</link><pubDate>Thu, 23 Jul 2026 06:07:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/agents.md-lint-schliff/</guid><description>Version updated for https://github.com/Zandereins/schliff to version v8.7.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the scoring of AGENTS.md files using the Schliff tool. It ensures that AI instruction files remain consistent across different systems by providing deterministic quality scores based on a versioned rubric. The action helps detect and prevent issues in instruction files that could degrade LLMs, ensuring better reliability in AI development workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Zandereins/schliff">https://github.com/Zandereins/schliff</a></strong> to version <strong>v8.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agents-md-lint-schliff">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the scoring of <code>AGENTS.md</code> files using the Schliff tool. It ensures that AI instruction files remain consistent across different systems by providing deterministic quality scores based on a versioned rubric. The action helps detect and prevent issues in instruction files that could degrade LLMs, ensuring better reliability in AI development workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Pre-launch audit batch A + C.</p>
<h2 id="changed">Changed</h2>
<ul>
<li><strong><code>structure</code> is now reproducible — a pure function of the file&rsquo;s bytes (#10).</strong>
It previously depended on the file&rsquo;s on-disk neighbourhood (a sibling
<code>references/</code> directory + whether declared references resolved on disk), so the
same file scored ~15 points higher in its real directory than in isolation — the
public badge disagreed with the author&rsquo;s own CLI, worst on AGENTS.md. Now
progressive disclosure is credited from content disclosure-links (not an on-disk
dir), references from the declaration (with a traversal/stuffing guard), and
dangling detection is a non-scoring lint issue emitted only from a provable
location. Also corrects a long-standing under-crediting of AGENTS.md/CLAUDE.md/
<code>.cursorrules</code> (always temp-scored). Scores for files that link detail move
upward and now match in-repo and in isolation. Golden rebaselined with
documented values; field-validated over 115 real skills; a new
isolation-equivalence test pins location-independence.</li>
</ul>
<h2 id="fixed">Fixed</h2>
<ul>
<li>The terminal no longer silently drops score warnings — the calibrated-weights
&ldquo;not comparable&rdquo; notice and &ldquo;no weighted dimensions&rdquo; warning now render (#22).</li>
<li><code>compare</code> no longer leaks the <code>-1</code> sentinel for unmeasured dimensions (#21).</li>
</ul>
<p><strong>Note for CI users:</strong> this is a scoring-model change; scores shift upward for
files that link detail. Pin <code>schliff-version: '8.7.0'</code> if you gate on an exact number.</p>
]]></content:encoded></item><item><title>Sparda Security Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/sparda-security-gate/</link><pubDate>Thu, 23 Jul 2026 06:06:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/23/sparda-security-gate/</guid><description>Version updated for https://github.com/zyx77550/sparda to version v0.67.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SPARDA is a tool that compiles and statically verifies the behavior of AI-written backend services to ensure their correctness before deployment. It provides deterministic proof that routes, guards, invariant checks, and transaction boundaries do not break, without requiring API keys or cloud accounts. The action automates the process of proving the safety of AI-written backends locally and can generate proofs, badges, and coverage reports.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zyx77550/sparda">https://github.com/zyx77550/sparda</a></strong> to version <strong>v0.67.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sparda-security-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SPARDA is a tool that compiles and statically verifies the behavior of AI-written backend services to ensure their correctness before deployment. It provides deterministic proof that routes, guards, invariant checks, and transaction boundaries do not break, without requiring API keys or cloud accounts. The action automates the process of proving the safety of AI-written backends locally and can generate proofs, badges, and coverage reports.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix(action): pass GitHub Marketplace validations (eca7328)</li>
<li>chore(brand): align copy for adoption and prestige (#28) (dea7e2b)</li>
<li>Merge pull request #27 from zyx77550/brand/residual-labs-identity (54339ee)</li>
<li>brand: Residual Labs identity — add llms.txt + lab footer with contact (f4c8acc)</li>
<li>chore(release): 0.66.0 — sparda gate + apocalypse refinements (36d87b7)</li>
<li>style: prettier tests/mutation/run.mjs (1e0167c)</li>
<li>chore(release): 0.65.0 - apocalypse &amp; docs consolidation (52af039)</li>
<li>style: run prettier on init.js (398b620)</li>
<li>chore(release): 0.64.0 - monorepo power jump (8db8a5d)</li>
<li>chore: bump inner package version to 0.63.0 in server.json (a1dd8a1)</li>
</ul>
]]></content:encoded></item><item><title>FHIR Validator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/fhir-validator/</link><pubDate>Wed, 22 Jul 2026 06:32:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/fhir-validator/</guid><description>Version updated for https://github.com/medvertical/records-fhir-validator to version validator-v0.4.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a TypeScript-based FHIR validator designed to automate validation of FHIR JSON resources in CI pipelines, GitHub Actions, or standalone Node.js environments. It supports multiple FHIR versions (R4, R4B, R5, R6) and provides features such as validating against StructureDefinitions, FHIRPath expressions, terminology bindings, references, slicing, extensions, Bundle rules, metadata, and custom rules without requiring a JVM or database. The action is available for both GitHub Actions pinning using floating tags and exact version pins, ensuring reproducibility and auditability.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/medvertical/records-fhir-validator">https://github.com/medvertical/records-fhir-validator</a></strong> to version <strong>validator-v0.4.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/fhir-validator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a TypeScript-based FHIR validator designed to automate validation of FHIR JSON resources in CI pipelines, GitHub Actions, or standalone Node.js environments. It supports multiple FHIR versions (R4, R4B, R5, R6) and provides features such as validating against StructureDefinitions, FHIRPath expressions, terminology bindings, references, slicing, extensions, Bundle rules, metadata, and custom rules without requiring a JVM or database. The action is available for both GitHub Actions pinning using floating tags and exact version pins, ensuring reproducibility and auditability.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>npm tarball release for <code>@records-fhir/validator@0.4.4</code>. Synced from medvertical/records monorepo.</p>
<h2 id="install">Install</h2>
<pre tabindex="0"><code>npm install @records-fhir/validator@0.4.4
</code></pre><h2 id="whats-new-in-044">What&rsquo;s new in 0.4.4</h2>
<p>Patch release hardening production metadata validation and terminology
expansion without changing the public validation API.</p>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Replaced runtime directory imports with explicit ESM entry files so packaged
metadata validation works in the production Node.js container.</li>
<li>Propagated metadata-engine exceptions to the host instead of representing
runtime failures as FHIR resource findings.</li>
<li>Traversed hierarchical terminology-server <code>$expand</code> results recursively, so
nested valid codes such as Questionnaire item types are recognized.</li>
<li>Accepted malformed primitive <code>meta</code> input as a normal structural metadata
finding instead of allowing completeness checks to throw.</li>
</ul>
<h3 id="verification">Verification</h3>
<ul>
<li>HL7 JSON parity: 536/536 (100.0%), 0 failed, 0 skipped, 0 errors.</li>
<li>MII 2026 reference parity: 231/231 measured (100.0%), 22 classified skips,
128/128 profiles prewarmed, and 0 FHIRPath constraint skips.</li>
<li>Verified the packed public package by executing real metadata validation and
rejecting any internal-error or directory-import finding.</li>
</ul>
<h2 id="matched-npm-tarballs">Matched npm tarballs</h2>
<ul>
<li><code>@records-fhir/validator@0.4.4</code> — also tagged <code>validator-v0.4.4</code></li>
<li><code>@records-fhir/validation-types@0.1.5</code></li>
</ul>
<p>The matching GitHub Action release (if any) is published separately under tag <code>v0.4.4</code> and is not auto-synced; this release covers the npm package only.</p>
]]></content:encoded></item><item><title>attest-vm-image</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/attest-vm-image/</link><pubDate>Wed, 22 Jul 2026 06:31:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/attest-vm-image/</guid><description>Version updated for https://github.com/meigma/attest-vm-image to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The attest-vm-image GitHub Action inspects a finished QCOW2 VM disk image to produce auditable evidence about its contents and optionally signs that evidence. It helps verify the integrity of an artifact, ensures compliance with security policies, and provides detailed reports on vulnerabilities and contamination during the build process. The action is designed to be run after an image has been built and does not modify the input image.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/meigma/attest-vm-image">https://github.com/meigma/attest-vm-image</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/attest-vm-image">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The attest-vm-image GitHub Action inspects a finished QCOW2 VM disk image to produce auditable evidence about its contents and optionally signs that evidence. It helps verify the integrity of an artifact, ensures compliance with security policies, and provides detailed reports on vulnerabilities and contamination during the build process. The action is designed to be run after an image has been built and does not modify the input image.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="110-2026-07-22"><a href="https://github.com/meigma/attest-vm-image/compare/v1.0.0...v1.1.0">1.1.0</a> (2026-07-22)</h2>
<h3 id="features">Features</h3>
<ul>
<li>add evidence handoff manifest (<a href="https://github.com/meigma/attest-vm-image/issues/20">#20</a>) (<a href="https://github.com/meigma/attest-vm-image/commit/f6752e7c746309d31593d33e88d108ccb43a4200">f6752e7</a>)</li>
</ul>
]]></content:encoded></item><item><title>Microsoft Store App Publisher</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/microsoft-store-app-publisher/</link><pubDate>Wed, 22 Jul 2026 06:30:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/microsoft-store-app-publisher/</guid><description>Version updated for https://github.com/microsoft/microsoft-store-apppublisher to version v1.4.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 53 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/microsoft/microsoft-store-apppublisher">https://github.com/microsoft/microsoft-store-apppublisher</a></strong> to version <strong>v1.4</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>53</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/microsoft-store-app-publisher">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>agent-bom Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/agent-bom-scan/</link><pubDate>Wed, 22 Jul 2026 06:30:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/agent-bom-scan/</guid><description>Version updated for https://github.com/msaad00/agent-bom to version v0.97.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the scanning and discovery of security vulnerabilities in AI, MCP, and cloud infrastructure. It can scan from CLI, CI, Docker, or a self-hosted control plane via cloud connect or scheduled estate scans. The action generates centralized evidence and enforces runtime MCP/tool calls.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/msaad00/agent-bom">https://github.com/msaad00/agent-bom</a></strong> to version <strong>v0.97.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-bom-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action automates the scanning and discovery of security vulnerabilities in AI, MCP, and cloud infrastructure. It can scan from CLI, CI, Docker, or a self-hosted control plane via cloud connect or scheduled estate scans. The action generates centralized evidence and enforces runtime MCP/tool calls.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): enforce version alignment across all deploy surfaces + fix 0.97.0 drift by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4332">https://github.com/msaad00/agent-bom/pull/4332</a></li>
<li>docs(audits): persona progress audit v0.93.5 → v0.97.1 by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4333">https://github.com/msaad00/agent-bom/pull/4333</a></li>
<li>fix(demo)+feat(attest,graph): harden demo path, MCP attest CLI, store-backed auto-enable by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4336">https://github.com/msaad00/agent-bom/pull/4336</a></li>
<li>chore(deps): batch UI + actions dependency bumps by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4345">https://github.com/msaad00/agent-bom/pull/4345</a></li>
<li>fix(deploy)+feat(auth): self-host first-run bootstrap, anonymous demo, and guided OIDC/SSO setup by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4335">https://github.com/msaad00/agent-bom/pull/4335</a></li>
<li>fix(helm): make control-plane self-host come up cleanly on first install by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4337">https://github.com/msaad00/agent-bom/pull/4337</a></li>
<li>fix(mcp,audit): align tool-count honesty and rich audit exit codes by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4346">https://github.com/msaad00/agent-bom/pull/4346</a></li>
<li>chore(release): prepare 0.97.2 by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4347">https://github.com/msaad00/agent-bom/pull/4347</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/msaad00/agent-bom/compare/v0.97.1...v0.97.2">https://github.com/msaad00/agent-bom/compare/v0.97.1...v0.97.2</a></p>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/go-proxy-cache-updater/</link><pubDate>Wed, 22 Jul 2026 06:28:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.29.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of updating a proxy cache with new Go module releases based on tag creations. It supports both standard and submodule version tags and can be configured to use custom proxies or import paths, allowing users to integrate it into their workflows for continuous integration of Go modules.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.29</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of updating a proxy cache with new Go module releases based on tag creations. It supports both standard and submodule version tags and can be configured to use custom proxies or import paths, allowing users to integrate it into their workflows for continuous integration of Go modules.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1129-2026-07-21"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.28...v1.1.29">1.1.29</a> (2026-07-21)</h2>
]]></content:encoded></item><item><title>Shoutrrr GitHub Notifications Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/shoutrrr-github-notifications-action/</link><pubDate>Wed, 22 Jul 2026 06:27:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/shoutrrr-github-notifications-action/</guid><description>Version updated for https://github.com/nicholas-fedor/shoutrrr-action to version v1.0.21.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of sending notifications using Shoutrrr from your GitHub Actions workflows. It allows you to easily integrate service notifications like Slack, Discord, or Telegram into your CI/CD pipelines without manually handling them. The action supports custom URLs for various services and provides an optional title parameter to customize notifications.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/shoutrrr-action">https://github.com/nicholas-fedor/shoutrrr-action</a></strong> to version <strong>v1.0.21</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/shoutrrr-github-notifications-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of sending notifications using Shoutrrr from your GitHub Actions workflows. It allows you to easily integrate service notifications like Slack, Discord, or Telegram into your CI/CD pipelines without manually handling them. The action supports custom URLs for various services and provides an optional <code>title</code> parameter to customize notifications.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="2026-07-21">(2026-07-21)</h2>
<h2 id="1021-2026-07-21"><small>1.0.21 (2026-07-21)</small></h2>
<ul>
<li>chore(deps): update docker.io/nickfedor/shoutrrr docker tag to v0.16.2 (#530) (<a href="https://github.com/nicholas-fedor/shoutrrr-action/commit/427a455">427a455</a>), closes <a href="https://github.com/nicholas-fedor/shoutrrr-action/issues/530">#530</a></li>
<li>chore(deps): update step-security/harden-runner action to v2.20.0 (#529) (<a href="https://github.com/nicholas-fedor/shoutrrr-action/commit/65862a9">65862a9</a>), closes <a href="https://github.com/nicholas-fedor/shoutrrr-action/issues/529">#529</a></li>
</ul>
]]></content:encoded></item><item><title>Cerberus AI-Agent Runtime Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/cerberus-ai-agent-runtime-check/</link><pubDate>Wed, 22 Jul 2026 06:27:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/cerberus-ai-agent-runtime-check/</guid><description>Version updated for https://github.com/Odingard/cerberus-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks Cerberus’s allow/block behavior by running two bundled, maintained fixtures through the Cerberus runtime security layer. It provides a PASS/FLAG/BLOCK verdict and an uploaded evidence artifact, ensuring CI runs without disruptions. The action is report-only by default but can be configured to fail if protection does not behave as expected.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Odingard/cerberus-action">https://github.com/Odingard/cerberus-action</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cerberus-ai-agent-runtime-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks Cerberus&rsquo;s allow/block behavior by running two bundled, maintained fixtures through the Cerberus runtime security layer. It provides a PASS/FLAG/BLOCK verdict and an uploaded evidence artifact, ensuring CI runs without disruptions. The action is report-only by default but can be configured to fail if protection does not behave as expected.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v101--positioning--hardening">v1.0.1 — positioning + hardening</h2>
<p>A correctness and honesty pass before broad promotion. No behavior change to the check itself.</p>
<ul>
<li><strong>Reframed positioning.</strong> This Action runs a <strong>reproducible Cerberus allow/block self-check</strong> against two bundled, maintained fixtures (a benign workflow that should run, a Lethal-Trifecta workflow that should be blocked). It does <strong>not</strong> analyze the caller&rsquo;s own application workflows — the README and summary now say so plainly.</li>
<li><strong>Pinned <code>core-version</code> default to <code>3.1.0</code></strong> (was <code>latest</code>) for reproducible runs.</li>
<li><strong>Default runtime is now Node 24</strong>, and the bundled official actions were bumped to current majors (<code>checkout@v5</code>, <code>setup-node@v5</code>, <code>upload-artifact@v7</code>) — clears the Node 20 deprecation warnings. Self-test now runs warning-free.</li>
<li><strong>README now links the public <code>Odingard/cerberus-core</code></strong> instead of the private core repo.</li>
<li>Refreshed Marketplace banner + listing screenshots to match the new wording.</li>
</ul>
<p>Usage is unchanged:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Odingard/cerberus-action@v1</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>MergeRisk</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/mergerisk/</link><pubDate>Wed, 22 Jul 2026 06:26:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/mergerisk/</guid><description>Version updated for https://github.com/One-Code-LLC/mergerisk-action to version v0.1.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary MergeRisk is a GitHub Action that provides a concise pull-request merge-risk report based on both deterministic scoring and optional AI insights. It helps developers identify potential risks associated with pull requests, especially those involving critical and medium path changes, without relying solely on AI. The action can be configured to fail the build if a certain risk level is reached, making it useful for maintaining code quality and security.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/One-Code-LLC/mergerisk-action">https://github.com/One-Code-LLC/mergerisk-action</a></strong> to version <strong>v0.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mergerisk">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>MergeRisk is a GitHub Action that provides a concise pull-request merge-risk report based on both deterministic scoring and optional AI insights. It helps developers identify potential risks associated with pull requests, especially those involving critical and medium path changes, without relying solely on AI. The action can be configured to fail the build if a certain risk level is reached, making it useful for maintaining code quality and security.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>MergeRisk v0.1.2 is the first stable release prepared for the GitHub Actions
Marketplace.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Deterministic pull-request merge-risk scoring that works without an AI
provider.</li>
<li>Optional OpenAI, Anthropic, and OpenAI-compatible AI summaries that cannot
lower the deterministic risk level.</li>
<li>Sticky pull-request comments, configurable failure thresholds, custom risk
profiles, and deterministic or agent-assisted test-impact review.</li>
<li>A committed <code>dist/</code> bundle, release preflight checks, and public contributor,
support, and security documentation.</li>
</ul>
<h2 id="upgrade-notes">Upgrade notes</h2>
<p>Use the stable major tag once it is created:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">One-Code-LLC/mergerisk-action@v0</span>
</span></span></code></pre></div><p>Pin to <code>v0.1.2</code> when a specific minor release is required. See the README for
the required permissions and the security guidance for fork pull requests.</p>
<h2 id="full-changelog">Full changelog</h2>
<p><a href="https://github.com/One-Code-LLC/mergerisk-action/compare/v0.1.1...v0.1.2">https://github.com/One-Code-LLC/mergerisk-action/compare/v0.1.1...v0.1.2</a></p>
]]></content:encoded></item><item><title>Postman API Onboarding</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/postman-api-onboarding/</link><pubDate>Wed, 22 Jul 2026 06:24:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/postman-api-onboarding/</guid><description>Version updated for https://github.com/postman-cs/postman-api-onboarding-action to version v2.1.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman API Onboarding action automates the setup and execution of a comprehensive suite of tasks to onboard an API repository, including workspace creation, OpenAPI upload, collection generation, repository artifact sync, and test execution. It provides a single entry point for handling the onboarding path, ensuring executable, standards-grounded tests are left behind in addition to assets.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-api-onboarding-action">https://github.com/postman-cs/postman-api-onboarding-action</a></strong> to version <strong>v2.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-api-onboarding">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman API Onboarding action automates the setup and execution of a comprehensive suite of tasks to onboard an API repository, including workspace creation, OpenAPI upload, collection generation, repository artifact sync, and test execution. It provides a single entry point for handling the onboarding path, ensuring executable, standards-grounded tests are left behind in addition to assets.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(tests): normalize CRLF and skip Windows-incompatible tests for CI by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/76">https://github.com/postman-cs/postman-api-onboarding-action/pull/76</a></li>
<li>chore: prepare composite v2.1.2 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/77">https://github.com/postman-cs/postman-api-onboarding-action/pull/77</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-api-onboarding-action/compare/v2...v2.1.2">https://github.com/postman-cs/postman-api-onboarding-action/compare/v2...v2.1.2</a></p>
]]></content:encoded></item><item><title>Postman Onboarding AWS Spec Discovery</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/postman-onboarding-aws-spec-discovery/</link><pubDate>Wed, 22 Jul 2026 06:23:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/postman-onboarding-aws-spec-discovery/</guid><description>Version updated for https://github.com/postman-cs/postman-aws-spec-discovery-action to version v3.1.3.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the discovery and export of API specifications from AWS services using your existing credentials. It handles AWS region setup, automatically detects providers based on IAM permissions, and resolves specs before calling AWS. The action is part of a suite to streamline Postman onboarding processes for AWS services, allowing users to integrate with their Postman environments efficiently without the need for additional GitHub tokens.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-aws-spec-discovery-action">https://github.com/postman-cs/postman-aws-spec-discovery-action</a></strong> to version <strong>v3.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-aws-spec-discovery">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the discovery and export of API specifications from AWS services using your existing credentials. It handles AWS region setup, automatically detects providers based on IAM permissions, and resolves specs before calling AWS. The action is part of a suite to streamline Postman onboarding processes for AWS services, allowing users to integrate with their Postman environments efficiently without the need for additional GitHub tokens.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: update dependencies for v3.1.3 by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/46">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/46</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/compare/v3...v3.1.3">https://github.com/postman-cs/postman-aws-spec-discovery-action/compare/v3...v3.1.3</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Workspace Bootstrap</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/postman-onboarding-workspace-bootstrap/</link><pubDate>Wed, 22 Jul 2026 06:22:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/postman-onboarding-workspace-bootstrap/</guid><description>Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.10.5.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the creation of a Postman workspace from an OpenAPI specification. It generates baseline, smoke, and contract collections that include executable test cases based on the spec, covering various protocols and standards like RFCs, gRPC, SOAP, GraphQL, AsyncAPI, and MCP. The action is part of a larger suite for automating API testing and onboarding in Postman.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-bootstrap-action">https://github.com/postman-cs/postman-bootstrap-action</a></strong> to version <strong>v2.10.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-workspace-bootstrap">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the creation of a Postman workspace from an OpenAPI specification. It generates baseline, smoke, and contract collections that include executable test cases based on the spec, covering various protocols and standards like RFCs, gRPC, SOAP, GraphQL, AsyncAPI, and MCP. The action is part of a larger suite for automating API testing and onboarding in Postman.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: rebind release receipt after squash merge by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/104">https://github.com/postman-cs/postman-bootstrap-action/pull/104</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-bootstrap-action/compare/v2.10.4...v2.10.5">https://github.com/postman-cs/postman-bootstrap-action/compare/v2.10.4...v2.10.5</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Insights Linking</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/postman-onboarding-insights-linking/</link><pubDate>Wed, 22 Jul 2026 06:21:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/postman-onboarding-insights-linking/</guid><description>Version updated for https://github.com/postman-cs/postman-insights-onboarding-action to version v2.1.4.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the linking of services discovered by the Postman Insights DaemonSet agent to a Postman workspace and git repository. It solves the problem of automatically associating new insights with existing workspaces, environments, and service accounts after deployment. The action provides capabilities to link a discovered service to a workspace, environment, and retrieve credentials for post-processing steps like acknowledging the discovery and binding applications.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-insights-onboarding-action">https://github.com/postman-cs/postman-insights-onboarding-action</a></strong> to version <strong>v2.1.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-insights-linking">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the linking of services discovered by the Postman Insights DaemonSet agent to a Postman workspace and git repository. It solves the problem of automatically associating new insights with existing workspaces, environments, and service accounts after deployment. The action provides capabilities to link a discovered service to a workspace, environment, and retrieve credentials for post-processing steps like acknowledging the discovery and binding applications.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: update dependencies for v2.1.4 by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/51">https://github.com/postman-cs/postman-insights-onboarding-action/pull/51</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-insights-onboarding-action/compare/v2...v2.1.4">https://github.com/postman-cs/postman-insights-onboarding-action/compare/v2...v2.1.4</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Repo Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/postman-onboarding-repo-sync/</link><pubDate>Wed, 22 Jul 2026 06:20:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/postman-onboarding-repo-sync/</guid><description>Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.1.10.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action Postman Onboarding: Repo Sync automates the process of exporting Postman collections and environments into a repository. It also sets up CI, mock servers, and monitors around these assets. The action requires a Postman API key or service-token to generate tokens and workspace IDs from inputs or .postman/resources.yaml. The example usage shows how to set up a full sync with workspace assets using the action.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-repo-sync-action">https://github.com/postman-cs/postman-repo-sync-action</a></strong> to version <strong>v2.1.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-repo-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>Postman Onboarding: Repo Sync</code> automates the process of exporting Postman collections and environments into a repository. It also sets up CI, mock servers, and monitors around these assets. The action requires a Postman API key or service-token to generate tokens and workspace IDs from inputs or <code>.postman/resources.yaml</code>. The example usage shows how to set up a full sync with workspace assets using the action.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(tests): increase npm pack timeout for Windows CI by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/89">https://github.com/postman-cs/postman-repo-sync-action/pull/89</a></li>
<li>feat: publish self-contained SEA binary by @mmorales-post in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/87">https://github.com/postman-cs/postman-repo-sync-action/pull/87</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@mmorales-post made their first contribution in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/87">https://github.com/postman-cs/postman-repo-sync-action/pull/87</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v2...v2.1.10">https://github.com/postman-cs/postman-repo-sync-action/compare/v2...v2.1.10</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Service Token</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/postman-onboarding-service-token/</link><pubDate>Wed, 22 Jul 2026 06:19:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/postman-onboarding-service-token/</guid><description>Version updated for https://github.com/postman-cs/postman-resolve-service-token-action to version v2.0.4.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action automates the process of minting a fresh service-account access token and team ID for use in Postman API Onboarding workflows. It ensures that the credentials are up-to-date and ready to be used by downstream actions, handling both quick start and scheduled repo-secret refresh scenarios based on the specified region.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-resolve-service-token-action">https://github.com/postman-cs/postman-resolve-service-token-action</a></strong> to version <strong>v2.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-service-token">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action automates the process of minting a fresh service-account access token and team ID for use in Postman API Onboarding workflows. It ensures that the credentials are up-to-date and ready to be used by downstream actions, handling both quick start and scheduled repo-secret refresh scenarios based on the specified region.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: update dependencies for v2.0.3 by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/34">https://github.com/postman-cs/postman-resolve-service-token-action/pull/34</a></li>
<li>chore: prepare v2.0.4 release by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/35">https://github.com/postman-cs/postman-resolve-service-token-action/pull/35</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-resolve-service-token-action/compare/v2...v2.0.4">https://github.com/postman-cs/postman-resolve-service-token-action/compare/v2...v2.0.4</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Smoke Flow</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/postman-onboarding-smoke-flow/</link><pubDate>Wed, 22 Jul 2026 06:18:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/postman-onboarding-smoke-flow/</guid><description>Version updated for https://github.com/postman-cs/postman-smoke-flow-action to version v2.1.6.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: This GitHub Action reshapes a Postman Smoke collection to match a curated flow.yaml file. It automates the process of integrating smoke tests into a project’s API onboarding workflow, providing optional runtime authentication injection for OAuth2 and API keys through the Postman gateway. The action is part of the Postman API Onboarding suite and requires credentials such as the Postman API key and access token to perform its operations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-smoke-flow-action">https://github.com/postman-cs/postman-smoke-flow-action</a></strong> to version <strong>v2.1.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-smoke-flow">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong>
This GitHub Action reshapes a Postman Smoke collection to match a curated <code>flow.yaml</code> file. It automates the process of integrating smoke tests into a project&rsquo;s API onboarding workflow, providing optional runtime authentication injection for OAuth2 and API keys through the Postman gateway. The action is part of the Postman API Onboarding suite and requires credentials such as the Postman API key and access token to perform its operations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: publish self-contained SEA binary by @mmorales-post in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/48">https://github.com/postman-cs/postman-smoke-flow-action/pull/48</a></li>
<li>chore: update dependencies for v2.1.6 by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/49">https://github.com/postman-cs/postman-smoke-flow-action/pull/49</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@mmorales-post made their first contribution in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/48">https://github.com/postman-cs/postman-smoke-flow-action/pull/48</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-smoke-flow-action/compare/v2...v2.1.6">https://github.com/postman-cs/postman-smoke-flow-action/compare/v2...v2.1.6</a></p>
]]></content:encoded></item><item><title>Rafter Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/rafter-security-scan/</link><pubDate>Wed, 22 Jul 2026 06:17:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/rafter-security-scan/</guid><description>Version updated for https://github.com/Raftersecurity/rafter-cli to version v0.9.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of scanning codebases using the Rafter security tool. It helps identify potential security vulnerabilities and ensures that code is compliant with security standards. The action supports various programming languages and can be integrated into CI/CD pipelines to enhance the overall security posture of applications.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Raftersecurity/rafter-cli">https://github.com/Raftersecurity/rafter-cli</a></strong> to version <strong>v0.9.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rafter-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of scanning codebases using the Rafter security tool. It helps identify potential security vulnerabilities and ensures that code is compliant with security standards. The action supports various programming languages and can be integrated into CI/CD pipelines to enhance the overall security posture of applications.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>Node.js:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npm install -g @rafter-security/cli@0.9.1
</span></span></code></pre></div><p><strong>Python:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rafter-cli<span style="color:#f92672">==</span>0.9.1
</span></span></code></pre></div><p><strong>OpenClaw (via ClawHub):</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>clawhub skill install rafter-security
</span></span></code></pre></div><p>See <a href="https://github.com/raftersecurity/rafter-cli/blob/main/CHANGELOG.md">CHANGELOG.md</a> for details.</p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: add mailchimp api key scanning pattern and tests by @Minh-Nguyen-2k7 in <a href="https://github.com/Raftersecurity/rafter-cli/pull/190">https://github.com/Raftersecurity/rafter-cli/pull/190</a></li>
<li>fix(audit): redact secret-named env-assignment prefixes before logging (ob-y5ep) by @Rome-1 in <a href="https://github.com/Raftersecurity/rafter-cli/pull/191">https://github.com/Raftersecurity/rafter-cli/pull/191</a></li>
<li>test(scan): Mailchimp negative-case tests + whitespace tidy (follow-up to #190) by @Rome-1 in <a href="https://github.com/Raftersecurity/rafter-cli/pull/194">https://github.com/Raftersecurity/rafter-cli/pull/194</a></li>
<li>docs(skills): scope rafter security skills by surface, not task label by @Rome-1 in <a href="https://github.com/Raftersecurity/rafter-cli/pull/195">https://github.com/Raftersecurity/rafter-cli/pull/195</a></li>
<li>fix(agent): scope injected instruction block by surface, not task label by @Rome-1 in <a href="https://github.com/Raftersecurity/rafter-cli/pull/196">https://github.com/Raftersecurity/rafter-cli/pull/196</a></li>
<li>fix(agent): correct Codex hooks dry-run plan string (PostToolUse parity with #196) by @Rome-1 in <a href="https://github.com/Raftersecurity/rafter-cli/pull/197">https://github.com/Raftersecurity/rafter-cli/pull/197</a></li>
<li>fix(deps): pin cryptography &gt;=46.0.7 (GHSA-537c-gmf6-5ccf) + resync stale poetry.lock by @Rome-1 in <a href="https://github.com/Raftersecurity/rafter-cli/pull/198">https://github.com/Raftersecurity/rafter-cli/pull/198</a></li>
<li>fix(skills): restore rafter SKILL.md line budget broken by #195 by @Rome-1 in <a href="https://github.com/Raftersecurity/rafter-cli/pull/199">https://github.com/Raftersecurity/rafter-cli/pull/199</a></li>
<li>fix(hook): argument-aware command matching so quoted prose isn&rsquo;t run as a command by @Rome-1 in <a href="https://github.com/Raftersecurity/rafter-cli/pull/200">https://github.com/Raftersecurity/rafter-cli/pull/200</a></li>
<li>feat(scan): add SendGrid API key secret pattern (#24) by @perez-eduardo in <a href="https://github.com/Raftersecurity/rafter-cli/pull/201">https://github.com/Raftersecurity/rafter-cli/pull/201</a></li>
<li>Add npm script by @Minh-Nguyen-2k7 in <a href="https://github.com/Raftersecurity/rafter-cli/pull/202">https://github.com/Raftersecurity/rafter-cli/pull/202</a></li>
<li>chore: post-merge tidy for #201 + #202 by @Rome-1 in <a href="https://github.com/Raftersecurity/rafter-cli/pull/203">https://github.com/Raftersecurity/rafter-cli/pull/203</a></li>
<li>feat(scan): opt-in approval gate for paid Plus scans (sable-9ddf) by @Rome-1 in <a href="https://github.com/Raftersecurity/rafter-cli/pull/204">https://github.com/Raftersecurity/rafter-cli/pull/204</a></li>
<li>chore(release): bump to v0.9.1 by @Rome-1 in <a href="https://github.com/Raftersecurity/rafter-cli/pull/206">https://github.com/Raftersecurity/rafter-cli/pull/206</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@perez-eduardo made their first contribution in <a href="https://github.com/Raftersecurity/rafter-cli/pull/201">https://github.com/Raftersecurity/rafter-cli/pull/201</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Raftersecurity/rafter-cli/compare/v0.9.0...v0.9.1">https://github.com/Raftersecurity/rafter-cli/compare/v0.9.0...v0.9.1</a></p>
]]></content:encoded></item><item><title>Agent-Safe Commit Guardrails</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/agent-safe-commit-guardrails/</link><pubDate>Wed, 22 Jul 2026 06:14:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/agent-safe-commit-guardrails/</guid><description>Version updated for https://github.com/ravisingh11/agent-safe-engineering to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent-Safe Engineering is an automated tool designed to ensure AI-generated code changes are understandable and maintainable by humans. It uses human-readable standards, configurable guardrails, focused agent skills, and deterministic validators to enforce constraints on automated code modifications. This ensures that the changes are not only safe but also auditable and reversible.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ravisingh11/agent-safe-engineering">https://github.com/ravisingh11/agent-safe-engineering</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-safe-commit-guardrails">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Agent-Safe Engineering</strong> is an automated tool designed to ensure AI-generated code changes are understandable and maintainable by humans. It uses human-readable standards, configurable guardrails, focused agent skills, and deterministic validators to enforce constraints on automated code modifications. This ensures that the changes are not only safe but also auditable and reversible.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Rejects unknown or misspelled policy parameters with a published strict schema.</li>
<li>Explains the resolved policy and included or excluded readability inputs.</li>
<li>Generates revision-bound verification receipts for staged trees and Git ranges.</li>
<li>Adds a safe dependency-free installer and history-based threshold calibration.</li>
<li>Adds hardened repository CI and a reusable GitHub Action pinned at v0.2.0.</li>
<li>Self-validates the composite action and its receipt in GitHub Actions.</li>
</ul>
<h2 id="validation">Validation</h2>
<ul>
<li>27 commit-guardrail and calibration tests passed.</li>
<li>3 installer tests passed.</li>
<li>Repository policy copies, schemas, skills, version, and YAML validated.</li>
<li>Remote Validate workflow passed on release commit 5f5a973.</li>
</ul>
]]></content:encoded></item><item><title>AIBOM Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/aibom-scanner/</link><pubDate>Wed, 22 Jul 2026 06:12:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/aibom-scanner/</guid><description>Version updated for https://github.com/saasvista/aibom-scanner to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action scans codebases for AI SDK usage and generates an AI Bill of Materials (AIBOM) with compliance risk findings mapped to NIST AI RMF, ISO 42001, and EU AI Act. It detects AI SDKs in various programming languages, including Python, JS/TS, Go, Java, Rust, Ruby, Swift, C#,/.NET, and provides comprehensive coverage accounting and zero dependencies.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/saasvista/aibom-scanner">https://github.com/saasvista/aibom-scanner</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aibom-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action scans codebases for AI SDK usage and generates an AI Bill of Materials (AIBOM) with compliance risk findings mapped to NIST AI RMF, ISO 42001, and EU AI Act. It detects AI SDKs in various programming languages, including Python, JS/TS, Go, Java, Rust, Ruby, Swift, C#,/.NET, and provides comprehensive coverage accounting and zero dependencies.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="120-2026-07-21">1.2.0 (2026-07-21)</h2>
<p>.NET detection depth.</p>
<p>1.1.0 taught the scanner to open <code>.cs</code>/<code>.fs</code>/<code>.vb</code> files; it still could not
understand them. 28 of the existing patterns are import-shaped (<code>from x</code>,
<code>import x</code>, <code>require('x')</code>) and none matched a C# <code>using</code> directive, and no NuGet
manifest format was parsed. Measured on <code>OneIdentity/safeguard-mcp</code>: 1 detection
across 13,689 lines of C#, and zero dependencies, despite the repo declaring
<code>ModelContextProtocol 1.4.0</code> in its <code>.csproj</code> and using it in 12 source files.</p>
<h3 id="added">Added</h3>
<ul>
<li><strong>C# <code>using</code>-directive patterns.</strong> 9 new patterns covering <code>ModelContextProtocol</code>
(including the <code>[McpServerTool]</code> / <code>[McpServerResource]</code> attribute family),
<code>Microsoft.SemanticKernel</code>, <code>Azure.AI.OpenAI</code>, <code>OpenAI</code>, <code>Anthropic</code>,
<code>Amazon.BedrockRuntime</code>, <code>Google.Cloud.AIPlatform</code>, and <code>Mscc.GenerativeAI</code>.
Every pattern is anchored to line start and requires a PascalCase namespace, so
<code>using</code>-as-resource-disposal (<code>using var client = ...</code>, <code>using (var stream = ...)</code>)
never triggers a false positive.</li>
<li><strong>NuGet manifest parsing.</strong> <code>.csproj</code>, <code>.fsproj</code>, <code>.vbproj</code>, <code>Directory.Packages.props</code>,
and <code>packages.config</code> are now parsed for <code>PackageReference</code> / <code>PackageVersion</code> /
<code>package</code> elements, matched against a new NuGet-specific package map
(<code>NUGET_DEPENDENCY_MAP</code>) using longest dot-boundary prefix matching, so
<code>Azure.AI.OpenAI</code> resolves to <code>azure_openai</code> and never collides with <code>openai</code>.
Central package management&rsquo;s optional <code>Version</code> attribute is handled — a
missing version does not drop the dependency. Manifests are parsed with regex,
not an XML parser, and a malformed manifest degrades to no dependencies found
rather than raising.</li>
<li>These manifests are scannable but are not counted as source, exactly like
<code>package.json</code> today — <code>coverage_pct</code> is unaffected by their presence.</li>
</ul>
<h3 id="result-on-the-measured-fixture">Result on the measured fixture</h3>
<p><code>OneIdentity/safeguard-mcp</code>: 1 detection / 0 dependencies before this release,
23 detections / 2 dependencies after, with <code>mcp</code> correctly surfaced as a detected
provider and <code>ModelContextProtocol</code> surfaced as a dependency.</p>
]]></content:encoded></item><item><title>Reelier replay</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/reelier-replay/</link><pubDate>Wed, 22 Jul 2026 06:11:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/reelier-replay/</guid><description>Version updated for https://github.com/seldonframe/reelier to version v1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Reelier is an open-source tool designed to help agents record and reproduce their work deterministically, ensuring that every run produces identical results. It automates the process of creating a “skill” file from an agent’s existing session, capturing all steps in a receipt that can be replayed without any LLM or tokens, and diffing it against previous versions to catch drift. This helps ensure that long-run operators can verify the reliability and reproducibility of their agent workflows without relying solely on manual verification.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/seldonframe/reelier">https://github.com/seldonframe/reelier</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/reelier-replay">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Reelier is an open-source tool designed to help agents record and reproduce their work deterministically, ensuring that every run produces identical results. It automates the process of creating a &ldquo;skill&rdquo; file from an agent&rsquo;s existing session, capturing all steps in a receipt that can be replayed without any LLM or tokens, and diffing it against previous versions to catch drift. This helps ensure that long-run operators can verify the reliability and reproducibility of their agent workflows without relying solely on manual verification.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First Marketplace release of the <strong>Reelier replay</strong> action: replay a recorded Reelier skill in CI — deterministic, 0 LLM tokens at Level 0, exit 1 on drift — and post the run receipt as a job summary.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">seldonframe/reelier@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">skill</span>: <span style="color:#ae81ff">skills/nightly-check.skill.md</span>
</span></span></code></pre></div><p>The <code>v1</code> tag floats to the latest validated action. Full docs, the assertion grammar, and the published N=1000 benchmark: <a href="https://github.com/seldonframe/reelier">https://github.com/seldonframe/reelier</a></p>
]]></content:encoded></item><item><title>Argus PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/argus-pr-review/</link><pubDate>Wed, 22 Jul 2026 06:09:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/argus-pr-review/</guid><description>Version updated for https://github.com/sibinms/argus to version v1.2.21.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Argus is an AI-driven code review tool that leverages multiple specialized AI reviewers to identify potential issues in a pull request. It uses an evidence-based curator to verify findings and only dismisses them if they can be substantiated with code from the diff, ensuring high recall and manageable false positives. The tool supports various LLM providers and allows for customization through Markdown-based lenses.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sibinms/argus">https://github.com/sibinms/argus</a></strong> to version <strong>v1.2.21</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/argus-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Argus is an AI-driven code review tool that leverages multiple specialized AI reviewers to identify potential issues in a pull request. It uses an evidence-based curator to verify findings and only dismisses them if they can be substantiated with code from the diff, ensuring high recall and manageable false positives. The tool supports various LLM providers and allows for customization through Markdown-based lenses.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s changed</h2>
<p><strong>fix: lenses never report positive findings — only flag problems</strong></p>
<p>Argus was posting &ldquo;positive findings&rdquo; on PRs: confirming that security controls exist, that checks are correct, or that implementations are well-designed. These are observations, not problems.</p>
<ul>
<li>Added explicit rule to lens base prompt: never report that something is correctly implemented; only report when something is WRONG or MISSING</li>
<li>Added curator rule: drop_noise any finding that states a control is present, a check is correct, or an implementation is good — regardless of confidence</li>
<li>Added curator rule: pre-existing issues (lines not in the diff as <code>+</code> lines) are out of scope and must be drop_noised</li>
</ul>
]]></content:encoded></item><item><title>Huawei AppGallery Connect Publish</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/huawei-appgallery-connect-publish/</link><pubDate>Wed, 22 Jul 2026 06:08:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/huawei-appgallery-connect-publish/</guid><description>Version updated for https://github.com/Siyabulela/huawei-appgallery-publish-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Huawei AppGallery Connect Publish Action uploads an app package (APK, AAB, or RPK) to Huawei AppGallery Connect via the official Publish API, automatically updating file info and leaving final submission as a manual step in the AGC console. This action is designed to replace unmaintained community actions and uses direct Huawei Publish API calls without third-party dependencies. It requires setting up an API client with specific permissions and scopes to avoid common pitfalls.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Siyabulela/huawei-appgallery-publish-action">https://github.com/Siyabulela/huawei-appgallery-publish-action</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/huawei-appgallery-connect-publish">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Huawei AppGallery Connect Publish Action uploads an app package (APK, AAB, or RPK) to Huawei AppGallery Connect via the official Publish API, automatically updating file info and leaving final submission as a manual step in the AGC console. This action is designed to replace unmaintained community actions and uses direct Huawei Publish API calls without third-party dependencies. It requires setting up an API client with specific permissions and scopes to avoid common pitfalls.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial public release. Uploads an app package to Huawei AppGallery Connect via the Publish API v2 (token, upload-url, file upload, app-file-info). Does not submit for review — that stays a manual step in the AGC console.</p>
<p>See the README for the setup gotcha that took a while to track down: the API client must be created with Project set to N/A, not scoped to your app&rsquo;s project, or every call past the token step fails with a 403 and an empty response body.</p>
]]></content:encoded></item><item><title>Graceful Boundaries Conformance Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/graceful-boundaries-conformance-check/</link><pubDate>Wed, 22 Jul 2026 06:07:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/graceful-boundaries-conformance-check/</guid><description>Version updated for https://github.com/snapsynapse/graceful-boundaries to version v1.5.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Graceful Boundaries is a specification for how services communicate their operational limits to humans and autonomous agents. It addresses three gaps in existing standards, providing proactive discovery of limits before they are hit, structured refusal with explanatory details and next steps, and constructive guidance. The specification applies to every HTTP error class, not just rate limits.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/snapsynapse/graceful-boundaries">https://github.com/snapsynapse/graceful-boundaries</a></strong> to version <strong>v1.5.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/graceful-boundaries-conformance-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Graceful Boundaries is a specification for how services communicate their operational limits to humans and autonomous agents. It addresses three gaps in existing standards, providing proactive discovery of limits before they are hit, structured refusal with explanatory details and next steps, and constructive guidance. The specification applies to every HTTP error class, not just rate limits.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="fixed">Fixed</h2>
<ul>
<li>Corrected the canonical public specification URL from the nonexistent <code>/spec</code> route to the deployed <code>/spec.md</code> resource across schemas, examples, the manifest, and release validation.</li>
<li>Added the canonical specification to <code>sitemap.xml</code> and refreshed sitemap dates.</li>
<li>Extended release-contract tests so future canonical URL drift fails CI.</li>
</ul>
<p>This patch does not change normative requirements or conformance-checker behavior.</p>
<h2 id="verification">Verification</h2>
<ul>
<li>259 tests pass.</li>
<li>The landing page renders with v1.5.3 metadata and no console errors.</li>
<li>The npm artifact contains 11 expected files and has SHA-256 <code>24433f9fb7998dbef89d54298a88ab9cbf6ba2b9f22650c2b299518740066a73</code>.</li>
<li>An adversarial regression restoring <code>/spec</code> in a schema is rejected by the release-contract tests.</li>
</ul>
]]></content:encoded></item><item><title>Skill Provenance Validate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/skill-provenance-validate/</link><pubDate>Wed, 22 Jul 2026 06:06:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/skill-provenance-validate/</guid><description>Version updated for https://github.com/snapsynapse/skill-provenance to version v6.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Skill Provenance is a GitHub Action that ensures the integrity and version control of Agent Skills. It helps teams manage and verify the version, staleness, and drift of their skills across different platforms and sessions. By embedding version information and hash-based integrity checks within the skill bundle, Skill Provenance allows for portable provenance and trust verification.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/snapsynapse/skill-provenance">https://github.com/snapsynapse/skill-provenance</a></strong> to version <strong>v6.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skill-provenance-validate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Skill Provenance is a GitHub Action that ensures the integrity and version control of Agent Skills. It helps teams manage and verify the version, staleness, and drift of their skills across different platforms and sessions. By embedding version information and hash-based integrity checks within the skill bundle, Skill Provenance allows for portable provenance and trust verification.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="skill-provenance-600">Skill Provenance 6.0.0</h1>
<p>Manifest-boundary hardening release for portable Agent Skill provenance and integrity.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Adds constrained, fail-closed manifest inventory parsing with traversal, ambiguous-path, duplicate-path, and symlink-component rejection.</li>
<li>Prevents partial manifest rewrites when structural validation fails.</li>
<li>Makes package generation revalidate every boundary and delegate derived hash updates to the canonical validator.</li>
<li>Requires exact agreement between package contents and the enclosed manifest.</li>
<li>Reports malformed or stale validation attestations without allowing them to override byte-level integrity results.</li>
<li>Expands and consolidates coverage to 39 core and 17 supplemental evals, 56 total.</li>
<li>Retains compatibility with macOS system Bash 3.2 and modern Bash.</li>
</ul>
<h2 id="verification">Verification</h2>
<ul>
<li>Canonical bundle hashes verified.</li>
<li>Strict and ClawHub package-boundary regressions passed.</li>
<li>GitHub Action input transport security checks passed.</li>
<li>Claude Settings archive matches every canonical manifest-listed file.</li>
</ul>
<h2 id="asset">Asset</h2>
<p><code>skill-provenance.skill</code></p>
<p>SHA-256: <code>b6bf9b9d2eaab2fff1dd084178b0df56b2cb6cee9a90d6f1de411fe07065abdb</code></p>
<p>See <code>CHANGELOG.md</code> in the repository for the complete file-by-file release record.</p>
]]></content:encoded></item><item><title>PlatformIO Dependency Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/platformio-dependency-updater/</link><pubDate>Wed, 22 Jul 2026 06:05:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/platformio-dependency-updater/</guid><description>Version updated for https://github.com/VIPnytt/platformio-dependency-updater to version v1.0.0-b2.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The PlatformIO Dependency Updater is a GitHub Action that checks for dependency updates in the platformio.ini file and creates pull requests when newer versions are available. It supports various dependency sources, including PlatformIO Registry, GitHub, GitLab, Bitbucket, and Arduino libraries, and can handle pre-release versions and custom package versions. The action automates dependency management by creating dedicated update branches, updating dependencies, and opening pull requests, while also maintaining the number of open dependency PRs to 5 and applying labels if they exist. It includes a 3-day cooldown for new releases to avoid faulty versions and manages updates for inactive repositories after 3 months.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VIPnytt/platformio-dependency-updater">https://github.com/VIPnytt/platformio-dependency-updater</a></strong> to version <strong>v1.0.0-b2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/platformio-dependency-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The PlatformIO Dependency Updater is a GitHub Action that checks for dependency updates in the <code>platformio.ini</code> file and creates pull requests when newer versions are available. It supports various dependency sources, including PlatformIO Registry, GitHub, GitLab, Bitbucket, and Arduino libraries, and can handle pre-release versions and custom package versions. The action automates dependency management by creating dedicated update branches, updating dependencies, and opening pull requests, while also maintaining the number of open dependency PRs to 5 and applying labels if they exist. It includes a 3-day cooldown for new releases to avoid faulty versions and manages updates for inactive repositories after 3 months.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="enhancements">Enhancements</h3>
<ul>
<li>Add support for PlatformIO-official registry packages without owner-prefix by @JanPetterMG in <a href="https://github.com/VIPnytt/platformio-dependency-updater/pull/21">https://github.com/VIPnytt/platformio-dependency-updater/pull/21</a></li>
</ul>
<h3 id="dependency-updates">Dependency updates</h3>
<ul>
<li>Bump ruff from 0.15.21 to 0.15.22 by @dependabot[bot] in <a href="https://github.com/VIPnytt/platformio-dependency-updater/pull/16">https://github.com/VIPnytt/platformio-dependency-updater/pull/16</a></li>
<li>Bump actions/checkout from 7.0.0 to 7.0.1 by @dependabot[bot] in <a href="https://github.com/VIPnytt/platformio-dependency-updater/pull/17">https://github.com/VIPnytt/platformio-dependency-updater/pull/17</a></li>
<li>Bump uv from 0.11.29 to 0.11.30 by @dependabot[bot] in <a href="https://github.com/VIPnytt/platformio-dependency-updater/pull/19">https://github.com/VIPnytt/platformio-dependency-updater/pull/19</a></li>
<li>Bump gitpython from 3.1.52 to 3.1.53 by @dependabot[bot] in <a href="https://github.com/VIPnytt/platformio-dependency-updater/pull/20">https://github.com/VIPnytt/platformio-dependency-updater/pull/20</a></li>
<li>Bump actions/labeler from 6.2.0 to 7.0.0 by @dependabot[bot] in <a href="https://github.com/VIPnytt/platformio-dependency-updater/pull/18">https://github.com/VIPnytt/platformio-dependency-updater/pull/18</a></li>
</ul>
<h3 id="miscellaneous">Miscellaneous</h3>
<ul>
<li>Bump project version to v1.0.0b2 by @JanPetterMG in <a href="https://github.com/VIPnytt/platformio-dependency-updater/pull/23">https://github.com/VIPnytt/platformio-dependency-updater/pull/23</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VIPnytt/platformio-dependency-updater/compare/v1.0.0-b1...v1.0.0-b2">https://github.com/VIPnytt/platformio-dependency-updater/compare/v1.0.0-b1...v1.0.0-b2</a></p>
]]></content:encoded></item><item><title>RustScript Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/rustscript-action/</link><pubDate>Wed, 22 Jul 2026 06:04:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/22/rustscript-action/</guid><description>Version updated for https://github.com/VladasZ/rustscript to version v0.1.6.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary RustScript is a tool that interprets and executes Rust scripts without compiling them, offering features like running scripts directly, validating code with rust check, caching compiled binaries with rust build, and managing builds with rust clean. It supports a subset of the Rust language and provides tools for interacting with files and system commands.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VladasZ/rustscript">https://github.com/VladasZ/rustscript</a></strong> to version <strong>v0.1.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rustscript-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>RustScript is a tool that interprets and executes Rust scripts without compiling them, offering features like running scripts directly, validating code with <code>rust check</code>, caching compiled binaries with <code>rust build</code>, and managing builds with <code>rust clean</code>. It supports a subset of the Rust language and provides tools for interacting with files and system commands.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VladasZ/rustscript/compare/v0.1...v0.1.6">https://github.com/VladasZ/rustscript/compare/v0.1...v0.1.6</a></p>
]]></content:encoded></item><item><title>setup-openapi</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/setup-openapi/</link><pubDate>Tue, 21 Jul 2026 15:13:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/setup-openapi/</guid><description>Version updated for https://github.com/remarkablemark/setup-openapi to version v1.1.11.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The setup-openapi GitHub Action installs and caches the OpenAPI Generator CLI, which allows users to generate API client libraries from OpenAPI specifications. It provides a simple way to automate the generation of clients for various programming languages within GitHub Actions workflows. The action supports specifying the version and binary name of the generator tool, making it flexible for different use cases.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remarkablemark/setup-openapi">https://github.com/remarkablemark/setup-openapi</a></strong> to version <strong>v1.1.11</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-openapi">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The setup-openapi GitHub Action installs and caches the OpenAPI Generator CLI, which allows users to generate API client libraries from OpenAPI specifications. It provides a simple way to automate the generation of clients for various programming languages within GitHub Actions workflows. The action supports specifying the version and binary name of the generator tool, making it flexible for different use cases.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1111-2026-07-21"><a href="https://github.com/remarkablemark/setup-openapi/compare/v1.1.10...v1.1.11">1.1.11</a> (2026-07-21)</h2>
<h3 id="build-system">Build System</h3>
<ul>
<li><strong>deps:</strong> bump openapi-generator-cli from 7.23.0 to 7.24.0 (<a href="https://github.com/remarkablemark/setup-openapi/issues/32">#32</a>) (<a href="https://github.com/remarkablemark/setup-openapi/commit/2a923be3fe790cc79a7618373c67da56b63cb03e">2a923be</a>)</li>
</ul>
]]></content:encoded></item><item><title>codemetrics complexity gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/codemetrics-complexity-gate/</link><pubDate>Tue, 21 Jul 2026 15:13:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/codemetrics-complexity-gate/</guid><description>Version updated for https://github.com/richardwooding/codemetrics to version v0.12.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action codemetrics automates the calculation of cyclomatic and cognitive complexities for functions across various programming languages. It provides a comprehensive solution for checking pull request complexity, helping developers maintain code quality by ensuring that new or modified functions do not exceed predefined thresholds. The action is designed to be efficient, using one pass analysis with support for multiple languages through Tree-sitter integration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/richardwooding/codemetrics">https://github.com/richardwooding/codemetrics</a></strong> to version <strong>v0.12.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/codemetrics-complexity-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>codemetrics</code> automates the calculation of cyclomatic and cognitive complexities for functions across various programming languages. It provides a comprehensive solution for checking pull request complexity, helping developers maintain code quality by ensuring that new or modified functions do not exceed predefined thresholds. The action is designed to be efficient, using one pass analysis with support for multiple languages through Tree-sitter integration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<h3 id="features">Features</h3>
<ul>
<li>c572b513a435905955013485c9428c004da900b8: feat(site): Open Graph card for the /playground/ page (#32) (@richardwooding)</li>
<li>3db64db77c59e9c77d549cd1f375a13846b36a8a: feat: live complexity playground at /playground (#27) (@richardwooding)</li>
<li>a766dcf1ec14fdb66e85161a7b3881eb93af5870: feat: syntax-highlight the playground editor with gotreesitter (#29) (@odvcencio)</li>
</ul>
<h3 id="bug-fixes">Bug fixes</h3>
<ul>
<li>04be44eb60ffd2832d6a911218a6a66f67154632: fix: correct C# grammar-subset build tag for the playground WASM (#28) (@richardwooding)</li>
</ul>
<h3 id="others">Others</h3>
<ul>
<li>621b0c00549d7e7aa66e7927b67ed0cc5a088a63: chore(deps): Bump actions/setup-go from 5 to 7 (#30) (@dependabot[bot])</li>
<li>92a13c42b4462750a3b7b899ef71b47d339e9a2a: chore(deps): Bump the minor-and-patch group with 3 updates (#31) (@dependabot[bot])</li>
</ul>
]]></content:encoded></item><item><title>file-search-on review gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/file-search-on-review-gate/</link><pubDate>Tue, 21 Jul 2026 15:11:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/file-search-on-review-gate/</guid><description>Version updated for https://github.com/richardwooding/file-search-on to version v0.119.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Purpose: The file-search-on GitHub Action helps in searching and filtering files based on metadata attributes using a CEL expression. It supports multiple file formats across various content type families, including documents, data, images, audio, video, office, ebooks, plain text, archives, compiled binaries, email, and source code.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/richardwooding/file-search-on">https://github.com/richardwooding/file-search-on</a></strong> to version <strong>v0.119.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/file-search-on-review-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Purpose:</strong> The <code>file-search-on</code> GitHub Action helps in searching and filtering files based on metadata attributes using a CEL expression. It supports multiple file formats across various content type families, including documents, data, images, audio, video, office, ebooks, plain text, archives, compiled binaries, email, and source code.</p>
<p><strong>Solves:</strong> The action automates the process of finding files that meet specific criteria based on metadata attributes such as document titles, author names, image dimensions, audio artists, or video codec types. This is particularly useful for developers who need to search through large file repositories efficiently.</p>
<p><strong>Key Capabilities:</strong></p>
<ul>
<li><strong>Content-Type Detection:</strong> Supports over 74 file formats and has thirteen content type families.</li>
<li><strong>Metadata Extraction:</strong> Extracts various metadata attributes for each file format.</li>
<li><strong>Search with CEL Expressions:</strong> Allows users to query files using a CEL expression, enabling flexible filtering based on multiple criteria.</li>
<li><strong>Integration with Claude Code:</strong> Provides access to MCP (Multi-Core Processing) tools like <code>find_definition</code>, <code>who_calls</code>, and <code>calls</code> to understand dependencies in the codebase.</li>
</ul>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<h3 id="others">Others</h3>
<ul>
<li>6f9dd9631b10f857ff0e9bab56b15b8a9c11245a chore(deps): Bump actions/setup-go from 6 to 7 (#565)</li>
<li>7333abeddaf5300b892934092b1e76e14fd4a62a chore(deps): Bump the minor-and-patch group with 6 updates (#564)</li>
<li>3699a2cbb97c4a51c19fbe11d86375e84e54dd05 chore(deps): bump codemetrics to v0.12.2, treesitter-symbols to v0.6.2</li>
<li>def6c0ef73d30e0bd23762ac574d2114e9994919 ci: take Go version from go.mod instead of pinning</li>
<li>aa3d7b93b101252ae4865a4e5441b55b492c8b6b ci: take Go version from go.mod instead of pinning</li>
<li>2146c2213c733c6a213a5e78d013144301e721bf ci: take Go version from go.mod instead of pinning</li>
</ul>
]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/rumdl-action/</link><pubDate>Tue, 21 Jul 2026 15:10:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.38.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary rumdl is a high-performance Markdown linter and formatter written in Rust that offers speed, numerous lint rules, automatic formatting with –fix, zero dependencies, configurable TOML-based settings, support for multiple Markdown flavors, installation options via Cargo, npm, pip, uv, mise, Nix, Termux User Repository, pacman, and binary downloads. It compares well to markdownlint and provides modern CLI tools with detailed error reporting and CI/CD integration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.38</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>rumdl is a high-performance Markdown linter and formatter written in Rust that offers speed, numerous lint rules, automatic formatting with &ndash;fix, zero dependencies, configurable TOML-based settings, support for multiple Markdown flavors, installation options via Cargo, npm, pip, uv, mise, Nix, Termux User Repository, pacman, and binary downloads. It compares well to markdownlint and provides modern CLI tools with detailed error reporting and CI/CD integration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>md044</strong>: add ignore-frontmatter-fields option (<a href="https://github.com/rvben/rumdl/commit/b664e5ac776963b18a52fc9fb7cead8287530e10">b664e5a</a>)</li>
<li><strong>config</strong>: warn when an inline enable cannot re-enable a config-disabled rule (<a href="https://github.com/rvben/rumdl/commit/a74a92322d556967f61a1dde86c0f9649fed89e0">a74a923</a>)</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>md044</strong>: stop flagging proper names inside frontmatter file paths (<a href="https://github.com/rvben/rumdl/commit/35649d9baf4d9452fbf0c669137e6c98280af9f3">35649d9</a>)</li>
<li><strong>md022</strong>: stop panicking when one blank-line requirement is unlimited (<a href="https://github.com/rvben/rumdl/commit/8a25eb2c9d76df171475b69a1f11f455a9bfdc60">8a25eb2</a>)</li>
<li><strong>config</strong>: report unknown option keys in inline configure-file comments (<a href="https://github.com/rvben/rumdl/commit/8f4c0ea63e732abc52da7786abbabc53984fdf5c">8f4c0ea</a>)</li>
<li><strong>config</strong>: apply markdownlint-configure-file when the comment spans lines (<a href="https://github.com/rvben/rumdl/commit/7a023a58079876674ca99f67b7f4e68c29472c8f">7a023a5</a>)</li>
<li><strong>config</strong>: honor booleans and alias keys in markdownlint-configure-file (#745) (<a href="https://github.com/rvben/rumdl/commit/acefc195b64003b3c1deef1dc9ac4c81b43f8bfa">acefc19</a>)</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.38-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.38-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.38-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.38-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-apple-darwin.tar.gz">rumdl-v0.2.38-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-aarch64-apple-darwin.tar.gz">rumdl-v0.2.38-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-pc-windows-msvc.zip">rumdl-v0.2.38-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.38/rumdl-v0.2.38-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>SchemaCrawler (Local) Action for GitHub Actions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/schemacrawler-local-action-for-github-actions/</link><pubDate>Tue, 21 Jul 2026 15:08:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/schemacrawler-local-action-for-github-actions/</guid><description>Version updated for https://github.com/schemacrawler/SchemaCrawler-Local-Action to version v17.12.2.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the generation of a SchemaCrawler report for database connections using local installations on Linux-based runners. It solves the need for continuous database schema inspection and compliance checks within GitHub workflows, providing detailed reports for database administrators or developers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/schemacrawler/SchemaCrawler-Local-Action">https://github.com/schemacrawler/SchemaCrawler-Local-Action</a></strong> to version <strong>v17.12.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/schemacrawler-local-action-for-github-actions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the generation of a SchemaCrawler report for database connections using local installations on Linux-based runners. It solves the need for continuous database schema inspection and compliance checks within GitHub workflows, providing detailed reports for database administrators or developers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>SchemaCrawler (Local) Action v17.12.2 release at last commit d8d51d8d3c9fe13d07daeb1b79bf40134603e41c
See the change history at <a href="https://www.schemacrawler.com/changes-report.html">https://www.schemacrawler.com/changes-report.html</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>v17.12.2 by @sualeh in <a href="https://github.com/schemacrawler/SchemaCrawler-Local-Action/pull/5">https://github.com/schemacrawler/SchemaCrawler-Local-Action/pull/5</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/schemacrawler/SchemaCrawler-Local-Action/compare/v17.12.1...v17.12.2">https://github.com/schemacrawler/SchemaCrawler-Local-Action/compare/v17.12.1...v17.12.2</a></p>
]]></content:encoded></item><item><title>BoundaryCI tenant-isolation scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/boundaryci-tenant-isolation-scan/</link><pubDate>Tue, 21 Jul 2026 15:08:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/boundaryci-tenant-isolation-scan/</guid><description>Version updated for https://github.com/sir-gig/boundaryci to version v0.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary BoundaryCI is a local-first CLI tool designed to scan Supabase and PostgreSQL projects for cross-tenant authorization issues before migrations are applied to production. It reconstructs the final security state from SQL migrations, applies deterministic tenant-isolation rules, and optionally adds managed or bring-your-own-key Fireworks review for policy interactions that static rules cannot reliably understand. The tool is particularly useful for identifying exposed schema restrictions and ensuring that RLS policies are correctly configured across multiple tenants.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sir-gig/boundaryci">https://github.com/sir-gig/boundaryci</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/boundaryci-tenant-isolation-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>BoundaryCI is a local-first CLI tool designed to scan Supabase and PostgreSQL projects for cross-tenant authorization issues before migrations are applied to production. It reconstructs the final security state from SQL migrations, applies deterministic tenant-isolation rules, and optionally adds managed or bring-your-own-key Fireworks review for policy interactions that static rules cannot reliably understand. The tool is particularly useful for identifying exposed schema restrictions and ensuring that RLS policies are correctly configured across multiple tenants.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>BoundaryCI v0.4.0 expands deterministic final-state analysis from six to twelve tenant-boundary checks.</p>
<h2 id="new-deterministic-checks">New deterministic checks</h2>
<ul>
<li><strong>BND007:</strong> exposed regular views without <code>security_invoker</code></li>
<li><strong>BND008:</strong> RLS policies that authorize with user-editable metadata</li>
<li><strong>BND009:</strong> selectable materialized views in exposed API schemas</li>
<li><strong>BND010:</strong> client-reachable foreign tables in exposed API schemas</li>
<li><strong>BND011:</strong> default table or function grants to API roles</li>
<li><strong>BND012:</strong> exposed <code>SECURITY DEFINER</code> functions executable by <code>anon</code> or <code>authenticated</code></li>
</ul>
<p>The relation and privilege inventory now follows ordered object/default grants, revokes, schema-wide and multi-object changes, materialized views, foreign tables, function overloads, replacements, and exact privilege provenance. AI input truncation also prioritizes the newest migrations and reports partial or omitted coverage.</p>
<h2 id="upgrade-impact">Upgrade impact</h2>
<p>BND007, BND008, BND009, BND010, and BND012 are high severity. An existing workflow using <code>fail-on: high</code> may fail when v0.4.0 identifies SQL that earlier versions did not report. Review each finding before changing a baseline; do not baseline a real exposure merely to restore CI.</p>
<ul>
<li>For BND007, use <code>security_invoker = true</code> on PostgreSQL 15+, or revoke <code>PUBLIC</code>, <code>anon</code>, and <code>authenticated</code> access and move the view to an unexposed schema.</li>
<li>For BND008, prefer a protected tenant-membership table. Never use <code>user_metadata</code> or <code>raw_user_meta_data</code> for authorization; even server-controlled JWT claims may remain stale until refresh.</li>
<li>For BND009/BND010, keep materialized views and foreign tables out of exposed schemas unless their API access is intentional and reviewed.</li>
<li>For BND012, revoke direct API-role execution or expose a narrow wrapper that validates identity, membership, tenant correlation, and writable fields.</li>
</ul>
<p>BoundaryCI remains static final-state migration analysis. It is not a penetration test or proof that an application is secure.</p>
<h2 id="validation">Validation</h2>
<ul>
<li>46 CLI tests and 44 web tests</li>
<li>production CLI/web builds and 29 pre-rendered public pages</li>
<li>Deno formatting and all Edge Function checks</li>
<li>secure fixture: zero findings; vulnerable fixture: all twelve deterministic checks</li>
<li>installed-package smoke test and zero high-severity npm audit findings</li>
</ul>
]]></content:encoded></item><item><title>Agent Gate for AI PRs</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/agent-gate-for-ai-prs/</link><pubDate>Tue, 21 Jul 2026 15:07:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/agent-gate-for-ai-prs/</guid><description>Version updated for https://github.com/sjh9714/mergewarden to version v0.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary MergeWarden is an AI PR review tool that checks GitHub pull requests against predefined boundaries and policies to ensure they do not interfere with the agent control plane or introduce unauthorized text into agentic workflows. It helps maintain the integrity of repositories by detecting potential security risks and ensuring compliance with defined scopes. MergeWarden does not execute code, load policy from the PR head, or call an LLM at runtime, providing deterministic evidence for each decision.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sjh9714/mergewarden">https://github.com/sjh9714/mergewarden</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-gate-for-ai-prs">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>MergeWarden is an AI PR review tool that checks GitHub pull requests against predefined boundaries and policies to ensure they do not interfere with the agent control plane or introduce unauthorized text into agentic workflows. It helps maintain the integrity of repositories by detecting potential security risks and ensuring compliance with defined scopes. MergeWarden does not execute code, load policy from the PR head, or call an LLM at runtime, providing deterministic evidence for each decision.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="mergewarden-v040-release-notes">MergeWarden v0.4.0 Release Notes</h1>
<p>MergeWarden v0.4.0 renames the project from Agent Gate and publishes the CLI
under the unscoped npm name <code>mergewarden</code>. The GitHub repository is now
<code>sjh9714/mergewarden</code>; old repository URLs redirect. The scoped package
<code>@jinhyuk9714/agent-gate</code> remains at v0.3.1 and is deprecated.</p>
<h2 id="try-it">Try It</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx --yes mergewarden@0.4.0 scan owner/repo#123
</span></span></code></pre></div><p>The CLI analyzes public pull requests without cloning, checking out,
installing, or executing target-repository code. Private repositories and
higher GitHub API limits use <code>GH_TOKEN</code>, with <code>GITHUB_TOKEN</code> as the fallback.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Rename the base-branch policy file to <code>mergewarden.yml</code> and the PR body
contract marker to <code>mergewarden-contract</code>. This is a clean break with no
compatibility alias; see the <a href="migration-v0.4.0.md">v0.4.0 migration guide</a>.</li>
<li>Rename default report outputs to <code>mergewarden-report.json</code> and
<code>mergewarden-report.md</code>. Finding IDs keep the <code>agf_</code> prefix so existing
waivers remain valid.</li>
<li>Reposition the README around agent-specific boundaries: declared PR scope,
agent-control-plane drift, and agentic workflow injection.</li>
<li>Add integration guides for gating <a href="integrations/claude-code.md">Claude Code</a>
and <a href="integrations/codex.md">Codex</a> pull requests.</li>
<li>Publish the <a href="study/methodology.md">AI-agent PR scan methodology</a> used for the
v0.4.0 launch study.</li>
</ul>
<p>The signed v0.3.x tags remain immutable. v0.4.0 is a new source, tarball, and
provenance identity under the MergeWarden name.</p>
<p>See the <a href="migration-v0.4.0.md">v0.4.0 migration guide</a>,
<a href="cli.md">CLI reference</a>, and <a href="release-checklist.md">release checklist</a>.</p>
]]></content:encoded></item><item><title>GuardLayer Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/guardlayer-scan/</link><pubDate>Tue, 21 Jul 2026 15:06:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/guardlayer-scan/</guid><description>Version updated for https://github.com/solvionsolutions/guardlayer-scan to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GuardLayer Scan is an open-source GitHub Action that provides security scanning for Next.js + Supabase applications by automating static analysis to identify and comment on potential vulnerabilities, such as exposed secrets, missing Row Level Security, unverified webhooks, and unguarded Server Actions. The action runs in your CI pipeline without requiring signup or account creation, providing inline annotations on pull requests before they are merged.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/solvionsolutions/guardlayer-scan">https://github.com/solvionsolutions/guardlayer-scan</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/guardlayer-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>GuardLayer Scan is an open-source GitHub Action that provides security scanning for Next.js + Supabase applications by automating static analysis to identify and comment on potential vulnerabilities, such as exposed secrets, missing Row Level Security, unverified webhooks, and unguarded Server Actions. The action runs in your CI pipeline without requiring signup or account creation, providing inline annotations on pull requests before they are merged.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Free static security scanner for Next.js + Supabase apps. Catches exposed secrets, missing RLS, unverified webhooks, and unguarded Server Actions in CI — no signup.</p>
]]></content:encoded></item><item><title>Environment/Output Setter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/environment/output-setter/</link><pubDate>Tue, 21 Jul 2026 15:05:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/environment/output-setter/</guid><description>Version updated for https://github.com/somaz94/env-output-setter to version v1.8.1.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Environment/Output Setter is a versatile action that enables users to dynamically set environment variables and outputs within their workflows. It supports setting multiple key-value pairs in both $GITHUB_ENV and $GITHUB_OUTPUT, making it ideal for automating tasks that require defining variables across different stages of the workflow. The action provides features like value transformation, masking sensitive values, JSON support, and retry mechanisms, enhancing its utility for complex environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somaz94/env-output-setter">https://github.com/somaz94/env-output-setter</a></strong> to version <strong>v1.8.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/environment-output-setter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Environment/Output Setter is a versatile action that enables users to dynamically set environment variables and outputs within their workflows. It supports setting multiple key-value pairs in both <code>$GITHUB_ENV</code> and <code>$GITHUB_OUTPUT</code>, making it ideal for automating tasks that require defining variables across different stages of the workflow. The action provides features like value transformation, masking sensitive values, JSON support, and retry mechanisms, enhancing its utility for complex environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="build">Build</h3>
<ul>
<li>bump actions/checkout from 6 to 7 by @dependabot[bot]</li>
<li>bump actions/setup-go from 6 to 7 by @dependabot[bot]</li>
</ul>
<h3 id="cicd">CI/CD</h3>
<ul>
<li>add DCO check via shared reusable workflow by @somaz94</li>
<li>add PR welcome workflow stub by @somaz94</li>
<li>add ok-to-test workflow stub by @somaz94</li>
<li>use reusable contributors workflow by @somaz94</li>
<li>use reusable dependabot-auto-merge workflow by @somaz94</li>
<li>use reusable issue-greeting workflow by @somaz94</li>
<li>use reusable stale-issues workflow by @somaz94</li>
<li>adopt semantic-pr, labels, lock-threads, PR size, and auto-assign reusables by @somaz94</li>
<li>remove DCO workflow by @somaz94</li>
</ul>
<h3 id="refactoring">Refactoring</h3>
<ul>
<li>replace transformer.New positional args with Options struct by @somaz94</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/somaz94/env-output-setter/compare/v1.8.0...v1.8.1">https://github.com/somaz94/env-output-setter/compare/v1.8.0...v1.8.1</a></p>
]]></content:encoded></item><item><title>Go Changelog Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/go-changelog-generator/</link><pubDate>Tue, 21 Jul 2026 15:04:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/go-changelog-generator/</guid><description>Version updated for https://github.com/somaz94/go-changelog-action to version v1.0.10.
This action is used across all versions by 10 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates a changelog from Conventional Commits in a Go project. It automates the process of creating detailed, structured change logs that include features, bug fixes, optimizations, and breaking changes. The action supports filtering by version tags, customizing section names, and includes options for dry runs and excluding certain authors or types of commits.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somaz94/go-changelog-action">https://github.com/somaz94/go-changelog-action</a></strong> to version <strong>v1.0.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-changelog-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates a changelog from Conventional Commits in a Go project. It automates the process of creating detailed, structured change logs that include features, bug fixes, optimizations, and breaking changes. The action supports filtering by version tags, customizing section names, and includes options for dry runs and excluding certain authors or types of commits.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="refactoring">Refactoring</h3>
<ul>
<li>hoist buildEntry invariant args into entryBuilder context struct by @somaz94</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/somaz94/go-changelog-action/compare/v1.0.9...v1.0.10">https://github.com/somaz94/go-changelog-action/compare/v1.0.9...v1.0.10</a></p>
]]></content:encoded></item><item><title>Go Git Commit Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/go-git-commit-action/</link><pubDate>Tue, 21 Jul 2026 15:03:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/go-git-commit-action/</guid><description>Version updated for https://github.com/somaz94/go-git-commit-action to version v1.8.0.
This action is used across all versions by 18 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates Git commit, push, tag, and pull request operations using Go. It is designed to be fast, reliable, and secure, with features such as flexible file pattern support and built-in authentication handling. The action can create tags, push changes to a specified branch, and automatically create pull requests.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somaz94/go-git-commit-action">https://github.com/somaz94/go-git-commit-action</a></strong> to version <strong>v1.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>18</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-git-commit-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates Git commit, push, tag, and pull request operations using Go. It is designed to be fast, reliable, and secure, with features such as flexible file pattern support and built-in authentication handling. The action can create tags, push changes to a specified branch, and automatically create pull requests.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="features">Features</h3>
<ul>
<li>propagate context to GitHub API calls for cancellable HTTP requests by @somaz94</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/somaz94/go-git-commit-action/compare/v1.7.8...v1.8.0">https://github.com/somaz94/go-git-commit-action/compare/v1.7.8...v1.8.0</a></p>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/ssg-static-site-generator/</link><pubDate>Tue, 21 Jul 2026 15:02:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.8.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website. It automates tasks such as building, deploying, and serving websites efficiently, making it suitable for blogs, documentation, and other content-driven projects. SSG supports various features like built-in themes, template engines, and deployment options to help users quickly create and deploy static sites.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website. It automates tasks such as building, deploying, and serving websites efficiently, making it suitable for blogs, documentation, and other content-driven projects. SSG supports various features like built-in themes, template engines, and deployment options to help users quickly create and deploy static sites.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Release v1.8.8 by @spagu in <a href="https://github.com/spagu/ssg/pull/32">https://github.com/spagu/ssg/pull/32</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.7...v1.8.8">https://github.com/spagu/ssg/compare/v1.8.7...v1.8.8</a></p>
]]></content:encoded></item><item><title>spek - OpenSpec Static Site</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/spek-openspec-static-site/</link><pubDate>Tue, 21 Jul 2026 15:00:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/spek-openspec-static-site/</guid><description>Version updated for https://github.com/spekhq/spek to version v1.9.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: spek is a lightweight, read-only viewer for OpenSpec content that provides a structured browsing interface with features such as BDD syntax highlighting, task progress tracking, and full-text search. It allows users to view specs, changes, and tasks in one place, aggregating worktrees of a repository into a single view for better visibility.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spekhq/spek">https://github.com/spekhq/spek</a></strong> to version <strong>v1.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spek-openspec-static-site">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary</strong>: spek is a lightweight, read-only viewer for OpenSpec content that provides a structured browsing interface with features such as BDD syntax highlighting, task progress tracking, and full-text search. It allows users to view specs, changes, and tasks in one place, aggregating worktrees of a repository into a single view for better visibility.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Highlight: Jujutsu (jj) workspace aggregation (experimental)</strong> — spek can now see OpenSpec changes in jj workspaces, not just git worktrees. In a colocated git+jj repo, jj workspaces are invisible to <code>git worktree list</code>, so changes authored there used to be silently missed. This is <strong>experimental and off by default</strong> — enable it to opt in. Thanks to <a href="https://github.com/DannyGoodall">@DannyGoodall</a> (Danny Goodall) for contributing this.</p>
<ul>
<li>When enabled, and a repo has jj initialised and the <code>jj</code> CLI is available, spek also discovers OpenSpec changes in every jj workspace and merges them into the same aggregated view as git worktrees</li>
<li>The colocated main directory (both a git worktree and the jj <code>default</code> workspace) is deduplicated by path, so it is never double-counted</li>
<li>Because jj workspaces share one commit graph (each materialises the full trunk), a shared change would otherwise appear once per workspace; jj changes are deduplicated by content, so a shared change is shown once. A workspace that has diverged on a change keeps its own entry, flagged &ldquo;conflicts with &lt;base&gt;&rdquo; (and &ldquo;editing&rdquo; if it&rsquo;s the <code>@</code> change)</li>
<li>This runs <strong>alongside, and separately from</strong>, the git-worktree deduplication added in 1.8.1. jj workspaces are invisible to git and their working-copy commit isn&rsquo;t a git ref, so they can&rsquo;t use git&rsquo;s history-based election; they get their own content-fingerprint path instead. Git-worktree behaviour is unchanged</li>
<li>Opt in via the VS Code setting <code>spek.aggregateJjWorkspaces</code> (<strong>experimental, off by default</strong>) or the Web aggregation control&rsquo;s &ldquo;Worktrees + jj&rdquo; option — independent of git worktree aggregation</li>
<li>Degrades gracefully: when disabled, or <code>jj</code> is not installed, or the repo is not a jj repo, behaviour is identical to before — <code>jj</code> is never required</li>
<li>Supported in the Web version and the VS Code extension (IntelliJ and Demo are unchanged)</li>
</ul>
<p><strong>The aggregation scope is now one control in the app header (Web and VS Code).</strong> It used to be a checkbox on the Changes page, which meant it only existed on that page even though it changes what the Dashboard, Graph and Timeline show as well. It is now a single control in the header — <code>Current dir</code> / <code>Worktrees</code> / <code>Worktrees + jj</code> — visible from every page, and it appears only when there is more than one working copy to aggregate.</p>
<ul>
<li>The three states are mutually exclusive, so the meaningless combination &ldquo;don&rsquo;t aggregate, but do include jj&rdquo; can no longer be selected. The <code>Worktrees + jj</code> option is offered only when a jj workspace is actually detected</li>
<li>In VS Code the control writes the settings, not a hidden preference: it edits <code>spek.aggregateWorktrees</code> and <code>spek.aggregateJjWorkspaces</code> in your workspace <code>settings.json</code> (and editing those settings by hand updates the control). <code>spek.aggregateWorktrees</code> is new — worktree aggregation was previously not configurable there. On the Web the choice is remembered in the browser</li>
<li>The IntelliJ plugin does not aggregate, so no control is shown there</li>
</ul>
]]></content:encoded></item><item><title>Node Semantic Release</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/node-semantic-release/</link><pubDate>Tue, 21 Jul 2026 14:59:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/node-semantic-release/</guid><description>Version updated for https://github.com/stairwaytowonderland/node-semantic-release to version v1.202.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The node-semantic-release GitHub Action automates Node.js project releases by installing dependencies, building the project, running semantic-release to determine and generate release notes, and optionally committing assets and creating a git tag or publishing a GitHub Release. The action supports two modes: release and publish, with options for using secrets.GITHUB_TOKEN or a Personal Access Token (PAT) for triggering downstream workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stairwaytowonderland/node-semantic-release">https://github.com/stairwaytowonderland/node-semantic-release</a></strong> to version <strong>v1.202.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/node-semantic-release">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The node-semantic-release GitHub Action automates Node.js project releases by installing dependencies, building the project, running semantic-release to determine and generate release notes, and optionally committing assets and creating a git tag or publishing a GitHub Release. The action supports two modes: release and publish, with options for using <code>secrets.GITHUB_TOKEN</code> or a Personal Access Token (PAT) for triggering downstream workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>chore(release): 1.202.0</p>
<h2 id="12020-2026-07-21"><a href="https://github.com/stairwaytowonderland/node-semantic-release/compare/v1.201.0...v1.202.0">1.202.0</a> (2026-07-21)</h2>
<h3 id="-features">✨ Features</h3>
<ul>
<li>update LICENSE (<a href="https://github.com/stairwaytowonderland/node-semantic-release/commit/c556b9e38d3a22a673d57ab6bfce8718034fd358">c556b9e</a>)</li>
</ul>
]]></content:encoded></item><item><title>Normalize Major Version Tag</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/normalize-major-version-tag/</link><pubDate>Tue, 21 Jul 2026 14:58:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/normalize-major-version-tag/</guid><description>Version updated for https://github.com/stairwaytowonderland/normalize-majorver to version v1.1.0.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action normalizes major version tags when a semantic versioning tag is pushed, ensuring that developers can consistently reference stable versions of the action. It works well with GitHub Actions versioning and supports dry runs to avoid unintended changes. To include the action in another repository, use the uses syntax with a branch or tag reference.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stairwaytowonderland/normalize-majorver">https://github.com/stairwaytowonderland/normalize-majorver</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/normalize-major-version-tag">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action normalizes major version tags when a semantic versioning tag is pushed, ensuring that developers can consistently reference stable versions of the action. It works well with GitHub Actions versioning and supports dry runs to avoid unintended changes. To include the action in another repository, use the <code>uses</code> syntax with a branch or tag reference.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>chore(release): 1.1.0</p>
<h2 id="110-2026-07-21"><a href="https://github.com/stairwaytowonderland/normalize-majorver/compare/v1.0.9...v1.1.0">1.1.0</a> (2026-07-21)</h2>
<h3 id="-features">✨ Features</h3>
<ul>
<li>update LICENSE (<a href="https://github.com/stairwaytowonderland/normalize-majorver/commit/7a23caa8eda5127c94cffa35328529f59f032023">7a23caa</a>)</li>
</ul>
<h3 id="-chores">🔧 Chores</h3>
<ul>
<li>update reuseable workflow references (<a href="https://github.com/stairwaytowonderland/normalize-majorver/commit/10296aa9d0b37aa721871f1c7faeb66440deb2a8">10296aa</a>)</li>
</ul>
]]></content:encoded></item><item><title>Repository Create</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/repository-create/</link><pubDate>Tue, 21 Jul 2026 14:57:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/repository-create/</guid><description>Version updated for https://github.com/stairwaytowonderland/repository-create to version v1.83.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The repository-create action is a Node.js CLI that uses Octokit.js to dynamically create GitHub organization repositories and apply predefined general settings and branch rulesets. It supports both blank creation and template-based repository generation, with options for specifying visibility and writing job summaries. The action requires a GitHub Personal Access Token with specific scopes and can be used as an action in other workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stairwaytowonderland/repository-create">https://github.com/stairwaytowonderland/repository-create</a></strong> to version <strong>v1.83.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/repository-create">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The repository-create action is a Node.js CLI that uses Octokit.js to dynamically create GitHub organization repositories and apply predefined general settings and branch rulesets. It supports both blank creation and template-based repository generation, with options for specifying visibility and writing job summaries. The action requires a GitHub Personal Access Token with specific scopes and can be used as an action in other workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>chore(release): 1.83.0</p>
<h2 id="1830-2026-07-21"><a href="https://github.com/stairwaytowonderland/repository-create/compare/v1.82.0...v1.83.0">1.83.0</a> (2026-07-21)</h2>
<h3 id="-features">✨ Features</h3>
<ul>
<li>update LICENSE (<a href="https://github.com/stairwaytowonderland/repository-create/commit/139fd1b7681962e6a151868cfcb98fbe5b221550">139fd1b</a>)</li>
</ul>
]]></content:encoded></item><item><title>SunsetPR AI Model Lifecycle Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/sunsetpr-ai-model-lifecycle-check/</link><pubDate>Tue, 21 Jul 2026 14:56:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/sunsetpr-ai-model-lifecycle-check/</guid><description>Version updated for https://github.com/synergia-yoshi/sunsetpr-action to version v0.2.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The SunsetPR AI Model Lifecycle Check action automatically detects deprecated OpenAI, Anthropic, and Google Gemini model IDs and API surfaces in CI before their shutdown date. It reports the exact file and line, shutdown date, official replacement or migration path, confidence, and provider-owned documentation. The action is user-friendly and provides a structured table to the GitHub Actions Job Summary with a machine-readable report written to .sunsetpr/report.json.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/synergia-yoshi/sunsetpr-action">https://github.com/synergia-yoshi/sunsetpr-action</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sunsetpr-ai-model-lifecycle-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The SunsetPR AI Model Lifecycle Check action automatically detects deprecated OpenAI, Anthropic, and Google Gemini model IDs and API surfaces in CI before their shutdown date. It reports the exact file and line, shutdown date, official replacement or migration path, confidence, and provider-owned documentation. The action is user-friendly and provides a structured table to the GitHub Actions Job Summary with a machine-readable report written to <code>.sunsetpr/report.json</code>.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="what-changed">What changed</h2>
<ul>
<li>Detects OpenAI Assistants API call sites and reports the official 2026-08-26 shutdown with the Responses API + Conversations API migration path.</li>
<li>Detects OpenAI Videos API call sites and preserves the official 2026-09-24 shutdown without inventing a replacement.</li>
<li>Resolves conservative single-use TypeScript model constants and legacy Gemini Python positional calls.</li>
<li>Adds API findings to JSON, annotations, Job Summary, outputs, lifecycle pages, and the official-source monitor.</li>
</ul>
<h2 id="reproducible-evidence">Reproducible evidence</h2>
<ul>
<li>Model-ID benchmark: 230/230 labeled positives detected; 0/230 labeled negatives flagged.</li>
<li>Fixed-commit API sample: 56/56 labeled Assistants API call sites detected across 8 files in 4 licensed public repositories. This is a curated positive engineering sample, not a prevalence, recall, or false-positive estimate.</li>
<li>Hosted Ubuntu packaging and self-run passed in GitHub Actions. CodeQL passed.</li>
</ul>
<h2 id="safety-boundary">Safety boundary</h2>
<p>API redesigns remain report-only. The Action does not rewrite Assistants into Responses/Conversations and does not propose a Videos successor. Dynamic values are never classified as unaffected. The free Action remains read-only and sends no repository code to SunsetPR or an external AI model.</p>
<h2 id="immutable-install">Immutable install</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">synergia-yoshi/sunsetpr-action@074b4e2aad0678075acad14d5e043e0ca788e77b</span> <span style="color:#75715e"># v0.2.0</span>
</span></span></code></pre></div><p>Source integration is available for human review in draft PR #3; the immutable tag already points to the CI-verified Linux runtime.</p>
]]></content:encoded></item><item><title>ArchGuard - Architectural Drift Detector</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/archguard-architectural-drift-detector/</link><pubDate>Tue, 21 Jul 2026 14:55:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/archguard-architectural-drift-detector/</guid><description>Version updated for https://github.com/Tgenz1213/ArchGuard to version v1.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ArchGuard is a tool that uses LLMs to detect architectural drift in code changes by comparing them against established Architectural Decision Records (ADRs). It helps prevent “architectural drift” by ensuring code adheres to the rules defined in ADRs. ArchGuard supports local analysis without sending sensitive data over the internet and can be configured via a YAML file for detailed settings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tgenz1213/ArchGuard">https://github.com/Tgenz1213/ArchGuard</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/archguard-architectural-drift-detector">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>ArchGuard is a tool that uses LLMs to detect architectural drift in code changes by comparing them against established Architectural Decision Records (ADRs). It helps prevent &ldquo;architectural drift&rdquo; by ensuring code adheres to the rules defined in ADRs. ArchGuard supports local analysis without sending sensitive data over the internet and can be configured via a YAML file for detailed settings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>dc7d7d97a225caa1dec90e418aeb0f91d59de63d build(deps): bump actions/setup-go from 6 to 7 (#31)</li>
<li>c5acd680540a65e471b00e9a5f367b0c6ef00622 build(deps): bump google.golang.org/grpc (#34)</li>
<li>a14af512df4af5442d0b905fc1f83095d9ced04e fix: use doublestar for recursive glob exclusion, fixing **/*_test.go depth bug (#25)</li>
<li>8ab6fa7eb2c89655aaca1de5e2b2743a70f34f9c refactor: replace hand-rolled worker pools with errgroup (#26)</li>
<li>d04f88e6d4be27814880e3cb76f167131845fd72 refactor: use cenkalti/backoff for AnalyzeDrift retry loop (#27)</li>
<li>94a8337c5281ca925ca4cc51d22dccd0f085b62c refactor: use godotenv for .env loading (#28)</li>
<li>2d6fe5a3160b7b14431a356060bb9f4f6abaafab refactor: use goquery for Confluence HTML text extraction (#33)</li>
<li>cf7c66051636357e6a113bae37c8be9854b1e0da refactor: use official google.golang.org/genai SDK for GeminiProvider (#30)</li>
<li>f436a4e673a2883605c91bd6370238ba61a93f25 refactor: use official ollama/ollama api client for OllamaProvider (#32)</li>
<li>dffc3859347e84703c4a5754794803f2a7b2b309 refactor: use official openai-go SDK for OpenAIProvider (#29)</li>
</ul>
]]></content:encoded></item><item><title>Expand AWS IAM Wildcards</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/expand-aws-iam-wildcards/</link><pubDate>Tue, 21 Jul 2026 14:54:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/expand-aws-iam-wildcards/</guid><description>Version updated for https://github.com/thekbb/expand-aws-iam-wildcards to version v1.4.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action automatically expands IAM wildcard actions in PR diffs and posts inline comments showing what each wildcard matches, with links to AWS docs. It helps reviewers understand security posture changes more easily by providing inline comments with expanded actions linked to AWS documentation. The recommended setup includes a pull_request workflow trigger with write permissions for pull-requests and uses a full 40-character commit SHA for immutable reference.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/thekbb/expand-aws-iam-wildcards">https://github.com/thekbb/expand-aws-iam-wildcards</a></strong> to version <strong>v1.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/expand-aws-iam-wildcards">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action automatically expands IAM wildcard actions in PR diffs and posts inline comments showing what each wildcard matches, with links to AWS docs. It helps reviewers understand security posture changes more easily by providing inline comments with expanded actions linked to AWS documentation. The recommended setup includes a pull_request workflow trigger with write permissions for pull-requests and uses a full 40-character commit SHA for immutable reference.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Move changelog release prep to TypeScript by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/130">https://github.com/thekbb/expand-aws-iam-wildcards/pull/130</a></li>
<li>deps: bump the npm-dependencies group with 3 updates by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/131">https://github.com/thekbb/expand-aws-iam-wildcards/pull/131</a></li>
<li>ci: bump github/codeql-action/init from 4.36.2 to 4.36.3 by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/132">https://github.com/thekbb/expand-aws-iam-wildcards/pull/132</a></li>
<li>dependabot should always update all codeql actions in same pr by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/134">https://github.com/thekbb/expand-aws-iam-wildcards/pull/134</a></li>
<li>Update IAM action data by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/138">https://github.com/thekbb/expand-aws-iam-wildcards/pull/138</a></li>
<li>deps: bump the npm-dependencies group across 1 directory with 5 updates by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/137">https://github.com/thekbb/expand-aws-iam-wildcards/pull/137</a></li>
<li>ci: bump the codeql group with 2 updates by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/136">https://github.com/thekbb/expand-aws-iam-wildcards/pull/136</a></li>
<li>big bang move of release script to typescrit (sorry james) by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/139">https://github.com/thekbb/expand-aws-iam-wildcards/pull/139</a></li>
<li>Prepare v1.4.0 release by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/140">https://github.com/thekbb/expand-aws-iam-wildcards/pull/140</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/thekbb/expand-aws-iam-wildcards/compare/v1...v1.4.0">https://github.com/thekbb/expand-aws-iam-wildcards/compare/v1...v1.4.0</a></p>
]]></content:encoded></item><item><title>gmetrics-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/gmetrics-action/</link><pubDate>Tue, 21 Jul 2026 14:53:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/gmetrics-action/</guid><description>Version updated for https://github.com/twangodev/gmetrics to version v1.7.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action gmetrics is a Go port of lowlighter/metrics, designed for generating SVG output paths using the metrics tool. It automates tasks related to performance monitoring and analysis by providing an alternative to the original metrics package. The action supports caching per-repo language stats across runs, optimizing processing for new commits.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/twangodev/gmetrics">https://github.com/twangodev/gmetrics</a></strong> to version <strong>v1.7.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gmetrics-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action gmetrics is a Go port of lowlighter/metrics, designed for generating SVG output paths using the metrics tool. It automates tasks related to performance monitoring and analysis by providing an alternative to the original metrics package. The action supports caching per-repo language stats across runs, optimizing processing for new commits.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="171-2026-07-21"><a href="https://github.com/twangodev/gmetrics/compare/v1.7.0...v1.7.1">1.7.1</a> (2026-07-21)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>base:</strong> split GraphQL query to avoid resource limits (<a href="https://github.com/twangodev/gmetrics/issues/24">#24</a>) (<a href="https://github.com/twangodev/gmetrics/commit/b0256b03a0649de0a6c7dc672de57b494ec3ec7c">b0256b0</a>)</li>
<li><strong>http:</strong> rate-limit retry attempts (<a href="https://github.com/twangodev/gmetrics/commit/a5dedafe60d23188e96dae646213fb2859d2b0aa">a5dedaf</a>)</li>
</ul>
<h3 id="performance-improvements">Performance Improvements</h3>
<ul>
<li><strong>languages:</strong> optimize incremental history scanning (<a href="https://github.com/twangodev/gmetrics/commit/7dba359e16744fd9e4924798b95719b0028d69bf">7dba359</a>)</li>
</ul>
]]></content:encoded></item><item><title>Medicare NPI Revalidation Lookup</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/medicare-npi-revalidation-lookup/</link><pubDate>Tue, 21 Jul 2026 14:52:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/medicare-npi-revalidation-lookup/</guid><description>Version updated for https://github.com/unitedideas/medicare-revalidation-action to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Medicare revalidation checks action in GitHub Actions automates the process of validating public enrollment evidence and revalidation due dates for a list of NPIs against the CMS Medicare Revalidation List. It supports both demo and real rosters, with options to set hard charge caps. For larger datasets, it uses Apify to handle the lookup operations and can be used as an email reminder service or scheduled comparison tool. The action provides a free two-NPI demo without a token but requires an API token for real use cases.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/unitedideas/medicare-revalidation-action">https://github.com/unitedideas/medicare-revalidation-action</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/medicare-npi-revalidation-lookup">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Medicare revalidation checks action in GitHub Actions automates the process of validating public enrollment evidence and revalidation due dates for a list of NPIs against the CMS Medicare Revalidation List. It supports both demo and real rosters, with options to set hard charge caps. For larger datasets, it uses Apify to handle the lookup operations and can be used as an email reminder service or scheduled comparison tool. The action provides a free two-NPI demo without a token but requires an API token for real use cases.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Adds a result-first operating-model choice in workflow summaries: $12 one-time team dashboard or $9/month managed monitoring. The completed lookup remains primary, and the Action never starts checkout.</p>
]]></content:encoded></item><item><title>MCP Test Harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/mcp-test-harness/</link><pubDate>Tue, 21 Jul 2026 14:51:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/mcp-test-harness/</guid><description>Version updated for https://github.com/vaquarkhan/mcp-test-harness to version v3.0.8.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary MCP Test Harness is a CI gate for MCP servers, ensuring that AI agents’ connectors work correctly before deployment. It automates deterministic tests using pytest-style syntax, providing JUnit/SARIF reports and conformance badges to audit and govern the server’s functionality. The action supports multiple transports (stdio, SSE, HTTP) and integrates seamlessly with GitHub Actions, JUnit consumers, and Code Scanning for comprehensive testing coverage and security checks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vaquarkhan/mcp-test-harness">https://github.com/vaquarkhan/mcp-test-harness</a></strong> to version <strong>v3.0.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcp-test-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>MCP Test Harness is a CI gate for MCP servers, ensuring that AI agents&rsquo; connectors work correctly before deployment. It automates deterministic tests using pytest-style syntax, providing JUnit/SARIF reports and conformance badges to audit and govern the server&rsquo;s functionality. The action supports multiple transports (stdio, SSE, HTTP) and integrates seamlessly with GitHub Actions, JUnit consumers, and Code Scanning for comprehensive testing coverage and security checks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Dual-mode MCP testing:</strong> stateful flows unchanged; new SEP-2575 stateless path for Streamable HTTP (2026-07-28)</li>
<li><strong><code>mcp-test conformance stateless</code></strong> — adversarial certification gate + README badge</li>
<li><strong><code>assert_stateless_throughput</code></strong> — protocol-aware hyperscale load without initialize handshake</li>
<li><strong>Docs:</strong> <a href="https://github.com/vaquarkhan/mcp-test-harness/blob/main/docs/TUTORIAL_STATELESS.md">TUTORIAL_STATELESS.md</a>, RFC-006, examples, <code>stateless-dual-mode.svg</code> diagram</li>
</ul>
<h2 id="install">Install</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install mcp-test-harness<span style="color:#f92672">==</span>3.0.8
</span></span><span style="display:flex;"><span>docker pull ghcr.io/vaquarkhan/mcp-test-harness:3.0.8
</span></span></code></pre></div><p>All <strong>18 PyPI artifacts</strong> aligned at 3.0.8.</p>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/vibgrate-scan/</link><pubDate>Tue, 21 Jul 2026 14:50:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.721.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The @vibgrate/cli GitHub Action provides a local tool to analyze codebases, assess drift scores, and generate drift breakdowns. It automates tasks such as generating code graphs, calculating drift scores, and identifying upgrade priorities. The main purpose is to help AI coding agents understand the current state of a project’s dependencies, runtime lag, and EOL proximity on the developer’s machine without relying on external APIs or data transfer.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.721.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>@vibgrate/cli</code> GitHub Action provides a local tool to analyze codebases, assess drift scores, and generate drift breakdowns. It automates tasks such as generating code graphs, calculating drift scores, and identifying upgrade priorities. The main purpose is to help AI coding agents understand the current state of a project&rsquo;s dependencies, runtime lag, and EOL proximity on the developer&rsquo;s machine without relying on external APIs or data transfer.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20267213">Vibgrate CLI 2026.721.3</h1>
<p><em>Released 2026-07-21</em></p>
<p>This release of the vg CLI includes significant improvements to dependency-injection call resolution across multiple languages, enhancing the accuracy of dependency reporting. A new benchmark for cross-language dependency-injection resolution has also been introduced.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="improved">Improved</h3>
<ul>
<li>C# dependency-injection call graph now accurately resolves interface-injected services, capturing their concrete implementations and linking tests.</li>
<li>Dependency-injection call resolution has been enhanced across seven languages, ensuring accurate reporting of dependents for DI-wired code.</li>
<li>PHP now supports dependency-injection resolution, linking tests to constructed classes and capturing injected interfaces.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>A new cross-language dependency-injection resolution benchmark (bench:di) has been published to measure interface injection conformance.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.721.2, interleaved on one runner against the pinned corpus (176 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>19238 count</td>
          <td>19238 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>7991 count</td>
          <td>8084 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.98 ratio</td>
          <td>0.98 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>622 ms</td>
          <td>612.90 ms</td>
      </tr>
  </tbody>
</table>
<p>3 regression(s) — published, not omitted:</p>
<ul>
<li>Call edges — java: 236 → 204 (-13.6%)</li>
<li>Response size p95 (est. tokens): 247 → 248 (0.4%)</li>
<li>Locate top-1 — cs: 1 → 0.98 (-2.2%)</li>
</ul>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.721.3">https://vibgrate.com/changelog/cli/2026.721.3</a></p>
]]></content:encoded></item><item><title>Gemini PR Reviewer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/gemini-pr-reviewer/</link><pubDate>Tue, 21 Jul 2026 14:48:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/gemini-pr-reviewer/</guid><description>Version updated for https://github.com/vivek180905/Gemini-AI-PR-Reviewer to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Gemini PR Reviewer automates code reviews for GitHub Pull Requests by leveraging Google’s Gemini AI to analyze git diffs, identifying bugs, performance issues, and security vulnerabilities. It posts actionable feedback directly on PRs, enhancing collaboration and maintaining high-quality code standards.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vivek180905/Gemini-AI-PR-Reviewer">https://github.com/vivek180905/Gemini-AI-PR-Reviewer</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gemini-pr-reviewer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Gemini PR Reviewer</strong> automates code reviews for GitHub Pull Requests by leveraging Google&rsquo;s Gemini AI to analyze git diffs, identifying bugs, performance issues, and security vulnerabilities. It posts actionable feedback directly on PRs, enhancing collaboration and maintaining high-quality code standards.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update action.yml with author and branding details (35f2160)</li>
<li>Fix: upgrade to gemini-3.5-flash model (f0692de)</li>
<li>new model (e090c43)</li>
<li>Fix: update model to gemini-1.5-flash-latest (3683de1)</li>
<li>Add CONTRIBUTING.md with contribution guidelines (35ec110)</li>
<li>Add MIT License to the project (fa4f455)</li>
<li>Initial commit: Add Gemini PR Reviewer GitHub Action (d54b03b)</li>
</ul>
]]></content:encoded></item><item><title>AGENTS.md Lint (Schliff)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/agents.md-lint-schliff/</link><pubDate>Tue, 21 Jul 2026 14:48:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/agents.md-lint-schliff/</guid><description>Version updated for https://github.com/Zandereins/schliff to version v8.6.1.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the scoring of AGENTS.md files to ensure consistent quality across different environments. It uses a deterministic rule engine to evaluate instruction files against explicit rubrics, preventing degradation due to inconsistencies or rotting prompts. The action ensures that AI tools are consistently evaluated and can be trusted for their accuracy and reliability.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Zandereins/schliff">https://github.com/Zandereins/schliff</a></strong> to version <strong>v8.6.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agents-md-lint-schliff">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the scoring of <code>AGENTS.md</code> files to ensure consistent quality across different environments. It uses a deterministic rule engine to evaluate instruction files against explicit rubrics, preventing degradation due to inconsistencies or rotting prompts. The action ensures that AI tools are consistently evaluated and can be trusted for their accuracy and reliability.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Patch release. Adversarial-review + real-repo field-sweep fixes for the <code>check-commands</code> gate shipped in 8.6.0.</p>
<p><strong>No API or scoring change</strong> — <code>operational_coverage</code> is untouched, golden scores are byte-identical. Every fix only demotes <code>dangling</code>→<code>unknown</code>, so the check can never gain a false claim.</p>
<h3 id="fixed--false-positives-on-real-repos">Fixed — false positives on real repos</h3>
<p>Shipped 8.6.0 reported 8 working commands as <code>dangling</code> across 3 of 4 real monorepos (palantir/blueprint, remotion, swc). All now correct:</p>
<ul>
<li><code>cd sub/dir &amp;&amp; npm run x</code> (monorepo cd context)</li>
<li><code>(cd x &amp;&amp; npm run build)</code> (trailing paren)</li>
<li><code>bun run index.ts</code> / <code>bun run dist/out.js</code> (bun file/binary fallback)</li>
<li><code>yarn tsc</code> / <code>yarn run x</code> (yarn <code>node_modules/.bin</code> fallback)</li>
<li><code>make -C dir target</code> (directory read as target)</li>
<li><code>pnpm run -r build</code> (flag read as script name)</li>
<li><code>$(TARGETS):</code> / <code>%.o: %.c</code> (variable/pattern targets)</li>
</ul>
<h3 id="fixed--denial-of-service-on-attacker-authored-build-files">Fixed — denial-of-service on attacker-authored build files</h3>
<ul>
<li><code>include</code> fan-out (N**5 → O(files) worklist)</li>
<li><code>include</code> regex quadratic backtracking (15.7s → 0.14s)</li>
<li><code>include ../../outside</code> read primitive (realpath-contained to repo root)</li>
<li>deeply-nested <code>package.json</code> <code>RecursionError</code> crash (→ <code>unknown</code>)</li>
</ul>
<p>1392 tests, ruff clean. See #117.</p>
]]></content:encoded></item><item><title>Pi Code Assist</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/pi-code-assist/</link><pubDate>Tue, 21 Jul 2026 14:46:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/21/pi-code-assist/</guid><description>Version updated for https://github.com/zeldrisho/pi-code-assist to version v1.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action installs the Pi coding agent, a small and composable tool that runs non-interactive prompts using pre-configured models and tools. It automates code reviews by providing actionable feedback on correctness, security, and test issues, while restricting permissions to read-only actions and untrusted project settings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zeldrisho/pi-code-assist">https://github.com/zeldrisho/pi-code-assist</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pi-code-assist">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action installs the Pi coding agent, a small and composable tool that runs non-interactive prompts using pre-configured models and tools. It automates code reviews by providing actionable feedback on correctness, security, and test issues, while restricting permissions to read-only actions and untrusted project settings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="100-2026-07-21"><a href="https://github.com/zeldrisho/pi-code-assist/compare/v0.2.1...v1.0.0">1.0.0</a> (2026-07-21)</h2>
<h3 id="-breaking-changes">⚠ BREAKING CHANGES</h3>
<ul>
<li>api-key, provider, and model must now be supplied explicitly.</li>
</ul>
<h3 id="features">Features</h3>
<ul>
<li>harden GitHub tools and validation (<a href="https://github.com/zeldrisho/pi-code-assist/commit/c75d235a5341fb2741c0944ac3730cadafa3295b">c75d235</a>)</li>
<li>require explicit model configuration (<a href="https://github.com/zeldrisho/pi-code-assist/commit/998a94f174d79ca26d36d25a9ed0b937435d046e">998a94f</a>)</li>
</ul>
<h3 id="performance-improvements">Performance Improvements</h3>
<ul>
<li>reduce validation runtime (<a href="https://github.com/zeldrisho/pi-code-assist/commit/57bd8375a6f83634c4109c115ce14d0a823c44d6">57bd837</a>)</li>
</ul>
]]></content:encoded></item><item><title>RoleCraft Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/rolecraft-action/</link><pubDate>Mon, 20 Jul 2026 23:19:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/rolecraft-action/</guid><description>Version updated for https://github.com/rolecraft-sh/rolecraft-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The rolecraft-action automates the installation and verification of AI agent skills in a CI environment using the RoleCraft tool. It simplifies the process of ensuring that AI agents have all necessary skills for testing or deployment, by running specific commands to check skill integrity, install new skills, perform system health checks, and more.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rolecraft-sh/rolecraft-action">https://github.com/rolecraft-sh/rolecraft-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rolecraft-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The rolecraft-action automates the installation and verification of AI agent skills in a CI environment using the RoleCraft tool. It simplifies the process of ensuring that AI agents have all necessary skills for testing or deployment, by running specific commands to check skill integrity, install new skills, perform system health checks, and more.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>chore: update references from sametcelikbicak to rolecraft-sh (f838a28)</li>
<li>docs: add LICENSE, badges, fix workflows (3428a10)</li>
<li>initial: rolecraft GitHub Action (11eff17)</li>
</ul>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/bernstein-multi-agent-orchestration/</link><pubDate>Mon, 20 Jul 2026 23:18:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.8.2.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bernstein orchestrates CLI coding agents deterministically using plain Python, ensuring reproducibility of tasks across runs. It maintains a lineage spine to track every artifact write and replay journal to preserve the execution history. The tool supports various providers like Claude Code, Codex, Gemini CLI, and more, with features for auditing and verifying run results offline.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.8.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Bernstein orchestrates CLI coding agents deterministically using plain Python, ensuring reproducibility of tasks across runs. It maintains a lineage spine to track every artifact write and replay journal to preserve the execution history. The tool supports various providers like Claude Code, Codex, Gemini CLI, and more, with features for auditing and verifying run results offline.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v382">v3.8.2</h1>
<p>Patch release: the local dashboard now authenticates its own browser, the startup banner is restored, <code>--idle</code> runs actually stay on the mock adapter, and a duplicated startup notice is quieted. All four were surfaced by an end-to-end run of the released 3.8.1 build.</p>
<h2 id="fixed">Fixed</h2>
<ul>
<li><strong>The local dashboard authenticates its own browser on loopback serve (#2739).</strong> On <code>bernstein gui serve</code> bound to loopback with dashboard auth configured but <code>BERNSTEIN_AUTH_TOKEN</code> unset, the UI shell loaded but every data panel returned 401: the panels poll the general API, which accepts only the process bearer, while a scoped dashboard token unlocks only the dashboard routes. The local serve path now mints an ephemeral operator bearer, exports it before the app is built so the general API accepts it, and seeds the same token into the opened browser, so the panels load with no operator steps. A non-loopback bind never auto-mints and still refuses without configured auth; an operator-supplied token is reused verbatim; the token rides only the browser URL fragment, never the console or access log.</li>
<li><strong>The startup banner is restored on program load (#2740).</strong> Two coupled defects had removed the recognisable ASCII wordmark. First, the bare <code>bernstein</code> invocation suppressed its fallback box banner even when the splash was disabled, so with <code>visual.splash: false</code> or <code>BERNSTEIN_NO_SPLASH=1</code> no banner showed at all; the fallback now prints whenever the splash renders nothing. Second, the block-art logo only rendered in colour-capable terminals on the bare invocation, so plain terminals and every <code>bernstein run</code> fell back to a one-liner; the compact splash now draws the block-art wordmark on any interactive terminal wide enough to hold it, and the <code>bernstein run</code> startup banner is routed through it. Non-interactive output (CI, pipes) keeps the terse form.</li>
<li><strong><code>bernstein run --idle</code> stays on the mock adapter (#2741).</strong> The orchestrator subprocess overrode the explicit adapter with the seed&rsquo;s <code>cli</code> field, and since <code>cli</code> defaults to <code>auto</code>, any workspace with a <code>bernstein.yaml</code> silently discarded the <code>mock</code> override that <code>--idle</code> sets. Idle runs then spawned real coding agents, which failed provider authentication, tripped the adapter health monitor, and left every task failed. An explicit <code>--adapter</code> or <code>BERNSTEIN_ADAPTER</code> choice now takes precedence over the seed <code>cli</code>, mirroring the existing model-resolution rule; the seed value is used only when no adapter was passed explicitly.</li>
<li><strong>The internal-LLM preflight notice is emitted once and reworded (#2742).</strong> The hint was logged on every seed construction, and the seed is parsed twice during <code>gui serve</code>, so operators saw it twice per process. It is now emitted at most once per process, and the wording states the fact and both remedies without alarmist phrasing.</li>
</ul>
]]></content:encoded></item><item><title>Muninn Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/muninn-security-scanner/</link><pubDate>Mon, 20 Jul 2026 23:17:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/muninn-security-scanner/</guid><description>Version updated for https://github.com/skaldlab/muninn to version v0.3.5.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Muninn is an open-source security scanner that integrates multiple best-in-class tools into a single workflow, automating security checks and reporting unified findings as GitHub PR comments, SARIF uploads, and structured JSON. It normalizes scanner outputs, collapses duplicate findings across different scanners, and provides attribution for each scan, improving visibility and reliability in CI/CD pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/skaldlab/muninn">https://github.com/skaldlab/muninn</a></strong> to version <strong>v0.3.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/muninn-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Muninn</strong> is an open-source security scanner that integrates multiple best-in-class tools into a single workflow, automating security checks and reporting unified findings as GitHub PR comments, SARIF uploads, and structured JSON. It normalizes scanner outputs, collapses duplicate findings across different scanners, and provides attribution for each scan, improving visibility and reliability in CI/CD pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="changelog">Changelog</h1>
<h2 id="035---2026-07-20">[0.3.5] - 2026-07-20</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>Docker image scanner updates: semgrep 1.170.0, zizmor 1.27.0 (checkov
remains at 3.2.531 pending aiohttp cap lift).</li>
</ul>
<h2 id="034---2026-07-04">[0.3.4] - 2026-07-04</h2>
<h3 id="changed-1">Changed</h3>
<ul>
<li>Docker image scanner updates: osv-scanner 2.4.0, trivy 0.72.0, semgrep
1.168.0, zizmor 1.26.1 (checkov remains at 3.2.531 pending aiohttp cap lift).</li>
</ul>
<h2 id="033---2026-06-17">[0.3.3] - 2026-06-17</h2>
<h3 id="changed-2">Changed</h3>
<ul>
<li>Trivy default severity is now all levels (<code>UNKNOWN</code> through <code>CRITICAL</code>) instead
of <code>CRITICAL</code> and <code>HIGH</code> only. osv-scanner and trivy now overlap on
medium/low advisories by default so cross-scanner dedup and <code>Detected by</code>
work without extra config. Consumers can narrow the Trivy scan with
<code>scanners.trivy.severity</code>; <code>fail-on</code> still controls which findings fail the run.</li>
</ul>
<h2 id="032---2026-06-16">[0.3.2] - 2026-06-16</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Suppressions with <code>tool</code> and/or <code>rule-id</code> are now applied. Previously only <code>id</code>
(path substring) and <code>fingerprint</code> matchers worked; tool+rule-id entries
parsed from <code>muninn.yml</code> but silently no-op&rsquo;d.</li>
</ul>
<h2 id="031---2026-06-16">[0.3.1] - 2026-06-16</h2>
<h3 id="fixed-1">Fixed</h3>
<ul>
<li>Poutine v1.x JSON parsing: findings from poutine 1.1.6+ (<code>rule_id</code>, <code>meta</code>,
<code>rules</code>, <code>blobshas</code>) now populate title, rule, and file in PR comments instead
of empty shells (<code>File: :0</code>, `Rule: ``) (#41).</li>
<li>Actionlint PR comments: fall back to <code>kind</code> (e.g. <code>expression</code>) when
<code>rule.name</code> is absent; omit empty Rule lines.</li>
<li>Poutine injection findings: render <code>injection_sources</code> as formatted
<strong>Sources</strong> instead of plain <code>meta.details</code> text.</li>
</ul>
<h3 id="changed-3">Changed</h3>
<ul>
<li>PR comment layout: shared field helpers; non-dependency findings follow
File → Rule → optional extras → description; single-scanner dependency
findings use <strong>File</strong> instead of a redundant <strong>Source</strong> line.</li>
</ul>
<h2 id="030---2026-06-16">[0.3.0] - 2026-06-16</h2>
<h3 id="added">Added</h3>
<ul>
<li>Cross-scanner deduplication by advisory id: findings that report the same
CVE/GHSA for the same package from different scanners (e.g. OSV-Scanner from a
lockfile and Trivy from a container layer) are now collapsed into a single
finding. The contributing scanners are recorded in a new <code>detected_by</code> field
(surfaced in the JSON report, the PR comment&rsquo;s &ldquo;Detected by&rdquo; line, and a
<code>detectedBy</code> SARIF result property). A CVE is preferred over GHSA so the same
vulnerability converges on one id across scanners (#27).</li>
<li>Richer dependency finding rendering: aggregated dependency findings now appear
under a neutral <code>[dependency]</code> heading (instead of a single scanner&rsquo;s name)
with <code>Package</code>, <code>Advisory</code> (including the shared CVE), <code>Detected by</code>, and a
<code>Sources</code> list showing where each scanner observed it. A new <code>sources</code> field on
the finding (per-scanner <code>tool</code> + <code>file</code>) backs the JSON report (#27).</li>
</ul>
<h3 id="fixed-2">Fixed</h3>
<ul>
<li>PR comment rendering: scanner descriptions are flattened to a single line and
their Markdown (code fences, headings) neutralized, so an unbalanced ``` fence
can no longer swallow later findings and the footer into a code block.</li>
</ul>
<h2 id="020---2026-06-15">[0.2.0] - 2026-06-15</h2>
<p>Supply-chain hardening for the scanner image and signed, verifiable releases
(closes #30).</p>
<h3 id="added-1">Added</h3>
<ul>
<li>Pinned every bundled binary scanner to an exact version with SHA256 checksum
verification in the Docker image — gitleaks, zizmor, actionlint, poutine,
osv-scanner, trivy (#31)</li>
<li>Hash-locked the pip-installed scanners (semgrep, checkov, zizmor) via a fully
pinned, multi-arch <code>requirements-scanners.txt</code> installed with
<code>pip --require-hashes</code> (#33)</li>
<li>Renovate configuration to auto-PR scanner version bumps, with a CI job that
refreshes the pinned checksums (#32)</li>
<li>Keyless (OIDC) cosign signing of the published container image and of the
release binary checksums (Sigstore bundle <code>checksums.txt.sigstore.json</code>) (#34)</li>
<li>SBOM (SPDX) attached to every release and as an image attestation (#34)</li>
<li>Max-mode SLSA build provenance attestation on the container image (#34)</li>
<li>&ldquo;Verifying releases&rdquo; instructions in the README (#34)</li>
</ul>
<h3 id="changed-4">Changed</h3>
<ul>
<li>Pinned checkov to 3.2.531 (from 3.3.1) so its dependency tree resolves the
patched aiohttp 3.14.1 and drops the unfixable python-ecdsa Minerva
dependency that checkov 3.3.x introduced. Revisit when a newer checkov lifts
its <code>aiohttp&lt;3.14</code> cap (#33)</li>
</ul>
<h2 id="010---2026-06-14">[0.1.0] - 2026-06-14</h2>
<h3 id="added-2">Added</h3>
<ul>
<li>8 security scanners: gitleaks, zizmor, actionlint, poutine,
semgrep, osv-scanner, trivy, checkov</li>
<li>Unified Finding schema with fingerprinting</li>
<li>Three output formats: SARIF 2.1.0, JSON, GitHub PR comment</li>
<li>GitHub Action with outputs</li>
<li>Config-driven scanner behavior via muninn.yml</li>
<li>Suppression management with expiry dates</li>
<li>90%+ test coverage enforced in CI</li>
<li>Integration tests with real scanner binaries</li>
<li>Self-scan: Muninn scans itself on every PR</li>
</ul>
<p>Built by Skald Lab — skaldlab.dev</p>
]]></content:encoded></item><item><title>Cloudflare API Shield Upload</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/cloudflare-api-shield-upload/</link><pubDate>Mon, 20 Jul 2026 23:16:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/cloudflare-api-shield-upload/</guid><description>Version updated for https://github.com/SocksTheWolf/cloudflare-upload-spec to version v1.1.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of uploading OpenAPI specifications to Cloudflare API Shield. It allows users to upload their specifications without manual intervention, which can save time and improve efficiency. The action provides parameters for specifying the zone ID, file name, and other options to customize the upload process. By using this action in a CI/CD pipeline, developers can ensure that their API specifications are up-to-date and available on Cloudflare’s platform automatically.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SocksTheWolf/cloudflare-upload-spec">https://github.com/SocksTheWolf/cloudflare-upload-spec</a></strong> to version <strong>v1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cloudflare-api-shield-upload">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of uploading OpenAPI specifications to Cloudflare API Shield. It allows users to upload their specifications without manual intervention, which can save time and improve efficiency. The action provides parameters for specifying the zone ID, file name, and other options to customize the upload process. By using this action in a CI/CD pipeline, developers can ensure that their API specifications are up-to-date and available on Cloudflare&rsquo;s platform automatically.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Turns out local actions doesn&rsquo;t rebuild the project, so the first build was a failure. Nice.</p>
]]></content:encoded></item><item><title>Pipr Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/pipr-review/</link><pubDate>Mon, 20 Jul 2026 23:16:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/pipr-review/</guid><description>Version updated for https://github.com/somus/pipr to version v0.5.0.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Pipr is a code review tool that uses AI to analyze and generate structured comments in repositories. It automates the process of reviewing pull requests, issues, and comments, providing insights into potential security vulnerabilities, dependencies risks, and other issues. By keeping the review logic in the repository, Pipr ensures consistency and traceability of reviews across different code hosts. The tool supports integration with GitHub, GitLab, Azure DevOps Services, and Bitbucket Cloud, using provider adapters to maintain a neutral configuration format.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somus/pipr">https://github.com/somus/pipr</a></strong> to version <strong>v0.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pipr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Pipr is a code review tool that uses AI to analyze and generate structured comments in repositories. It automates the process of reviewing pull requests, issues, and comments, providing insights into potential security vulnerabilities, dependencies risks, and other issues. By keeping the review logic in the repository, Pipr ensures consistency and traceability of reviews across different code hosts. The tool supports integration with GitHub, GitLab, Azure DevOps Services, and Bitbucket Cloud, using provider adapters to maintain a neutral configuration format.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="050-2026-07-20"><a href="https://github.com/somus/pipr/compare/v0.4.3...v0.5.0">0.5.0</a> (2026-07-20)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>cli:</strong> version local review JSON output (<a href="https://github.com/somus/pipr/issues/101">#101</a>) (<a href="https://github.com/somus/pipr/commit/312b31e54f325befa3b67da7a1e4941d8c101508">312b31e</a>)</li>
<li><strong>config:</strong> add explicit memory curation (<a href="https://github.com/somus/pipr/issues/102">#102</a>) (<a href="https://github.com/somus/pipr/commit/30f8b01cbb8d5f7457eb11f8fdbf5d2aeacbb895">30f8b01</a>)</li>
<li><strong>runtime:</strong> add run results and webhook history (<a href="https://github.com/somus/pipr/issues/106">#106</a>) (<a href="https://github.com/somus/pipr/commit/1aaed2ba238df9bdf4fc133b204ac260eaa2a8ed">1aaed2b</a>)</li>
<li><strong>sdk:</strong> expose review run context (<a href="https://github.com/somus/pipr/issues/107">#107</a>) (<a href="https://github.com/somus/pipr/commit/9bc33ed6b338575a242f073995bcf9d12b9836de">9bc33ed</a>)</li>
<li>stabilize review outputs and release packages (<a href="https://github.com/somus/pipr/issues/104">#104</a>) (<a href="https://github.com/somus/pipr/commit/a25b6bc0e85199d6381b43a31eb8c1943a50e7f9">a25b6bc</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>runtime:</strong> bound diff manifest construction (<a href="https://github.com/somus/pipr/issues/99">#99</a>) (<a href="https://github.com/somus/pipr/commit/9bb367a5d2cd9392e5e5e7fc858eb2ade9e20edd">9bb367a</a>)</li>
<li><strong>sdk:</strong> harden public runtime boundaries (<a href="https://github.com/somus/pipr/issues/103">#103</a>) (<a href="https://github.com/somus/pipr/commit/d1f45c638f24f8fe3e69934b7c10d916cc2ab83d">d1f45c6</a>)</li>
</ul>
<h3 id="miscellaneous-chores">Miscellaneous Chores</h3>
<ul>
<li>release 0.5.0 (<a href="https://github.com/somus/pipr/commit/4656539e7260294675f2a3ad9688403519f6c07a">4656539</a>)</li>
</ul>
]]></content:encoded></item><item><title>stackql-exec</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/stackql-exec/</link><pubDate>Mon, 20 Jul 2026 23:14:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/stackql-exec/</guid><description>Version updated for https://github.com/stackql/stackql-exec to version v2.4.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 11 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the execution of stackql queries within a GitHub workflow. It supports various authentication methods and provides options for querying, data processing, and output format customization. Key features include handling inline queries, query files with external variables, and support for JSON/JSONnet data preprocessing. The action simplifies integration of stackql operations into CI/CD pipelines, making it easier to manage cloud resource configurations and validations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stackql/stackql-exec">https://github.com/stackql/stackql-exec</a></strong> to version <strong>v2.4.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>11</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/stackql-exec">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the execution of stackql queries within a GitHub workflow. It supports various authentication methods and provides options for querying, data processing, and output format customization. Key features include handling inline queries, query files with external variables, and support for JSON/JSONnet data preprocessing. The action simplifies integration of stackql operations into CI/CD pipelines, making it easier to manage cloud resource configurations and validations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/stackql/stackql-exec/compare/v2.3.1...v2.4.0">https://github.com/stackql/stackql-exec/compare/v2.3.1...v2.4.0</a></p>
]]></content:encoded></item><item><title>Tenzai Test</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/tenzai-test/</link><pubDate>Mon, 20 Jul 2026 23:13:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/tenzai-test/</guid><description>Version updated for https://github.com/TenzaiLtd/tenzai-github-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Tenzai Test GitHub Action automates the process of triggering an AI-powered security test on a deployed application after a successful CI/CD pipeline. It checks if the deployment is a valid step in the workflow and initiates a commit-diff test against an existing Tenzai application. The action provides real-time feedback through the Tenzai GitHub App, which posts a check run with the results of the security scan upon completion.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TenzaiLtd/tenzai-github-action">https://github.com/TenzaiLtd/tenzai-github-action</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tenzai-test">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Tenzai Test GitHub Action automates the process of triggering an AI-powered security test on a deployed application after a successful CI/CD pipeline. It checks if the deployment is a valid step in the workflow and initiates a commit-diff test against an existing Tenzai application. The action provides real-time feedback through the Tenzai GitHub App, which posts a check run with the results of the security scan upon completion.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ENG-5087: Guard compatibility-sensitive dependency upgrades by @Dor256 in <a href="https://github.com/TenzaiLtd/tenzai-github-action/pull/4">https://github.com/TenzaiLtd/tenzai-github-action/pull/4</a></li>
<li>Bump prettier from 3.8.1 to 3.9.4 in the npm group by @dependabot[bot] in <a href="https://github.com/TenzaiLtd/tenzai-github-action/pull/5">https://github.com/TenzaiLtd/tenzai-github-action/pull/5</a></li>
<li>Bump prettier from 3.9.4 to 3.9.5 in the npm group by @dependabot[bot] in <a href="https://github.com/TenzaiLtd/tenzai-github-action/pull/7">https://github.com/TenzaiLtd/tenzai-github-action/pull/7</a></li>
<li>Bump actions/setup-node from 6.4.0 to 7.0.0 in the github-actions group by @dependabot[bot] in <a href="https://github.com/TenzaiLtd/tenzai-github-action/pull/6">https://github.com/TenzaiLtd/tenzai-github-action/pull/6</a></li>
<li>ENG-5582: Send repository slug from GitHub Action by @Dor256 in <a href="https://github.com/TenzaiLtd/tenzai-github-action/pull/8">https://github.com/TenzaiLtd/tenzai-github-action/pull/8</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/TenzaiLtd/tenzai-github-action/compare/v1.0.0...v1.0.1">https://github.com/TenzaiLtd/tenzai-github-action/compare/v1.0.0...v1.0.1</a></p>
]]></content:encoded></item><item><title>Keep Node Current</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/keep-node-current/</link><pubDate>Mon, 20 Jul 2026 23:12:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/keep-node-current/</guid><description>Version updated for https://github.com/TimothyJones/github-action-keep-node-current to version v1.0.2.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action synchronizes Node.js versions used across the repository with the official Node.js release schedule, updating CI matrices, single-version pins, .nvmrc, and package.json files. It automatically detects and removes end-of-life major versions and adds new ones when necessary, ensuring all declared versions are compatible with the current schedule. The action creates separate commits for each change (drop or add) and updates the PR title accordingly.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TimothyJones/github-action-keep-node-current">https://github.com/TimothyJones/github-action-keep-node-current</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/keep-node-current">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action synchronizes Node.js versions used across the repository with the official Node.js release schedule, updating CI matrices, single-version pins, <code>.nvmrc</code>, and <code>package.json</code> files. It automatically detects and removes end-of-life major versions and adds new ones when necessary, ensuring all declared versions are compatible with the current schedule. The action creates separate commits for each change (drop or add) and updates the PR title accordingly.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Bug fix: pushing could fail with <code>Duplicate header: &quot;Authorization&quot;</code> when <code>actions/checkout</code> had persisted more than one credential header. The action now clears all persisted <code>extraheader</code> entries and authenticates with a single one from the supplied token.</p>
<p>Recommended for all users. <code>@v1</code> now points here.</p>
]]></content:encoded></item><item><title>grype_me</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/grype_me/</link><pubDate>Mon, 20 Jul 2026 23:11:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/grype_me/</guid><description>Version updated for https://github.com/TomTonic/grype_me to version v1.3.18-release.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the scanning of project dependencies and vulnerabilities using the latest Grype database. It provides a simple interface to scan repositories, container images, directories, or SBOMs, generating detailed reports and badges that can be used in READMEs. The action is designed to be lightweight and fast, leveraging pre-downloaded databases to speed up vulnerability scans compared to installing Grype during each run.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TomTonic/grype_me">https://github.com/TomTonic/grype_me</a></strong> to version <strong>v1.3.18-release</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/grype_me">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the scanning of project dependencies and vulnerabilities using the latest Grype database. It provides a simple interface to scan repositories, container images, directories, or SBOMs, generating detailed reports and badges that can be used in READMEs. The action is designed to be lightweight and fast, leveraging pre-downloaded databases to speed up vulnerability scans compared to installing Grype during each run.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v1318-release">v1.3.18-release</h1>
<h2 id="source-code-updates">Source Code Updates</h2>
<p>None. No Go module, Go toolchain, or Dockerfile <em>base image tag</em> changes in this release — only a digest refresh of the already-current <code>golang:1.26.5-bookworm</code> build stage (Debian point-release rebuild, same Go version).</p>
<h2 id="ci-updates">CI Updates</h2>
<ul>
<li>Bumped GitHub Actions used in this repository&rsquo;s own workflows: <code>actions/checkout</code> v7.0.0 → v7.0.1, <code>actions/setup-go</code> v6.5.0 → v7.0.0, <code>actions/setup-python</code> v6.3.0 → v7.0.0, <code>github/codeql-action</code> v4.37.0 → v4.37.1.
<ul>
<li><code>actions/setup-go</code> v7 and <code>actions/setup-python</code> v7 migrate to ESM internally and now require GitHub Actions runner v2.327.1 or later; this only affects how this repository&rsquo;s own CI executes and has no effect on consumers of the <code>grype_me</code> action itself.</li>
<li><code>actions/checkout</code> v7.0.1 is a minor point release on top of the pull-request-target/fork-checkout hardening already shipped in v7.0.0 (introduced in the previous release); it adds small fixes (safer handling of the &ldquo;unsafe PR checkout&rdquo; opt-in default, stricter branch-name whitespace trimming, escaping of values passed to <code>git config --unset</code>). No CVE is associated with this point release.</li>
</ul>
</li>
<li>Refreshed the <code>golang:1.26.5-bookworm</code> build-stage image digest (routine upstream rebuild; Go version unchanged).</li>
<li>Updated the <code>platformdirs</code> Python dependency (used by the yamllint CI tooling) 4.10.0 → 4.10.1.</li>
</ul>
<h2 id="changed-behavior">Changed Behavior</h2>
<p>None.</p>
<h2 id="new-features">New Features</h2>
<p>None.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/TomTonic/grype_me/compare/v1.3.17-release...v1.3.18-release">https://github.com/TomTonic/grype_me/compare/v1.3.17-release...v1.3.18-release</a></p>
]]></content:encoded></item><item><title>GSC Indexer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/gsc-indexer/</link><pubDate>Mon, 20 Jul 2026 23:10:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/gsc-indexer/</guid><description>Version updated for https://github.com/toolsura/gsc-indexer to version v1.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action toolsura/gsc-indexer re-indexes URLs via the Google Search Console URL Inspection API. It automates the process of pushing blog pages into or refreshing them in the index when at least “site full user” rights are held on the property. The action can handle single URLs, batch files, and sitemaps, providing a way to track indexed vs not over time with -report/-diff. It is also published as a GitHub Action, enabling CI re-indexing of blog content directly from pushes to the repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/toolsura/gsc-indexer">https://github.com/toolsura/gsc-indexer</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gsc-indexer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>toolsura/gsc-indexer</code> re-indexes URLs via the Google Search Console URL Inspection API. It automates the process of pushing blog pages into or refreshing them in the index when at least &ldquo;site full user&rdquo; rights are held on the property. The action can handle single URLs, batch files, and sitemaps, providing a way to track indexed vs not over time with <code>-report</code>/<code>-diff</code>. It is also published as a GitHub Action, enabling CI re-indexing of blog content directly from pushes to the repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="gsc-indexer-v1--now-a-github-action">gsc-indexer v1 — now a GitHub Action</h2>
<p><code>gsc-indexer</code> is a CLI that submits URLs to Google Search Console&rsquo;s URL Inspection API to request (re)indexing — built by <a href="https://www.toolsura.com">ToolSura</a>, a privacy-first collection of free online tools.</p>
<h3 id="features">Features</h3>
<ul>
<li>Submit individual URLs, a <code>--urls</code> list, or a whole <code>--sitemap</code></li>
<li><code>--delay</code> between requests, <code>--quiet</code> mode, <code>--limit</code> to cap submissions</li>
<li><code>--dry-run</code> to preview, <code>--report</code> / <code>--diff</code> for change tracking</li>
<li>Docker-based GitHub Action — drop it into any CI workflow</li>
</ul>
<h3 id="why">Why</h3>
<p>Stop manually pinging the GSC console after every deploy. Add the action to your workflow and your new URLs get inspected automatically.</p>
<p>Learn more and read the full guides on the <a href="https://www.toolsura.com/blog/">ToolSura blog</a>.</p>
]]></content:encoded></item><item><title>AWS CDK Diff PR Commenter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/aws-cdk-diff-pr-commenter/</link><pubDate>Mon, 20 Jul 2026 23:09:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/aws-cdk-diff-pr-commenter/</guid><description>Version updated for https://github.com/towardsthecloud/aws-cdk-diff-pr-commenter to version v1.5.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 6 repositories.
Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically posts the output of cdk diff as a comment on Pull Requests, helping teams review infrastructure changes directly within their PR workflow. It updates existing comments and supports custom headers for better organization in multi-stack setups, parsing and highlighting IAM statement changes, Security Group changes, Parameters, and Resources.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/towardsthecloud/aws-cdk-diff-pr-commenter">https://github.com/towardsthecloud/aws-cdk-diff-pr-commenter</a></strong> to version <strong>v1.5.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>6</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aws-cdk-diff-pr-commenter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically posts the output of <code>cdk diff</code> as a comment on Pull Requests, helping teams review infrastructure changes directly within their PR workflow. It updates existing comments and supports custom headers for better organization in multi-stack setups, parsing and highlighting IAM statement changes, Security Group changes, Parameters, and Resources.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="150-2026-07-20"><a href="https://github.com/towardsthecloud/github-actions-builder/compare/v1.4.0...v1.5.0">1.5.0</a> (2026-07-20)</h2>
<h3 id="features">Features</h3>
<ul>
<li>add pnpm workspace configuration and update TypeScript settings (<a href="https://github.com/towardsthecloud/github-actions-builder/commit/5a03822eaf4d988f7b2ed48c92d519f7cbaa68e4">5a03822</a>)</li>
<li>integrate Dependabot and Mergify for automated dependency management (<a href="https://github.com/towardsthecloud/github-actions-builder/commit/0e249c82318d470240a03332b3bac18e4a8b63cc">0e249c8</a>)</li>
<li>update workflows to use self-hosted runners with arm64, fargate, and small labels (<a href="https://github.com/towardsthecloud/github-actions-builder/commit/15ce06a86a03f995aafe21ba2da71872d819fc69">15ce06a</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>update release workflow triggers to only activate on changes in src/ and build directories (<a href="https://github.com/towardsthecloud/github-actions-builder/commit/008a4ed4906d107d187264932a9389dafa365b8f">008a4ed</a>)</li>
<li>update resource change handling in parsePlanfileJSON function (<a href="https://github.com/towardsthecloud/github-actions-builder/commit/f34ee6785782a4ef2858a9dd40917c3d4a646dc5">f34ee67</a>)</li>
</ul>
]]></content:encoded></item><item><title>Terraform Plan PR Commenter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/terraform-plan-pr-commenter/</link><pubDate>Mon, 20 Jul 2026 23:08:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/terraform-plan-pr-commenter/</guid><description>Version updated for https://github.com/towardsthecloud/terraform-plan-pr-commenter to version v1.5.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 2 repositories.
Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of posting the output of terraform plan as a comment on Pull Requests, helping teams review infrastructure changes directly within their workflow. It supports custom headers for better organization and works with binary plan files for accurate change detection. Additionally, it provides cost impact analysis through CloudBurn, a third-party app that integrates seamlessly with GitHub workflows to provide comprehensive insights into infrastructure changes before they are applied.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/towardsthecloud/terraform-plan-pr-commenter">https://github.com/towardsthecloud/terraform-plan-pr-commenter</a></strong> to version <strong>v1.5.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>2</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/terraform-plan-pr-commenter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of posting the output of <code>terraform plan</code> as a comment on Pull Requests, helping teams review infrastructure changes directly within their workflow. It supports custom headers for better organization and works with binary plan files for accurate change detection. Additionally, it provides cost impact analysis through CloudBurn, a third-party app that integrates seamlessly with GitHub workflows to provide comprehensive insights into infrastructure changes before they are applied.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="150-2026-07-20"><a href="https://github.com/towardsthecloud/github-actions-builder/compare/v1.4.0...v1.5.0">1.5.0</a> (2026-07-20)</h2>
<h3 id="features">Features</h3>
<ul>
<li>add pnpm workspace configuration and update TypeScript settings (<a href="https://github.com/towardsthecloud/github-actions-builder/commit/5a03822eaf4d988f7b2ed48c92d519f7cbaa68e4">5a03822</a>)</li>
<li>integrate Dependabot and Mergify for automated dependency management (<a href="https://github.com/towardsthecloud/github-actions-builder/commit/0e249c82318d470240a03332b3bac18e4a8b63cc">0e249c8</a>)</li>
<li>update workflows to use self-hosted runners with arm64, fargate, and small labels (<a href="https://github.com/towardsthecloud/github-actions-builder/commit/15ce06a86a03f995aafe21ba2da71872d819fc69">15ce06a</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>update release workflow triggers to only activate on changes in src/ and build directories (<a href="https://github.com/towardsthecloud/github-actions-builder/commit/008a4ed4906d107d187264932a9389dafa365b8f">008a4ed</a>)</li>
<li>update resource change handling in parsePlanfileJSON function (<a href="https://github.com/towardsthecloud/github-actions-builder/commit/f34ee6785782a4ef2858a9dd40917c3d4a646dc5">f34ee67</a>)</li>
</ul>
]]></content:encoded></item><item><title>TrustBeat Anchor — qualified EU timestamps</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/trustbeat-anchor-qualified-eu-timestamps/</link><pubDate>Mon, 20 Jul 2026 23:07:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/trustbeat-anchor-qualified-eu-timestamps/</guid><description>Version updated for https://github.com/TrustBeat/anchor-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action anchors release artifacts with an eIDAS-qualified timestamp, providing court-grade evidence of artifact existence and integrity. It supports batch processing, secure file hashing, and independent verification through Merkle inclusion proofs and RFC 3161 tokens. The action is designed for use in CI/CD pipelines to ensure regulatory compliance and legal evidence generation without relying on a self-run Timestamping Authority (TSA).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TrustBeat/anchor-action">https://github.com/TrustBeat/anchor-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/trustbeat-anchor-qualified-eu-timestamps">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action anchors release artifacts with an eIDAS-qualified timestamp, providing court-grade evidence of artifact existence and integrity. It supports batch processing, secure file hashing, and independent verification through Merkle inclusion proofs and RFC 3161 tokens. The action is designed for use in CI/CD pipelines to ensure regulatory compliance and legal evidence generation without relying on a self-run Timestamping Authority (TSA).</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Legal proof of <em>when</em>, in one YAML block.</strong> Anchor your CI artifacts with an eIDAS-<strong>qualified</strong> timestamp — the only kind <em>presumed valid in court</em> across all 27 EU member states (eIDAS Art. 41). Audit-grade evidence for NIS2 / DORA, with no QTSP contract.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">name</span>: <span style="color:#ae81ff">Anchor release artifacts</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">TrustBeat/anchor-action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.TRUSTBEAT_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">files</span>: |<span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">      dist/*.tar.gz</span>
</span></span></code></pre></div><p>Free tier — 100 anchors/month, no card: <strong><a href="https://trustbeat.eu/register">trustbeat.eu/register</a></strong>.</p>
<h3 id="what-it-does">What it does</h3>
<ul>
<li>⚖️ <strong>Court-grade evidence</strong> — qualified timestamps from EU Trusted List providers, not a self-run TSA</li>
<li>🛡️ <strong>NIS2 / DORA audit evidence</strong> — prove artifacts, SBOMs and reports existed unmodified at a point in time</li>
<li>🔒 <strong>Nothing leaves your runner</strong> — SHA-256 computed locally; only the 64-hex digest is transmitted</li>
<li>🔍 <strong>Independently verifiable</strong> — Merkle inclusion proof + RFC 3161 token, verifiable offline without trusting TrustBeat</li>
</ul>
<blockquote>
<p><strong>Not a signing tool.</strong> Sigstore/Cosign prove <em>who</em> built an artifact; TrustBeat proves <em>when</em> it existed, with EU legal standing. The two compose.</p>
</blockquote>
<h3 id="inputs">Inputs</h3>
<p><code>api-key</code> (required), <code>files</code> (required), plus optional <code>description</code>, <code>client-ref</code>, <code>wait</code>, <code>api-url</code>. See the <a href="https://github.com/TrustBeat/anchor-action#inputs">README</a>.</p>
<h3 id="outputs">Outputs</h3>
<p><code>results</code> (JSON array of <code>{file, hash, id, verify_url, badge_url}</code>) and <code>ids</code>.</p>
<p>Pure bash + curl composite action. MIT licensed.</p>
]]></content:encoded></item><item><title>Install bashunit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/install-bashunit/</link><pubDate>Mon, 20 Jul 2026 23:06:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/install-bashunit/</guid><description>Version updated for https://github.com/TypedDevs/bashunit to version 0.42.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The bashunit GitHub Action is a lightweight, fast testing framework for Bash scripts. It provides numerous assertions, spies, mocks, data providers, and snapshots to simplify testing and improve developer experience. The action supports Bash 3.0+ and can be installed with a simple script and used to test scripts in your project.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TypedDevs/bashunit">https://github.com/TypedDevs/bashunit</a></strong> to version <strong>0.42.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-bashunit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The bashunit GitHub Action is a lightweight, fast testing framework for Bash scripts. It provides numerous assertions, spies, mocks, data providers, and snapshots to simplify testing and improve developer experience. The action supports Bash 3.0+ and can be installed with a simple script and used to test scripts in your project.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-bug-fixes">🐛 Bug Fixes</h2>
<ul>
<li>A failing <code>set_up_before_script</code>/<code>set_up</code> now fails every test in the file with the hook&rsquo;s error, keeps the totals consistent, and lets the suite continue — a strict test file can no longer abort the whole run mid-suite (#836)</li>
<li>Run-mode flags (<code>--parallel</code>, <code>--simple</code>, <code>--strict</code>, <code>--retry</code>, <code>--seed</code>, report paths, …) no longer leak through the environment into nested bashunit runs, so a script under test that calls bashunit gets default behavior; <code>BASHUNIT_*=…</code> configuration is unchanged (#834, #837)</li>
<li><code>install.sh</code> fails fast: a failed download, clone, build or copy aborts with a clear error instead of reporting success, and a failed beta clone no longer runs <code>build.sh</code> in the caller&rsquo;s directory (#840)</li>
<li><code>./build.sh --verify</code> exits non-zero when the built binary fails the suite, and the verification run no longer crashes mid-suite from tests resolving repo paths against the build folder (#834)</li>
<li><code>./bashunit bench</code> works again from a repository checkout (the dev entrypoint never sourced <code>src/benchmark.sh</code>) (#834)</li>
<li>Snapshot placeholders (<code>::ignore::</code>) now work on systems without perl; multi-line placeholders still need perl (#823)</li>
<li>Runs no longer leak a scratch directory under <code>$TMPDIR/bashunit/run/</code> — it is removed on exit, including <code>--version</code>/<code>--help</code>, subcommands and Ctrl-C (#811)</li>
<li><code>bashunit::helper::get_function_line_number</code> no longer disables <code>extdebug</code> for its caller (#808)</li>
<li><code>--test-timeout</code> no longer intermittently reports a fast test as timed out; the watchdog signals by pid and skips a test that already completed</li>
</ul>
<h2 id="-improvements">✨ Improvements</h2>
<ul>
<li><code>watch</code> subcommand no longer fails when neither <code>inotifywait</code> nor <code>fswatch</code> is installed — it falls back to pure-shell polling (interval via <code>BASHUNIT_WATCH_INTERVAL</code>, default <code>2</code>s) instead of exiting (#779)</li>
<li>Shell tab-completion scripts for bash and zsh under <code>completions/</code> (subcommands, <code>test</code> flags with value hints, assertion names), kept in sync by an anti-drift CI test (#778)</li>
<li><code>--rerun-failed</code> (<code>BASHUNIT_RERUN_FAILED</code>) replays only the previously failing tests, recorded in <code>.bashunit/last-failed</code>; composes with <code>--filter</code>/<code>--tag</code>/<code>--parallel</code> and falls back to the full suite when empty (add <code>.bashunit/</code> to <code>.gitignore</code>) (#776)</li>
<li>Optional nightly <code>coverage.yml</code> workflow publishes a shields.io coverage badge from <code>--coverage</code> over the unit suite; schedule/manual only, never gates merges (#754)</li>
<li><code>--jobs auto</code> / <code>-j auto</code> caps parallel concurrency at the CPU core count (portable across Linux/macOS/BSD); the default stays unlimited (#766)</li>
</ul>
<h2 id="-changes">🛠️ Changes</h2>
<ul>
<li><code>build.sh</code> hardened: runs under <code>set -euo pipefail</code>, derives the embed list from the entrypoint&rsquo;s <code>source</code> order (single source of truth), guards against duplicate embeds and missing doc markers, drops <code>eval</code>, and gates every build behind <code>bash -n</code> (#834)</li>
<li><code>bashunit doc</code> no longer forks an <code>echo | sed</code> pipe per line of the assertion docs: a single awk pass prints the same bytes in ~50ms instead of ~5s (#832)</li>
<li>Multi-file runs are no longer quadratic in file count; bashunit&rsquo;s own 63-file unit suite: ~64s -&gt; ~22s sequential, ~26s -&gt; ~7s parallel (#829)</li>
<li>Major performance work with no behaviour change (near fork-free hot paths, cached snapshot/<code>--tag</code> scans, single-pass failure rendering). On bash 3.2: 100x10 <code>assert_equals</code> ~1.50s -&gt; ~0.76s, 500 snapshot assertions ~7.5s -&gt; ~3.0s, 100 tagged tests ~2.92s -&gt; ~0.68s, acceptance suite ~61s -&gt; ~17s (#761-#764, #772-#775, #798, #801-#807, #809, #810, #813, #817)</li>
<li>Per-test timing now defaults to <code>auto</code> (<code>BASHUNIT_SHOW_EXECUTION_TIME=true|false|auto</code>): shown only when the clock is fork-free, avoiding <code>perl</code> forks on bash 3.2; <code>--profile</code>/<code>--verbose</code>/reports still measure (see <code>adrs/adr-008-auto-skip-per-test-timing.md</code>) (#765)</li>
<li><code>assert_equals</code>/<code>assert_same</code> failures with multiline values now render a git word-diff below the header (requires git, opt out with <code>BASHUNIT_NO_DIFF=true</code>, respects <code>--no-color</code>); machine reports keep the raw values (#777)</li>
</ul>
<h2 id="-contributors">👥 Contributors</h2>
<ul>
<li>@Chemaclass</li>
</ul>
<h2 id="checksum">Checksum</h2>
<p>SHA256: <code>a0e39761363d8b6876059cd5927cd4bed1b578be616c5490a8bf4102284a308c</code></p>
<p><strong>Full Changelog:</strong> <a href="https://github.com/TypedDevs/bashunit/compare/0.41.0...0.42.0">0.41.0&hellip;0.42.0</a></p>
]]></content:encoded></item><item><title>New Behavioral Health Practices Weekly</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/new-behavioral-health-practices-weekly/</link><pubDate>Mon, 20 Jul 2026 23:05:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/new-behavioral-health-practices-weekly/</guid><description>Version updated for https://github.com/unitedideas/behavioral-health-practice-leads-action to version v1.0.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action downloads and processes behavioral health practice leads from the CMS weekly file, providing a preview or full edition of up to 15 records. It supports free previews using a public dataset without an API token, or fully automated workflows with an Apify account and a token. The action handles states and can set a charge cap for each run.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/unitedideas/behavioral-health-practice-leads-action">https://github.com/unitedideas/behavioral-health-practice-leads-action</a></strong> to version <strong>v1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/new-behavioral-health-practices-weekly">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action downloads and processes behavioral health practice leads from the CMS weekly file, providing a preview or full edition of up to 15 records. It supports free previews using a public dataset without an API token, or fully automated workflows with an Apify account and a token. The action handles states and can set a charge cap for each run.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Adds a clearly disclosed $19 one-time direct CSV option alongside the existing cost-capped $9 Apify automation path. Preview users can now choose private browser delivery without an Apify account or keep the workflow-native route.</p>
]]></content:encoded></item><item><title>MIU PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/miu-pr-review/</link><pubDate>Mon, 20 Jul 2026 23:04:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/miu-pr-review/</guid><description>Version updated for https://github.com/vanducng/miu-cr to version v0.89.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary miu-cr is an AI code review tool that automates the process of reviewing staged changes, GitHub pull requests, and commits locally or in CI pipelines. It uses LLMs for deterministic analysis and outputs JSON envelopes on stdout, making it suitable for integration into various development workflows. The tool supports local reviews, GitHub PR reviews with inline comments, and can be used as a reusable action in CI pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vanducng/miu-cr">https://github.com/vanducng/miu-cr</a></strong> to version <strong>v0.89.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/miu-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>miu-cr is an AI code review tool that automates the process of reviewing staged changes, GitHub pull requests, and commits locally or in CI pipelines. It uses LLMs for deterministic analysis and outputs JSON envelopes on stdout, making it suitable for integration into various development workflows. The tool supports local reviews, GitHub PR reviews with inline comments, and can be used as a reusable action in CI pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="miu-cr-v0892">miu-cr v0.89.2</h2>
<p>AI code review for local changes and GitHub pull requests. Use it as a CLI, CI gate, or GitHub Action with your own LLM key.</p>
<h3 id="install">Install</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>curl -fsSL https://cr.miu.sh/install.sh | sh -s -- v0.89.2
</span></span><span style="display:flex;"><span>brew install vanducng/tap/miucr
</span></span><span style="display:flex;"><span>go install github.com/vanducng/miu-cr/cmd/miucr@v0.89.2
</span></span></code></pre></div><p>GitHub Action:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v6</span>
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">vanducng/miu-cr@v0.89.2</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span></code></pre></div><h3 id="common-commands">Common commands</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>miucr login --provider openai
</span></span><span style="display:flex;"><span>miucr review --staged
</span></span><span style="display:flex;"><span>miucr review --from main --to HEAD --gate high
</span></span><span style="display:flex;"><span>miucr review --pr owner/repo#123 --post
</span></span><span style="display:flex;"><span>miucr upgrade
</span></span></code></pre></div><p>Docs: <a href="https://cr.miu.sh">https://cr.miu.sh</a></p>
]]></content:encoded></item><item><title>mdship markdown check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/mdship-markdown-check/</link><pubDate>Mon, 20 Jul 2026 23:03:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/mdship-markdown-check/</guid><description>Version updated for https://github.com/verhas/mdship to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, mdship, is a command-line and MCP tool for manipulating markdown files. It automates tasks such as fixing heading levels, shifting headings up or down, inserting checksums, reflowing paragraphs, breaking lines at sentence boundaries, numbering headings, adding variables, generating tables of contents, including files, rendering Mermaid diagrams, and using template placeholders. The action ensures consistent content formatting and improves readability by maintaining a hierarchical structure and variable management throughout the markdown document.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/verhas/mdship">https://github.com/verhas/mdship</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mdship-markdown-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>mdship</code>, is a command-line and MCP tool for manipulating markdown files. It automates tasks such as fixing heading levels, shifting headings up or down, inserting checksums, reflowing paragraphs, breaking lines at sentence boundaries, numbering headings, adding variables, generating tables of contents, including files, rendering Mermaid diagrams, and using template placeholders. The action ensures consistent content formatting and improves readability by maintaining a hierarchical structure and variable management throughout the markdown document.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Check the integrity of a markdown document, missing heading, being up to date with the checksums.</p>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/vibgrate-scan/</link><pubDate>Mon, 20 Jul 2026 23:01:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.720.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action provides a local codebase intelligence tool that automatically analyzes a repository to generate a deterministic code graph, drift score, and ranked upgrade priorities. It helps developers understand their codebase’s dependencies, runtime lag, and EOL proximity, enabling them to identify potential issues and prioritize updates locally. The action runs on the user’s machine without requiring network calls or data leaving the repository unless explicitly pushed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.720.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action provides a local codebase intelligence tool that automatically analyzes a repository to generate a deterministic code graph, drift score, and ranked upgrade priorities. It helps developers understand their codebase&rsquo;s dependencies, runtime lag, and EOL proximity, enabling them to identify potential issues and prioritize updates locally. The action runs on the user&rsquo;s machine without requiring network calls or data leaving the repository unless explicitly pushed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20267204">Vibgrate CLI 2026.720.4</h1>
<p><em>Released 2026-07-20</em></p>
<p>This release of the vg command-line scanner includes significant performance improvements for symbol searches, fixes for path reporting on Windows, and enhancements to session statistics tracking. These changes aim to streamline the user experience and increase efficiency when working with large repositories.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="improved">Improved</h3>
<ul>
<li>vg serve session stats now count search_symbols toward estimated context-token savings.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>search_symbols literal results are no longer dropped on Windows when ripgrep is installed.</li>
<li>File paths are now reported with forward slashes on every platform.</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li>search_symbols is much faster on large repositories, with optimizations for exact lookups and parallel processing.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.720.3, interleaved on one runner against the pinned corpus (157 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>19127 count</td>
          <td>19127 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>7923 count</td>
          <td>7923 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.98 ratio</td>
          <td>0.98 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>614 ms</td>
          <td>621.20 ms</td>
      </tr>
  </tbody>
</table>
<p>No regressions against the previous release.</p>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.720.4">https://vibgrate.com/changelog/cli/2026.720.4</a></p>
]]></content:encoded></item><item><title>Pixtex — Render n8n Workflow</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/pixtex-render-n8n-workflow/</link><pubDate>Mon, 20 Jul 2026 23:00:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/pixtex-render-n8n-workflow/</guid><description>Version updated for https://github.com/VicegerentPrince/pixtex to version v0.1.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, pixtex, automates the rendering and hosting of n8n workflow diagrams. It allows users to convert n8n workflow JSON files into share-ready images that update automatically when the workflow changes. The action supports a variety of output formats and can be integrated into CI/CD pipelines to keep documentation up-to-date with the latest workflow configurations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VicegerentPrince/pixtex">https://github.com/VicegerentPrince/pixtex</a></strong> to version <strong>v0.1.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pixtex-render-n8n-workflow">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, pixtex, automates the rendering and hosting of n8n workflow diagrams. It allows users to convert n8n workflow JSON files into share-ready images that update automatically when the workflow changes. The action supports a variety of output formats and can be integrated into CI/CD pipelines to keep documentation up-to-date with the latest workflow configurations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VicegerentPrince/pixtex/compare/v0.1.5...v0.1.6">https://github.com/VicegerentPrince/pixtex/compare/v0.1.5...v0.1.6</a></p>
]]></content:encoded></item><item><title>Pixi-Pack Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/pixi-pack-action/</link><pubDate>Mon, 20 Jul 2026 22:59:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/pixi-pack-action/</guid><description>Version updated for https://github.com/Wytamma/pixi-pack-action to version v7.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Pixi-Pack Action automates the creation of cross-platform self-extracting binaries for pixi environments. It solves the problem of manually managing and distributing multiple versions of an environment across different platforms by providing a single, easy-to-use action that can be triggered on GitHub releases or workflow dispatches. The action supports macOS, Linux, and Windows and can be used to package environments created with Pixi, making it simpler for users to deploy and manage their applications in various environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Wytamma/pixi-pack-action">https://github.com/Wytamma/pixi-pack-action</a></strong> to version <strong>v7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pixi-pack-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Pixi-Pack Action automates the creation of cross-platform self-extracting binaries for pixi environments. It solves the problem of manually managing and distributing multiple versions of an environment across different platforms by providing a single, easy-to-use action that can be triggered on GitHub releases or workflow dispatches. The action supports macOS, Linux, and Windows and can be used to package environments created with Pixi, making it simpler for users to deploy and manage their applications in various environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Wytamma/pixi-pack-action/compare/v6...v7">https://github.com/Wytamma/pixi-pack-action/compare/v6...v7</a></p>
]]></content:encoded></item><item><title>DevSecOps Trust Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/devsecops-trust-gate/</link><pubDate>Mon, 20 Jul 2026 22:58:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/devsecops-trust-gate/</guid><description>Version updated for https://github.com/xkobxx/devsecops-dissertation to version v.1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The DevSecOps Trust Gate GitHub Action runs several security scanning tools like Bandit, Semgrep, pip-audit, Trivy, and Gitleaks against a repository to identify potential vulnerabilities. It aggregates these findings into one unified gate with a severity score per finding based on empirical precision data, allowing users to prioritize which issues are worth acting on. The action also provides an HTML dashboard as a build artifact for easy visualization of the scan results.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/xkobxx/devsecops-dissertation">https://github.com/xkobxx/devsecops-dissertation</a></strong> to version <strong>v.1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/devsecops-trust-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The DevSecOps Trust Gate GitHub Action runs several security scanning tools like Bandit, Semgrep, pip-audit, Trivy, and Gitleaks against a repository to identify potential vulnerabilities. It aggregates these findings into one unified gate with a severity score per finding based on empirical precision data, allowing users to prioritize which issues are worth acting on. The action also provides an HTML dashboard as a build artifact for easy visualization of the scan results.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Free scanners already exist. What&rsquo;s missing is trust: every vendor sells you a scan, but nobody publishes how often their own tool is wrong. Meanwhile per-seat pricing on the incumbents (Snyk, Semgrep Team, &hellip;) stacks up fast for a small team running more than one product.</p>
<p>This tool doesn&rsquo;t replace your scanners - it aggregates the free ones you already trust, and adds a confidence score per finding based on empirically measured precision, not vendor marketing.</p>
<table>
  <thead>
      <tr>
          <th></th>
          <th>Free</th>
          <th>Paid</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Bandit / Semgrep / pip-audit / Trivy / Gitleaks scan + aggregation</td>
          <td>✅</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Unified severity gate (fails the build on HIGH+, configurable)</td>
          <td>✅</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>HTML dashboard</td>
          <td>✅</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>Confidence score per finding (empirical precision, not a guess)</td>
          <td>—</td>
          <td>✅</td>
      </tr>
      <tr>
          <td>&ldquo;Act on these first&rdquo; ranked triage list</td>
          <td>—</td>
          <td>✅</td>
      </tr>
  </tbody>
</table>
<h2 id="flat-monthly-pricing-not-per-seat--one-price-regardless-of-team-size">Flat monthly pricing, not per-seat — one price regardless of team size.</h2>
<h2 id="quick-start">Quick Start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#75715e"># .github/workflows/security.yml</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">on</span>: [<span style="color:#ae81ff">push, pull_request]</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">scan</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on: ubuntu-latest   # required</span>: <span style="color:#ae81ff">Trivy/Gitleaks run as Docker container actions (Linux only)</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">&lt;owner&gt;/&lt;repo&gt;@&lt;version&gt;</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">target</span>: <span style="color:#ae81ff">.</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span><span style="display:flex;"><span>          <span style="color:#75715e"># license-key: ${{ secrets.TRUST_GATE_LICENSE }}   # paid tier only</span>
</span></span></code></pre></div><p>That&rsquo;s it - no separate install step, no manual scanner invocations. The dashboard is uploaded as a build artifact (<code>security-dashboard</code>) on every run.</p>
]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/cowork-harness/</link><pubDate>Mon, 20 Jul 2026 22:57:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary cowork-harness is a headless test harness for Claude Cowork skills that reproduces its observable runtime contract across many scenarios, without using the locked Desktop app. It supports both headless and CI environments by providing different fidelity tiers with varying requirements such as running inside Docker or Lima, and supports various platforms including macOS Apple Silicon and Linux.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v1.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>cowork-harness is a headless test harness for Claude Cowork skills that reproduces its observable runtime contract across many scenarios, without using the locked Desktop app. It supports both headless and CI environments by providing different fidelity tiers with varying requirements such as running inside Docker or Lima, and supports various platforms including macOS Apple Silicon and Linux.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong><code>critique</code> now accepts the <code>skill</code> flags a graded run needs — starting with uploads.</strong> A skill whose
whole job is &ldquo;here is a document, analyze it&rdquo; (cap table, pitch deck, financial model, transcript) could
not be critiqued at all: there was no way to attach the file, so the agent was asked to analyze a
document that was never there and then asked what confused it — you harvested a finding about the test
rig. <code>--upload</code>, <code>--folder</code>, <code>--plugin</code>, <code>--marketplace</code>/<code>--enable</code> (all repeatable), <code>--model</code> and
<code>--allow-missing-capability</code> now reach <strong>both</strong> spawned turns; that is forced, not stylistic, because
those paths are part of the session-origin key the reflection turn&rsquo;s <code>--resume</code> recomputes. <code>--label</code>,
<code>--timeout</code>, <code>--answer</code>/<code>--answer-policy</code>, <code>--on-unanswered</code> and the decider flags reach the graded turn
only. <code>--answer</code>/<code>--answer-policy</code> make <strong>gated</strong> skills critiquable for the first time — the inner spawn
has no TTY, so an unscripted gate previously killed the task turn before anything could be graded.
Anything that cannot work is refused <strong>with its reason</strong> rather than silently ignored:
<code>--session-id</code>/<code>--resume</code>, the <code>--repeat</code> family, <code>--ablate-skill</code>, and the rendering/preview flags.</li>
<li><strong><code>critique --prompt-file &lt;path&gt;</code></strong> — read the probe verbatim from a file, so a probe containing quotes,
<code>$</code> or newlines does not have to survive shell parsing.</li>
<li><strong>&ldquo;Attached inputs&rdquo; evidence section</strong> — upload filenames and sizes, plus connected-folder mount names,
never content. Without it the evaluator could not tell &ldquo;the agent said there was no file, and correctly
so&rdquo; from a confabulation.</li>
<li><strong>One source of truth for the <code>skill</code> flag surface</strong> (<code>src/run/skill-flag-surface.ts</code>), where each flag&rsquo;s
critique disposition is a <strong>required</strong> field, plus a parity guard that fails CI when a new <code>skill</code> flag
arrives without one. The old hand-rolled subset drifted silently — this repo&rsquo;s recurring bug shape.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>Repeating a single-valued <code>critique</code> flag is now a usage error (exit <code>2</code>) instead of silent
last-wins.</strong> <code>--upload</code>, <code>--folder</code>, <code>--plugin</code>, <code>--marketplace</code>, <code>--enable</code> and <code>--answer</code> accumulate —
repeating them is how you pass several. Everything else is single-valued, and <code>--prompt a --prompt b</code>
silently discarding a probe you typed is the class of no-op this command refuses on principle. Boolean
flags may still be repeated harmlessly. Documented in <code>critique --help</code> and
<a href="./docs/critique.md">docs/critique.md</a>.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong><code>critique --dotenv &lt;path&gt;</code> was documented but unreachable</strong> (shipped that way in 1.5.0). The
misplaced-global guard rejected the token after any subcommand, and the <code>--dotenv=x</code> form that slipped
past it then hit critique&rsquo;s exact-match parser as &ldquo;unknown flag&rdquo;. <code>critique</code> is now exempt from the guard
(<code>--run-dir</code> still has no per-command meaning and stays rejected everywhere), and a missing file fails
fast with critique&rsquo;s own error instead of surfacing later as an instrument-failure diagnostic.</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>release: 1.6.0 — critique skill-flag parity by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/58">https://github.com/yaniv-golan/cowork-harness/pull/58</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v1.5.0...v1.6.0">https://github.com/yaniv-golan/cowork-harness/compare/v1.5.0...v1.6.0</a></p>
]]></content:encoded></item><item><title>Kover Report Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/kover-report-action/</link><pubDate>Mon, 20 Jul 2026 22:56:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/kover-report-action/</guid><description>Version updated for https://github.com/yshrsmz/kover-report-action to version v3.1.5.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of generating and reporting code coverage from Kover XML reports in Kotlin/Android projects using multi-module support. It supports both command-based module discovery and glob pattern paths, allows configurable thresholds per module type and name, and integrates with PRs to provide automatic updates on coverage trends. The action also enables tracking coverage history for trend analysis.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yshrsmz/kover-report-action">https://github.com/yshrsmz/kover-report-action</a></strong> to version <strong>v3.1.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kover-report-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of generating and reporting code coverage from Kover XML reports in Kotlin/Android projects using multi-module support. It supports both command-based module discovery and glob pattern paths, allows configurable thresholds per module type and name, and integrates with PRs to provide automatic updates on coverage trends. The action also enables tracking coverage history for trend analysis.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>v3.1.5: PR #142 - chore(deps): update npm devdependencies to v4.1.10</p>
]]></content:encoded></item><item><title>Vibe-Guard-AICoding</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/vibe-guard-aicoding/</link><pubDate>Mon, 20 Jul 2026 22:55:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/vibe-guard-aicoding/</guid><description>Version updated for https://github.com/YUTAKONDO1205/VibeGuard to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary VibeGuard is a security scanner designed to detect common bugs in AI-generated code. It automates the detection of issues like missing input checks, hard-coded passwords, skipped login checks, and exceptions silently caught. The tool provides inline diagnostics in VS Code, scans code snippets in the browser, and blocks risky PRs in CI using GitHub Actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YUTAKONDO1205/VibeGuard">https://github.com/YUTAKONDO1205/VibeGuard</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibe-guard-aicoding">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>VibeGuard is a security scanner designed to detect common bugs in AI-generated code. It automates the detection of issues like missing input checks, hard-coded passwords, skipped login checks, and exceptions silently caught. The tool provides inline diagnostics in VS Code, scans code snippets in the browser, and blocks risky PRs in CI using GitHub Actions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps-dev): bump ovsx from 0.10.12 to 1.0.0 by @dependabot[bot] in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/36">https://github.com/YUTAKONDO1205/VibeGuard/pull/36</a></li>
<li>chore(deps-dev): bump @vscode/vsce from 3.9.1 to 3.9.2 by @dependabot[bot] in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/38">https://github.com/YUTAKONDO1205/VibeGuard/pull/38</a></li>
<li>chore(deps-dev): bump the typescript-tooling group with 2 updates by @dependabot[bot] in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/37">https://github.com/YUTAKONDO1205/VibeGuard/pull/37</a></li>
<li>chore(deps-dev): bump ovsx from 1.0.0 to 1.0.1 by @dependabot[bot] in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/42">https://github.com/YUTAKONDO1205/VibeGuard/pull/42</a></li>
<li>chore(deps-dev): bump @types/node from 20.19.42 to 20.19.43 in the typescript-tooling group by @dependabot[bot] in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/40">https://github.com/YUTAKONDO1205/VibeGuard/pull/40</a></li>
<li>chore(deps-dev): bump esbuild from 0.28.0 to 0.28.1 by @dependabot[bot] in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/41">https://github.com/YUTAKONDO1205/VibeGuard/pull/41</a></li>
<li>chore(deps): bump actions/checkout from 6 to 7 by @dependabot[bot] in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/43">https://github.com/YUTAKONDO1205/VibeGuard/pull/43</a></li>
<li>chore(deps-dev): bump the typescript-tooling group across 1 directory with 2 updates by @dependabot[bot] in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/44">https://github.com/YUTAKONDO1205/VibeGuard/pull/44</a></li>
<li>chore(deps-dev): bump ovsx from 1.0.1 to 1.0.2 by @dependabot[bot] in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/45">https://github.com/YUTAKONDO1205/VibeGuard/pull/45</a></li>
<li>chore(deps-dev): bump @types/chrome from 0.2.0 to 0.2.2 in the typescript-tooling group by @dependabot[bot] in <a href="https://github.com/YUTAKONDO1205/VibeGuard/pull/46">https://github.com/YUTAKONDO1205/VibeGuard/pull/46</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/YUTAKONDO1205/VibeGuard/compare/v0.1.3...v0.2.0">https://github.com/YUTAKONDO1205/VibeGuard/compare/v0.1.3...v0.2.0</a></p>
]]></content:encoded></item><item><title>Install The Hive Skill</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/install-the-hive-skill/</link><pubDate>Mon, 20 Jul 2026 22:54:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/install-the-hive-skill/</guid><description>Version updated for https://github.com/yuzuruu29/the-hive-skill to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Hive Skill is a protocol designed to handle multi-model execution in coding hosts. It automates structured handoffs, evidence rules, safety boundaries, and orchestration presets, ensuring that tasks are completed safely and efficiently. The protocol provides explicit stop conditions and bounded repair cycles, making it suitable for agentic coding agents like Claude Code, Codex, OpenCode, and generic workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yuzuruu29/the-hive-skill">https://github.com/yuzuruu29/the-hive-skill</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-the-hive-skill">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Hive Skill is a protocol designed to handle multi-model execution in coding hosts. It automates structured handoffs, evidence rules, safety boundaries, and orchestration presets, ensuring that tasks are completed safely and efficiently. The protocol provides explicit stop conditions and bounded repair cycles, making it suitable for agentic coding agents like Claude Code, Codex, OpenCode, and generic workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="030--machine-readable-protocol-and-adapter-conformance">[0.3.0] — Machine-Readable Protocol and Adapter Conformance</h2>
<h3 id="added">Added</h3>
<ul>
<li>Versioned JSON Schemas for HIVE protocol artifacts</li>
<li>Artifact and bundle validation CLI</li>
<li>Runtime capability negotiation contract</li>
<li>Adapter conformance levels and manifests</li>
<li>Portable <code>.hive-run</code> artifact bundle format</li>
<li>Negative, semantic, and mutation tests</li>
<li>Cross-runtime live-validation methodology</li>
<li>Generated adapter conformance report</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>Protocol, skill, schema, and artifact versions are tracked independently</li>
<li>JSON Schemas are the canonical source for field names and enums</li>
<li>Adapters now declare supported protocol versions and tested capabilities</li>
<li>Examples and conformance fixtures are schema-validated</li>
</ul>
<h3 id="compatibility">Compatibility</h3>
<ul>
<li>Existing Markdown workflows remain supported</li>
<li>v0.2.x artifacts can be migrated by adding protocol and run identifiers</li>
<li>Host-runtime execution and enforcement remain runtime-dependent</li>
</ul>
<p>This release preserves the project boundary established in v0.2.1: The Hive Skill is a portable orchestration protocol executed by a host runtime. Adapter support is currently structurally validated; no live runtime conformance is claimed.</p>
]]></content:encoded></item><item><title>AGENTS.md Lint (Schliff)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/agents.md-lint-schliff/</link><pubDate>Mon, 20 Jul 2026 22:53:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/agents.md-lint-schliff/</guid><description>Version updated for https://github.com/Zandereins/schliff to version v8.6.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the scoring of AGENTS.md files using Schliff, a tool that provides deterministic quality scores based on a versioned rubric. It helps ensure that AI instruction files remain consistent across different environments and tools by comparing them against an explicit evaluation standard. The action is designed to help identify and address issues in AI instruction files before they degrade over time, ensuring better performance and reliability of AI-driven tools.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Zandereins/schliff">https://github.com/Zandereins/schliff</a></strong> to version <strong>v8.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agents-md-lint-schliff">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the scoring of AGENTS.md files using Schliff, a tool that provides deterministic quality scores based on a versioned rubric. It helps ensure that AI instruction files remain consistent across different environments and tools by comparing them against an explicit evaluation standard. The action is designed to help identify and address issues in AI instruction files before they degrade over time, ensuring better performance and reliability of AI-driven tools.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong><code>check-commands</code></strong> — a deterministic CI gate that flags setup/build/test
commands in an <code>AGENTS.md</code>/<code>CLAUDE.md</code> that don&rsquo;t resolve to a real make
target, npm script, or path in the repo (exit 1 if dangling). Reuses the
<code>operational_coverage</code> command extractor (no scoring impact); false-positive
safe (unprovable absence → <code>unknown</code>, never <code>dangling</code>); live-hardened against
~70 real repos. schliff dogfoods it against its own <code>AGENTS.md</code> in CI. (#112)</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong><code>operational_coverage</code> object-first prohibitions</strong>, badge temp-dir leak, and
badge error caching (#110).</li>
</ul>
]]></content:encoded></item><item><title>GSC Opportunity Analyzer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/gsc-opportunity-analyzer/</link><pubDate>Mon, 20 Jul 2026 07:43:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/gsc-opportunity-analyzer/</guid><description>Version updated for https://github.com/demi-valerith/gsc-opportunity-analyzer to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action analyzes Google Search Console Performance CSV exports to identify SEO opportunities, such as striking-distance queries, site-relative CTR gaps, and rising demand. It helps prioritize operational work by providing evidence-ledger reports with priority scores and recommendations. The action supports Markdown, JSON, and CSV output formats and integrates with SEO Report Kit for additional insights.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/demi-valerith/gsc-opportunity-analyzer">https://github.com/demi-valerith/gsc-opportunity-analyzer</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gsc-opportunity-analyzer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action analyzes Google Search Console Performance CSV exports to identify SEO opportunities, such as striking-distance queries, site-relative CTR gaps, and rising demand. It helps prioritize operational work by providing evidence-ledger reports with priority scores and recommendations. The action supports Markdown, JSON, and CSV output formats and integrates with SEO Report Kit for additional insights.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First stable release.</p>
<ul>
<li>Analyze current and prior GSC Queries CSV exports plus an optional Pages export</li>
<li>Flag striking-distance queries, site-relative CTR gaps, rising demand, decay, and page opportunities</li>
<li>Export Markdown, JSON, or CSV from a zero-dependency Node CLI</li>
<li>Run the same deterministic engine as a Node 24 GitHub Action</li>
<li>Keep imported query and URL data inside the local process</li>
</ul>
<p>Rules version: 1.0.0.</p>
]]></content:encoded></item><item><title>easySFTP</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/easysftp/</link><pubDate>Mon, 20 Jul 2026 07:43:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/easysftp/</guid><description>Version updated for https://github.com/eiserv/easySFTP to version v2.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary easySFTP is a fast, secure, and simple GitHub Actions action that automates the process of uploading build output to any SFTP server. It offers features such as host key verification, atomic file uploads, skip unchanged files, delete safety guards, and multiple target deployments. The action uses a prebuilt Go binary for fast execution and supports Linux, macOS, and Windows runners without requiring Docker.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/eiserv/easySFTP">https://github.com/eiserv/easySFTP</a></strong> to version <strong>v2.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/easysftp">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>easySFTP is a fast, secure, and simple GitHub Actions action that automates the process of uploading build output to any SFTP server. It offers features such as host key verification, atomic file uploads, skip unchanged files, delete safety guards, and multiple target deployments. The action uses a prebuilt Go binary for fast execution and supports Linux, macOS, and Windows runners without requiring Docker.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="210-2026-07-19"><a href="https://github.com/eiserv/easySFTP/compare/v2.0.1...v2.1.0">2.1.0</a> (2026-07-19)</h2>
<h3 id="features">Features</h3>
<ul>
<li>accept OpenSSH known_hosts entries via a new known-hosts input (<a href="https://github.com/eiserv/easySFTP/issues/88">#88</a>) (<a href="https://github.com/eiserv/easySFTP/commit/bf9d5d7edd5434c000dec50594c336b125a38c5a">bf9d5d7</a>), closes <a href="https://github.com/eiserv/easySFTP/issues/7">#7</a></li>
<li>add stall-timeout to fail fast when transfers stop progressing (<a href="https://github.com/eiserv/easySFTP/issues/89">#89</a>) (<a href="https://github.com/eiserv/easySFTP/commit/08359e8031cf8f8edb89747c86e2f81eac2e739f">08359e8</a>), closes <a href="https://github.com/eiserv/easySFTP/issues/45">#45</a></li>
<li>added github pages site (<a href="https://github.com/eiserv/easySFTP/commit/7031633ba51aae8e3cf2ab40121baed23d58ae0e">7031633</a>)</li>
<li><strong>overlay:</strong> opt-in skip-unchanged skips same-size remote files (<a href="https://github.com/eiserv/easySFTP/issues/87">#87</a>) (<a href="https://github.com/eiserv/easySFTP/commit/89861912b8aa3fe7e6da3e783daddbe07834c622">8986191</a>), closes <a href="https://github.com/eiserv/easySFTP/issues/24">#24</a></li>
<li>reconnect when the SSH connection drops mid-run (<a href="https://github.com/eiserv/easySFTP/issues/90">#90</a>) (<a href="https://github.com/eiserv/easySFTP/commit/66a780b50f0b105ad68224c596cb13512a6934bd">66a780b</a>), closes <a href="https://github.com/eiserv/easySFTP/issues/43">#43</a></li>
<li><strong>sync:</strong> persist a merged manifest when a run fails partway (<a href="https://github.com/eiserv/easySFTP/issues/86">#86</a>) (<a href="https://github.com/eiserv/easySFTP/commit/6a6a90d1ed4ace19b99df55f28b6519a7f6dc231">6a6a90d</a>), closes <a href="https://github.com/eiserv/easySFTP/issues/47">#47</a></li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>renamed the self-test fixture dir to selftest-site/ in .github/workflows/ci.yml (<a href="https://github.com/eiserv/easySFTP/commit/9619df7d1f2516d82b9f90773eea7f958c358f1b">9619df7</a>)</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li><strong>sync:</strong> derive remote directories from the actual upload set (<a href="https://github.com/eiserv/easySFTP/issues/85">#85</a>) (<a href="https://github.com/eiserv/easySFTP/commit/37bc54d53fa337aca81dec8de3c590106f261120">37bc54d</a>), closes <a href="https://github.com/eiserv/easySFTP/issues/69">#69</a></li>
</ul>
]]></content:encoded></item><item><title>Skip Duplicate Actions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/skip-duplicate-actions/</link><pubDate>Mon, 20 Jul 2026 07:41:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/skip-duplicate-actions/</guid><description>Version updated for https://github.com/fkirc/skip-duplicate-actions to version v5.3.2.
This action is used across all versions by 9,714 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The skip-duplicate-actions GitHub Action provides features to optimize workflows by skipping duplicate runs, concurrent or parallel runs based on content changes, skipping ignored paths for performance, and canceling outdated workflow runs. It helps save time and costs by preventing unnecessary executions of workflows triggered under similar conditions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/fkirc/skip-duplicate-actions">https://github.com/fkirc/skip-duplicate-actions</a></strong> to version <strong>v5.3.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>9,714</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skip-duplicate-actions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>skip-duplicate-actions</code> GitHub Action provides features to optimize workflows by skipping duplicate runs, concurrent or parallel runs based on content changes, skipping ignored paths for performance, and canceling outdated workflow runs. It helps save time and costs by preventing unnecessary executions of workflows triggered under similar conditions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>v5.3.2</p>
]]></content:encoded></item><item><title>ReleaseKit – Automated Versioning &amp; Release</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/releasekit-automated-versioning-release/</link><pubDate>Mon, 20 Jul 2026 07:40:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/releasekit-automated-versioning-release/</guid><description>Version updated for https://github.com/goosewobbler/releasekit to version v0.41.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ReleaseKit automates the release process by integrating with various package registries (npm, crates.io, pub.dev) using Conventional Commits. It provides a unified CLI (release) that can run versioning, notes generation, and publishing in a single command, streamlining the workflow for JavaScript/TypeScript, Rust, and Dart/Flutter packages.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/goosewobbler/releasekit">https://github.com/goosewobbler/releasekit</a></strong> to version <strong>v0.41.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/releasekit-automated-versioning-release">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>ReleaseKit automates the release process by integrating with various package registries (npm, crates.io, pub.dev) using Conventional Commits. It provides a unified CLI (<code>release</code>) that can run versioning, notes generation, and publishing in a single command, streamlining the workflow for JavaScript/TypeScript, Rust, and Dart/Flutter packages.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="new">New:</h3>
<ul>
<li>Required an explicit <code>llm.model</code> and validated <code>provider</code> as a closed enum at config load, ensuring fail-loud behavior instead of silent model defaults that can rot. (#564)</li>
<li>Made ecosystem enablement symmetric with detection enabling versioning and publishing by default, adding <code>version.npm.enabled</code> toggle and flipping <code>publish.cargo.enabled</code> and <code>publish.pub.enabled</code> defaults from false to true. (#563)</li>
</ul>
<h3 id="fixed">Fixed:</h3>
<ul>
<li>Escaped few-shot example field interpolation to prevent prompt self-poisoning where crafted content could forge markers or inject instructions. (#572, #571)</li>
<li>Included test commits in generated changelogs instead of silently dropping them, fixing undercounting in standing-PR previews and preventing placeholder entries for test-only packages. (#570, #569)</li>
<li>Neutralized marker sequences in notes prose to prevent forged markers from truncating regions, hijacking sibling package notes, or spoofing release ownership checks. (#565)</li>
<li>Redacted URL credentials (<code>user:password@</code>) from <code>GitError</code> message, args, and stderr to prevent token disclosure on push failures. (#562)</li>
</ul>
<h3 id="documentation">Documentation:</h3>
<ul>
<li>Clarified ADR-0005 title and filename to make clear its &ldquo;explicit model, no defaults&rdquo; decision applies only to LLM-enhanced release notes, not ReleaseKit as a whole. (#568)</li>
<li>Added ADR-0004 documenting the detection-enables, config-opts-out ecosystem enablement philosophy and ADR-0005 documenting the no-default-LLM-model decision. (#566)</li>
<li>Added a themed ROADMAP.md with capability tracks, ecosystem support status, and evaluation criteria, and established the docs/adr/ convention with initial architectural decisions (ADR-0001 through ADR-0003). (#553)</li>
</ul>
<h3 id="developer">Developer:</h3>
<ul>
<li><strong>Testing</strong>: Added end-to-end coverage for the npm-disabled cargo-only version path in the multi-registry harness. (#567)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/goosewobbler/releasekit/compare/0.40.0...0.41.0">https://github.com/goosewobbler/releasekit/compare/0.40.0...0.41.0</a></p>
]]></content:encoded></item><item><title>action-tag-release-build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/action-tag-release-build/</link><pubDate>Mon, 20 Jul 2026 07:39:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/action-tag-release-build/</guid><description>Version updated for https://github.com/heronlabs/action-tag-release-build to version v6.0.11.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action tag-release-build automates the process of bumping a version number, tagging a commit, moving floating major/minor tags, and publishing a GitHub release with a CHANGELOG. It supports semver bump types (major, minor, or patch) inferred from merge/HEAD commits using Conventional Commits, and optionally syncs package.json or Claude Code plugin files.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/heronlabs/action-tag-release-build">https://github.com/heronlabs/action-tag-release-build</a></strong> to version <strong>v6.0.11</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/action-tag-release-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>tag-release-build</code> automates the process of bumping a version number, tagging a commit, moving floating major/minor tags, and publishing a GitHub release with a CHANGELOG. It supports semver bump types (<code>major</code>, <code>minor</code>, or <code>patch</code>) inferred from merge/HEAD commits using Conventional Commits, and optionally syncs <code>package.json</code> or Claude Code plugin files.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>[skip ci] bump v6.0.11 (bc2b7b0)</li>
<li>chore: remove npm group from dependabot configuration (fd31085)</li>
<li>[skip ci] bump v6.0.10 (7a78b9b)</li>
<li>chore: remove minimumReleaseAge from .npmrc and pnpm-workspace.yaml (6f0872f)</li>
<li>[skip ci] bump v6.0.9 (2706505)</li>
<li>chore(deps-dev): bump eslint-plugin-simple-import-sort in the npm group (#42) (afc38db)</li>
<li>[skip ci] chore: update bin/ build artifact (f3d6a95)</li>
<li>[skip ci] bump v6.0.8 (99af17c)</li>
<li>fix: remove bin build cache from CI (#41) (9a7026b)</li>
<li>[skip ci] bump v6.0.7 (4f529d9)</li>
</ul>
]]></content:encoded></item><item><title>Docker Hub repository description</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/docker-hub-repository-description/</link><pubDate>Mon, 20 Jul 2026 07:38:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/docker-hub-repository-description/</guid><description>Version updated for https://github.com/its-me/action.hub.description to version v0.1.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Docker Hub repository action updates a Docker Hub repository’s short and full descriptions from a markdown file, replacing duplicated configuration across multiple repositories. It automates the process of updating description metadata in Docker Hub, saving time and effort by reducing redundancy in project configurations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/its-me/action.hub.description">https://github.com/its-me/action.hub.description</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/docker-hub-repository-description">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Docker Hub repository action updates a Docker Hub repository&rsquo;s short and full descriptions from a markdown file, replacing duplicated configuration across multiple repositories. It automates the process of updating description metadata in Docker Hub, saving time and effort by reducing redundancy in project configurations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/its-me/action.hub.description/compare/v0.1.0...v0.1.1">https://github.com/its-me/action.hub.description/compare/v0.1.0...v0.1.1</a></p>
]]></content:encoded></item><item><title>Aeroflare CI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/aeroflare-ci/</link><pubDate>Mon, 20 Jul 2026 07:38:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/aeroflare-ci/</guid><description>Version updated for https://github.com/ItzEmoji/aeroflare to version v1.11.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Aeroflare is a high-performance Nix binary cache proxy that allows developers to store and retrieve Nix packages in an OCI registry. It provides stateless, zero-infrastructure caching with O(1) manifest lookups. The action automates the process of building and pushing Nix outputs to an OCI cache from CI, simplifying package management and reducing build times.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ItzEmoji/aeroflare">https://github.com/ItzEmoji/aeroflare</a></strong> to version <strong>v1.11.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aeroflare-ci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Aeroflare is a high-performance Nix binary cache proxy that allows developers to store and retrieve Nix packages in an OCI registry. It provides stateless, zero-infrastructure caching with O(1) manifest lookups. The action automates the process of building and pushing Nix outputs to an OCI cache from CI, simplifying package management and reducing build times.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1110-2026-07-19"><a href="https://github.com/ItzEmoji/aeroflare/compare/v1.10.0...v1.11.0">1.11.0</a> (2026-07-19)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>ui:</strong> add Dracula theme (<a href="https://github.com/ItzEmoji/aeroflare/issues/40">#40</a>) (<a href="https://github.com/ItzEmoji/aeroflare/commit/c1bedc1f56d9261ea35fd7287be40e72351de075">c1bedc1</a>)</li>
</ul>
]]></content:encoded></item><item><title>Semantic Release by Jedi Knights</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/semantic-release-by-jedi-knights/</link><pubDate>Mon, 20 Jul 2026 07:37:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/semantic-release-by-jedi-knights/</guid><description>Version updated for https://github.com/jedi-knights/go-semantic-release to version v0.11.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The semantic-release action is a production-grade tool written in Go that automates the process of generating semantic versions, creating changelogs, and publishing releases to GitHub. It supports monorepos with independent project versioning and branch policies, including stable releases on main, prereleases on beta/alpha/next. The action parses commit messages to determine release types, calculates next versions based on commit impact, and generates Markdown release notes grouped by commit type. It also provides features like dry-run mode for previewing releases without any mutations and dependency propagation for optional triggering dependent project releases.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jedi-knights/go-semantic-release">https://github.com/jedi-knights/go-semantic-release</a></strong> to version <strong>v0.11.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/semantic-release-by-jedi-knights">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The semantic-release action is a production-grade tool written in Go that automates the process of generating semantic versions, creating changelogs, and publishing releases to GitHub. It supports monorepos with independent project versioning and branch policies, including stable releases on main, prereleases on beta/alpha/next. The action parses commit messages to determine release types, calculates next versions based on commit impact, and generates Markdown release notes grouped by commit type. It also provides features like dry-run mode for previewing releases without any mutations and dependency propagation for optional triggering dependent project releases.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
]]></content:encoded></item><item><title>mdsmith Markdown linter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/mdsmith-markdown-linter/</link><pubDate>Mon, 20 Jul 2026 07:36:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/mdsmith-markdown-linter/</guid><description>Version updated for https://github.com/jeduden/mdsmith to version v0.53.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The mdsmith action checks and formats Markdown files in a repository using a static Go binary. It automates the process of maintaining consistent Markdown across different files and pipelines, providing auto-fix capabilities to improve readability and structure.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jeduden/mdsmith">https://github.com/jeduden/mdsmith</a></strong> to version <strong>v0.53.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mdsmith-markdown-linter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The mdsmith action checks and formats Markdown files in a repository using a static Go binary. It automates the process of maintaining consistent Markdown across different files and pipelines, providing auto-fix capabilities to improve readability and structure.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>arch(lsp): split server.go into focused sibling files by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/680">https://github.com/jeduden/mdsmith/pull/680</a></li>
<li>arch: add trivial-accessor exemption comments in workspace.go by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/681">https://github.com/jeduden/mdsmith/pull/681</a></li>
<li>arch(lint): split layer0.go into focused sibling files by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/678">https://github.com/jeduden/mdsmith/pull/678</a></li>
<li>perf: replace map[string]bool sets with map[string]struct{} across hot paths by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/679">https://github.com/jeduden/mdsmith/pull/679</a></li>
<li>bench(lint): add inline scanner benchmark and corpus hit-rate test by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/682">https://github.com/jeduden/mdsmith/pull/682</a></li>
<li>perf: reduce GC scan span and eliminate padding in hot structs by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/683">https://github.com/jeduden/mdsmith/pull/683</a></li>
<li>security: retire resolved findings from 2026-06-19 SARIF files by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/685">https://github.com/jeduden/mdsmith/pull/685</a></li>
<li>test(samefileanchor): add dedicated unit tests for 12 unexported helpers by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/687">https://github.com/jeduden/mdsmith/pull/687</a></li>
<li>test(inline_scan): add dedicated unit tests for 12 unexported helpers by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/686">https://github.com/jeduden/mdsmith/pull/686</a></li>
<li>docs(benchmarks): restructure the benchmark write-up for scannability by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/684">https://github.com/jeduden/mdsmith/pull/684</a></li>
<li>perf: apply high-performance-go guidelines across 5 hot paths (3-round review) by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/688">https://github.com/jeduden/mdsmith/pull/688</a></li>
<li>audit(2026-06-24): flag test-debt and rename dedup tax by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/689">https://github.com/jeduden/mdsmith/pull/689</a></li>
<li>refactor(rename): export NormalizedLabel/RefDefBracketBytes, remove lsp duplicates by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/690">https://github.com/jeduden/mdsmith/pull/690</a></li>
<li>test(lsp/rename): add dedicated unit tests for 13 unexported helpers by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/692">https://github.com/jeduden/mdsmith/pull/692</a></li>
<li>chore(deps): bump github.com/tetratelabs/wazero from 1.11.0 to 1.12.0 by @dependabot[bot] in <a href="https://github.com/jeduden/mdsmith/pull/691">https://github.com/jeduden/mdsmith/pull/691</a></li>
<li>test: add dedicated unit tests for export helpers and two small rename helpers (plan 2606240213) by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/693">https://github.com/jeduden/mdsmith/pull/693</a></li>
<li>audit(arch): 2026-06-24 sweep (09f22d3..3d35b77); add plans 2606241814-15 by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/696">https://github.com/jeduden/mdsmith/pull/696</a></li>
<li>perf: five high-performance-go fixes from codebase audit by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/697">https://github.com/jeduden/mdsmith/pull/697</a></li>
<li>security: upgrade golang.org/x/net to v0.56.0 (fixes 5 CVEs) by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/698">https://github.com/jeduden/mdsmith/pull/698</a></li>
<li>test(lsp): add dedicated unit tests for rename dispatch helpers (plan 2606241814) by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/699">https://github.com/jeduden/mdsmith/pull/699</a></li>
<li>fix: bump Go to 1.25.11 and golang.org/x/net to v0.56.0 to fix 22 CVEs by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/700">https://github.com/jeduden/mdsmith/pull/700</a></li>
<li>test(lint): add unit tests for layer0_html.go helpers (plan 2606260211) by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/701">https://github.com/jeduden/mdsmith/pull/701</a></li>
<li>test(lint): add dedicated unit tests for 9 lineclass_scan HTML helpers (plan 2606260614) by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/702">https://github.com/jeduden/mdsmith/pull/702</a></li>
<li>test(cuelite): add dedicated unit tests for 7 engine.go unexported helpers (plan 2606260615) by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/703">https://github.com/jeduden/mdsmith/pull/703</a></li>
<li>fix(plan): resolve merge conflict markers in plan 2606260615 by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/704">https://github.com/jeduden/mdsmith/pull/704</a></li>
<li>chore(arch): architecture audit 2026-06-26 — clean pass by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/705">https://github.com/jeduden/mdsmith/pull/705</a></li>
<li>Add opt-in reflow auto-fix to line-length (MDS001) by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/709">https://github.com/jeduden/mdsmith/pull/709</a></li>
<li>chore(arch): architecture audit 2026-06-28 — clean pass by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/708">https://github.com/jeduden/mdsmith/pull/708</a></li>
<li>docs(features): explain the Claude Code integration from a user view by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/710">https://github.com/jeduden/mdsmith/pull/710</a></li>
<li>docs(vscode): lead the VS Code page with the install decision by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/713">https://github.com/jeduden/mdsmith/pull/713</a></li>
<li>Plan: scope the LSP workspace singleton per client so instances coexist by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/714">https://github.com/jeduden/mdsmith/pull/714</a></li>
<li>perf: replace manual byte loops with bytes package SIMD functions; fix CRLF reflow corruption by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/712">https://github.com/jeduden/mdsmith/pull/712</a></li>
<li>ci(merge-queue): only run queue job when the queue label is added by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/717">https://github.com/jeduden/mdsmith/pull/717</a></li>
<li>chore(deps): bump golang.org/x/tools from 0.45.0 to 0.47.0 by @dependabot[bot] in <a href="https://github.com/jeduden/mdsmith/pull/716">https://github.com/jeduden/mdsmith/pull/716</a></li>
<li>perf: fix top 5 high-performance-go.md violations by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/715">https://github.com/jeduden/mdsmith/pull/715</a></li>
<li>docs(comparison): refresh mdbase section for rename, backlinks, and deps by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/718">https://github.com/jeduden/mdsmith/pull/718</a></li>
<li>Forbid &ldquo;honest&rdquo; + AI-speak repo-wide, and make the vocabulary a user-extensible word-list resource by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/694">https://github.com/jeduden/mdsmith/pull/694</a></li>
<li>docs(plan): plan deterministic prose-tell rules and redraw the Vale boundary by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/719">https://github.com/jeduden/mdsmith/pull/719</a></li>
<li>fix(arch): route reflow abbreviation lookup through internal/mdtext by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/722">https://github.com/jeduden/mdsmith/pull/722</a></li>
<li>plan: redesign move/rename as one refactor engine (CLI, LSP, WASM) by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/721">https://github.com/jeduden/mdsmith/pull/721</a></li>
<li>APM research: how mdsmith supports Agent Package Manager workflows by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/728">https://github.com/jeduden/mdsmith/pull/728</a></li>
<li>chore(deps): bump markdownlint-cli2 from 0.22.1 to 0.23.0 in /docs/research/benchmarks/npm by @dependabot[bot] in <a href="https://github.com/jeduden/mdsmith/pull/727">https://github.com/jeduden/mdsmith/pull/727</a></li>
<li>perf: fix top 5 high-performance-go.md violations in the rule hot path by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/725">https://github.com/jeduden/mdsmith/pull/725</a></li>
<li>perf: fix top 5 high-performance-go.md violations found by audit by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/729">https://github.com/jeduden/mdsmith/pull/729</a></li>
<li>security: 2026-07-03 post-audit diff review (low findings only) by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/720">https://github.com/jeduden/mdsmith/pull/720</a></li>
<li>perf: fix top 5 high-performance-go.md violations by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/723">https://github.com/jeduden/mdsmith/pull/723</a></li>
<li>plan: extractable per-file metrics (readability) with YAML output by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/724">https://github.com/jeduden/mdsmith/pull/724</a></li>
<li>security: 2026-07-10 post-audit diff review (no findings) by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/730">https://github.com/jeduden/mdsmith/pull/730</a></li>
<li>perf: fix top 5 high-performance-go.md violations from audit by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/731">https://github.com/jeduden/mdsmith/pull/731</a></li>
<li>perf: fix top 5 high-performance-go.md violations by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/732">https://github.com/jeduden/mdsmith/pull/732</a></li>
<li>refactor: export wordlist.Dedup/ToAnySlice, remove duplicate implementations by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/726">https://github.com/jeduden/mdsmith/pull/726</a></li>
<li>feat: Open Knowledge Format (OKF) support — required-frontmatter rule, <code>init --starter okf</code>, and dev guide by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/711">https://github.com/jeduden/mdsmith/pull/711</a></li>
<li>refactor(astutil): export CountLeadingSpaces and IsBlank, remove per-rule duplicates by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/734">https://github.com/jeduden/mdsmith/pull/734</a></li>
<li>feat(init): redesign around config sources and additive packs by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/733">https://github.com/jeduden/mdsmith/pull/733</a></li>
<li>test(architecture): add missing tests for public rule/directive contract methods by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/736">https://github.com/jeduden/mdsmith/pull/736</a></li>
<li>perf: fix top 5 high-performance-go.md violations (round 6) by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/737">https://github.com/jeduden/mdsmith/pull/737</a></li>
<li>review: fix double-scan, allocation regression, and test gaps by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/735">https://github.com/jeduden/mdsmith/pull/735</a></li>
<li>chore(deps): bump golang.org/x/tools from 0.47.0 to 0.48.0 by @dependabot[bot] in <a href="https://github.com/jeduden/mdsmith/pull/741">https://github.com/jeduden/mdsmith/pull/741</a></li>
<li>perf: fix top 5 high-performance-go.md violations (round 7) by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/742">https://github.com/jeduden/mdsmith/pull/742</a></li>
<li>test: add dedicated unit tests for unexported helpers (plan 2607051919) by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/738">https://github.com/jeduden/mdsmith/pull/738</a></li>
<li>Fix linkgraph purity-contract mismatch for wikilink resolution by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/739">https://github.com/jeduden/mdsmith/pull/739</a></li>
<li>perf: fix top 5 high-performance-go.md violations (round 8) by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/740">https://github.com/jeduden/mdsmith/pull/740</a></li>
<li>feat(placeholders): add apm-input-token for APM ${input:NAME} prompt parameters by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/743">https://github.com/jeduden/mdsmith/pull/743</a></li>
<li>feat(output): add SARIF 2.1.0 output format for mdsmith check and fix &ndash;dry-run by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/744">https://github.com/jeduden/mdsmith/pull/744</a></li>
<li>docs(security): 2026-07-17 post-audit diff review by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/746">https://github.com/jeduden/mdsmith/pull/746</a></li>
<li>feat(metrics): add <code>metrics get</code> subcommand with readability metrics by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/747">https://github.com/jeduden/mdsmith/pull/747</a></li>
<li>feat(MDS072): add external-link-check rule (issue #47) by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/707">https://github.com/jeduden/mdsmith/pull/707</a></li>
<li>fix(merge-driver): scope ignore-derived -merge lines to Markdown (#750) by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/752">https://github.com/jeduden/mdsmith/pull/752</a></li>
<li>docs(wordlists): complete plan 2606251522 — integration test and doc updates by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/748">https://github.com/jeduden/mdsmith/pull/748</a></li>
<li>feat: foreign managed-region protection for <code>mdsmith fix</code> by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/749">https://github.com/jeduden/mdsmith/pull/749</a></li>
<li>Split init-subcommand logic out of cmd/mdsmith/main.go by @jeduden in <a href="https://github.com/jeduden/mdsmith/pull/751">https://github.com/jeduden/mdsmith/pull/751</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jeduden/mdsmith/compare/v0.52.0...v0.53.0">https://github.com/jeduden/mdsmith/compare/v0.52.0...v0.53.0</a></p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/neurolink-ai/</link><pubDate>Mon, 20 Jul 2026 07:35:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v9.95.3.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is an AI integration platform that allows developers to seamlessly integrate various AI providers and models into their applications. It provides a unified API that supports multiple providers such as OpenAI, Anthropic, Google, AWS Bedrock, Azure, and more. NeuroLink offers features like single parameter changes for provider switching, built-in tools, multi-provider failover, intelligent routing, and integration via CLI or TypeScript SDKs. The platform also includes new functionalities for avatar and music modalities, making it versatile for a wide range of applications.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v9.95.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>NeuroLink is an AI integration platform that allows developers to seamlessly integrate various AI providers and models into their applications. It provides a unified API that supports multiple providers such as OpenAI, Anthropic, Google, AWS Bedrock, Azure, and more. NeuroLink offers features like single parameter changes for provider switching, built-in tools, multi-provider failover, intelligent routing, and integration via CLI or TypeScript SDKs. The platform also includes new functionalities for avatar and music modalities, making it versatile for a wide range of applications.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="9953-2026-07-19"><a href="https://github.com/juspay/neurolink/compare/v9.95.2...v9.95.3">9.95.3</a> (2026-07-19)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(pdf):</strong>  harden image conversion — accurate pages, per-page resilience, scale, streaming, aggregate &amp; URL limits (<a href="https://github.com/juspay/neurolink/commit/d58b0c9f375fdabce913e0b85f30f6996c2d6f6a">d58b0c9</a>)</li>
</ul>
]]></content:encoded></item><item><title>datamodel-code-generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/datamodel-code-generator/</link><pubDate>Mon, 20 Jul 2026 07:34:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/datamodel-code-generator/</guid><description>Version updated for https://github.com/koxudaxi/datamodel-code-generator to version 0.69.0.
This action is used across all versions by 3,338 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action datamodel-code-generator automates the process of generating Python data models from various schema formats, including OpenAPI 3, AsyncAPI, JSON Schema, Avro, XML Schema, Protocol Buffers/gRPC, GraphQL, and raw data. It supports converting existing Python types to Pydantic, dataclass, or TypedDict classes, and generates models in different styles such as Pydantic v2, v2 dataclass, dataclasses, and msgspec. The action handles complex schemas and provides type-safe, validated code suitable for IDEs and type checkers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/koxudaxi/datamodel-code-generator">https://github.com/koxudaxi/datamodel-code-generator</a></strong> to version <strong>0.69.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3,338</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/datamodel-code-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <strong>datamodel-code-generator</strong> automates the process of generating Python data models from various schema formats, including OpenAPI 3, AsyncAPI, JSON Schema, Avro, XML Schema, Protocol Buffers/gRPC, GraphQL, and raw data. It supports converting existing Python types to Pydantic, dataclass, or TypedDict classes, and generates models in different styles such as Pydantic v2, v2 dataclass, dataclasses, and msgspec. The action handles complex schemas and provides type-safe, validated code suitable for IDEs and type checkers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="breaking-changes">Breaking Changes</h2>
<ul>
<li>Discriminated unions with duplicate or unresolvable discriminator values now fall back to a plain union - When a discriminated union contains variants that resolve to the same discriminator value, or variants that are containers, <code>RootModel</code>/type-alias wrappers, <code>None</code>/<code>str</code> members, or otherwise lack a resolvable discriminator literal, the generator no longer emits <code>Field(..., discriminator='...')</code> and instead produces a regular union. Previously such schemas emitted a <code>discriminator=</code> argument. Users regenerating models from these schemas will see the <code>discriminator</code> keyword removed from the affected fields (#3603)</li>
</ul>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-python" data-lang="python"><span style="display:flex;"><span><span style="color:#75715e"># Before (invalid duplicate-value discriminator was emitted):</span>
</span></span><span style="display:flex;"><span><span style="color:#66d9ef">class</span> <span style="color:#a6e22e">GroupedItem</span>(RootModel[Item <span style="color:#f92672">|</span> ItemReference]):
</span></span><span style="display:flex;"><span>    root: Item <span style="color:#f92672">|</span> ItemReference <span style="color:#f92672">=</span> Field(<span style="color:#f92672">...</span>, discriminator<span style="color:#f92672">=</span><span style="color:#e6db74">&#39;type&#39;</span>)
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># After (falls back to a plain union when variants are not valid discriminated members):</span>
</span></span><span style="display:flex;"><span><span style="color:#66d9ef">class</span> <span style="color:#a6e22e">MixedItem</span>(RootModel[str <span style="color:#f92672">|</span> ItemReference <span style="color:#f92672">|</span> <span style="color:#66d9ef">None</span>]):
</span></span><span style="display:flex;"><span>    root: str <span style="color:#f92672">|</span> ItemReference <span style="color:#f92672">|</span> <span style="color:#66d9ef">None</span>
</span></span></code></pre></div><h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Update CHANGELOG for 0.68.1 by @dcg-generated-docs[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3594">https://github.com/koxudaxi/datamodel-code-generator/pull/3594</a></li>
<li>Update release benchmark data by @dcg-generated-docs[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3595">https://github.com/koxudaxi/datamodel-code-generator/pull/3595</a></li>
<li>Skip unused formatter construction by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3599">https://github.com/koxudaxi/datamodel-code-generator/pull/3599</a></li>
<li>Retain model import caches by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3600">https://github.com/koxudaxi/datamodel-code-generator/pull/3600</a></li>
<li>Fix pydantic typed extra runtime compatibility by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3601">https://github.com/koxudaxi/datamodel-code-generator/pull/3601</a></li>
<li>[pre-commit.ci] pre-commit autoupdate by @pre-commit-ci[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3605">https://github.com/koxudaxi/datamodel-code-generator/pull/3605</a></li>
<li>Fix legacy pydantic extra templates by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3602">https://github.com/koxudaxi/datamodel-code-generator/pull/3602</a></li>
<li>Handle duplicate discriminator values by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3603">https://github.com/koxudaxi/datamodel-code-generator/pull/3603</a></li>
<li>Bump the github-actions group across 1 directory with 7 updates by @dependabot[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3598">https://github.com/koxudaxi/datamodel-code-generator/pull/3598</a></li>
<li>Allow custom and generated file headers by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3607">https://github.com/koxudaxi/datamodel-code-generator/pull/3607</a></li>
<li>Fix payload runtime validation exclusions by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3609">https://github.com/koxudaxi/datamodel-code-generator/pull/3609</a></li>
<li>Fix optional discriminator literals by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3608">https://github.com/koxudaxi/datamodel-code-generator/pull/3608</a></li>
<li>Fix invalid dotted model names by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3610">https://github.com/koxudaxi/datamodel-code-generator/pull/3610</a></li>
<li>Add multi-module stdout guard by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3611">https://github.com/koxudaxi/datamodel-code-generator/pull/3611</a></li>
<li>Fix empty (&quot;&quot;) property name dropping its alias by @chuenchen309 in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3612">https://github.com/koxudaxi/datamodel-code-generator/pull/3612</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@chuenchen309 made their first contribution in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3612">https://github.com/koxudaxi/datamodel-code-generator/pull/3612</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/koxudaxi/datamodel-code-generator/compare/0.68.1...0.69.0">https://github.com/koxudaxi/datamodel-code-generator/compare/0.68.1...0.69.0</a></p>
]]></content:encoded></item><item><title>HoverStare</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/hoverstare/</link><pubDate>Mon, 20 Jul 2026 07:33:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/hoverstare/</guid><description>Version updated for https://github.com/liuchong/hoverstare to version v0.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary HoverStare is an AI code review tool for GitHub pull requests that reads your repository like a human reviewer would. It provides a multi-pass voting system with an independent verifier to catch bugs that hide outside the diff, and generates precise inline comments. The action runs as a GitHub Action and can be customized with different models or endpoints.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/liuchong/hoverstare">https://github.com/liuchong/hoverstare</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hoverstare">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>HoverStare is an AI code review tool for GitHub pull requests that reads your repository like a human reviewer would. It provides a multi-pass voting system with an independent verifier to catch bugs that hide outside the diff, and generates precise inline comments. The action runs as a GitHub Action and can be customized with different models or endpoints.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>[hoverstare] Add CONTRIBUTING.md with build &amp; test commands by @liuchong in <a href="https://github.com/liuchong/hoverstare/pull/3">https://github.com/liuchong/hoverstare/pull/3</a></li>
<li>[hoverstare] Docs: explain the review pipeline voting in docs/ by @liuchong in <a href="https://github.com/liuchong/hoverstare/pull/5">https://github.com/liuchong/hoverstare/pull/5</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@liuchong made their first contribution in <a href="https://github.com/liuchong/hoverstare/pull/3">https://github.com/liuchong/hoverstare/pull/3</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/liuchong/hoverstare/compare/v0.0.7...v0.1.0">https://github.com/liuchong/hoverstare/compare/v0.0.7...v0.1.0</a></p>
]]></content:encoded></item><item><title>SlimRepo Media Optimizer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/slimrepo-media-optimizer/</link><pubDate>Mon, 20 Jul 2026 07:32:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/slimrepo-media-optimizer/</guid><description>Version updated for https://github.com/medoyad/slimrepo-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The SlimRepo Media Optimizer Action automates the compression of image files in GitHub repositories to improve performance, reduce costs, and optimize Docker images. It supports PNG, JPG, JPEG, and WebP formats without loss of quality and can be used for free up to 50 files per run or for unlimited use with a PRO license, which includes support for SVG and GIF formats. The action is simple to integrate into GitHub workflows and automatically commits optimized files back to the repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/medoyad/slimrepo-action">https://github.com/medoyad/slimrepo-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/slimrepo-media-optimizer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The SlimRepo Media Optimizer Action automates the compression of image files in GitHub repositories to improve performance, reduce costs, and optimize Docker images. It supports PNG, JPG, JPEG, and WebP formats without loss of quality and can be used for free up to 50 files per run or for unlimited use with a PRO license, which includes support for SVG and GIF formats. The action is simple to integrate into GitHub workflows and automatically commits optimized files back to the repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/medoyad/slimrepo-action/commits/v1.0.0">https://github.com/medoyad/slimrepo-action/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>Mipiti Verify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/mipiti-verify/</link><pubDate>Mon, 20 Jul 2026 07:32:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/mipiti-verify/</guid><description>Version updated for https://github.com/Mipiti/mipiti-verify to version v0.48.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Mipiti-verify is a CI verification tool for Mipiti threat model assertions that automates security controls, ensuring they never drift. It supports both OpenAI and Anthropic AI providers to verify assertions against models, providing options for local Tier 1 verification and offline batch verification from JSON files. The tool also offers features like list, report, audit, and check commands to manage and verify Mipiti assertions effectively.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Mipiti/mipiti-verify">https://github.com/Mipiti/mipiti-verify</a></strong> to version <strong>v0.48.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mipiti-verify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Mipiti-verify is a CI verification tool for Mipiti threat model assertions that automates security controls, ensuring they never drift. It supports both OpenAI and Anthropic AI providers to verify assertions against models, providing options for local Tier 1 verification and offline batch verification from JSON files. The tool also offers features like list, report, audit, and check commands to manage and verify Mipiti assertions effectively.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="docker-image">Docker Image</h3>
<p>Pre-built image for faster CI (pulls cached image instead of building from source):</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">docker://ghcr.io/mipiti/mipiti-verify:v0.48.0@sha256:ed46a5641c48615a8ec36e215c8b0d6ba3b818643a88bb6ab0bd90e7913cf9ce</span>
</span></span></code></pre></div><p>Image: <code>ghcr.io/mipiti/mipiti-verify:v0.48.0</code>
Digest: <code>sha256:ed46a5641c48615a8ec36e215c8b0d6ba3b818643a88bb6ab0bd90e7913cf9ce</code></p>
]]></content:encoded></item><item><title>repro-check runnability</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/repro-check-runnability/</link><pubDate>Mon, 20 Jul 2026 07:31:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/repro-check-runnability/</guid><description>Version updated for https://github.com/nelsonjordanme/repro-check to version v0.10.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary repro-check is a tool designed to run old research code and automatically fix issues that cause it to crash. It finds scripts, tries to execute them, and applies known fixes if they break, repeating until the script runs successfully or provides a detailed explanation of where it stopped and what needs to be done next. This helps researchers recreate and verify scientific results from archived papers by automating the process of fixing code rot and dependency issues.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nelsonjordanme/repro-check">https://github.com/nelsonjordanme/repro-check</a></strong> to version <strong>v0.10.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/repro-check-runnability">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>repro-check</code> is a tool designed to run old research code and automatically fix issues that cause it to crash. It finds scripts, tries to execute them, and applies known fixes if they break, repeating until the script runs successfully or provides a detailed explanation of where it stopped and what needs to be done next. This helps researchers recreate and verify scientific results from archived papers by automating the process of fixing code rot and dependency issues.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Adds CITATION.cff and is the first release archived by Zenodo, minting a citable DOI. No behaviour change. <code>pip install --upgrade repro-check</code> — <a href="https://pypi.org/project/repro-check/0.10.3/">https://pypi.org/project/repro-check/0.10.3/</a></p>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/go-proxy-cache-updater/</link><pubDate>Mon, 20 Jul 2026 07:30:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.27.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action automatically updates a Go proxy cache by pulling new module versions when tags matching semantic version patterns are created. It supports standard and submodule version tags, custom proxy configurations, and configurable Go versions via setup-go. The workflow can be triggered on GitHub release events and includes options to customize the import path and check for the latest version.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.27</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action automatically updates a Go proxy cache by pulling new module versions when tags matching semantic version patterns are created. It supports standard and submodule version tags, custom proxy configurations, and configurable Go versions via setup-go. The workflow can be triggered on GitHub release events and includes options to customize the import path and check for the latest version.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1127-2026-07-20"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.26...v1.1.27">1.1.27</a> (2026-07-20)</h2>
]]></content:encoded></item><item><title>Multi-Style Contribution Snake</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/multi-style-contribution-snake/</link><pubDate>Mon, 20 Jul 2026 07:29:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/multi-style-contribution-snake/</guid><description>Version updated for https://github.com/Pro-Bandey/multi-style-snake-contribution-grid to version v20.07.26.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action multi-style-snake-contribution-grid generates animated snake contributions for a user’s repository, offering 5 distinct styles and shapes. It automates the process of generating multiple snake variations and displays them in an output branch. The action also supports SVGs and GIFs for high-quality rendering and includes a gallery feature to view all assets in one place.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Pro-Bandey/multi-style-snake-contribution-grid">https://github.com/Pro-Bandey/multi-style-snake-contribution-grid</a></strong> to version <strong>v20.07.26</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/multi-style-contribution-snake">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>multi-style-snake-contribution-grid</code> generates animated snake contributions for a user&rsquo;s repository, offering 5 distinct styles and shapes. It automates the process of generating multiple snake variations and displays them in an output branch. The action also supports SVGs and GIFs for high-quality rendering and includes a gallery feature to view all assets in one place.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-multi-style-snake-daily-update">🐍 Multi-Style Snake Daily Update</h2>
<p>Automated daily release to the GitHub Marketplace.</p>
<p><strong>Version Details:</strong></p>
<ul>
<li><strong>Tag:</strong> <code>v20.07.26</code></li>
<li><strong>Release Date:</strong> $(date +&rsquo;%A, %B %d, 20%y')</li>
</ul>
<p><strong>Included Features:</strong></p>
<ul>
<li>5 Unique Snake Styles (Blocks, Rounds, Triangles, Stars, Diamonds)</li>
<li>Automated Month Labels above grids</li>
<li>Dynamic Username Detection</li>
<li>Auto-generated Asset Gallery</li>
</ul>
]]></content:encoded></item><item><title>TCalc Workspace Report</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/tcalc-workspace-report/</link><pubDate>Mon, 20 Jul 2026 07:28:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/tcalc-workspace-report/</guid><description>Version updated for https://github.com/Sandesh13fr/TCalc to version v0.1.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary TCalc is a local codebase analysis tool that measures and recommends coding models based on the workspace’s token usage. It automates the process of identifying which models are necessary for coding tasks, provides budgeted repository maps, and generates agent rules to guide development without relying on cloud services or external APIs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Sandesh13fr/TCalc">https://github.com/Sandesh13fr/TCalc</a></strong> to version <strong>v0.1.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tcalc-workspace-report">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>TCalc is a local codebase analysis tool that measures and recommends coding models based on the workspace&rsquo;s token usage. It automates the process of identifying which models are necessary for coding tasks, provides budgeted repository maps, and generates agent rules to guide development without relying on cloud services or external APIs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Sandesh13fr/TCalc/compare/v0.1.3...v0.1.4">https://github.com/Sandesh13fr/TCalc/compare/v0.1.3...v0.1.4</a></p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/bernstein-multi-agent-orchestration/</link><pubDate>Mon, 20 Jul 2026 07:27:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.8.1.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bernstein orchestrates a crew of CLI coding agents to automate tasks deterministically, ensuring reproducible results end-to-end. It uses plain Python scheduling and record-keeping mechanisms without relying on large language models (LLMs). The action provides features such as deterministic multi-agent orchestration, per-artefact lineage tracking, always-on replay journals, and audit logs for traceability and verification.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.8.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Bernstein orchestrates a crew of CLI coding agents to automate tasks deterministically, ensuring reproducible results end-to-end. It uses plain Python scheduling and record-keeping mechanisms without relying on large language models (LLMs). The action provides features such as deterministic multi-agent orchestration, per-artefact lineage tracking, always-on replay journals, and audit logs for traceability and verification.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v381">v3.8.1</h1>
<p>Patch release: two operator-facing fixes to the local dashboard and a missing runtime dependency, both surfaced by an end-to-end run of the released 3.8.0 build.</p>
<h2 id="fixed">Fixed</h2>
<ul>
<li><strong><code>bernstein doctor</code> no longer crashes on a clean install (#2735).</strong> <code>doctor</code> (and its adapter last-green, security-floor, and advisory checks) import <code>packaging.version</code> at runtime, but <code>packaging</code> was only present transitively via dev tooling and was never a declared runtime dependency, so a <code>uv tool install bernstein</code> shipped without it and <code>doctor</code> raised <code>ModuleNotFoundError: No module named 'packaging'</code>. <code>packaging</code> is now a direct runtime dependency, with a contract test that fails if any runtime module imports it while it is undeclared.</li>
<li><strong>The local dashboard no longer locks the operator out (#2736).</strong> Running <code>bernstein gui serve</code> on loopback with dashboard auth configured loaded the UI shell but returned 401 on every data panel, because the local serve path never handed the browser a credential and the bundled SPA wrote the onboarding token to a different localStorage key than the API layer read. The local serve path now seeds a token for the loopback browser, and the shipped SPA bundle was rebuilt so the write and read keys agree. External unauthenticated access still returns 401; the auth posture is unchanged.</li>
</ul>
<h2 id="build">Build</h2>
<ul>
<li>The bundled web UI could not be rebuilt: an earlier dependency bump moved it to Tailwind v4 while the stylesheet and PostCSS config stayed on the v3 form, so <code>npm run build</code> failed. Tailwind is pinned back to the version the configuration targets, and the regenerated bundle ships with this release.</li>
</ul>
]]></content:encoded></item><item><title>BoundaryCI tenant-isolation scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/boundaryci-tenant-isolation-scan/</link><pubDate>Mon, 20 Jul 2026 07:26:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/boundaryci-tenant-isolation-scan/</guid><description>Version updated for https://github.com/sir-gig/boundaryci to version v0.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary BoundaryCI is a local CLI that helps developers catch cross-tenant authorization mistakes in Supabase and PostgreSQL projects by scanning SQL migrations, applying deterministic tenant isolation rules, and optionally using a Fireworks model for review. It catches specific types of security issues related to row-level security (RLS) policies and provides a way to manage baseline findings and waivers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sir-gig/boundaryci">https://github.com/sir-gig/boundaryci</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/boundaryci-tenant-isolation-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>BoundaryCI is a local CLI that helps developers catch cross-tenant authorization mistakes in Supabase and PostgreSQL projects by scanning SQL migrations, applying deterministic tenant isolation rules, and optionally using a Fireworks model for review. It catches specific types of security issues related to row-level security (RLS) policies and provides a way to manage baseline findings and waivers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="managed-fireworks-review">Managed Fireworks review</h2>
<ul>
<li>Team, Growth, and Enterprise organizations can explicitly authorize server-managed Fireworks semantic review without exposing a provider key to GitHub.</li>
<li>The runner performs a metadata-only eligibility check before sending locally redacted migration text.</li>
<li>Organization, repository, and workflow opt-outs keep customer control explicit.</li>
<li>Managed findings remain advisory by default, and deterministic scanning continues through provider failures.</li>
<li>The dashboard now includes consent controls, repository settings, AI scan history, permanent setup guidance, and managed-AI documentation.</li>
</ul>
<p>See the <a href="https://boundaryci.com/docs/managed-ai/">managed AI documentation</a> for the full data flow and setup.</p>
]]></content:encoded></item><item><title>Node Semantic Release</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/node-semantic-release/</link><pubDate>Mon, 20 Jul 2026 07:26:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/node-semantic-release/</guid><description>Version updated for https://github.com/stairwaytowonderland/node-semantic-release to version v1.200.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the Node.js release process by installing dependencies, building a project, running semantic-release, and optionally committing and tagging releases. It can be used in two modes: regular release with tag creation or publish mode that creates a GitHub Release from an existing tag using base64-encoded release notes or direct release notes from the tag. The action requires either secrets.GITHUB_TOKEN or a PAT to create tags, and it provides detailed token behavior information for users to choose the appropriate method.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stairwaytowonderland/node-semantic-release">https://github.com/stairwaytowonderland/node-semantic-release</a></strong> to version <strong>v1.200.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/node-semantic-release">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the Node.js release process by installing dependencies, building a project, running semantic-release, and optionally committing and tagging releases. It can be used in two modes: regular release with tag creation or publish mode that creates a GitHub Release from an existing tag using base64-encoded release notes or direct release notes from the tag. The action requires either <code>secrets.GITHUB_TOKEN</code> or a PAT to create tags, and it provides detailed token behavior information for users to choose the appropriate method.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>chore(release): 1.200.0</p>
<h2 id="12000-2026-07-19"><a href="https://github.com/stairwaytowonderland/node-semantic-release/compare/v1.199.0...v1.200.0">1.200.0</a> (2026-07-19)</h2>
<h3 id="-features">✨ Features</h3>
<ul>
<li>update releaserc files (<a href="https://github.com/stairwaytowonderland/node-semantic-release/commit/bf9b62f53e71aa048e33b70286892229d84ed38f">bf9b62f</a>)</li>
</ul>
]]></content:encoded></item><item><title>hotlane deploy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/hotlane-deploy/</link><pubDate>Mon, 20 Jul 2026 07:25:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/hotlane-deploy/</guid><description>Version updated for https://github.com/StefanIancu/hotlane-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment process with hotlane from GitHub Actions. It supports various commands such as pushing, testing, promoting, discarding, rolling back, and checking drift between live and source build versions. The action installs hotlane’s binary, runs specified commands with optional arguments, and outputs verification results to the job summary or logs for failed pushes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/StefanIancu/hotlane-action">https://github.com/StefanIancu/hotlane-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hotlane-deploy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment process with hotlane from GitHub Actions. It supports various commands such as pushing, testing, promoting, discarding, rolling back, and checking drift between live and source build versions. The action installs hotlane&rsquo;s binary, runs specified commands with optional arguments, and outputs verification results to the job summary or logs for failed pushes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release: install a pinned hotlane binary, run any client command (push by default), and surface the verify verdict as action outputs plus a job-summary table. See the README for deploy / rollback / drift-check workflow examples.</p>
]]></content:encoded></item><item><title>runward gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/runward-gate/</link><pubDate>Mon, 20 Jul 2026 07:24:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/runward-gate/</guid><description>Version updated for https://github.com/stranxik/runward to version v0.21.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Runward automates the verification of engineering decisions made by AI-generated code, ensuring that all critical design points are followed and documented. It provides a deterministic gate to verify load-bearing decisions and offers comprehensive compliance evidence, making it suitable for ISO 42001, NIST AI RMF, and EU AI Act standards.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stranxik/runward">https://github.com/stranxik/runward</a></strong> to version <strong>v0.21.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/runward-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Runward automates the verification of engineering decisions made by AI-generated code, ensuring that all critical design points are followed and documented. It provides a deterministic gate to verify load-bearing decisions and offers comprehensive compliance evidence, making it suitable for ISO 42001, NIST AI RMF, and EU AI Act standards.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>A launch-review pass (multi-agent, adversarially verified) found the first-contact story promised more than one command delivered. The fix is in the product, not the copy: the demo path now <em>is</em> one command.</p>
<ul>
<li><strong><code>init --example</code> ends by running the gate itself.</strong> After scaffolding the filled <code>request-triage</code> reference, <code>init --example</code> chains <code>check --strict</code> on the fresh mission — the whole chain goes green in front of you, in one command, exactly as advertised. Deterministic, zero-network, skipped under <code>--dry-run</code>. The example&rsquo;s next-steps now point at the guard demo (<code>cd code &amp;&amp; npm install &amp;&amp; npm run demo</code> — req-005 carries a fabricated account reference the deterministic guard refuses, fail-closed) instead of asking you to run a check that already ran.</li>
<li><strong>README accuracy pass (the HN landing).</strong> The hand-over uniqueness claim is aligned with the project&rsquo;s own sourced comparison (Spec Kitty <em>does</em> carry the mission past tested code; runward&rsquo;s difference is a plain-code succession check and standardized OSCAL evidence, not bespoke YAML). &ldquo;FDE&rdquo; is expanded on first use (Forward Deployed Engineer), the Why section leads with what runward does, and the sourced comparison + dropyour case study are linked from the Documentation list.</li>
<li><strong>Example docs.</strong> The reference floor&rsquo;s README now counts all five demo requests, including the guard-refused fabrication.</li>
</ul>
<p>Full changelog: <a href="https://github.com/stranxik/runward/blob/main/CHANGELOG.md">CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>Keep Node Current</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/keep-node-current/</link><pubDate>Mon, 20 Jul 2026 07:23:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/keep-node-current/</guid><description>Version updated for https://github.com/TimothyJones/github-action-keep-node-current to version v1.1.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action “Keep Node Current” automates the process of keeping Node.js versions declared across a repository synchronized with the official Node.js release schedule. It updates CI matrix configurations, single-version pins in actions/setup-node, .nvmrc, and package.json files, and opens pull requests for each change. The action ensures that all active even (LTS) majors are included and end-of-life majors are removed, while also managing version floors in engines.node. It provides clear commit and PR titles to reflect the changes made.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TimothyJones/github-action-keep-node-current">https://github.com/TimothyJones/github-action-keep-node-current</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/keep-node-current">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action &ldquo;Keep Node Current&rdquo; automates the process of keeping Node.js versions declared across a repository synchronized with the official Node.js release schedule. It updates CI matrix configurations, single-version pins in <code>actions/setup-node</code>, <code>.nvmrc</code>, and <code>package.json</code> files, and opens pull requests for each change. The action ensures that all active even (LTS) majors are included and end-of-life majors are removed, while also managing version floors in <code>engines.node</code>. It provides clear commit and PR titles to reflect the changes made.</p>
]]></content:encoded></item><item><title>GitHub Actions Version Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/github-actions-version-audit/</link><pubDate>Mon, 20 Jul 2026 07:22:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/20/github-actions-version-audit/</guid><description>Version updated for https://github.com/varunchandak/gh-actions-version-audit to version v1.1.8.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action audits your repository’s workflows to identify outdated GitHub Actions, mutable action tags, and CI/CD supply-chain drift. It checks each uses: reference against the GitHub API to ensure it points to the most recent release, reporting any version drift or insecure tag pinning. The action can help prevent supply chain attacks by recommending full-length commit SHA pinning and send Slack notifications for any changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/varunchandak/gh-actions-version-audit">https://github.com/varunchandak/gh-actions-version-audit</a></strong> to version <strong>v1.1.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-actions-version-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action audits your repository&rsquo;s workflows to identify outdated GitHub Actions, mutable action tags, and CI/CD supply-chain drift. It checks each <code>uses:</code> reference against the GitHub API to ensure it points to the most recent release, reporting any version drift or insecure tag pinning. The action can help prevent supply chain attacks by recommending full-length commit SHA pinning and send Slack notifications for any changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Refresh Marketplace README with SHA-pinned usage examples.</p>
]]></content:encoded></item><item><title>patchnotes changelog validator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/patchnotes-changelog-validator/</link><pubDate>Sun, 19 Jul 2026 22:20:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/patchnotes-changelog-validator/</guid><description>Version updated for https://github.com/Londopy/patchnotes to version v2.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The patchnotes GitHub Action parses and validates Keep a Changelog formatted CHANGELOG.md files or YAML changelogs into structured Python objects. It automates tasks such as parsing, diffing changes between versions, validating the format, and rendering changelogs to various formats like HTML, RSS, or plain text. The action is built for use in Python code, shell scripts, and CI/CD pipelines, with pure Python and type support, including YAML parsing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Londopy/patchnotes">https://github.com/Londopy/patchnotes</a></strong> to version <strong>v2.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/patchnotes-changelog-validator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The patchnotes GitHub Action parses and validates Keep a Changelog formatted CHANGELOG.md files or YAML changelogs into structured Python objects. It automates tasks such as parsing, diffing changes between versions, validating the format, and rendering changelogs to various formats like HTML, RSS, or plain text. The action is built for use in Python code, shell scripts, and CI/CD pipelines, with pure Python and type support, including YAML parsing.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><code>patchnotes init</code> scaffolds a spec-compliant starter CHANGELOG.md (strict-validation clean out of the box); <code>--workflow</code> also writes a ready-made <code>.github/workflows/changelog.yml</code> PR check.</li>
<li><code>dep --requirements old.txt new.txt</code> diffs two requirements files and runs the breaking/security analysis for every changed pin at once — built for reviewing lockfile bump PRs. With <code>--strict</code>, flagged changes fail CI.</li>
<li>mkdocs plugin: add <code>patchnotes</code> to <code>plugins:</code> in mkdocs.yml and a <code>&lt;!-- patchnotes --&gt;</code> marker in any docs page renders the styled changelog at build time (<code>pip install patchnotes[mkdocs]</code>).</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>An empty [Unreleased] section no longer triggers a PN203 warning — it&rsquo;s the normal state right after a release (and what <code>bump</code> leaves behind). Empty <em>versioned</em> releases still warn.</li>
</ul>
]]></content:encoded></item><item><title>treegen — File Tree for README</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/treegen-file-tree-for-readme/</link><pubDate>Sun, 19 Jul 2026 22:18:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/treegen-file-tree-for-readme/</guid><description>Version updated for https://github.com/lucianofedericopereira/treegen to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action converts Markdown files into a directory tree, providing options to render the tree in ASCII, SVG, or collapsible format, with support for descriptions and excluding certain files. It supports themes for SVG rendering and can be integrated into any repository without additional dependencies.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lucianofedericopereira/treegen">https://github.com/lucianofedericopereira/treegen</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/treegen-file-tree-for-readme">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action converts Markdown files into a directory tree, providing options to render the tree in ASCII, SVG, or collapsible format, with support for descriptions and excluding certain files. It supports themes for SVG rendering and can be integrated into any repository without additional dependencies.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>🌳 First release of treegen.</p>
<p>Turn <code>[[files]]</code> markers (or <code>&lt;!-- filetree --&gt;</code> blocks) into a directory tree
in your README — kept in sync on every push.</p>
<ul>
<li><strong>Three styles:</strong> ASCII, a theme-aware <strong>SVG</strong> with folder icons, and a native <strong>collapsible</strong> <code>&lt;details&gt;</code> tree</li>
<li><strong>SVG colours:</strong> <code>github</code> (default, matches GitHub) + blue/green/red/orange/yellow/purple/pink/gray, light &amp; dark</li>
<li><strong>HTML output</strong> mode for landing pages / GitHub Pages</li>
<li><strong>CI check mode</strong>, per-marker options, <code>.gitignore</code>-aware</li>
<li>Pure standard-library Python · <code>mypy --strict</code> · zero runtime deps</li>
</ul>
<p>Usage: <code>uses: lucianofedericopereira/treegen@v1</code></p>
]]></content:encoded></item><item><title>SecureSoroban</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/securesoroban/</link><pubDate>Sun, 19 Jul 2026 22:17:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/securesoroban/</guid><description>Version updated for https://github.com/mammumammi/Secure-soroban-marketplace-Action to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SecureSoroban automates the detection of critical vulnerabilities in Soroban smart contracts by simulating real attack vectors, confirming what actually breaks, and calculating estimated financial loss in XLM and USD. It helps prevent vulnerabilities from reaching mainnet and blocks deployment automatically if critical issues are found. SecureSoroban also includes a local AI agent powered by Qwen2.5-coder:7b for more advanced analysis and targeted attacks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mammumammi/Secure-soroban-marketplace-Action">https://github.com/mammumammi/Secure-soroban-marketplace-Action</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/securesoroban">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SecureSoroban automates the detection of critical vulnerabilities in Soroban smart contracts by simulating real attack vectors, confirming what actually breaks, and calculating estimated financial loss in XLM and USD. It helps prevent vulnerabilities from reaching mainnet and blocks deployment automatically if critical issues are found. SecureSoroban also includes a local AI agent powered by Qwen2.5-coder:7b for more advanced analysis and targeted attacks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release of SecureSoroban — automated smart contract attack simulator for the Stellar ecosystem.</p>
<h2 id="whats-included">What&rsquo;s included</h2>
<ul>
<li>Authorization bypass detection</li>
<li>Unauthorized drain detection</li>
<li>Reentrancy pattern detection</li>
<li>Integer overflow detection</li>
<li>Static source code analysis</li>
<li>Financial loss calculation in XLM and USD</li>
<li>Automatic push blocking on critical findings</li>
</ul>
<h2 id="setup">Setup</h2>
<p>See README.md for full setup instructions.</p>
<p>Built at Stellar Build Station Kerala 2026.</p>
]]></content:encoded></item><item><title>guardmarly</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/guardmarly/</link><pubDate>Sun, 19 Jul 2026 22:16:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/guardmarly/</guid><description>Version updated for https://github.com/mattybellx/Guardmarly to version v6.6.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Guardmarly is a static analysis tool that focuses on identifying and flagging common security issues related to authorization gaps and risky code paths, such as IDOR (Insecure Direct Object Reference) vulnerabilities. It analyzes HTTP routes, checks for authentication guards, and traces data flow to potential sinks, helping developers identify and address these critical security flaws in their applications.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mattybellx/Guardmarly">https://github.com/mattybellx/Guardmarly</a></strong> to version <strong>v6.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/guardmarly">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Guardmarly is a static analysis tool that focuses on identifying and flagging common security issues related to authorization gaps and risky code paths, such as IDOR (Insecure Direct Object Reference) vulnerabilities. It analyzes HTTP routes, checks for authentication guards, and traces data flow to potential sinks, helping developers identify and address these critical security flaws in their applications.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="650--2026-07-18">[6.5.0] — 2026-07-18</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>VS Code Extension v1.2.0</strong> — Gutter severity decorations (red/orange/yellow dots), findings quick-pick (click status bar), scan spinner animation, auto CLI detection (pip/python -m/python3 -m), friendly install prompt when CLI missing. Slim 28KB package.</li>
<li><strong>Live scan counter</strong> on guardmarly.onrender.com landing page</li>
<li><strong>CI pipeline reference</strong> at <code>.github/CI.md</code> documenting all auto-deploy triggers</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>VS Code extension now auto-detects guardmarly CLI via multiple methods</li>
<li>Extension publish triggers on every push to main (vscode-extension/** changes)</li>
<li>Render.com auto-deploys via Dockerfile with persistent scan counter</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Release workflow: <code>softprops/action-gh-release</code> downgraded to v1 (v2 API bug)</li>
<li>Extension CI: <code>@types/node</code> types resolution, icon files tracked in git</li>
<li>Webapp Docker build: removed redundant guardmarly pip install (source copied directly)</li>
</ul>
]]></content:encoded></item><item><title>Mipiti Verify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/mipiti-verify/</link><pubDate>Sun, 19 Jul 2026 22:15:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/mipiti-verify/</guid><description>Version updated for https://github.com/Mipiti/mipiti-verify to version v0.47.3.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Mipiti-verify automates the verification of Mipiti threat model assertions using AI models, offering local and online verification options. It supports OpenAI and Anthropic models for Tier 2 verification and provides a command-line interface for running and checking individual assertions locally. The action also includes features to list and report on pending and verified assertions, as well as audit signed reports for integrity and provenance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Mipiti/mipiti-verify">https://github.com/Mipiti/mipiti-verify</a></strong> to version <strong>v0.47.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mipiti-verify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Mipiti-verify automates the verification of Mipiti threat model assertions using AI models, offering local and online verification options. It supports OpenAI and Anthropic models for Tier 2 verification and provides a command-line interface for running and checking individual assertions locally. The action also includes features to list and report on pending and verified assertions, as well as audit signed reports for integrity and provenance.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="docker-image">Docker Image</h3>
<p>Pre-built image for faster CI (pulls cached image instead of building from source):</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">docker://ghcr.io/mipiti/mipiti-verify:v0.47.3@sha256:92cd7948a5c902adfc16d844916569a9c6a54d18e01e62ef95de38d1fbdd6fd6</span>
</span></span></code></pre></div><p>Image: <code>ghcr.io/mipiti/mipiti-verify:v0.47.3</code>
Digest: <code>sha256:92cd7948a5c902adfc16d844916569a9c6a54d18e01e62ef95de38d1fbdd6fd6</code></p>
]]></content:encoded></item><item><title>Upload UI Evidence</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/upload-ui-evidence/</link><pubDate>Sun, 19 Jul 2026 22:14:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/upload-ui-evidence/</guid><description>Version updated for https://github.com/mtzack-org/upload-ui-evidence to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of uploading UI test evidence from CI/CD pipelines to a private UI Evidence Portal. It supports various testing frameworks like Playwright, Maestro, and Appium, allowing you to visualize and share screenshots, videos, reports, traces, and logs directly from your CI job summaries. The action provides flexibility in specifying which files to upload and handles cases where no evidence is found by configuring the behavior via output options.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mtzack-org/upload-ui-evidence">https://github.com/mtzack-org/upload-ui-evidence</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/upload-ui-evidence">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of uploading UI test evidence from CI/CD pipelines to a private UI Evidence Portal. It supports various testing frameworks like Playwright, Maestro, and Appium, allowing you to visualize and share screenshots, videos, reports, traces, and logs directly from your CI job summaries. The action provides flexibility in specifying which files to upload and handles cases where no evidence is found by configuring the behavior via output options.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Mobile testing documentation release.</p>
<ul>
<li>Add Maestro workflow example</li>
<li>Add Appium workflow example</li>
<li>Document Playwright, Maestro, and Appium support in English and Japanese</li>
<li>Improve Marketplace discoverability for mobile UI testing</li>
</ul>
<p>The Action runtime is unchanged.</p>
]]></content:encoded></item><item><title>lacuna-cli</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/lacuna-cli/</link><pubDate>Sun, 19 Jul 2026 22:12:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/lacuna-cli/</guid><description>Version updated for https://github.com/Octagon-simon/lacuna to version v0.3.5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Lacuna is a command-line tool that automates the process of writing unit and integration tests for untested code in your project using OpenAI-compatible models. It reads your existing code, identifies parts without coverage, generates corresponding test cases, runs them, and retries those that fail. This ensures that what lands in your repository actually passes, while maintaining the quality of your tests through continuous refactoring.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Octagon-simon/lacuna">https://github.com/Octagon-simon/lacuna</a></strong> to version <strong>v0.3.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lacuna-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Lacuna is a command-line tool that automates the process of writing unit and integration tests for untested code in your project using OpenAI-compatible models. It reads your existing code, identifies parts without coverage, generates corresponding test cases, runs them, and retries those that fail. This ensures that what lands in your repository actually passes, while maintaining the quality of your tests through continuous refactoring.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Octagon-simon/lacuna/compare/v0.3.4...v0.3.5">https://github.com/Octagon-simon/lacuna/compare/v0.3.4...v0.3.5</a></p>
]]></content:encoded></item><item><title>Otzaria Plugin Validator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/otzaria-plugin-validator/</link><pubDate>Sun, 19 Jul 2026 22:10:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/otzaria-plugin-validator/</guid><description>Version updated for https://github.com/Otzaria/otzaria-plugin-validator to version v1.9.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action validates and automatically publishes an Otzaria plugin to the store upon pushing changes to the main branch, ensuring that only updates are published after approval from store administrators. It supports multiple plugins in a monorepo and requires API reference URLs for dynamic validation. The action can run as a pull_request check without publishing by default, but requires secrets for automated publication.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Otzaria/otzaria-plugin-validator">https://github.com/Otzaria/otzaria-plugin-validator</a></strong> to version <strong>v1.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/otzaria-plugin-validator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action validates and automatically publishes an Otzaria plugin to the store upon pushing changes to the main branch, ensuring that only updates are published after approval from store administrators. It supports multiple plugins in a monorepo and requires API reference URLs for dynamic validation. The action can run as a pull_request check without publishing by default, but requires secrets for automated publication.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>אירועי lifecycle חדשים ברשימת האירועים המוכרים: plugin.suspended, plugin.resumed, plugin.page_opened</li>
<li>מתודות שנוספו: app.openUrl (0.9.95), plugin.openSelf (0.9.96) כולל מיפויי גרסה והרשאה</li>
<li>הרשאות שנוספו: app.open_url, fs.user_files.read, network.localhost</li>
<li>network.localhost מספק כעת את דרישת ההרשאה של network.fetch/download (תוקנה אזהרת שווא)</li>
<li>מיפוי הרשאה ל-ui.pickFolder ולמתודות fs.*</li>
<li>בדיקות רגרסיה חדשות לכל האמור</li>
</ul>
]]></content:encoded></item><item><title>OWASP Noir Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/owasp-noir-action/</link><pubDate>Sun, 19 Jul 2026 22:09:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/owasp-noir-action/</guid><description>Version updated for https://github.com/owasp-noir/noir to version v1.2.0.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action leverages the Noir SAST tool to identify and document all exposed endpoints in code, including parameters, headers, cookies, and the source files behind them. It supports various languages and frameworks, provides AI context for LLM-based SAST, and integrates with DAST tools like ZAP, Burp Suite, and Caido. The action is designed to be integrated into CI/CD pipelines and can output results in multiple formats.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/owasp-noir/noir">https://github.com/owasp-noir/noir</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/owasp-noir-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action leverages the Noir SAST tool to identify and document all exposed endpoints in code, including parameters, headers, cookies, and the source files behind them. It supports various languages and frameworks, provides AI context for LLM-based SAST, and integrates with DAST tools like ZAP, Burp Suite, and Caido. The action is designed to be integrated into CI/CD pipelines and can output results in multiple formats.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v120">v1.2.0</h2>
<p>Noir v1.2.0 broadens attack-surface coverage beyond web frameworks — CLI applications, built-in HTTP servers, schema-generated platforms, and enterprise legacy stacks — and lands a codebase-wide performance sweep across every supported language.</p>
<h3 id="added">Added</h3>
<ul>
<li><strong>CLI application endpoints</strong>: detect command-line attack surface (argv, flags, environment variables) as endpoints across 17 languages and 40+ CLI libraries (Cobra, Click, clap, Commander, Thor, picocli, Spectre.Console, and more).</li>
<li><strong>Built-in web server analyzers</strong>: stdlib HTTP servers for Go (<code>net/http</code>), Python (<code>http.server</code>), Node (<code>node:http</code>), Java (<code>com.sun.net.httpserver</code>), C# (<code>HttpListener</code>), Ruby (WEBrick), Crystal (<code>HTTP::Server</code>), Dart (<code>dart:io</code>), and Zig (<code>std.http.Server</code>).</li>
<li><strong>Schema-generated API analyzers</strong>: Strapi, Directus, Payload CMS, Supabase/PostgREST, Hasura, and Appwrite — platforms that derive their HTTP surface from schema files rather than source-level routes, with attribute definitions expanded into params.</li>
<li><strong>Enterprise legacy stacks</strong>: CFML/ColdFusion, Classic ASP, and ASP.NET WebForms, plus the CFML frameworks Taffy, ColdBox, Wheels, and FW/1.</li>
<li><strong>BEAM languages</strong>: Erlang (Cowboy, Elli) and Gleam (Wisp).</li>
<li>New PHP CMS/platform analyzers: WordPress (REST API, admin-ajax, admin-post), Drupal (<code>*.routing.yml</code>), and Magento (Web API + MVC controller routes).</li>
<li>New framework analyzers: Django Ninja (Python) and Plumber (R).</li>
<li><strong>Terraform / OpenTofu analyzer</strong>: AWS API Gateway v1/v2 routes from <code>.tf</code> HCL and <code>.tf.json</code>, resolved module-wide.</li>
<li>Realtime/event endpoint detection for SignalR, Socket.IO, Phoenix Channels, and Action Cable.</li>
<li>New specification analyzers: OpenRPC service descriptions, and <code>.http</code> / <code>.rest</code> request files (VS Code REST Client, JetBrains HTTP Client).</li>
<li>Machine-readable output for <code>noir list</code> and documented <code>noir cache purge</code>.</li>
<li>Added Claude Sonnet 5, Grok 4.5, and GPT-5.6 to the AI provider token map.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>Redesigned the HTML report (<code>-f html</code>) as a dark-tech theme with semantic method/severity colors, path grouping, table view, and copy URL/curl actions.</li>
<li>Rebuilt the documentation site around the project&rsquo;s own film-noir artwork.</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li>Codebase-wide analyzer and detector sweep across all 24 language groups: eliminated O(n²) non-ASCII character scans, collapsed chained <code>includes?</code> gates into precompiled <code>Regex.union</code>, memoized interpolated regexes, and routed file reads through the content cache. Large wins on real projects (e.g. F#/Giraffe 31.7s → 1.1s, Servant 101s → 4ms).</li>
<li>Guarded specification detectors before YAML/JSON parsing and memoized <code>applicable?</code> by extension/basename.</li>
<li>Memoized tree-sitter extraction results and consolidated multi-pass pre-scans into single-parse surfaces.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Fixed a wide class of byte-vs-char offset bugs on non-ASCII sources, plus allocation-free line counting.</li>
<li>Robustness and correctness fixes across the <code>noir config</code>, <code>rules</code>, <code>cache</code>, <code>list</code>, and completion subcommands.</li>
<li>Fidelity and render fixes for the Mermaid mindmap output format.</li>
<li>Made endpoint ordering deterministic across machines and ran the log spinner as a fiber instead of a bare thread.</li>
<li>macOS release binaries now ship as portable <code>.tar.gz</code> archives with bundled OpenSSL, instead of a bare executable linked against Homebrew <code>openssl@1.1</code> that failed to launch on clean machines.</li>
<li>GitHub Action entrypoint CI coverage, robust image-tag resolution, and injection-safe examples.</li>
<li>Improved Java, Go, Python, Ruby, Kotlin, Rust (Axum), and tRPC v9 route accuracy.</li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@gords2 made their first contribution in <a href="https://github.com/owasp-noir/noir/pull/2175">https://github.com/owasp-noir/noir/pull/2175</a></li>
<li>@c0d33ngr made their first contribution in <a href="https://github.com/owasp-noir/noir/pull/2199">https://github.com/owasp-noir/noir/pull/2199</a></li>
<li>@ahfoysal made their first contribution in <a href="https://github.com/owasp-noir/noir/pull/2247">https://github.com/owasp-noir/noir/pull/2247</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/owasp-noir/noir/compare/v1.1.0...v1.2.0">https://github.com/owasp-noir/noir/compare/v1.1.0...v1.2.0</a></p>
]]></content:encoded></item><item><title>rl-package</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/rl-package/</link><pubDate>Sun, 19 Jul 2026 22:07:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/rl-package/</guid><description>Version updated for https://github.com/rl-lang/rl-package to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The rl-package GitHub Action packages an .rl source file into a self-contained binary for Linux, macOS, or Windows using the RL language and uploads it as a workflow artifact. It solves the problem of automating the packaging process for RL programs in CI/CD pipelines by providing a simple configuration interface to specify input parameters such as the source file path and output name. The action supports caching for quick repeat runs and is compatible with various runners including Ubuntu, macOS, and Windows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rl-lang/rl-package">https://github.com/rl-lang/rl-package</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rl-package">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The rl-package GitHub Action packages an <code>.rl</code> source file into a self-contained binary for Linux, macOS, or Windows using the RL language and uploads it as a workflow artifact. It solves the problem of automating the packaging process for RL programs in CI/CD pipelines by providing a simple configuration interface to specify input parameters such as the source file path and output name. The action supports caching for quick repeat runs and is compatible with various runners including Ubuntu, macOS, and Windows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/rl-lang/rl-package/compare/v0.1.0...v1.0.0">https://github.com/rl-lang/rl-package/compare/v0.1.0...v1.0.0</a></p>
]]></content:encoded></item><item><title>AAB to APK with Bundletool</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/aab-to-apk-with-bundletool/</link><pubDate>Sun, 19 Jul 2026 22:06:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/aab-to-apk-with-bundletool/</guid><description>Version updated for https://github.com/roberteggl/bundletool-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Bundletool Action is a GitHub Action that automates the conversion of Android App Bundles (.aab) to APKs using Google’s bundletool. It automatically downloads and caches bundletool with version pinning, supports both universal APK generation and device-specific APK extraction, provides optional APK signing from a keystore path or base64 GitHub Secret, and includes features like dry-run and verbose logging. The action validates configuration inputs and masks secrets in logs for enhanced security.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/roberteggl/bundletool-action">https://github.com/roberteggl/bundletool-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aab-to-apk-with-bundletool">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Bundletool Action is a GitHub Action that automates the conversion of Android App Bundles (<code>.aab</code>) to APKs using Google&rsquo;s bundletool. It automatically downloads and caches bundletool with version pinning, supports both universal APK generation and device-specific APK extraction, provides optional APK signing from a keystore path or base64 GitHub Secret, and includes features like dry-run and verbose logging. The action validates configuration inputs and masks secrets in logs for enhanced security.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="100---2026-07-19"><a href="https://github.com/roberteggl/bundletool-action/compare/v0.1.3..v1.0.0">1.0.0</a> - 2026-07-19</h2>
<h3 id="-miscellaneous-tasks">⚙️ Miscellaneous Tasks</h3>
<ul>
<li>Add workflow steps to build and assert signed universal APK from AAB -  by @roberteggl (<a href="https://github.com/roberteggl/bundletool-action/commit/66e9a73a1e0837559ecd2e6b55912e5fd62a89de">66e9a73</a>)</li>
<li>Update README and SECURITY documentation for version 1.x and adjust CI workflow for keystore location -  by @roberteggl (<a href="https://github.com/roberteggl/bundletool-action/commit/ed2f10873743e3de8dcd315cb9f8fc58fde271c3">ed2f108</a>)</li>
<li>Update version to 1.0.0 in package.json and adjust release instructions in AGENTS.md -  by @roberteggl (<a href="https://github.com/roberteggl/bundletool-action/commit/64713a9081adc6f5ea408a9c19917a3e23f9f287">64713a9</a>)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/roberteggl/bundletool-action/compare/v0.1.3...v1.0.0">https://github.com/roberteggl/bundletool-action/compare/v0.1.3...v1.0.0</a></p>
]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/rumdl-action/</link><pubDate>Sun, 19 Jul 2026 22:04:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.37.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
rumdl is a high-performance Markdown linter and formatter built with Rust. It offers speed, extensive linting rules (76 in total), automatic formatting, and multiple Markdown flavors support. The action simplifies the process of checking and fixing markdown files, making it easier to maintain consistency across projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.37</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>rumdl is a high-performance Markdown linter and formatter built with Rust. It offers speed, extensive linting rules (76 in total), automatic formatting, and multiple Markdown flavors support. The action simplifies the process of checking and fixing markdown files, making it easier to maintain consistency across projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>reflow</strong>: add atomic_spans configuration and refactor inline wrapping (#742) (<a href="https://github.com/rvben/rumdl/commit/aeabec1070d6f87baa7d2e817c75c86047d7ad2a">aeabec1</a>)</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>BREAKING</strong>: the MD013 <code>emphasis-spans</code> option is renamed to <code>atomic-spans</code> (default <code>true</code>), with inverted meaning (<code>emphasis-spans = true</code> is now <code>atomic-spans = false</code>). Configs setting the old key should migrate; it is no longer recognized</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>reflow</strong>: keep code spans atomic when wrapping would collapse whitespace (<a href="https://github.com/rvben/rumdl/commit/d43618ba07a231eab8cf0babe9d170a38fc38986">d43618b</a>)</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.37-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.37-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.37-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.37-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-apple-darwin.tar.gz">rumdl-v0.2.37-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-apple-darwin.tar.gz">rumdl-v0.2.37-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-pc-windows-msvc.zip">rumdl-v0.2.37-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.37/rumdl-v0.2.37-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>TCalc Workspace Report</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/tcalc-workspace-report/</link><pubDate>Sun, 19 Jul 2026 22:03:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/tcalc-workspace-report/</guid><description>Version updated for https://github.com/Sandesh13fr/TCalc to version v0.1.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary TCalc is a local tool that measures and recommends models and context for coding agents. It analyzes a workspace to identify token-heavy files, folders, and languages, comparing them against different models to generate budgeted repo maps and agent rules. The tool respects workspace ignore rules and can be used in VS Code or as a CLI tool.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Sandesh13fr/TCalc">https://github.com/Sandesh13fr/TCalc</a></strong> to version <strong>v0.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tcalc-workspace-report">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>TCalc is a local tool that measures and recommends models and context for coding agents. It analyzes a workspace to identify token-heavy files, folders, and languages, comparing them against different models to generate budgeted repo maps and agent rules. The tool respects workspace ignore rules and can be used in VS Code or as a CLI tool.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Sandesh13fr/TCalc/compare/v0.1.2...v0.1.3">https://github.com/Sandesh13fr/TCalc/compare/v0.1.2...v0.1.3</a></p>
]]></content:encoded></item><item><title>seekrit — load secrets</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/seekrit-load-secrets/</link><pubDate>Sun, 19 Jul 2026 22:02:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/seekrit-load-secrets/</guid><description>Version updated for https://github.com/seekritdev/github-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of loading secrets from seekrit, a secure secret management tool. It decrypts secrets locally using a private key associated with a service token and injects them into subsequent steps as environment variables, ensuring that sensitive information is not exposed in logs or visible to other team members. The action supports various configurations such as prefixing variable names, filtering which secrets to include or exclude, and exposing secrets as step outputs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/seekritdev/github-action">https://github.com/seekritdev/github-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/seekrit-load-secrets">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of loading secrets from seekrit, a secure secret management tool. It decrypts secrets locally using a private key associated with a service token and injects them into subsequent steps as environment variables, ensuring that sensitive information is not exposed in logs or visible to other team members. The action supports various configurations such as prefixing variable names, filtering which secrets to include or exclude, and exposing secrets as step outputs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: seekrit secrets loader for GitHub Actions (591d2ea)</li>
</ul>
]]></content:encoded></item><item><title>Argus PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/argus-pr-review/</link><pubDate>Sun, 19 Jul 2026 22:01:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/argus-pr-review/</guid><description>Version updated for https://github.com/sibinms/argus to version v1.2.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Argus is a GitHub Action that automates the process of code reviews using AI. It runs multiple specialized AI reviewers in parallel, providing a more comprehensive view than relying on a single model. The action uses an evidence-based curator to verify findings before posting review comments on pull requests, ensuring only valid issues are highlighted. This approach helps in finding more real bugs while minimizing false positives.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sibinms/argus">https://github.com/sibinms/argus</a></strong> to version <strong>v1.2.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/argus-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Argus is a GitHub Action that automates the process of code reviews using AI. It runs multiple specialized AI reviewers in parallel, providing a more comprehensive view than relying on a single model. The action uses an evidence-based curator to verify findings before posting review comments on pull requests, ensuring only valid issues are highlighted. This approach helps in finding more real bugs while minimizing false positives.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Pin the Action to this tag:</p>
<pre><code>- uses: sibinms/argus@v1.2.4
</code></pre>
<h2 id="whats-new-since-v123">What&rsquo;s new since v1.2.3</h2>
<p><strong>Reviewing</strong></p>
<ul>
<li><strong>Precision overhaul</strong> of the lenses and curator: a finding must now assert a real problem (not narrate a change), the contracts lens is scoped to genuine public/consumer-facing surfaces, and the curator can drop pure narration and mis-scoped-impact findings. Cut self-review noise dramatically.</li>
</ul>
<p><strong>Posting — the &ldquo;moderator&rdquo;</strong></p>
<ul>
<li>Idempotent posting: <strong>one rolling summary</strong> comment edited in place, each finding posted <strong>once</strong> (drift-proof fingerprint), addressed threads <strong>resolved</strong>, a hard <strong><code>max_inline_comments</code></strong> cap (default 10), and no new review when nothing changed — a PR can&rsquo;t fill up with comments.</li>
<li>Inline comments only ever attach to lines in the diff (fixes 422 &ldquo;line could not be resolved&rdquo;).</li>
<li><strong>Opt-in real approvals</strong> via <code>approve_reviews</code> (default off); falls back to a comment where the repo hasn&rsquo;t enabled Actions approvals, so a clean PR never fails.</li>
</ul>
<p><strong>Providers</strong></p>
<ul>
<li><strong>OpenRouter</strong> documented as a first-class provider (any litellm provider works: Anthropic, OpenAI, Gemini, OpenRouter, &hellip;).</li>
<li>Timeout on the LLM call; salvage JSON when a model wraps it in prose.</li>
</ul>
<p><strong>Docs &amp; project</strong></p>
<ul>
<li>Branded, theme-aware architecture diagram in the README.</li>
<li>62 tests; lint, type-check, security (Bandit + pip-audit + CodeQL) all green.</li>
</ul>
<p>This entire release was reviewed and <strong>approved by Argus itself</strong> (PR #1).</p>
]]></content:encoded></item><item><title>ifttt-lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/ifttt-lint/</link><pubDate>Sun, 19 Jul 2026 22:00:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/ifttt-lint/</guid><description>Version updated for https://github.com/simonepri/ifttt-lint to version v0.10.8.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action ifttt-lint automates the catchment of cross-file drift by enforcing consistent changes across related codebases through comments. It helps in maintaining synchronization between different programming languages, databases, and APIs to prevent issues that arise from uncoordinated updates. The action supports GitHub Actions for push and pull_request events, pre-commit hooks, and manual installation via Cargo.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/simonepri/ifttt-lint">https://github.com/simonepri/ifttt-lint</a></strong> to version <strong>v0.10.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ifttt-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>ifttt-lint</code> automates the catchment of cross-file drift by enforcing consistent changes across related codebases through comments. It helps in maintaining synchronization between different programming languages, databases, and APIs to prevent issues that arise from uncoordinated updates. The action supports GitHub Actions for push and pull_request events, pre-commit hooks, and manual installation via Cargo.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>chore: release v0.10.8 (#44) (5193c10)</li>
<li>fix: don&rsquo;t misparse deleted &ldquo;&ndash;&rdquo; lines as file headers (#42) (d767ed4)</li>
<li>chore(deps): bump crossbeam-epoch to fix RUSTSEC-2026-0204 (#43) (a5182a3)</li>
<li>chore: release v0.10.7 (#40) (3468fe7)</li>
<li>fix: don&rsquo;t panic on a mid-hunk no-newline marker (#38) (b2da92d)</li>
<li>fix: don&rsquo;t crash on diff sections without hunks (#39) (5aed9e2)</li>
<li>chore: release v0.10.6 (#35) (24a9ecd)</li>
<li>fix: don&rsquo;t fire when a new directive pair wraps changed content (#34) (348f008)</li>
<li>chore: release v0.10.5 (#29) (bfaec4d)</li>
<li>feat(jj): add Jujutsu VCS backend (#32) (1a190d4)</li>
</ul>
]]></content:encoded></item><item><title>SJ_TEST Giphy PR Comments</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/sj_test-giphy-pr-comments/</link><pubDate>Sun, 19 Jul 2026 21:59:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/sj_test-giphy-pr-comments/</guid><description>Version updated for https://github.com/SJWarrior-17/js_pr-giphy-comment to version alpha-v1.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the addition of a Giphy GIF comment to new pull requests in a GitHub repository. It simplifies the process by using Node.js and the @octokit/rest package to interact with the GitHub API, along with the giphy-api package to fetch a random GIF from the Giphy service. The action is configured to accept input parameters for GitHub token and Giphy API token, ensuring that it can be easily integrated into various repositories to enhance communication and engagement during pull requests.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SJWarrior-17/js_pr-giphy-comment">https://github.com/SJWarrior-17/js_pr-giphy-comment</a></strong> to version <strong>alpha-v1.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sj_test-giphy-pr-comments">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the addition of a Giphy GIF comment to new pull requests in a GitHub repository. It simplifies the process by using Node.js and the <code>@octokit/rest</code> package to interact with the GitHub API, along with the <code>giphy-api</code> package to fetch a random GIF from the Giphy service. The action is configured to accept input parameters for GitHub token and Giphy API token, ensuring that it can be easily integrated into various repositories to enhance communication and engagement during pull requests.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Updated-3 the index.js (7e16380)</li>
<li>Updated-2 the index.js (2f6a5da)</li>
<li>Updated-1 the index.js (96188b5)</li>
<li>Updated th index.js (25b64f1)</li>
<li>Preparing for publish on Marketplace (90ce8a7)</li>
<li>Initial commit (80b0518)</li>
</ul>
]]></content:encoded></item><item><title>spek - OpenSpec Static Site</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/spek-openspec-static-site/</link><pubDate>Sun, 19 Jul 2026 21:58:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/spek-openspec-static-site/</guid><description>Version updated for https://github.com/spekhq/spek to version v1.8.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Spek is a lightweight read-only viewer for OpenSpec content that automates tasks such as browsing specs, changes, and tasks with structure. It solves problems related to managing parallel worktrees in AI-agent environments by aggregating all in-flight changes into one view, providing full-text search capabilities, and offering a responsive layout across various screen sizes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spekhq/spek">https://github.com/spekhq/spek</a></strong> to version <strong>v1.8.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spek-openspec-static-site">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Spek is a lightweight read-only viewer for OpenSpec content that automates tasks such as browsing specs, changes, and tasks with structure. It solves problems related to managing parallel worktrees in AI-agent environments by aggregating all in-flight changes into one view, providing full-text search capabilities, and offering a responsive layout across various screen sizes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li><strong>Lists with blank lines between their items render correctly again (Web, VS Code and IntelliJ).</strong> Every bullet and number was pushed onto its own line, above the text it belonged to, which made proposals and task lists hard to scan. Markers now sit inline with the first line of their item. Thanks to <a href="https://github.com/nthansen">@nthansen</a> (Norman Hansen) for reporting and contributing this.</li>
</ul>
]]></content:encoded></item><item><title>runward gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/runward-gate/</link><pubDate>Sun, 19 Jul 2026 21:57:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/runward-gate/</guid><description>Version updated for https://github.com/stranxik/runward to version v0.20.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Runward is a tool that automates the verification of engineering decisions made by AI-generated code. It checks whether the architectural, security, and operational aspects were correctly implemented during the development process. By running the deterministic gate, Runward ensures that the load-bearing decisions are accurately recorded and can be verified deterministically without relying on an LLM.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stranxik/runward">https://github.com/stranxik/runward</a></strong> to version <strong>v0.20.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/runward-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Runward is a tool that automates the verification of engineering decisions made by AI-generated code. It checks whether the architectural, security, and operational aspects were correctly implemented during the development process. By running the deterministic gate, Runward ensures that the load-bearing decisions are accurately recorded and can be verified deterministically without relying on an LLM.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Regulated-adoption evidence + SBOM/provenance (ADR-0031), OSCAL 1.2.2 proven by a third-party tool (ADR-0032), security-audit hardening, TypeScript 7 forward-compat, docs/README. Full changelog: <a href="https://github.com/stranxik/runward/blob/main/CHANGELOG.md">https://github.com/stranxik/runward/blob/main/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>Setup Tombi</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/setup-tombi/</link><pubDate>Sun, 19 Jul 2026 21:56:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/setup-tombi/</guid><description>Version updated for https://github.com/tombi-toml/setup-tombi to version v1.2.4.
This action is used across all versions by 138 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up Tombi, a dependency manager for TOML files in your GitHub Actions workflows. It allows users to install Tombi and its dependencies efficiently, with options for specifying specific versions, using lock files, enabling checksum verification, and configuring cache behavior.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tombi-toml/setup-tombi">https://github.com/tombi-toml/setup-tombi</a></strong> to version <strong>v1.2.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>138</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-tombi">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up Tombi, a dependency manager for TOML files in your GitHub Actions workflows. It allows users to install Tombi and its dependencies efficiently, with options for specifying specific versions, using lock files, enabling checksum verification, and configuring cache behavior.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This setup-tombi release matches <a href="https://github.com/tombi-toml/tombi/releases/tag/v1.2.4">tombi v1.2.4</a>.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/tombi-toml/setup-tombi/compare/v1...v1.2.4">https://github.com/tombi-toml/setup-tombi/compare/v1...v1.2.4</a></p>
]]></content:encoded></item><item><title>Setup Upwarden</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/setup-upwarden/</link><pubDate>Sun, 19 Jul 2026 21:53:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/setup-upwarden/</guid><description>Version updated for https://github.com/upwarden-io/setup-upwarden to version v2.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The setup-upwarden GitHub Action automates the authentication and authorization of package manager dependencies, enabling keyless OIDC access to private registries. It ensures that every dependency fetch in a CI pipeline is authenticated, attributed, and policy-enforced, mitigating security risks associated with unauthenticated and unattributed package fetches. The action works seamlessly across various toolchains (npm, pnpm, yarn, pip, maven, gradle) and provides a simple setup process to integrate OIDC authentication into your CI pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/upwarden-io/setup-upwarden">https://github.com/upwarden-io/setup-upwarden</a></strong> to version <strong>v2.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-upwarden">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>setup-upwarden</code> GitHub Action automates the authentication and authorization of package manager dependencies, enabling <strong>keyless</strong> OIDC access to private registries. It ensures that every dependency fetch in a CI pipeline is authenticated, attributed, and policy-enforced, mitigating security risks associated with unauthenticated and unattributed package fetches. The action works seamlessly across various toolchains (npm, pnpm, yarn, pip, maven, gradle) and provides a simple setup process to integrate OIDC authentication into your CI pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Adds the <code>block-report</code> sub-action — an opt-in, <strong>zero-secret, zero-config</strong> run-end digest of the dependencies Upwarden blocked in a CI run (CVE/policy id + severity + why + remediation), printed to the job log and the job-summary page.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">upwarden-io/setup-upwarden/block-report@v2</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">if</span>: <span style="color:#ae81ff">always()</span>
</span></span></code></pre></div><p>It reuses the run&rsquo;s own credential (already in the env from <code>setup-upwarden</code>) and reads the run&rsquo;s <strong>own</strong> report via the self-scoped CI route <code>GET /api/v1/ci/run/blocked</code> — no admin token, no org slug, no run id. Recommended for <strong>maven/gradle</strong> (which hide the inline 403 reason), optional elsewhere. Never fails your build.</p>
<p>Validated maven end-to-end: the run&rsquo;s own credential self-read its <code>/blocked</code> and surfaced the CVE that maven had buried behind &ldquo;Failed to read artifact descriptor&rdquo;. The core <code>setup-upwarden</code> action is unchanged from v2.0.1.</p>
]]></content:encoded></item><item><title>Premature Contribution Firewall dry-run</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/premature-contribution-firewall-dry-run/</link><pubDate>Sun, 19 Jul 2026 21:52:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/premature-contribution-firewall-dry-run/</guid><description>Version updated for https://github.com/VrtxOmega/premature-contribution-firewall to version v0.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Premature Contribution Firewall automates the review-readiness assessment of pull requests and patches, helping maintainers prioritize actionable tasks before submission. It ensures that contributions meet key criteria such as reproducibility, scope, testing, and worth human attention, reducing the workload by focusing on issues most likely to be beneficial for the project.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VrtxOmega/premature-contribution-firewall">https://github.com/VrtxOmega/premature-contribution-firewall</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/premature-contribution-firewall-dry-run">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Premature Contribution Firewall automates the review-readiness assessment of pull requests and patches, helping maintainers prioritize actionable tasks before submission. It ensures that contributions meet key criteria such as reproducibility, scope, testing, and worth human attention, reducing the workload by focusing on issues most likely to be beneficial for the project.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>PCF v0.2.0 adds an offline, fail-closed way to reason about contributions after upstream has moved.</p>
<h2 id="contribution-lifecycle-gate">Contribution lifecycle gate</h2>
<p>The new <code>pcf lifecycle</code> command decomposes a contribution into atomic claims and distinguishes:</p>
<ul>
<li><code>CURRENT_AND_APPLICABLE</code></li>
<li><code>DRIFTED_BUT_REBASEABLE</code></li>
<li><code>SALVAGEABLE_INVARIANT</code></li>
<li><code>PARTIALLY_SUPERSEDED</code></li>
<li><code>SUPERSEDED_EQUIVALENT</code></li>
<li><code>INVALIDATED</code></li>
<li><code>NEEDS_MAINTAINER_DECISION</code></li>
</ul>
<p>Each result includes a controlled next action, claim-level reasoning, and—when appropriate—a bounded salvage packet. JSON, Markdown, and plain-text output are available without network access or GitHub writes.</p>
<h2 id="hindsight-boundary">Hindsight boundary</h2>
<p>Later outcomes and attribution may be recorded as provenance, but they are excluded from the observation-time classification and assessment SHA-256. Removing the later outcome from the retrospective Hermes Agent fixture produces the same decision and fingerprint.</p>
<p>This release does not claim that a lifecycle assessment proves correctness, mergeability, maintainer endorsement, or permission to publish.</p>
<h2 id="verification">Verification</h2>
<ul>
<li>274/274 unit and integration tests</li>
<li>77/77 maintainer benchmark cases</li>
<li>29/29 adversarial cases</li>
<li>maintainer demo and MCP no-write smoke passed</li>
<li>published package exposes <code>pcf</code>, <code>premature-contribution-firewall</code>, and <code>pcf-mcp</code></li>
<li>registry-installed lifecycle CLI reproduced the expected assessment hash</li>
<li>registry-installed MCP server exposed 25 tools and no write-like tools</li>
</ul>
<h2 id="install-or-run">Install or run</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx premature-contribution-firewall@0.2.0 lifecycle lifecycle-input.json
</span></span></code></pre></div><p>Feature PR: #13<br>
Release PR: #14</p>
]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/cowork-harness/</link><pubDate>Sun, 19 Jul 2026 21:51:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the testing of Claude Cowork skills in a headless and CI-friendly manner. It reproduces the observable runtime contract closely enough to test skills across various scenarios without relying on the locked Desktop app. Key features include:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v1.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the testing of Claude Cowork skills in a headless and CI-friendly manner. It reproduces the observable runtime contract closely enough to test skills across various scenarios without relying on the locked Desktop app. Key features include:</p>
<ul>
<li>Scriptable: Allows developers to create and run tests for their skills.</li>
<li>CI-ready: Facilitates integration into continuous integration pipelines.</li>
<li>Fidelity tiers: Supports different levels of fidelity in testing (replay, linting, live).</li>
<li>Test a local skill in one command.</li>
</ul>
<p>Overall, this action helps developers ensure that their skills meet the limitations and behaviors of Claude Cowork.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong><code>coworkWebFetchDedup</code> enacted (hostloop <code>web_fetch</code>).</strong> Real Cowork keeps a per-session negative-work
cache: a repeat <code>web_fetch</code> of the same normalized URL within a TTL (default 15 min; cap 100; FIFO
eviction; a hit does not refresh recency) makes <strong>no network request</strong> and returns a marker telling the
model to re-use the earlier result. The harness now reproduces this on the host-API (<code>coworkWebFetchViaApi</code>)
path — <strong>baseline-gated</strong> (only when the resolved baseline&rsquo;s <code>coworkWebFetchDedup</code> gate is on, i.e. Desktop
≥ 1.22209.3), keyed under both the request URL and the terminal <code>destination_url</code>, never caching errors /
empty / non-2xx responses, and emitting <strong>no egress event</strong> on a hit (matching production&rsquo;s zero-network
dedup). A hit is observable via the marker text (<code>tool_result_contains: &quot;Already fetched&quot;</code>).</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>Platform baseline synced to Desktop 1.22209.3</strong> (agent <code>2.1.215</code>). No prompt / spawn-env / egress-allowlist
drift vs 1.21459.0; the sync captured the new <code>coworkWebFetchDedup</code> runtime config (enacted above) plus a
few new (off) GrowthBook gates. The skill/README/reference version floors and agent-binary pins track the
new baseline.</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.4.0">https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.4.0</a></p>
]]></content:encoded></item><item><title>Open License Auditor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/open-license-auditor/</link><pubDate>Sun, 19 Jul 2026 21:50:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/open-license-auditor/</guid><description>Version updated for https://github.com/yanovian/open-license-auditor to version v1.2.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Open License Auditor GitHub Action automates the process of identifying and flagging potentially problematic open source licenses in a repository. It supports various package managers, checks dependencies (direct and indirect), and provides detailed reports about any risky licenses found on pull requests. The action can be configured to filter results based on severity, fail the build if critical issues are detected, and optionally post comments with the audit report.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yanovian/open-license-auditor">https://github.com/yanovian/open-license-auditor</a></strong> to version <strong>v1.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/open-license-auditor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Open License Auditor GitHub Action automates the process of identifying and flagging potentially problematic open source licenses in a repository. It supports various package managers, checks dependencies (direct and indirect), and provides detailed reports about any risky licenses found on pull requests. The action can be configured to filter results based on severity, fail the build if critical issues are detected, and optionally post comments with the audit report.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yanovian/open-license-auditor/compare/v1.2.1...v1.2.2">https://github.com/yanovian/open-license-auditor/compare/v1.2.1...v1.2.2</a></p>
]]></content:encoded></item><item><title>PR Rigor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/pr-rigor/</link><pubDate>Sun, 19 Jul 2026 14:58:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/pr-rigor/</guid><description>Version updated for https://github.com/Hassan7253/pr-rigor to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary PR Rigor automates deterministic checks to ensure that pull requests are prepared for focused human review. It identifies missing context, tests, security issues, supply chain problems, release readiness, and compatibility, providing clear evidence and recovery steps. The action is designed to help maintainers keep final authority over pull request acceptance, using repeatable first-pass checks with a stable GitHub comment update.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Hassan7253/pr-rigor">https://github.com/Hassan7253/pr-rigor</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pr-rigor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>PR Rigor automates deterministic checks to ensure that pull requests are prepared for focused human review. It identifies missing context, tests, security issues, supply chain problems, release readiness, and compatibility, providing clear evidence and recovery steps. The action is designed to help maintainers keep final authority over pull request acceptance, using repeatable first-pass checks with a stable GitHub comment update.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="changelog">Changelog</h1>
<h2 id="100---2026-07-19">1.0.0 - 2026-07-19</h2>
<h3 id="added">Added</h3>
<ul>
<li>GitHub Action and CLI with zero runtime dependencies</li>
<li>26 deterministic readiness, testing, security, supply-chain, release, and compatibility checks</li>
<li>Balanced, strict, library, and docs presets</li>
<li>Markdown, text, JSON, and SARIF output</li>
<li>Trusted base-commit configuration loading</li>
<li>Bot-safe comment updates, workflow annotations, and step summaries</li>
<li>Maintainer waiver and skip labels</li>
<li>Configuration schema, security model, tests, and publication guide</li>
</ul>
]]></content:encoded></item><item><title>Supply Chain Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/supply-chain-guard/</link><pubDate>Sun, 19 Jul 2026 14:57:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/supply-chain-guard/</guid><description>Version updated for https://github.com/homeofe/supply-chain-guard to version v5.17.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Supply-chain-guard is an open-source supply-chain security scanner that detects malware campaigns, fake AI tool repos, account takeovers, and over 350 threat indicators across various ecosystems including npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, Terraform, VS Code extensions, GitHub Actions, and GitHub repositories. It generates CycloneDX 1.6 SBOMs with real dependency inventories, parses and validates in-toto/DSSE attestations, and correlates findings into attack-chain incidents.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/homeofe/supply-chain-guard">https://github.com/homeofe/supply-chain-guard</a></strong> to version <strong>v5.17.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/supply-chain-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Supply-chain-guard is an open-source supply-chain security scanner that detects malware campaigns, fake AI tool repos, account takeovers, and over 350 threat indicators across various ecosystems including npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, Terraform, VS Code extensions, GitHub Actions, and GitHub repositories. It generates CycloneDX 1.6 SBOMs with real dependency inventories, parses and validates in-toto/DSSE attestations, and correlates findings into attack-chain incidents.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="5175---2026-07-19">[5.17.5] - 2026-07-19</h2>
<p><strong>Threat intel: NadMesh botnet - Go-based botnet hunting exposed AI services</strong></p>
<p>Added detection for the NadMesh botnet (XLab, reported by The Hacker News on
2026-07-17). NadMesh is a Go-based botnet that scans for exposed AI services
(Ollama, vLLM and similar) and CI/CD hosts, harvesting AWS keys and Kubernetes
tokens; its operator claimed 3,811 unique AWS keys. Detection rides on XLab&rsquo;s
published network infrastructure plus the agent-sample hash - there are no
package IOCs because this is a scanning botnet rather than a poisoned registry
package.</p>
<h3 id="added">Added</h3>
<ul>
<li>Command-and-control domain <code>cdnorigin[.]net</code> to <code>KNOWN_C2_DOMAINS</code> and as a
<code>domain</code> FeedIOC in <code>BUNDLED_FEED</code> (src/threat-intel.ts).</li>
<li>Command-and-control IP <code>209[.]99[.]186[.]235</code> to <code>KNOWN_C2_IPS</code> and as an <code>ip</code>
FeedIOC.</li>
<li>Agent-sample SHA1 <code>31c69b3e12936abca770d430066f379ec1d997ec</code> to
<code>KNOWN_MALICIOUS_HASHES</code> and as a <code>hash</code> FeedIOC. XLab published a SHA1 (not
MD5/SHA256); it is stored as a content-reference indicator, matched by the
same substring check as the existing Git-SHA entry.</li>
<li><code>NadMesh botnet (July 2026)</code> describe block to <code>src/__tests__/campaigns.test.ts</code>
asserting the domain, IP and hash each produce a critical finding.</li>
</ul>
]]></content:encoded></item><item><title>ASCII profile card</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/ascii-profile-card/</link><pubDate>Sun, 19 Jul 2026 14:55:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/ascii-profile-card/</guid><description>Version updated for https://github.com/hu553in/ascii-profile-card to version v1.1.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates Neofetch-style SVG profile cards with daily ASCII art and live GitHub stats, automating the process of maintaining up-to-date profile information in a dedicated branch. It supports customizable configurations through inline YAML documents and provides dark and light variants for easy integration into profiles. The action ensures that the generated files are updated regularly, enhancing user experience by keeping their profiles fresh.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hu553in/ascii-profile-card">https://github.com/hu553in/ascii-profile-card</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ascii-profile-card">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates Neofetch-style SVG profile cards with daily ASCII art and live GitHub stats, automating the process of maintaining up-to-date profile information in a dedicated branch. It supports customizable configurations through inline YAML documents and provides dark and light variants for easy integration into profiles. The action ensures that the generated files are updated regularly, enhancing user experience by keeping their profiles fresh.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hu553in/ascii-profile-card/compare/v1.0.0...v1.1.0">https://github.com/hu553in/ascii-profile-card/compare/v1.0.0...v1.1.0</a></p>
]]></content:encoded></item><item><title>droast — Dockerfile linter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/droast-dockerfile-linter/</link><pubDate>Sun, 19 Jul 2026 14:54:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/droast-dockerfile-linter/</guid><description>Version updated for https://github.com/immanuwell/dockerfile-roast to version 1.4.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary of the droast GitHub Action
The droast GitHub Action is a lint tool that checks Dockerfiles for best practices and potential issues, providing real-time feedback to developers during development. It can catch malformed syntax and catches bad practices in the Dockerfile, offering clear messages about these problems. The action works by analyzing the Dockerfile using a parser that understands various aspects of Dockerfiles, including heredocs, shell forms, Windows paths, and PowerShell.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/immanuwell/dockerfile-roast">https://github.com/immanuwell/dockerfile-roast</a></strong> to version <strong>1.4.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/droast-dockerfile-linter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary of the droast GitHub Action</strong></p>
<p>The droast GitHub Action is a lint tool that checks Dockerfiles for best practices and potential issues, providing real-time feedback to developers during development. It can catch malformed syntax and catches bad practices in the Dockerfile, offering clear messages about these problems. The action works by analyzing the Dockerfile using a parser that understands various aspects of Dockerfiles, including heredocs, shell forms, Windows paths, and PowerShell.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>chore: release version 1.4.4 (9d855d8)</li>
<li>Merge pull request #15 from UnknownPlatypus/pre-commit-hook (7e0b3f2)</li>
<li>fix: correct pre-commit release guidance (90e2f93)</li>
<li>docs: add CI platform integration examples (25cc7ba)</li>
<li>fix: repair container and Wasmer release builds (e28aed6)</li>
<li>chore: release version 1.4.3 (ff50a1f)</li>
<li>test: track ignored repository discovery fixture (606e5de)</li>
<li>feat: add Wasmer package distribution (826844b)</li>
<li>ci: expose policy controls and generated rule metadata (5ff72dc)</li>
<li>docs: document team policy configuration (68e3918)</li>
</ul>
]]></content:encoded></item><item><title>Invigil — Product Quality Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/invigil-product-quality-gate/</link><pubDate>Sun, 19 Jul 2026 14:53:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/invigil-product-quality-gate/</guid><description>Version updated for https://github.com/invigil/invigil to version v1.7.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Invigil is a CI quality gate that grades open-source projects against a product-quality doctrine by checking if the project boots, reads, and fixes errors in ten minutes. It ensures legibility, error hygiene, and supply-chain security through various gates and tools like linters, dependabot, and OpenSSF Scorecard.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/invigil/invigil">https://github.com/invigil/invigil</a></strong> to version <strong>v1.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/invigil-product-quality-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Invigil is a CI quality gate that grades open-source projects against a product-quality doctrine by checking if the project boots, reads, and fixes errors in ten minutes. It ensures legibility, error hygiene, and supply-chain security through various gates and tools like linters, dependabot, and OpenSSF Scorecard.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: accept list-form disabled checks by @leemeo3 in <a href="https://github.com/invigil/invigil/pull/17">https://github.com/invigil/invigil/pull/17</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@leemeo3 made their first contribution in <a href="https://github.com/invigil/invigil/pull/17">https://github.com/invigil/invigil/pull/17</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/invigil/invigil/compare/v1.6.0...v1.7.0">https://github.com/invigil/invigil/compare/v1.6.0...v1.7.0</a></p>
]]></content:encoded></item><item><title>zizmor - static analysis tool for Actions workflows</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/zizmor-static-analysis-tool-for-actions-workflows/</link><pubDate>Sun, 19 Jul 2026 14:52:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/zizmor-static-analysis-tool-for-actions-workflows/</guid><description>Version updated for https://github.com/its-me/action.zizmor to version v1.0.1.
This action is used across all versions by 32 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action runs the zizmor static analysis tool on GitHub Actions workflows. It automates finding security issues in workflows, providing inline annotations and SARIF files when code scanning is enabled, or simply streaming findings to the job log otherwise. The action uses a Docker image based on its own checked-out files, ensuring consistent behavior across different repositories calling it.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/its-me/action.zizmor">https://github.com/its-me/action.zizmor</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>32</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zizmor-static-analysis-tool-for-actions-workflows">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action runs the zizmor static analysis tool on GitHub Actions workflows. It automates finding security issues in workflows, providing inline annotations and SARIF files when code scanning is enabled, or simply streaming findings to the job log otherwise. The action uses a Docker image based on its own checked-out files, ensuring consistent behavior across different repositories calling it.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changed">Changed</h2>
<ul>
<li>Bump <code>github/codeql-action/upload-sarif</code> from 4.36.2 to 4.37.0 (#1, via Dependabot)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/its-me/action.zizmor/compare/v1.0.0...v1.0.1">https://github.com/its-me/action.zizmor/compare/v1.0.0...v1.0.1</a></p>
]]></content:encoded></item><item><title>Lazaretto Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/lazaretto-scan/</link><pubDate>Sun, 19 Jul 2026 14:51:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/lazaretto-scan/</guid><description>Version updated for https://github.com/jamesdfinance-dev/lazaretto-scan-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Lazaretto Scan GitHub Action automatically checks npm packages, repositories, skills, or files for malicious behavior by sending them to the Lazaretto API. It fails the build if any target is marked as “malicious” or “flagged,” providing a clear verdict in a sticky comment on pull requests. The action supports scanning specific targets or using the package.json file by default, and it integrates with GitHub Actions for CI/CD integration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jamesdfinance-dev/lazaretto-scan-action">https://github.com/jamesdfinance-dev/lazaretto-scan-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lazaretto-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Lazaretto Scan GitHub Action automatically checks npm packages, repositories, skills, or files for malicious behavior by sending them to the Lazaretto API. It fails the build if any target is marked as &ldquo;malicious&rdquo; or &ldquo;flagged,&rdquo; providing a clear verdict in a sticky comment on pull requests. The action supports scanning specific targets or using the package.json file by default, and it integrates with GitHub Actions for CI/CD integration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Adds a sticky pull-request comment with the verdict table (needs pull-requests: write). Recommended PR setup with a paths filter so it only runs when dependencies change. uses: jamesdfinance-dev/lazaretto-scan-action@v1</p>
]]></content:encoded></item><item><title>Agent Guard Secret Guardrails</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/agent-guard-secret-guardrails/</link><pubDate>Sun, 19 Jul 2026 14:50:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/agent-guard-secret-guardrails/</guid><description>Version updated for https://github.com/JeongJaeSoon/agent-guard to version v3.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Guard is an AI coding agent guardrail that blocks common secret leaks before they happen, protecting sensitive information like .env files and credentials from accidental exposure. It uses gitleaks for detection and shell scripts for integration, with support for Claude Code, Codex, Git hooks, CLI usage, and more.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/JeongJaeSoon/agent-guard">https://github.com/JeongJaeSoon/agent-guard</a></strong> to version <strong>v3.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-guard-secret-guardrails">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Agent Guard is an AI coding agent guardrail that blocks common secret leaks before they happen, protecting sensitive information like <code>.env</code> files and credentials from accidental exposure. It uses gitleaks for detection and shell scripts for integration, with support for Claude Code, Codex, Git hooks, CLI usage, and more.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat!: simplify managed deployment to settings merge plus developer setup by @JeongJaeSoon in <a href="https://github.com/JeongJaeSoon/agent-guard/pull/122">https://github.com/JeongJaeSoon/agent-guard/pull/122</a></li>
<li>release: v3.0.0 by @github-actions[bot] in <a href="https://github.com/JeongJaeSoon/agent-guard/pull/123">https://github.com/JeongJaeSoon/agent-guard/pull/123</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/JeongJaeSoon/agent-guard/compare/v2...v3.0.0">https://github.com/JeongJaeSoon/agent-guard/compare/v2...v3.0.0</a></p>
]]></content:encoded></item><item><title>Check Empty Files</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/check-empty-files/</link><pubDate>Sun, 19 Jul 2026 14:49:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/check-empty-files/</guid><description>Version updated for https://github.com/jonathandung/check-empty to version 0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks if specified files are empty and clears them if they are. It automates the process of ensuring that certain files remain empty, which can be useful for maintaining consistency across projects or environments. The action is also available as a CLI tool and library, allowing for flexibility in how it is used within different development workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jonathandung/check-empty">https://github.com/jonathandung/check-empty</a></strong> to version <strong>0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/check-empty-files">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks if specified files are empty and clears them if they are. It automates the process of ensuring that certain files remain empty, which can be useful for maintaining consistency across projects or environments. The action is also available as a CLI tool and library, allowing for flexibility in how it is used within different development workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jonathandung/check-empty/commits/0.1.0">https://github.com/jonathandung/check-empty/commits/0.1.0</a></p>
]]></content:encoded></item><item><title>Landsafe — Postgres migration safety</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/landsafe-postgres-migration-safety/</link><pubDate>Sun, 19 Jul 2026 14:48:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/landsafe-postgres-migration-safety/</guid><description>Version updated for https://github.com/landsafe-dev/action to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Landsafe GitHub Action checks PostgreSQL migration PRs for potential issues that could cause downtime on production, such as blocking index builds or full table rewrites. It analyzes the .sql files in the PR diff and provides warnings about critical risks before merging the changes. The action does not connect to the database and is designed to be used alongside schema-as-code tools.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/landsafe-dev/action">https://github.com/landsafe-dev/action</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/landsafe-postgres-migration-safety">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Landsafe GitHub Action checks PostgreSQL migration PRs for potential issues that could cause downtime on production, such as blocking index builds or full table rewrites. It analyzes the <code>.sql</code> files in the PR diff and provides warnings about critical risks before merging the changes. The action does not connect to the database and is designed to be used alongside schema-as-code tools.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Two small distribution additions — no rule or detection changes.</p>
<ul>
<li>
<p>A badge for repos that install Landsafe to show off:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-md" data-lang="md"><span style="display:flex;"><span>[<span style="color:#f92672">![Checked with Landsafe</span>](<span style="color:#a6e22e">https://img.shields.io/badge/checked%20with-Landsafe-brightgreen</span>)](https://landsafe.dev)
</span></span></code></pre></div></li>
<li>
<p>Free-tier PR comments now end with one footer line inviting whoever reads the PR to add Landsafe to their own repo, linking straight to the copy-paste Action YAML at <a href="https://landsafe.dev/#quickstart">landsafe.dev/#quickstart</a>. Pro and Business comments stay clean — that&rsquo;s part of what paying for it buys.</p>
</li>
</ul>
]]></content:encoded></item><item><title>move-test-gen coverage check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/move-test-gen-coverage-check/</link><pubDate>Sun, 19 Jul 2026 14:47:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/move-test-gen-coverage-check/</guid><description>Version updated for https://github.com/mehvetero/move-test-gen to version v1.1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The move-test-gen GitHub Action generates edge-case test suites for Sui Move functions, covering various scenarios such as boundary values, arithmetic edges, access control, state machine, and economic issues. It uses the skills CLI to install and integrates into Claude Code environments, allowing users to generate tests by inputting function sources or audit findings. The coverage checker verifies that all asserts have corresponding expected failures and catches injected bugs using mutation testing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mehvetero/move-test-gen">https://github.com/mehvetero/move-test-gen</a></strong> to version <strong>v1.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/move-test-gen-coverage-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The move-test-gen GitHub Action generates edge-case test suites for Sui Move functions, covering various scenarios such as boundary values, arithmetic edges, access control, state machine, and economic issues. It uses the skills CLI to install and integrates into Claude Code environments, allowing users to generate tests by inputting function sources or audit findings. The coverage checker verifies that all asserts have corresponding expected failures and catches injected bugs using mutation testing.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new-in-v112">What&rsquo;s new in v1.1.2</h2>
<p>Campaign 4 validated Layer 1 on real protocol code. The gate got four reliability fixes — gate-selftest now 10 cases.</p>
<h3 id="campaign-4--layer-1-field-proven">Campaign 4 — Layer 1 field-proven</h3>
<ul>
<li><strong>14/14</strong> asserts covered on Interest Protocol&rsquo;s <code>fixed_point64</code> (4 rounds, 477 lines)</li>
<li><strong>15/15</strong> on Cetus IntegerMate&rsquo;s <code>i128</code> (5 rounds, 233 lines)</li>
<li>Never missed an abort path across 9 rounds — two different teams, two different module styles</li>
</ul>
<p>This retires the &ldquo;fixture-only&rdquo; qualifier. The skill covers real protocol abort paths.</p>
<h3 id="gate-reliability">Gate reliability</h3>
<table>
  <thead>
      <tr>
          <th>Feature</th>
          <th>What it prevents</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><strong>Baseline 0-tests warning</strong></td>
          <td>Empty check silently reading as a pass</td>
      </tr>
      <tr>
          <td><strong>Testability pre-flight</strong></td>
          <td>Wasting 5 rounds on modules with no test constructor (the farm incident)</td>
      </tr>
      <tr>
          <td><strong>Target-scoped Layer 1</strong></td>
          <td>Dependency-inflated denominators (10/95 → 11/11)</td>
      </tr>
      <tr>
          <td><strong>Scope filter pure function</strong></td>
          <td>Untestable core logic (now pinned by selftest)</td>
      </tr>
  </tbody>
</table>
<h3 id="infrastructure">Infrastructure</h3>
<ul>
<li>gate-selftest: <strong>10 cases</strong>, green on every push (CI-attested)</li>
<li>Campaign records: <a href="https://github.com/mehvetero/move-test-gen/blob/v1.1.2/eval/RESULTS.md">eval/RESULTS.md</a></li>
<li>12 scenarios, 43 rounds, all RETIRED across 4 campaigns</li>
</ul>
<hr>
<p>The lab&rsquo;s methodology is borrowed from <a href="https://github.com/TheColliery">TheColliery</a>. Full lineage in the record. Thanks @HetCreep.</p>
]]></content:encoded></item><item><title>Mipiti Verify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/mipiti-verify/</link><pubDate>Sun, 19 Jul 2026 14:46:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/mipiti-verify/</guid><description>Version updated for https://github.com/Mipiti/mipiti-verify to version v0.47.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, mipiti-verify, automates the verification of threat model assertions for Mipiti tools. It can verify assertions against OpenAI or Anthropic models or check them locally using Tier 1 controls. It supports multiple commands including running all models, verifying a single assertion, checking assertions from a JSON file, listing pending assertions, reporting results, and auditing signed reports. The audit envelope contract ensures the integrity and authenticity of the verification results by leveraging public cryptographic chains and signatures.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Mipiti/mipiti-verify">https://github.com/Mipiti/mipiti-verify</a></strong> to version <strong>v0.47.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mipiti-verify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, mipiti-verify, automates the verification of threat model assertions for Mipiti tools. It can verify assertions against OpenAI or Anthropic models or check them locally using Tier 1 controls. It supports multiple commands including running all models, verifying a single assertion, checking assertions from a JSON file, listing pending assertions, reporting results, and auditing signed reports. The audit envelope contract ensures the integrity and authenticity of the verification results by leveraging public cryptographic chains and signatures.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="docker-image">Docker Image</h3>
<p>Pre-built image for faster CI (pulls cached image instead of building from source):</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">docker://ghcr.io/mipiti/mipiti-verify:v0.47.0@sha256:12dff163f7c7f8e8b03d313b449bf53b55555f73bec5faed1fbd291d85e3a86f</span>
</span></span></code></pre></div><p>Image: <code>ghcr.io/mipiti/mipiti-verify:v0.47.0</code>
Digest: <code>sha256:12dff163f7c7f8e8b03d313b449bf53b55555f73bec5faed1fbd291d85e3a86f</code></p>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/totem-shield/</link><pubDate>Sun, 19 Jul 2026 14:45:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.101.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Totem is a file-based toolkit that provides a zero-LLM linter and a queryable knowledge index derived from plain markdown lessons. It ensures project lessons, rules, and context survive across sessions by keeping them in the repository alongside the code. The tool is designed to prevent architectural mistakes by enforcing best practices with deterministic linting rules and a local, offline knowledge index.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.101.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Totem is a file-based toolkit that provides a zero-LLM linter and a queryable knowledge index derived from plain markdown lessons. It ensures project lessons, rules, and context survive across sessions by keeping them in the repository alongside the code. The tool is designed to prevent architectural mistakes by enforcing best practices with deterministic linting rules and a local, offline knowledge index.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>AI Harness Doctor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/ai-harness-doctor/</link><pubDate>Sun, 19 Jul 2026 14:43:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/ai-harness-doctor/</guid><description>Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v1.13.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Harness Doctor is a GitHub Action that audits AI harness files to ensure consistency, reliability, and security. It helps consolidate scattered guidance into one canonical AGENTS.md, keeps tool-specific files as small pointers, and measures whether the resulting harness actually improves agent answers. The action checks for various issues such as duplicate instructions, conflicts, security vulnerabilities, and incorrect permissions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NieZhuZhu/ai-harness-doctor">https://github.com/NieZhuZhu/ai-harness-doctor</a></strong> to version <strong>v1.13.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-harness-doctor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AI Harness Doctor is a GitHub Action that audits AI harness files to ensure consistency, reliability, and security. It helps consolidate scattered guidance into one canonical <code>AGENTS.md</code>, keeps tool-specific files as small pointers, and measures whether the resulting harness actually improves agent answers. The action checks for various issues such as duplicate instructions, conflicts, security vulnerabilities, and incorrect permissions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Fix shadcn path false positives by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/285">https://github.com/NieZhuZhu/ai-harness-doctor/pull/285</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NieZhuZhu/ai-harness-doctor/compare/v1...v1.13.6">https://github.com/NieZhuZhu/ai-harness-doctor/compare/v1...v1.13.6</a></p>
]]></content:encoded></item><item><title>Droidwatch APK Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/droidwatch-apk-scan/</link><pubDate>Sun, 19 Jul 2026 14:41:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/droidwatch-apk-scan/</guid><description>Version updated for https://github.com/Omar1123/droidwatch-scan to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action scans Android APKs for malware and threats, using the Droidwatch platform. It uploads the build artifact to Droidwatch for analysis and fails the build if a malicious verdict is detected. The action provides outputs like verdict, risk score, and report URL. Users can configure fail-on-verbs and set a timeout for analysis.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Omar1123/droidwatch-scan">https://github.com/Omar1123/droidwatch-scan</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/droidwatch-apk-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action scans Android APKs for malware and threats, using the Droidwatch platform. It uploads the build artifact to Droidwatch for analysis and fails the build if a malicious verdict is detected. The action provides outputs like verdict, risk score, and report URL. Users can configure fail-on-verbs and set a timeout for analysis.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial Marketplace release - scan Android APKs (and iOS IPAs, static) with Droidwatch and gate builds on the verdict.</p>
]]></content:encoded></item><item><title>railward</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/railward/</link><pubDate>Sun, 19 Jul 2026 14:40:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/railward/</guid><description>Version updated for https://github.com/Ourbando/railward to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Railward is a deterministic guardrail that automatically tests and validates AI policies. It runs predefined attack scenarios against the policy to ensure it behaves as expected. The action provides signed, hash-chained logs of allowed, blocked, and leaked actions, allowing users to verify the policy’s compliance and detect potential vulnerabilities.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Ourbando/railward">https://github.com/Ourbando/railward</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/railward">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Railward is a deterministic guardrail that automatically tests and validates AI policies. It runs predefined attack scenarios against the policy to ensure it behaves as expected. The action provides signed, hash-chained logs of allowed, blocked, and leaked actions, allowing users to verify the policy&rsquo;s compliance and detect potential vulnerabilities.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>railward v0.2.0: first public release.</p>
<p>A fail-closed, veto-only gate for untrusted AI coding agents that ships with its own adversary and a re-runnable signed proof. The agent proposes; a small pure function decides allow, deny, or ask; and every run signs a hash-chained proof of what was blocked. Flip one rule and the proof goes red.</p>
<ul>
<li>41 attack classes, all refused by the example policy</li>
<li>fail-open probe battery (a broken policy asks, never allows)</li>
<li>Ed25519 signed, hash-chained proof; verify in the browser with nothing installed</li>
<li>Claude Code PreToolUse hook, plus a CLI and a Python API</li>
<li>offline, pure Python, MIT</li>
</ul>
<p>pip install railward</p>
]]></content:encoded></item><item><title>raviqqe/muffy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/raviqqe/muffy/</link><pubDate>Sun, 19 Jul 2026 14:39:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/raviqqe/muffy/</guid><description>Version updated for https://github.com/raviqqe/muffy to version v0.3.16.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a tool for validating static websites, similar to the muffet CLI. It automates the process of checking website structure and accessibility, helping developers ensure their sites meet quality standards. The action provides features like checking for broken links, duplicate content, and HTML errors, which can be integrated into CI/CD pipelines to maintain website quality continuously.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/raviqqe/muffy">https://github.com/raviqqe/muffy</a></strong> to version <strong>v0.3.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/raviqqe-muffy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a tool for validating static websites, similar to the <code>muffet</code> CLI. It automates the process of checking website structure and accessibility, helping developers ensure their sites meet quality standards. The action provides features like checking for broken links, duplicate content, and HTML errors, which can be integrated into CI/CD pipelines to maintain website quality continuously.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>1deed2f7557d0c59fa391cd98e63c6de2240fd8c Bump version (#1101)</li>
<li>8f4162e15dc3838aaf98b08aaf3cb5361747fab2 Refactor version script (#1100)</li>
<li>1b9e3dbeb1873a81b52b48f41436dc8215311f72 Refactor Muffy cache key (#1099)</li>
<li>c33a0ddfda9d9422e17c2732b3d133747c8101b3 Evict cache entries of retried responses (#1095)</li>
<li>d955afcd97494b3d149d11d3c3140b32808ada72 Fix flaky test (#1097)</li>
<li>75dd73c42eeb1f4fb7097f4da2841e26cf273059 Revert &ldquo;Use short cache (#1094)&rdquo; (#1098)</li>
<li>ffd4a1c71c7c7aa14e79a5e550ac420627510fe4 Fix bench job (#1096)</li>
</ul>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/agentauditkit-mcp-security-scan/</link><pubDate>Sun, 19 Jul 2026 14:39:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.52.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentAuditKit automates security scans for AI agent pipelines, providing offline determinism and auditor-ready compliance-evidence packs. It finds misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across 13 agent platforms. The action ensures consistent findings and produces comprehensive SARIF reports mapped to 13 security frameworks and compliance regimes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.52</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AgentAuditKit automates security scans for AI agent pipelines, providing offline determinism and auditor-ready compliance-evidence packs. It finds misconfigurations, hardcoded secrets, tool poisoning, rug pulls, trust boundary violations, and tainted data flows across 13 agent platforms. The action ensures consistent findings and produces comprehensive SARIF reports mapped to 13 security frameworks and compliance regimes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.52
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.52
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.52</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(rules): AAK-OAUTH-008 (RFC 9728 PRM) + mcp-2026-07-28 auth profile + readiness report by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/470">https://github.com/sattyamjjain/agent-audit-kit/pull/470</a></li>
<li>chore(docs): prune 6 unused/stale docs by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/471">https://github.com/sattyamjjain/agent-audit-kit/pull/471</a></li>
<li>feat(research): State of MCP 2026 report — corpus to 1,374 configs + auth metrics (closes #23) by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/473">https://github.com/sattyamjjain/agent-audit-kit/pull/473</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.50...v0.3.52">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.50...v0.3.52</a></p>
]]></content:encoded></item><item><title>Setup BATS</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/setup-bats/</link><pubDate>Sun, 19 Jul 2026 14:37:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/setup-bats/</guid><description>Version updated for https://github.com/sgerrand/setup-bats-action to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the installation of BATS (Bash Automated Testing System) in a workflow, allowing for easy testing of Bash scripts. It resolves the latest release version or allows pinning to specific versions using a token for API calls, providing outputs for the installed version and supporting examples on how to use it.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sgerrand/setup-bats-action">https://github.com/sgerrand/setup-bats-action</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-bats">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the installation of BATS (Bash Automated Testing System) in a workflow, allowing for easy testing of Bash scripts. It resolves the latest release version or allows pinning to specific versions using a token for API calls, providing outputs for the installed version and supporting examples on how to use it.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="102-2026-07-19"><a href="https://github.com/sgerrand/setup-bats-action/compare/v1.0.1...v1.0.2">1.0.2</a> (2026-07-19)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>lint:</strong> unwrap eslint-plugin-n v18 default export (<a href="https://github.com/sgerrand/setup-bats-action/commit/498540f79271a26fd17aee4e7e4a8df13bb79e66">498540f</a>)</li>
</ul>
]]></content:encoded></item><item><title>BoundaryCI tenant-isolation scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/boundaryci-tenant-isolation-scan/</link><pubDate>Sun, 19 Jul 2026 14:37:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/boundaryci-tenant-isolation-scan/</guid><description>Version updated for https://github.com/sir-gig/boundaryci to version v0.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary BoundaryCI is a local-first CLI that scans Supabase and PostgreSQL projects for security issues related to tenant isolation in RLS rules. It checks for exposed tables without RLS, missing or incorrect policies, and identifies potential bypasses by SECURITY DEFINER functions. BoundaryCI can also review policy interactions using a Fireworks model if configured, providing insights into how different policies interact. The tool is designed to help catch errors before a migration reaches production and offers features for baselining and managing security findings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sir-gig/boundaryci">https://github.com/sir-gig/boundaryci</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/boundaryci-tenant-isolation-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>BoundaryCI is a local-first CLI that scans Supabase and PostgreSQL projects for security issues related to tenant isolation in RLS rules. It checks for exposed tables without RLS, missing or incorrect policies, and identifies potential bypasses by <code>SECURITY DEFINER</code> functions. BoundaryCI can also review policy interactions using a Fireworks model if configured, providing insights into how different policies interact. The tool is designed to help catch errors before a migration reaches production and offers features for baselining and managing security findings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>BoundaryCI Cloud private beta.</p>
<p>Added:</p>
<ul>
<li>Opt-in, secret-redacted scan upload from the CLI and GitHub Action.</li>
<li>Repository-bound ingestion tokens and tenant-isolated Supabase scan history.</li>
<li>Subscription status and monthly scan-limit enforcement.</li>
<li>Authenticated organization and repository onboarding dashboard.</li>
<li>Repository health, usage, scan history, and finding evidence views.</li>
</ul>
<p>Dashboard: <a href="https://sir-gig.github.io/boundaryci/">https://sir-gig.github.io/boundaryci/</a></p>
<p>CLI:</p>
<p>npx boundaryci scan .</p>
]]></content:encoded></item><item><title>Skaphos Oiax</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/skaphos-oiax/</link><pubDate>Sun, 19 Jul 2026 14:35:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/skaphos-oiax/</guid><description>Version updated for https://github.com/skaphos/oiax to version v1.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Oiax is a GitOps tool that reconciles promotion requests between long-lived branches in Git repositories, ensuring each branch has only one active pull request promoting changes to the next environment. It automates branch-based environments and handles backflow from production to development.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/skaphos/oiax">https://github.com/skaphos/oiax</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skaphos-oiax">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Oiax is a GitOps tool that reconciles promotion requests between long-lived branches in Git repositories, ensuring each branch has only one active pull request promoting changes to the next environment. It automates branch-based environments and handles backflow from production to development.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>See <a href="https://github.com/skaphos/oiax/blob/v1.2.0/CHANGELOG.md">CHANGELOG.md</a> for the full release notes.</p>
]]></content:encoded></item><item><title>Console CensorChecker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/console-censorchecker/</link><pubDate>Sun, 19 Jul 2026 14:34:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/console-censorchecker/</guid><description>Version updated for https://github.com/SpaceTimee/Console-CensorChecker to version 1.1.4.55.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Console CensorChecker: 这是一个基于 PowerShell 的 TCPing 批量拨测脚本，主要用于检查网络是否被审查设备拦截。它适用于任何平台，并且旨在帮助开发者监控和测试服务的可用性，同时遵守相关法律法规。通过该脚本，用户可以自动化检测目标主机的响应时间，以便在潜在的审查环境中进行验证。
What’s Changed 添加 Test Checker 工作流 添加 Module、Script、MCPB 的发布工作流 添加 Check Censor 工作流 修改 Invoke-Check 输出为 target-latency 键值对 修改 Action 结果聚合为 hashtable 合并 修改 App 结果对象构造为普通 hashtable 属性袋 移除 Action 中的无效依赖</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SpaceTimee/Console-CensorChecker">https://github.com/SpaceTimee/Console-CensorChecker</a></strong> to version <strong>1.1.4.55</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/console-censorchecker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Console CensorChecker</strong>: 这是一个基于 PowerShell 的 TCPing 批量拨测脚本，主要用于检查网络是否被审查设备拦截。它适用于任何平台，并且旨在帮助开发者监控和测试服务的可用性，同时遵守相关法律法规。通过该脚本，用户可以自动化检测目标主机的响应时间，以便在潜在的审查环境中进行验证。</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ol>
<li>添加 Test Checker 工作流</li>
<li>添加 Module、Script、MCPB 的发布工作流</li>
<li>添加 Check Censor 工作流</li>
<li>修改 Invoke-Check 输出为 target-latency 键值对</li>
<li>修改 Action 结果聚合为 hashtable 合并</li>
<li>修改 App 结果对象构造为普通 hashtable 属性袋</li>
<li>移除 Action 中的无效依赖</li>
</ol>
]]></content:encoded></item><item><title>GuardLine Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/guardline-security-scan/</link><pubDate>Sun, 19 Jul 2026 14:34:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/guardline-security-scan/</guid><description>Version updated for https://github.com/toutlawbradley/GuardLine to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GuardLine is a GitHub Action designed to perform security scans on pull requests, focusing on secrets detection, dependency vulnerabilities, configuration risks, code patterns, and permission issues. It posts findings in the PR comment and SARIF format, allowing for easy visibility of potential security risks. The action supports three scan levels: quick, standard, and deep, with the standard level being the default for most repositories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/toutlawbradley/GuardLine">https://github.com/toutlawbradley/GuardLine</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/guardline-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>GuardLine is a GitHub Action designed to perform security scans on pull requests, focusing on secrets detection, dependency vulnerabilities, configuration risks, code patterns, and permission issues. It posts findings in the PR comment and SARIF format, allowing for easy visibility of potential security risks. The action supports three scan levels: quick, standard, and deep, with the standard level being the default for most repositories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>GuardLine v1.1.0 — five scanners, SARIF integration, and a configurable policy gate.</p>
<h2 id="whats-included">What&rsquo;s included</h2>
<ul>
<li><strong>Secrets Scanner</strong> — Detects hardcoded API keys, tokens, passwords, and credentials (regex + entropy analysis)</li>
<li><strong>Dependency Scanner</strong> — Checks packages against the OSV.dev vulnerability database for known CVEs</li>
<li><strong>Config Auditor</strong> — Identifies insecure Dockerfile and configuration issues</li>
<li><strong>Code Pattern Analyzer</strong> — Flags SQL injection and unsafe <code>eval()</code> usage</li>
<li><strong>Permission Scanner</strong> — Detects overly permissive file permissions on sensitive files (new in this release)</li>
</ul>
<h2 id="new-in-v110">New in v1.1.0</h2>
<ul>
<li>SARIF output — findings now appear natively in GitHub&rsquo;s Security tab</li>
<li>Configurable policy gate — fails the build based on <code>.guardline.yml</code>&rsquo;s <code>thresholds.fail-on</code> setting (defaults to <code>critical</code>)</li>
<li>Fixed: PermissionsScanner is now correctly registered and actually runs (was previously built but never wired into the orchestrator)</li>
</ul>
<h2 id="quick-start">Quick start</h2>
<p>​```yaml
permissions:
security-events: write
issues: write
pull-requests: write</p>
<ul>
<li>uses: <a href="mailto:toutlawbradley/GuardLine@v1.1.0">toutlawbradley/GuardLine@v1.1.0</a>
with:
scan-level: standard
​```</li>
</ul>
<p>Full test suite: 10/10 passing.</p>
]]></content:encoded></item><item><title>Open License Auditor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/open-license-auditor/</link><pubDate>Sun, 19 Jul 2026 14:32:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/open-license-auditor/</guid><description>Version updated for https://github.com/yanovian/open-license-auditor to version v1.2.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action Open License Auditor automates the identification of risky open-source licenses in a repository’s dependencies. It supports various package managers and scans all dependencies to flag any license that could pose security or licensing risks. The action posts comments on pull requests, listing risky dependencies and providing full dependency maps for further inspection.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yanovian/open-license-auditor">https://github.com/yanovian/open-license-auditor</a></strong> to version <strong>v1.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/open-license-auditor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>Open License Auditor</code> automates the identification of risky open-source licenses in a repository&rsquo;s dependencies. It supports various package managers and scans all dependencies to flag any license that could pose security or licensing risks. The action posts comments on pull requests, listing risky dependencies and providing full dependency maps for further inspection.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yanovian/open-license-auditor/compare/v1.2.0...v1.2.1">https://github.com/yanovian/open-license-auditor/compare/v1.2.0...v1.2.1</a></p>
]]></content:encoded></item><item><title>MCPScan by yyyutakaaa</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/mcpscan-by-yyyutakaaa/</link><pubDate>Sun, 19 Jul 2026 14:31:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/mcpscan-by-yyyutakaaa/</guid><description>Version updated for https://github.com/yyyutakaaa/mcpscan to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary mcpscan is an automated security tool designed to detect common security issues in machine learning models and related configurations, such as injection attacks, dangerous code execution, misconfigured servers, exfiltration vulnerabilities, supply chain risks, and secrets exposure. It analyzes Python scripts, configs, and skill folders to provide detailed reports on potential security weaknesses, helping developers prevent threats before they reach their models.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yyyutakaaa/mcpscan">https://github.com/yyyutakaaa/mcpscan</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcpscan-by-yyyutakaaa">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>mcpscan is an automated security tool designed to detect common security issues in machine learning models and related configurations, such as injection attacks, dangerous code execution, misconfigured servers, exfiltration vulnerabilities, supply chain risks, and secrets exposure. It analyzes Python scripts, configs, and skill folders to provide detailed reports on potential security weaknesses, helping developers prevent threats before they reach their models.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="mcpscan-v010">MCPScan v0.1.0</h2>
<p>Shipped the first release. MCPScan scans MCP servers and AI agent skills for the stuff that tends to get missed in review.</p>
<h3 id="detects">Detects</h3>
<ul>
<li>Prompt-injection and tool-poisoning patterns</li>
<li>Hidden Unicode and bidirectional control characters</li>
<li>Dangerous Python calls like <code>eval</code>, <code>exec</code>, <code>subprocess</code>, and <code>os.system</code></li>
<li>Unsafe file access and path traversal risks</li>
<li>Hardcoded external exfiltration endpoints</li>
<li>Embedded credentials and leaked secrets</li>
<li>MCP servers running wide open (overly permissive flags)</li>
<li>Unpinned installs and remote shell scripts piped into <code>sh</code></li>
</ul>
<h3 id="features">Features</h3>
<ul>
<li>Terminal, JSON, and SARIF output</li>
<li>Adjustable severity threshold</li>
<li>GitHub Code Scanning integration</li>
<li>Custom YAML rules for stuff specific to your stack</li>
<li>Tested on Python 3.11, 3.12, and 3.13
This is static analysis, not proof. Findings are patterns worth a second look, not confirmed exploits — a developer or security engineer should still review them before acting.</li>
</ul>
]]></content:encoded></item><item><title>terraform-plan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/terraform-plan/</link><pubDate>Sun, 19 Jul 2026 06:45:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/terraform-plan/</guid><description>Version updated for https://github.com/dflook/terraform-plan to version v3.0.0.
This action is used across all versions by 369 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This Terraform action generates and optionally comments on a plan for a given Terraform project. It supports PRs by adding comments with the generated plan, automating the creation of plans for other events, and providing options to customize variables, backend configurations, and resource targeting. The action is part of a suite of actions for managing Terraform projects in GitHub Actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/dflook/terraform-plan">https://github.com/dflook/terraform-plan</a></strong> to version <strong>v3.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>369</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/terraform-plan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This Terraform action generates and optionally comments on a plan for a given Terraform project. It supports PRs by adding comments with the generated plan, automating the creation of plans for other events, and providing options to customize variables, backend configurations, and resource targeting. The action is part of a suite of actions for managing Terraform projects in GitHub Actions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This is one of a suite of terraform related actions - find them at <a href="https://github.com/dflook/terraform-github-actions">dflook/terraform-github-actions</a>.</p>
<p>You can see the changes for this release in the <a href="https://github.com/dflook/terraform-github-actions/blob/main/CHANGELOG.md">CHANGELOG</a></p>
<p>You can specify the action version as:</p>
<ul>
<li><code>@v3.0.0</code> to use exactly this release</li>
<li><code>@v3.0</code> to use the latest patch release for the specific minor version</li>
<li><code>@v3</code> to use the latest patch release for the specific major version</li>
</ul>
]]></content:encoded></item><item><title>terraform-validate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/terraform-validate/</link><pubDate>Sun, 19 Jul 2026 06:44:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/terraform-validate/</guid><description>Version updated for https://github.com/dflook/terraform-validate to version v3.0.0.
This action is used across all versions by 605 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates Terraform validation by running the terraform validate command to check that a Terraform configuration is valid. It can detect and fail builds if the configuration contains syntax errors or other issues before attempting a plan. The action supports specifying workspace, backend configurations, and environment variables for customizing the validation process.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/dflook/terraform-validate">https://github.com/dflook/terraform-validate</a></strong> to version <strong>v3.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>605</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/terraform-validate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates Terraform validation by running the <code>terraform validate</code> command to check that a Terraform configuration is valid. It can detect and fail builds if the configuration contains syntax errors or other issues before attempting a plan. The action supports specifying workspace, backend configurations, and environment variables for customizing the validation process.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This is one of a suite of terraform related actions - find them at <a href="https://github.com/dflook/terraform-github-actions">dflook/terraform-github-actions</a>.</p>
<p>You can see the changes for this release in the <a href="https://github.com/dflook/terraform-github-actions/blob/main/CHANGELOG.md">CHANGELOG</a></p>
<p>You can specify the action version as:</p>
<ul>
<li><code>@v3.0.0</code> to use exactly this release</li>
<li><code>@v3.0</code> to use the latest patch release for the specific minor version</li>
<li><code>@v3</code> to use the latest patch release for the specific major version</li>
</ul>
]]></content:encoded></item><item><title>terraform-version</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/terraform-version/</link><pubDate>Sun, 19 Jul 2026 06:43:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/terraform-version/</guid><description>Version updated for https://github.com/dflook/terraform-version to version v3.0.0.
This action is used across all versions by 25 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action determines and outputs the Terraform version to use based on various sources including cloud workspace configurations, module configuration, environment variables, and available binaries. It supports both Hashicorp’s Terraform and OpenTofu, automatically discovering the appropriate version for a given Terraform root module.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/dflook/terraform-version">https://github.com/dflook/terraform-version</a></strong> to version <strong>v3.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>25</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/terraform-version">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action determines and outputs the Terraform version to use based on various sources including cloud workspace configurations, module configuration, environment variables, and available binaries. It supports both Hashicorp&rsquo;s Terraform and OpenTofu, automatically discovering the appropriate version for a given Terraform root module.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This is one of a suite of terraform related actions - find them at <a href="https://github.com/dflook/terraform-github-actions">dflook/terraform-github-actions</a>.</p>
<p>You can see the changes for this release in the <a href="https://github.com/dflook/terraform-github-actions/blob/main/CHANGELOG.md">CHANGELOG</a></p>
<p>You can specify the action version as:</p>
<ul>
<li><code>@v3.0.0</code> to use exactly this release</li>
<li><code>@v3.0</code> to use the latest patch release for the specific minor version</li>
<li><code>@v3</code> to use the latest patch release for the specific major version</li>
</ul>
]]></content:encoded></item><item><title>Composite Linter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/composite-linter/</link><pubDate>Sun, 19 Jul 2026 06:42:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/composite-linter/</guid><description>Version updated for https://github.com/georglauterbach/linter to version v0.4.1.
This action is used across all versions by 6 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action runs multiple linters, including Actionlint, EditorConfig Checker, Hadolint, Shellcheck, YAMLLint, and Zizmor, to analyze various files such as GitHub CI/CD workflows, EditorConfig configurations, Dockerfiles, shell scripts, YAML files, and GitHub workflows. It allows users to disable specific linters or provide custom configuration files and arguments for each linter.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/georglauterbach/linter">https://github.com/georglauterbach/linter</a></strong> to version <strong>v0.4.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/composite-linter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action runs multiple linters, including Actionlint, EditorConfig Checker, Hadolint, Shellcheck, YAMLLint, and Zizmor, to analyze various files such as GitHub CI/CD workflows, EditorConfig configurations, Dockerfiles, shell scripts, YAML files, and GitHub workflows. It allows users to disable specific linters or provide custom configuration files and arguments for each linter.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Refer to <a href="https://github.com/georglauterbach/linter/blob/main/CHANGELOG.md#v041"><code>CHANGELOG.md</code></a> for the list of all changes.</p>
]]></content:encoded></item><item><title>ReleaseKit – Automated Versioning &amp; Release</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/releasekit-automated-versioning-release/</link><pubDate>Sun, 19 Jul 2026 06:42:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/releasekit-automated-versioning-release/</guid><description>Version updated for https://github.com/goosewobbler/releasekit to version v0.40.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ReleaseKit is an automated tool that automates the process of releasing npm packages, crates.io libraries, and Dart/Flutter packages. It uses Conventional Commits to generate changelogs and version numbers, and supports CI-native workflows with JSON output and OIDC publishing. The action provides three independent CLIs for versioning, generating notes, and publishing packages, making it flexible for different ecosystems and projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/goosewobbler/releasekit">https://github.com/goosewobbler/releasekit</a></strong> to version <strong>v0.40.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/releasekit-automated-versioning-release">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>ReleaseKit is an automated tool that automates the process of releasing npm packages, crates.io libraries, and Dart/Flutter packages. It uses Conventional Commits to generate changelogs and version numbers, and supports CI-native workflows with JSON output and OIDC publishing. The action provides three independent CLIs for versioning, generating notes, and publishing packages, making it flexible for different ecosystems and projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="new">New:</h3>
<ul>
<li>Added a release summary line and version-summary table to the standing PR body, showing channel splits, major-bump warnings, and held packages. (#524) (#524, #520)</li>
<li>Added per-package channel toggles (<code>rk-pre</code> / <code>rk-grad</code>) to the standing PR selection list, allowing selective prerelease or graduation without narrowing the release. (#525) (#525, #521)</li>
<li>Added configurable <code>changelog.demoteScopes</code> option to move dependency and version-bump entries to a separate section at the end of changelogs, keeping main content clean. (#523) (#523, #522)</li>
</ul>
<h3 id="fixed">Fixed:</h3>
<ul>
<li>Fixed the <code>releasekit</code> dispatcher to register <code>gate</code>, <code>refresh-after-release</code>, and <code>backfill</code> commands so they work from the public binary instead of only from <code>releasekit-release</code>. (#538) (#538, #519)</li>
<li>Fixed the standing PR&rsquo;s open-age display to show days (e.g., <code>26d 36m</code>) instead of just hours (e.g., <code>624h 36m</code>). (#536) (#536, #535)</li>
<li><strong>Security</strong>: Fixed unauthorized actors being able to edit channel toggles on the standing PR by reconciling them against the manifest, matching the behavior of ad-hoc deselection. (#534) (#534)</li>
</ul>
<h3 id="changed">Changed:</h3>
<ul>
<li><strong>Dependencies</strong>: Updated the Claude Code GitHub Action to the latest version. (#531) (#531)</li>
<li><strong>Dependencies</strong>: Updated production dependencies including Anthropic SDK, OpenAI, LiquidJS, Figlet, Biome, and Vitest. (#533) (#533)</li>
<li><strong>Dependencies</strong>: Updated development dependencies including ESLint, TypeScript ESLint parser, and Turbo. (#532) (#532)</li>
</ul>
<h3 id="removed">Removed:</h3>
<ul>
<li><strong>CI</strong>: Removed the unused Claude code-review workflow since Greptile already auto-reviews every PR. (#537) (#537)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/goosewobbler/releasekit/compare/0.39.0...0.40.0">https://github.com/goosewobbler/releasekit/compare/0.39.0...0.40.0</a></p>
]]></content:encoded></item><item><title>ASCII profile card</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/ascii-profile-card/</link><pubDate>Sun, 19 Jul 2026 06:41:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/ascii-profile-card/</guid><description>Version updated for https://github.com/hu553in/ascii-profile-card to version v1.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates Neofetch-style SVG profile cards with daily ASCII art and live GitHub stats. It automates the creation of a dedicated branch for generated files, which can be embedded in a profile README. The action supports various card configurations, including header, section, key/value, and blank rows, allowing users to customize the appearance of their profile cards.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hu553in/ascii-profile-card">https://github.com/hu553in/ascii-profile-card</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ascii-profile-card">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates Neofetch-style SVG profile cards with daily ASCII art and live GitHub stats. It automates the creation of a dedicated branch for generated files, which can be embedded in a profile README. The action supports various card configurations, including header, section, key/value, and blank rows, allowing users to customize the appearance of their profile cards.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(sync): synced file(s) with hu553in/common-things by @hu553in in <a href="https://github.com/hu553in/ascii-profile-card/pull/1">https://github.com/hu553in/ascii-profile-card/pull/1</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@hu553in made their first contribution in <a href="https://github.com/hu553in/ascii-profile-card/pull/1">https://github.com/hu553in/ascii-profile-card/pull/1</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hu553in/ascii-profile-card/commits/v1.0.0">https://github.com/hu553in/ascii-profile-card/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>Codex Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/codex-action/</link><pubDate>Sun, 19 Jul 2026 06:40:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/codex-action/</guid><description>Version updated for https://github.com/icoretech/codex-action to version v0.9.22.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Codex Action automates the execution of OpenAI’s Codex CLI in GitHub Actions workflows using a containerized version of the tool. It supports both API key and OAuth/Device Auth authentication methods, offering flexibility depending on user preferences and needs. The action simplifies integration with Codex for tasks such as summarizing changes or generating text, providing a clean and automated way to leverage Codex’s capabilities within GitHub Actions pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/icoretech/codex-action">https://github.com/icoretech/codex-action</a></strong> to version <strong>v0.9.22</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/codex-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Codex Action automates the execution of OpenAI&rsquo;s Codex CLI in GitHub Actions workflows using a containerized version of the tool. It supports both API key and OAuth/Device Auth authentication methods, offering flexibility depending on user preferences and needs. The action simplifies integration with Codex for tasks such as summarizing changes or generating text, providing a clean and automated way to leverage Codex&rsquo;s capabilities within GitHub Actions pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="0922-2026-07-18"><a href="https://github.com/icoretech/codex-action/compare/v0.9.21...v0.9.22">0.9.22</a> (2026-07-18)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> update codex-docker image to v0.144.6 (<a href="https://github.com/icoretech/codex-action/issues/58">#58</a>) (<a href="https://github.com/icoretech/codex-action/commit/f98bf17a896b3a60cf40816cc9ec48931af2aad3">f98bf17</a>)</li>
</ul>
]]></content:encoded></item><item><title>cibuild-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/cibuild-action/</link><pubDate>Sun, 19 Jul 2026 06:39:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/cibuild-action/</guid><description>Version updated for https://github.com/invarnhq/cibuild to version v2.4.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, cibuild, automates the setup of CI/CD pipelines for iOS and Android projects. It provides an interactive wizard for creating and customizing workflows using YAML files, which can be run locally or on remote runners with AI agents. The action supports auto-detection of platforms, secret management, and pipeline validation, facilitating a streamlined development process for mobile applications.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/invarnhq/cibuild">https://github.com/invarnhq/cibuild</a></strong> to version <strong>v2.4.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cibuild-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, cibuild, automates the setup of CI/CD pipelines for iOS and Android projects. It provides an interactive wizard for creating and customizing workflows using YAML files, which can be run locally or on remote runners with AI agents. The action supports auto-detection of platforms, secret management, and pipeline validation, facilitating a streamlined development process for mobile applications.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release v2.4.1</p>
]]></content:encoded></item><item><title>riskratchet</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/riskratchet/</link><pubDate>Sun, 19 Jul 2026 06:39:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/riskratchet/</guid><description>Version updated for https://github.com/KayhanB21/riskratchet-action to version v1.0.7.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a wrapper for KayhanB21’s riskratchet maintainability ratchet tool, designed to help with automated code reviews in AI-assisted Python projects. It allows users to integrate riskratchet into their workflows using GitHub Actions without needing to clone and install the riskratchet package directly. The action automates the process of checking code for maintainability issues based on coverage data provided by tools like Coverage.py, making it easier to maintain high-quality Python code in AI-driven projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/KayhanB21/riskratchet-action">https://github.com/KayhanB21/riskratchet-action</a></strong> to version <strong>v1.0.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/riskratchet">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a wrapper for KayhanB21&rsquo;s riskratchet maintainability ratchet tool, designed to help with automated code reviews in AI-assisted Python projects. It allows users to integrate riskratchet into their workflows using GitHub Actions without needing to clone and install the riskratchet package directly. The action automates the process of checking code for maintainability issues based on coverage data provided by tools like Coverage.py, making it easier to maintain high-quality Python code in AI-driven projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Bumps the delegated ref to <strong><code>KayhanB21/riskratchet@v0.2.16</code></strong> (LCOV coverage support for the TypeScript backend).</p>
<p><code>@v1</code> and <code>@v1.0.7</code> both resolve to riskratchet 0.2.16. No input or behavior changes — this is a passthrough wrapper; the delegated ref is the only release-time change.</p>
]]></content:encoded></item><item><title>OSS Warrior</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/oss-warrior/</link><pubDate>Sun, 19 Jul 2026 06:38:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/oss-warrior/</guid><description>Version updated for https://github.com/masatohoshino/oss-warrior to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The OSS Warrior GitHub Action measures an account’s OSS power level across three domains: CONTRIBUTOR, MAINTAINER, and SOLO, and displays it as a living warrior card. The action automates the process of tracking public GitHub events to generate a reproducible card without requiring sign-up or additional servers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/masatohoshino/oss-warrior">https://github.com/masatohoshino/oss-warrior</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/oss-warrior">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The OSS Warrior GitHub Action measures an account&rsquo;s OSS power level across three domains: CONTRIBUTOR, MAINTAINER, and SOLO, and displays it as a living warrior card. The action automates the process of tracking public GitHub events to generate a reproducible card without requiring sign-up or additional servers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Respect to every OSS warrior. Every contribution counts.</strong></p>
<p>First public release. Measure any GitHub account&rsquo;s OSS power level across three combat domains and wear it as a living warrior card on your profile.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Warrior card</strong> in your profile README — metal-framed (BRONZE → MYTHIC), tap to post to X with the card image unfurled via your own GitHub Pages</li>
<li><strong>Three leagues</strong>: CONTRIBUTOR / MAINTAINER / SOLO, one unified PR-equivalent formula</li>
<li><strong>Capacity-anchored ranks</strong>: Rookie → Weekend Warrior → Mainstay → Pro (<em>the pre-AI ceiling</em>) → Super Warrior → <strong>AI Sorcerer (it&rsquo;s over 9000)</strong></li>
<li><strong>Scouter</strong>: scan any account from your Pages console; results reply on an issue, never touch your README</li>
<li><strong>Honest by construction</strong>: public events only, reproducible numbers, documented limitations, ⚡ Limit Break when the API caps out</li>
</ul>
<h2 id="setup">Setup</h2>
<p>5 minutes: see the <a href="https://github.com/masatohoshino/oss-warrior#get-your-own-card-5-minutes">README</a>. Formulas: <a href="https://github.com/masatohoshino/oss-warrior/blob/main/SPEC.md">SPEC.md</a>.</p>
]]></content:encoded></item><item><title>Sentrik Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/sentrik-gate/</link><pubDate>Sun, 19 Jul 2026 06:37:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/sentrik-gate/</guid><description>Version updated for https://github.com/maxgerhardson/sentrik-community to version v1.8.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sentrik is a governance runtime that automates compliance checks on AI-generated code. It enforces coding standards, security policies, and compliance rules before code ships by scanning every change against regulatory standards and gating PRs that fail. The free tier includes 6 standards packs with 193 rules for free, while paid tiers offer more features like OWASP, SOC 2, and supply chain standards. Sentrik integrates seamlessly with GitHub Actions to enforce gates in CI/CD pipelines, providing a comprehensive solution for AI-generated code quality and governance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/maxgerhardson/sentrik-community">https://github.com/maxgerhardson/sentrik-community</a></strong> to version <strong>v1.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sentrik-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Sentrik is a governance runtime that automates compliance checks on AI-generated code. It enforces coding standards, security policies, and compliance rules before code ships by scanning every change against regulatory standards and gating PRs that fail. The free tier includes 6 standards packs with 193 rules for free, while paid tiers offer more features like OWASP, SOC 2, and supply chain standards. Sentrik integrates seamlessly with GitHub Actions to enforce gates in CI/CD pipelines, providing a comprehensive solution for AI-generated code quality and governance.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v180">v1.8.0</h2>
<ul>
<li><strong>Claude Code integration</strong> — <code>sentrik claude-init</code> makes any repo Claude-ready: a project skill with an onboarding interview (Claude interviews you about your project and enables the right standards packs), MCP server registration, a maintained CLAUDE.md section, and a scan-on-edit hook that feeds findings back to Claude after every file edit (<code>--no-hooks</code> to opt out). One-time hint after <code>sentrik scan</code> when Claude Code is detected but not yet wired up</li>
<li><strong>New MCP tools (26 total)</strong> — <code>suggest_packs</code> (what should this project enable, and why), <code>manage_pack</code> (enable/disable with license gating), <code>lint_pack_yaml</code> (validate draft packs) — the onboarding interview is fully executable by AI agents</li>
<li><strong>Java and C#/.NET security packs</strong> (Team tier) — JDBC/JPA and EF injection, unsafe deserialization, XXE, weak crypto, TLS bypass, framework misconfig — now 26 packs, 632 rules</li>
<li><strong>Suppression governance</strong> — every waiver carries provenance (who, when, why), expiry dates resurface findings instead of hiding them forever, full audit trail plus <code>out/suppressed.json</code> and a dashboard suppressions view</li>
<li><strong><code>sentrik exclude</code> and <code>sentrik lint-pack</code></strong> — one-command scan exclusions; lint custom packs for authoring footguns (over-broad globs, unanchored wildcards, bare-word patterns, ReDoS shapes)</li>
<li><strong>Dashboard</strong> — Vue migration feature-complete across all pages; persona home views (Developer / Compliance / Agent Ops); AI chat on threats and vulnerabilities; Fix-with-AI restored on findings</li>
<li><strong>Deeper dependency scanning</strong> — optional dependency groups and nested manifests are now covered</li>
<li><strong>Executive summary</strong> now explains severity vs contextual risk so auditors see why a medium can outrank a high</li>
<li><strong>Pack quality</strong> — major false-positive cleanup across EU AI Act, GDPR, NIST 800-53, CMMC, HIPAA, ISO 27001, SOC2, and PCI packs: system-level obligations no longer fire on every file, doc placeholders are no longer flagged as hardcoded secrets</li>
<li><strong>Fixes</strong> — SDK <code>check_code</code> silently scanned nothing when given absolute paths (also fixed the MCP <code>check_file</code> tool); MCP <code>run_scan</code> no longer inherits the protocol stdin and reports diagnostics on timeout; telemetry no longer counts CI runners as installs; tree-sitter text predicates now evaluated in-engine</li>
</ul>
<p><strong>Install:</strong> <code>npm install -g sentrik</code> (prebuilt binary, no Python needed) — binaries below report engine 1.5.113.</p>
]]></content:encoded></item><item><title>Miso PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/miso-pr-review/</link><pubDate>Sun, 19 Jul 2026 06:36:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/miso-pr-review/</guid><description>Version updated for https://github.com/misospace/pr-reviewer-action to version v2.1.5.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically reviews pull requests using a language model, providing detailed feedback on the code changes and potential risks. It uses OpenAI-compatible models or local models hosted on platforms like llama.cpp, vLLM, LiteLLM, or Anthropic to generate comments and decide if further action is needed for security or risk classification. The action supports CI checks, structured findings with severity tagging, and can publish reviews as sticky comments or native GitHub reviews. It optimizes token usage through incremental review processing and safe defaults, ensuring a seamless AI-driven PR review process.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/misospace/pr-reviewer-action">https://github.com/misospace/pr-reviewer-action</a></strong> to version <strong>v2.1.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/miso-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically reviews pull requests using a language model, providing detailed feedback on the code changes and potential risks. It uses OpenAI-compatible models or local models hosted on platforms like llama.cpp, vLLM, LiteLLM, or Anthropic to generate comments and decide if further action is needed for security or risk classification. The action supports CI checks, structured findings with severity tagging, and can publish reviews as sticky comments or native GitHub reviews. It optimizes token usage through incremental review processing and safe defaults, ensuring a seamless AI-driven PR review process.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(github-action): update action misospace/pr-reviewer-action (v2.1.3 → v2.1.4) by @its-miso[bot] in <a href="https://github.com/misospace/pr-reviewer-action/pull/417">https://github.com/misospace/pr-reviewer-action/pull/417</a></li>
<li>fix(review): preserve forced verdict safety by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/422">https://github.com/misospace/pr-reviewer-action/pull/422</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/misospace/pr-reviewer-action/compare/v2.1.4...v2.1.5">https://github.com/misospace/pr-reviewer-action/compare/v2.1.4...v2.1.5</a></p>
]]></content:encoded></item><item><title>Polygraph MCP gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/polygraph-mcp-gate/</link><pubDate>Sun, 19 Jul 2026 06:34:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/polygraph-mcp-gate/</guid><description>Version updated for https://github.com/polygraphso/litmus to version litmus-v0.35.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, litmus, is designed to automate the process of evaluating and grading MCP servers based on their behavior. It connects to an MCP endpoint, runs a set of probes to evaluate the server’s performance, and provides a grade along with evidence files. The action can be used for both lookup and execution purposes, allowing users to quickly assess server capabilities and reproduce grades.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/polygraphso/litmus">https://github.com/polygraphso/litmus</a></strong> to version <strong>litmus-v0.35.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/polygraph-mcp-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, litmus, is designed to automate the process of evaluating and grading MCP servers based on their behavior. It connects to an MCP endpoint, runs a set of probes to evaluate the server&rsquo;s performance, and provides a grade along with evidence files. The action can be used for both lookup and execution purposes, allowing users to quickly assess server capabilities and reproduce grades.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li><code>list_servers</code> is paged: <code>grade</code> / <code>limit</code> (default 25, max 100) / <code>offset</code> inputs, with a full-corpus summary (total plus per-grade counts). Default calls no longer return the full graded list.</li>
<li>The hosted lookup endpoint (<code>https://polygraph.so/api/mcp</code>, Streamable HTTP, lookup tools only) is advertised in <code>server.json</code> <code>remotes</code> and leads the install docs for lookup use. Grading (<code>run_litmus</code>, <code>run_skill_litmus</code>) remains a local stdio install by design.</li>
<li>Tool descriptions trimmed for context budget; safety guidance retained verbatim and the tool-ordering guidance moved into the descriptions themselves.</li>
<li>Version pins (<code>server.json</code>, plugin <code>.mcp.json</code>, <code>action.yml</code>) are now held in lockstep by <code>scripts/check-versions.mjs</code> in CI. Plugin 0.7.2 ships the 0.35.0 pin.</li>
</ul>
]]></content:encoded></item><item><title>embd-check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/embd-check/</link><pubDate>Sun, 19 Jul 2026 06:33:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/embd-check/</guid><description>Version updated for https://github.com/ptsouchlos/embd to version v0.1.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary embd is a CLI tool designed to manage embedded repositories within a project, providing an alternative to git subtree and git submodule. It automates the process of cloning and updating dependencies, while also allowing for selective filtering of content. This helps in maintaining clear separation between project code and its dependencies and ensures that all changes are tracked in version control. The tool is particularly useful for managing Git submodules within larger projects to improve maintainability and simplify deployment processes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ptsouchlos/embd">https://github.com/ptsouchlos/embd</a></strong> to version <strong>v0.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/embd-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>embd</code> is a CLI tool designed to manage embedded repositories within a project, providing an alternative to <code>git subtree</code> and <code>git submodule</code>. It automates the process of cloning and updating dependencies, while also allowing for selective filtering of content. This helps in maintaining clear separation between project code and its dependencies and ensures that all changes are tracked in version control. The tool is particularly useful for managing Git submodules within larger projects to improve maintainability and simplify deployment processes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>chore: prepare for new release (c82367c)</li>
<li>fix: wrong names (4dc1a80)</li>
<li>fix: use corrected gh action name (652d0f3)</li>
<li>chore: add another check to use published gh action (d47f827)</li>
<li>chore: update actions.yaml to allow for publishing (9a67f30)</li>
<li>feat: first pass at a github action (#36) (39558e7)</li>
<li>fix: wrong version in Cargo.lock (526ea89)</li>
<li>chore: update version (11c6fac)</li>
<li>chore: include sha256 checksum files for releases (#39) (71ff819)</li>
<li>fix: normalize CRLF to LF when hashing embed files (#41) (ab509cf)</li>
</ul>
]]></content:encoded></item><item><title>raviqqe/muffy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/raviqqe/muffy/</link><pubDate>Sun, 19 Jul 2026 06:32:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/raviqqe/muffy/</guid><description>Version updated for https://github.com/raviqqe/muffy to version v0.3.15.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a static website validator that automates the process of checking for errors in HTML, CSS, and JavaScript files used to build websites. It solves the problem of manual validation by providing automated checks during the build process, helping developers catch issues early before deploying their sites. The action provides capabilities to validate HTML structure, missing alt text, SEO compliance, and more.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/raviqqe/muffy">https://github.com/raviqqe/muffy</a></strong> to version <strong>v0.3.15</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/raviqqe-muffy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a static website validator that automates the process of checking for errors in HTML, CSS, and JavaScript files used to build websites. It solves the problem of manual validation by providing automated checks during the build process, helping developers catch issues early before deploying their sites. The action provides capabilities to validate HTML structure, missing alt text, SEO compliance, and more.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>d96a223841984613548822f83df5e30f7fd39026 Cache benchmarks (#1093)</li>
<li>04eeebd6f786015055ef0a3d3d9c3ab7c594c472 Bump version (#1092)</li>
<li>79bcc201bea21cbce52691a4826e80ffbf642e69 Use short cache (#1094)</li>
<li>bc909a8dca7d3fe58203ac3c109c0ea86950e874 Remove error cache entries (#1084)</li>
<li>01cd4f7061839faeef0b78a73e5924fa8a614079 Increase max age in config (#1090)</li>
<li>80910ca29249f9aa3254b64c695c096d98d2d99a Remove stale cache entries (#1083)</li>
<li>289e58de0cd35df0d94afaea7e0959cf8e99a507 Bump fjall from 3.1.7 to 3.1.8 (#1088)</li>
<li>7a01def58bf547e83496e059d25ca5af0830d5fe Bump futures from 0.3.32 to 0.3.33 (#1089)</li>
<li>fc6cb7f03a5060603ec065877779d5e4ea0c7be0 Bump tokio from 1.52.4 to 1.53.0 (#1087)</li>
<li>82e0680ff56ea2b64ab2c6125bdc835af8e67c06 Bump fjall from 3.1.6 to 3.1.7 (#1086)</li>
<li>e4bb3afab3b7f9932e14bbe5ca66881c86e84034 Bump astro from 7.1.0 to 7.1.1 in /doc in the astro group (#1085)</li>
</ul>
]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/rumdl-action/</link><pubDate>Sun, 19 Jul 2026 06:32:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.36.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
rumdl is a high-performance Rust-based Markdown linter and formatter with over 76 lint rules, offering automatic formatting and zero dependencies. It’s built for speed and supports multiple Markdown flavors, including GFM, MkDocs, MDX, Quarto, and MyST. The tool is highly configurable through TOML files and integrates well with various editors and CI/CD pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.36</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>rumdl is a high-performance Rust-based Markdown linter and formatter with over 76 lint rules, offering automatic formatting and zero dependencies. It&rsquo;s built for speed and supports multiple Markdown flavors, including GFM, MkDocs, MDX, Quarto, and MyST. The tool is highly configurable through TOML files and integrates well with various editors and CI/CD pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>code-block-tools</strong>: add shuck:format as a built-in shell formatter (<a href="https://github.com/rvben/rumdl/commit/5b232610a871755fd3900fe1b67f263b1fcd1474">5b23261</a>)</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>wasm</strong>: stop double-converting already-character-based columns (<a href="https://github.com/rvben/rumdl/commit/4178cdf8c0d64cba53340c17ce1dfa9a0ed9ff39">4178cdf</a>)</li>
<li><strong>tests</strong>: resolve String addition compilation errors under Rust 1.96 (#737) (<a href="https://github.com/rvben/rumdl/commit/38f36cf3dfb523f4ced6daf0b7e3f505018be713">38f36cf</a>)</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.36/rumdl-v0.2.36-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.36-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.36/rumdl-v0.2.36-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.36/rumdl-v0.2.36-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.36-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.36/rumdl-v0.2.36-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.36/rumdl-v0.2.36-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.36-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.36/rumdl-v0.2.36-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.36/rumdl-v0.2.36-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.36-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.36/rumdl-v0.2.36-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.36/rumdl-v0.2.36-x86_64-apple-darwin.tar.gz">rumdl-v0.2.36-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.36/rumdl-v0.2.36-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.36/rumdl-v0.2.36-aarch64-apple-darwin.tar.gz">rumdl-v0.2.36-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.36/rumdl-v0.2.36-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.36/rumdl-v0.2.36-x86_64-pc-windows-msvc.zip">rumdl-v0.2.36-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.36/rumdl-v0.2.36-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>SJ_TEST Giphy PR Comments</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/sj_test-giphy-pr-comments/</link><pubDate>Sun, 19 Jul 2026 06:31:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/sj_test-giphy-pr-comments/</guid><description>Version updated for https://github.com/SJWarrior-17/js_pr-giphy-comment to version alpha-v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is designed to automatically add a Giphy GIF comment to new pull requests in a multi-node Kubernetes 1.34 environment. It automates the process of generating and posting a relevant GIF to help newcomers and contributors feel welcome. The action uses Node.js, Octokit for interacting with GitHub’s API, and Giphy’s API to fetch and display a GIF comment on a new pull request.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SJWarrior-17/js_pr-giphy-comment">https://github.com/SJWarrior-17/js_pr-giphy-comment</a></strong> to version <strong>alpha-v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sj_test-giphy-pr-comments">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is designed to automatically add a Giphy GIF comment to new pull requests in a multi-node Kubernetes 1.34 environment. It automates the process of generating and posting a relevant GIF to help newcomers and contributors feel welcome. The action uses Node.js, Octokit for interacting with GitHub&rsquo;s API, and Giphy&rsquo;s API to fetch and display a GIF comment on a new pull request.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Exploring JavaScript GitHub Custom Action.</p>
]]></content:encoded></item><item><title>Skaphos Oiax</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/skaphos-oiax/</link><pubDate>Sun, 19 Jul 2026 06:30:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/skaphos-oiax/</guid><description>Version updated for https://github.com/skaphos/oiax to version v1.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Oiax is a declarative Git branch promotion reconciler for GitOps repositories. It ensures that pull requests exist between adjacent branches to move changes through an environment graph, automating the management of environment promotion requests and backflow. The action supports GitHub Actions and requires git 2.45 or newer for its functionality.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/skaphos/oiax">https://github.com/skaphos/oiax</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skaphos-oiax">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Oiax is a declarative Git branch promotion reconciler for GitOps repositories. It ensures that pull requests exist between adjacent branches to move changes through an environment graph, automating the management of environment promotion requests and backflow. The action supports GitHub Actions and requires git 2.45 or newer for its functionality.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>See <a href="https://github.com/skaphos/oiax/blob/v1.1.0/CHANGELOG.md">CHANGELOG.md</a> for the full release notes.</p>
]]></content:encoded></item><item><title>vibestats</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/vibestats/</link><pubDate>Sun, 19 Jul 2026 06:29:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/vibestats/</guid><description>Version updated for https://github.com/stephenleo/vibestats to version v2.4.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary VibeStats is an open-source GitHub Action that tracks Claude Code and Codex sessions to provide users with a heatmap on their GitHub profile and a full analytics dashboard at vibestats.dev/&amp;lt;username&amp;gt;. It synchronizes aggregated daily stats to a private GitHub repo, ensuring history past 30 days without changing Claude Code’s default settings. The action helps users keep track of usage trends, privacy, and survival across machine wipes and reinstalls, offering detailed metrics such as tokens, sessions, minutes, model breakdowns, harness mixes, and more.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stephenleo/vibestats">https://github.com/stephenleo/vibestats</a></strong> to version <strong>v2.4.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibestats">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>VibeStats is an open-source GitHub Action that tracks Claude Code and Codex sessions to provide users with a heatmap on their GitHub profile and a full analytics dashboard at <code>vibestats.dev/&lt;username&gt;</code>. It synchronizes aggregated daily stats to a private GitHub repo, ensuring history past 30 days without changing Claude Code&rsquo;s default settings. The action helps users keep track of usage trends, privacy, and survival across machine wipes and reinstalls, offering detailed metrics such as tokens, sessions, minutes, model breakdowns, harness mixes, and more.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="fixes">Fixes</h2>
<ul>
<li><code>vibestats sync</code> now reports failed uploads and exits non-zero; failed uploads do not update checkpoint hashes, so later syncs retry them.</li>
<li><code>vibestats auth</code> now pipes its token to <code>gh secret set</code> without the unsupported <code>--body-file</code> flag.</li>
</ul>
]]></content:encoded></item><item><title>Setup Tombi</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/setup-tombi/</link><pubDate>Sun, 19 Jul 2026 06:28:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/setup-tombi/</guid><description>Version updated for https://github.com/tombi-toml/setup-tombi to version v1.2.3.
This action is used across all versions by 138 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up Tombi, a package manager for TOML files, in your GitHub Actions workflow. It allows you to install specific versions of Tombi or resolve versions using lockfiles like uv.lock. The action supports checksum verification for both the archive and binary binaries, ensuring the integrity of the installed version.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tombi-toml/setup-tombi">https://github.com/tombi-toml/setup-tombi</a></strong> to version <strong>v1.2.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>138</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-tombi">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up Tombi, a package manager for TOML files, in your GitHub Actions workflow. It allows you to install specific versions of Tombi or resolve versions using lockfiles like <code>uv.lock</code>. The action supports checksum verification for both the archive and binary binaries, ensuring the integrity of the installed version.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This setup-tombi release matches <a href="https://github.com/tombi-toml/tombi/releases/tag/v1.2.3">tombi v1.2.3</a>.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/tombi-toml/setup-tombi/compare/v1...v1.2.3">https://github.com/tombi-toml/setup-tombi/compare/v1...v1.2.3</a></p>
]]></content:encoded></item><item><title>MIU PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/miu-pr-review/</link><pubDate>Sun, 19 Jul 2026 06:27:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/miu-pr-review/</guid><description>Version updated for https://github.com/vanducng/miu-cr to version v0.89.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary miu-cr is an AI code review tool designed for the CLI, CI, and MCP hosts. It automates code reviews locally, gates PRs in CI, or drives the engine from any MCP-capable agent. The tool provides deterministic engine functionality, stable JSON envelopes on stdout, and supports local review, GitHub PR review, and CI/GitHub Action integration with project rules and evaluation capabilities.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vanducng/miu-cr">https://github.com/vanducng/miu-cr</a></strong> to version <strong>v0.89.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/miu-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>miu-cr is an AI code review tool designed for the CLI, CI, and MCP hosts. It automates code reviews locally, gates PRs in CI, or drives the engine from any MCP-capable agent. The tool provides deterministic engine functionality, stable JSON envelopes on stdout, and supports local review, GitHub PR review, and CI/GitHub Action integration with project rules and evaluation capabilities.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="miu-cr-v0891">miu-cr v0.89.1</h2>
<p>AI code review for local changes and GitHub pull requests. Use it as a CLI, CI gate, or GitHub Action with your own LLM key.</p>
<h3 id="install">Install</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>curl -fsSL https://cr.miu.sh/install.sh | sh -s -- v0.89.1
</span></span><span style="display:flex;"><span>brew install vanducng/tap/miucr
</span></span><span style="display:flex;"><span>go install github.com/vanducng/miu-cr/cmd/miucr@v0.89.1
</span></span></code></pre></div><p>GitHub Action:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v6</span>
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">vanducng/miu-cr@v0.89.1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span></code></pre></div><h3 id="common-commands">Common commands</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>miucr login --provider openai
</span></span><span style="display:flex;"><span>miucr review --staged
</span></span><span style="display:flex;"><span>miucr review --from main --to HEAD --gate high
</span></span><span style="display:flex;"><span>miucr review --pr owner/repo#123 --post
</span></span><span style="display:flex;"><span>miucr upgrade
</span></span></code></pre></div><p>Docs: <a href="https://cr.miu.sh">https://cr.miu.sh</a></p>
]]></content:encoded></item><item><title>Pixtex — Render n8n Workflow</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/pixtex-render-n8n-workflow/</link><pubDate>Sun, 19 Jul 2026 06:26:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/pixtex-render-n8n-workflow/</guid><description>Version updated for https://github.com/VicegerentPrince/pixtex to version v0.1.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the conversion and hosting of n8n workflow JSON into interactive diagrams using Pixtex, a web-based diagramming tool. It allows developers to render local images, host them as permanent URLs with stable IDs, update existing diagrams in CI workflows, and embed them directly in documentation or other platforms. The action simplifies the process by rendering the workflow at build time and automatically updating it in place whenever changes are pushed to the repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VicegerentPrince/pixtex">https://github.com/VicegerentPrince/pixtex</a></strong> to version <strong>v0.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pixtex-render-n8n-workflow">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the conversion and hosting of n8n workflow JSON into interactive diagrams using Pixtex, a web-based diagramming tool. It allows developers to render local images, host them as permanent URLs with stable IDs, update existing diagrams in CI workflows, and embed them directly in documentation or other platforms. The action simplifies the process by rendering the workflow at build time and automatically updating it in place whenever changes are pushed to the repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release from the standalone repo.</p>
<p><strong>CLI</strong> — <code>npx pixtex</code> renders n8n workflow JSON into share-ready diagrams: local files (<code>render</code>) or hosted images with a permanent URL that updates in place (<code>push --id</code>). Published to npm with provenance.</p>
<p><strong>GitHub Action</strong> — keep the workflow diagram in your README always current:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">VicegerentPrince/pixtex@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">workflow</span>: <span style="color:#ae81ff">workflows/order-sync.json</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.PIXTEX_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">image-id</span>: <span style="color:#ae81ff">${{ vars.PIXTEX_IMAGE_ID }}</span>
</span></span></code></pre></div><p>Docs: <a href="https://pixtex.dev/developers">https://pixtex.dev/developers</a></p>
]]></content:encoded></item><item><title>luacheck for FiveM - WTP</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/luacheck-for-fivem-wtp/</link><pubDate>Sun, 19 Jul 2026 06:25:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/luacheck-for-fivem-wtp/</guid><description>Version updated for https://github.com/We-The-People-RP/fivem-lua-lint-action to version V2.0.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically runs luacheck on a developer’s Lua codebase to ensure compliance with FiveM coding standards. It supports the use of backtick syntax and provides options for generating JUnit reports, which can be used to visually display linting results in GitHub Actions workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/We-The-People-RP/fivem-lua-lint-action">https://github.com/We-The-People-RP/fivem-lua-lint-action</a></strong> to version <strong>V2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/luacheck-for-fivem-wtp">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically runs <code>luacheck</code> on a developer&rsquo;s Lua codebase to ensure compliance with FiveM coding standards. It supports the use of backtick syntax and provides options for generating JUnit reports, which can be used to visually display linting results in GitHub Actions workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/We-The-People-RP/fivem-lua-lint-action/commits/V2.0.0">https://github.com/We-The-People-RP/fivem-lua-lint-action/commits/V2.0.0</a></p>
]]></content:encoded></item><item><title>Move Closed Issue to Top of Project Column</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/move-closed-issue-to-top-of-project-column/</link><pubDate>Sun, 19 Jul 2026 06:25:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/move-closed-issue-to-top-of-project-column/</guid><description>Version updated for https://github.com/wozaki/project-closed-issue-move-to-top-action to version v1.21.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of moving closed issues to the top of a specified column in GitHub Project V2. It checks if an issue belongs to a specific project and updates its status to a given column, ensuring recently closed issues are visible at the top of the project board. The action supports multiple projects with different settings and requires a GitHub token with project and repo permissions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wozaki/project-closed-issue-move-to-top-action">https://github.com/wozaki/project-closed-issue-move-to-top-action</a></strong> to version <strong>v1.21.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/move-closed-issue-to-top-of-project-column">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of moving closed issues to the top of a specified column in GitHub Project V2. It checks if an issue belongs to a specific project and updates its status to a given column, ensuring recently closed issues are visible at the top of the project board. The action supports multiple projects with different settings and requires a GitHub token with <code>project</code> and <code>repo</code> permissions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">uses</span>: <span style="color:#ae81ff">wozaki/project-closed-issue-move-to-top-action@4c3888f50026b434bd0b0ac2c5250e46e3e44442</span> <span style="color:#75715e"># v1.21.0</span>
</span></span></code></pre></div><h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): update int128/release-typescript-action action to v1.75.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/152">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/152</a></li>
<li>chore(deps): update int128/update-generated-files-action action to v2.100.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/153">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/153</a></li>
<li>chore(deps): update int128/wait-for-workflows-action action to v1.86.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/154">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/154</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/155">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/155</a></li>
<li>chore(deps): update dependency vitest to v4.1.10 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/156">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/156</a></li>
<li>chore(deps): update pnpm to v10.34.5 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/157">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/157</a></li>
<li>chore(deps): update int128/update-generated-files-action action to v2.101.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/158">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/158</a></li>
<li>chore(deps): update int128/release-typescript-action action to v1.76.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/160">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/160</a></li>
<li>chore(deps): update int128/update-generated-files-action action to v2.102.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/161">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/161</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/162">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/162</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/compare/v1.20.0...v1.21.0">https://github.com/wozaki/project-closed-issue-move-to-top-action/compare/v1.20.0...v1.21.0</a></p>
]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/cowork-harness/</link><pubDate>Sun, 19 Jul 2026 06:24:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/19/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a scriptable test harness designed to simulate and reproduce the observable runtime contract of Claude Cowork’s skills. It helps in testing local skills without using the locked Desktop app, across various scenarios and CI jobs. The action supports different fidelity tiers with varying requirements including Node.js version, Python (for linting), and a running runtime for live tests. It is designed to mimic the limitations of Cowork, such as sealed filesystems and default-deny egress, ensuring green tests reflect real-world behavior.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a scriptable test harness designed to simulate and reproduce the observable runtime contract of Claude Cowork&rsquo;s skills. It helps in testing local skills without using the locked Desktop app, across various scenarios and CI jobs. The action supports different fidelity tiers with varying requirements including Node.js version, Python (for linting), and a running runtime for live tests. It is designed to mimic the limitations of Cowork, such as sealed filesystems and default-deny egress, ensuring green tests reflect real-world behavior.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong><code>no_lost_write_back: true</code> scenario assertion</strong> — gate a scenario on &ldquo;the agent didn&rsquo;t emit an
interactive artifact whose Submit is lost under Cowork&rdquo;. It runs the shipped static Tier A analyzer
(<code>analyze-artifact</code>, deterministic, no headless DOM) over the files the run authored — diffed against the
pre-run manifest — so a lost relative <code>fetch</code>/XHR/<code>sendBeacon</code>/<code>&lt;form method=post&gt;</code> write-back becomes a
per-scenario verdict, not just an out-of-band <code>analyze-skill</code> scan. A lost write-back on an <strong>added</strong>
agent-authored source (<code>outputs/</code> or the scratchpad) fails; a <strong>pre-existing</strong> file the skill only modified
on a read-write connected mount is advisory (not the skill&rsquo;s to own); <code>-suspect</code> findings surface but pass.
Honest evidence-unavailable semantics: could-not-verify (fail-closed, never a silent clean) on a <code>--resume</code>
scratchpad walk or an authored candidate that couldn&rsquo;t be analyzed. Runs on every live sandbox tier
including <strong>microvm</strong> (its outputs are snapshotted from the VM into the run dir — see the #52 entry below).
<strong>Live/verify-run only</strong> — skipped-loud on replay (a cassette embedding the key never
hard-fails its replay); <code>verify-run</code> recomputes the authored set from the kept work dir. Only <code>true</code> is
valid (omit to skip).</p>
</li>
<li>
<p><strong><code>tool_result_matches</code> / <code>tool_result_not_matches</code> scenario assertion keys</strong> — the case-insensitive regex
siblings of <code>tool_result_contains</code>/<code>tool_result_not_contains</code>, evaluated per captured tool result (subject
to the same 10 KB per-result assertText cap). Useful for catching an error-signature <em>family</em> (e.g. a
script&rsquo;s non-zero exit swallowed by its wrapper, but the message still printed) that a literal substring
match can&rsquo;t express. Same evidence-unavailable wording as the <code>_contains</code> pair: a bad regex fails the
assertion with a compile error, and a no-match against a display-truncated result is reported as
could-not-verify rather than a silent pass/fail.</p>
</li>
<li>
<p><strong>A folder-grant refusal for <code>request_cowork_directory</code>, ported from Desktop 1.22209.0.</strong> Cowork now
refuses (pre-prompt) a mid-session folder grant that targets a security-sensitive home-directory path —
<code>.ssh</code>, <code>.aws</code>, <code>.gnupg</code>, <code>.kube</code>, <code>.docker</code>, <code>.claude</code>, <code>.config/{gcloud,gh,powershell}</code>, the darwin
<code>Library/{Keychains,LaunchAgents,LaunchDaemons,Application Support,Cookies}</code> paths, or a protected shell
dotfile (<code>.zshrc</code>, <code>.netrc</code>, etc.) — either directly, as a descendant, or as an ancestor whose grant would
incidentally expose one (e.g. requesting the home directory itself). The harness&rsquo;s <code>hostloop</code> canUseTool
gate ports this byte-faithfully, denying with Desktop&rsquo;s own message. <strong>Currently dead code in a stock
run</strong>: no built-in workspace/cowork server registers <code>request_cowork_directory</code> yet (a pre-existing,
separately tracked gap), so this only fires for a scenario that supplies its own <code>mcp_config</code> registering
a matching tool name. Ported ahead of that gap closing so the refusal semantics are ready the moment it
does. Two GrowthBook feature-gate ids Desktop 1.22209.0 introduced for a related &ldquo;auto mode always-allow&rdquo;
tool-approval feature are pinned as drift sentinels (<code>sync</code>&rsquo;s <code>PINNED_GATES</code>) without being behaviorally
modeled — this harness has no persistent per-tool permission concept to model them against.</p>
</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong><code>cowork-harness status &lt;run-dir&gt;</code> now resolves the newest session under a run-dir root.</strong> Previously
<code>status</code> only worked against the exact per-session out-dir printed at run start; pointing it at the root
passed to <code>run --run-dir</code> failed with &ldquo;no status.json&rdquo;. It now scans up to two levels under a directory
lacking its own <code>status.json</code> for the newest session that has one, and reads that instead.</li>
<li><strong><code>doctor</code>&rsquo;s two staged-agent checks are now titled distinctly</strong> — &ldquo;Staged agent binary (VM/container
ELF)&rdquo; vs. &ldquo;Staged native agent binary (hostloop)&rdquo; — so a failure on either is attributable to the right
one instead of reading as an ambiguous duplicate.</li>
<li><strong>The run-completion footer now prints a <code>→ result: &lt;run-dir&gt;/result.json</code> pointer</strong>, on both success and
failure, since the run directory is always kept on disk. Suppressed on the replay lane, which never
writes a <code>result.json</code>.</li>
<li><strong>The <code>on_unanswered=fail</code> unscripted-gate error now also mentions <code>on_unanswered: llm</code> as a secondary
escape valve.</strong> Previously it suggested only <code>--answer &quot;&lt;regex&gt;=&lt;choice&gt;&quot;</code>, which is the right primary
fix but the wrong tool for a gate whose wording drifts run-to-run — a regex chases a moving target. The
added line explicitly says &ldquo;in the scenario YAML&rdquo; (<code>--on-unanswered llm</code> is rejected on the CLI in favor
of <code>--decider-llm</code>) and notes the tradeoff (non-deterministic, one model call per gate) so it doesn&rsquo;t
read as unconditionally preferable to fixing the script.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>
<p><strong>Silent false-green on a missing workspace root (<code>#52</code>).</strong> When the workspace root (<code>outDir/work/session/mnt</code>)
couldn&rsquo;t be walked — the canonical case is a <strong>microvm</strong> run, whose outputs stage into the VM work tree, not
into the run dir — <code>RunResult.workspaceFiles</code>/<code>artifacts</code> persisted as <code>[]</code>, <strong>indistinguishable from a run
that genuinely wrote nothing.</strong> A consumer reading <code>result.json</code> (e.g. skill-creator-plus) saw &ldquo;zero
artifacts, clean.&rdquo; They now persist as <strong><code>undefined</code> (unavailable)</strong> — the same convention replay already
uses for &ldquo;no live filesystem to scan&rdquo; — with a loud <code>::warning::</code> naming the reason. Applied across the
success, partial-salvage, and chat lanes; the walk&rsquo;s <code>complete</code>/root-absent health (F18) is now <em>consumed</em>
at the call site rather than discarded. A genuinely-empty run (root present, no files) still correctly
reports <code>[]</code>; only an unobservable root flips to unavailable.</p>
</li>
<li>
<p><strong>microvm outputs are now observable — root-cause fix for <code>#52</code>.</strong> A microvm run&rsquo;s outputs already live on
host disk (<code>VM_WORK_HOST</code> is mounted writable into the VM at <code>/sessions</code>), just at a different path than the
run dir the post-run pipeline walks. The run now <strong>snapshots the session-root tree from the VM mount into
<code>outDir/work/session</code></strong> (mirroring how <code>hostloop</code> snapshots connected folders) — rm-before-copy,
symlinks copied verbatim (<code>dereference: false</code>), fail-loud if the tree is unexpectedly absent — plus captures
the pre-run manifest on this tier. Result: <strong><code>workspaceFiles</code>/<code>artifacts</code>, <code>file_exists</code>, <code>artifact_json</code>,
<code>user_visible_artifact</code>, <code>no_lost_write_back</code>, <code>no_unexpected_files</code>, and <code>input_unmodified</code> now work on
<code>microvm</code></strong> instead of being evidence-unavailable — verified live to be identical to <code>container</code>. It&rsquo;s also
fidelity-positive: real Cowork&rsquo;s VM outputs are host-observable too. (<code>no_scratchpad_leak</code> /
<code>present_files_called</code> stay <code>container</code>-only — they key off the <code>present_files</code> tool, not workspace
observability.) Doc/message sweep: the &ldquo;use container/hostloop&rdquo; carve-outs for these keys are removed.</p>
</li>
<li>
<p><strong><code>sync</code>&rsquo;s non-macOS guard no longer blames Claude Desktop for a limitation that&rsquo;s actually this
harness&rsquo;s own.</strong> The error previously read &ldquo;sync requires macOS (the Cowork Desktop app is macOS-only)&rdquo;
— false, Desktop ships a Windows build too; only this harness&rsquo;s <code>sync</code> tooling doesn&rsquo;t support non-macOS
install layouts yet. The message now says so.</p>
</li>
<li>
<p><strong>The web_fetch provenance-miss denial is synced to Desktop 1.22209.0&rsquo;s wording.</strong> The message now notes
that a URL surfaced in a WebSearch result also counts as provenance, and tells a subagent that can&rsquo;t ask
the user to continue without the page and report the blocked URL rather than stall. No logic change —
Desktop&rsquo;s underlying provenance rules are unchanged between releases, only the wording moved.</p>
</li>
<li>
<p><strong>The hostloop path-gate no longer emits a spurious &ldquo;cwd mismatch&rdquo; warning when the run-dir is reached
through a symlink</strong> (e.g. macOS <code>/tmp</code> → <code>/private/tmp</code>). The diagnostic now compares the wire and
spawner cwds after best-effort realpath canonicalization, so the same directory reached via two spellings
no longer false-alarms; the path-gate&rsquo;s actual allow/deny decision was already realpath-rooted and is
unaffected.</p>
</li>
<li>
<p><strong><code>verify-cassettes</code> no longer flags <code>claude.com</code> as a <code>domain</code> PII finding on every MCP-session
cassette.</strong> The scanner&rsquo;s capability-manifest exclusion (<code>isCapabilityManifest()</code>) recognized only two
structural forms (the <code>system/init</code> event and the <code>initialize</code> registry <code>control_response</code>); it missed
the MCP <code>initialize</code> handshake itself — both Claude Code&rsquo;s own <code>control_request</code> (<code>clientInfo.websiteUrl</code>)
and the configured MCP server&rsquo;s <code>control_response</code> (<code>serverInfo</code>) — which fell through to the full
<code>domain</code>/<code>currency</code> net on every recording that talks to an MCP server. The only previous workaround,
<code>--allow-domain 'claude\.com'</code> in CI, was a class-scoped (not location-scoped) allow that would have
silently cleared a genuine <code>claude.com</code>-hosted leak anywhere else in the same cassette. Both handshake
forms are now recognized (shape-matched on the response side, since <code>serverInfo</code> is server-authored, not
Claude Code&rsquo;s own fixed string), and the CI gate no longer needs any <code>--allow-domain</code>/<code>--allow-email</code>
flag to pass on the committed example cassettes.</p>
</li>
<li>
<p><strong><code>hostloop</code>/<code>cowork</code> runs and <code>doctor --tier cowork</code> no longer hard-block when the pinned VM/container
ELF was pruned by a Desktop update but a patch-newer sibling is staged.</strong> At that tier the ELF is
bind-mounted into the bash sidecar for parity and is not run by any harness-spawned process (the native
binary is the agent), so a same-major.minor patch bump is now auto-tolerated (loud note, advisory sha) —
matching the native binary&rsquo;s existing policy. The sha-pinned strictness is unchanged for
<code>container</code>/<code>microvm</code>, where the ELF is the executed agent.</p>
</li>
<li>
<p><strong><code>doctor --tier cowork</code> now mirrors the resolved loop</strong> (<code>decideLoopFromBaseline</code>) for both agent
binaries, so it neither false-greens nor false-not-readies. When <code>cowork</code> resolves to host-loop it
tolerates the ELF patch bump and requires the native binary (the executed agent there); when it resolves
to VM-loop it keeps the ELF strict like <code>container</code> <strong>and</strong> stops requiring the native binary that a
VM-loop run doesn&rsquo;t use. Previously the tier&rsquo;s checks were unconditional, disagreeing with the actual
run on a VM-loop-resolving baseline.</p>
</li>
<li>
<p><strong><code>analyze-skill</code>: a <code>&lt;script&gt;…&lt;/script&gt;</code> pair inside a docstring or comment no longer aborts a whole
file to could-not-verify.</strong> The lexical block extractor could pull English prose out of a docstring or
comment as a phantom &ldquo;script block&rdquo;; its parse failure short-circuited the entire file to a
could-not-verify (exit 3), discarding the verdict already computed for the file&rsquo;s real, parseable
write-back block. The per-block analysis now accumulates: a block that fails to parse with no
<code>fetch</code>/XHR-<code>open</code>/<code>sendBeacon</code>/<code>axios</code>/<code>.post()</code> write-back hint is discounted as prose, while one that
carries a hint — or any block large enough to trip the analysis cap — is still reported as a
could-not-verify surfaced alongside any finding. A candidate whose every isolated <code>&lt;script&gt;</code> block is
unparseable stays a could-not-verify (fail-closed), never a silent clean pass. Several follow-on gaps in
that accumulation are also closed. First: whenever at least one <code>&lt;script&gt;</code> block was discounted as
prose, a parseable sibling block (or an already-flagged <code>&lt;form method=post&gt;</code>) no longer vouches for
write-back surface OUTSIDE every extracted block (top-level <code>.js</code>/<code>.ts</code> code, an inline <code>on*=</code> handler,
or surrounding template markup) — any write-back hint left in that un-analyzed remainder is now its own
could-not-verify, reported alongside any finding rather than silently passed; a source with no
discounted block, or an inline-handler write-back with nothing else in play, is unaffected. Second: the
write-back hint check (and the earlier candidacy check) now also recognizes optional-call spellings —
<code>fetch?.(</code>, <code>xhr?.open?.(</code>, <code>$.post?.(</code>, <code>navigator?.sendBeacon?.(</code> — so a source whose only write-back
uses <code>?.</code> is neither missed as a candidate nor discounted as prose inside an unparseable block; that
optional-call matching is also linearized (no more quadratic backtracking on a long non-matching
whitespace run). Third: a member-spelled write-back inside a block that DOES parse —
<code>window.fetch(...)</code>, <code>globalThis.fetch(...)</code>, <code>self.fetch(...)</code>, or the same spelling inside a same-file
fetch-wrapper&rsquo;s own body — is now classified the same as a bare <code>fetch(...)</code> call instead of going
unrecognized and falling through as clean; a bare <code>sendBeacon(...)</code> identifier call (e.g. a locally
bound alias of <code>navigator.sendBeacon</code>) is now recognized the same way as the member-spelled
<code>navigator.sendBeacon(...)</code>. Fourth: a <code>.post(...)</code>/<code>.put(...)</code>/<code>.patch(...)</code> call on a receiver outside
the known <code>axios</code>/<code>$</code>/<code>jQuery</code> set — the common miss being an axios instance,
<code>const api = axios.create(); api.post(&quot;/api/save&quot;, data)</code> — targeting a relative URL is no longer
invisible; it is now reported as an advisory finding (never escalated to an error, since the receiver
isn&rsquo;t provably a write-back client and could be unrelated code; <code>.delete(...)</code> is deliberately excluded
from this, since it&rsquo;s common on non-HTTP collection types). Fifth: the axios/<code>$</code>/<code>jQuery</code> verb set
recognized on the whitelisted identifier itself is widened from <code>.post(...)</code> alone to
<code>.post(...)</code>/<code>.put(...)</code>/<code>.patch(...)</code>/<code>.delete(...)</code>/<code>.postForm(...)</code>/<code>.putForm(...)</code>/<code>.patchForm(...)</code>
(the last three are axios v1&rsquo;s multipart form-data verb aliases; <code>.delete(...)</code> is INCLUDED here,
unlike the any-receiver advisory case above, since the literal <code>axios</code>/<code>$</code>/<code>jQuery</code> identifier has no
ambiguity about what it means); a bare config-object call — <code>axios({method:&quot;POST&quot;, url:&quot;/api/save&quot;, ...})</code> — and <code>axios.request({...})</code> are both recognized, whether the config argument is an inline
object literal or a hoisted identifier (<code>const cfg = {...}; axios(cfg)</code>). This is not exhaustive: axios&rsquo;s
alternate <code>$.ajax({...})</code>-style config-key vocabulary, and any computed-member, whitespace-separated, or
aliased/re-exported spelling, remain a documented, lexically/structurally invisible accepted class (see
the relevant doc comments in <code>analyze-artifact.ts</code>) — as does a <code>formaction</code>/<code>formmethod</code> override on a
submit button that redirects an otherwise-remote <code>&lt;form&gt;</code> back to a relative, in-scope URL.</p>
</li>
<li>
<p><strong><code>analyze-skill</code>: a delete/remove flow that claims success now classifies as a lost write-back (error),
not just a suspect (advisory).</strong> The success-claim vocabulary that distinguishes a lost write-back (an
unconditional &ldquo;it worked&rdquo; toast) from a merely-suspect one gained delete-flow words (<code>deleted</code>,
<code>removed</code>, …) alongside the existing <code>saved</code>/<code>submitted</code>/<code>persisted</code>/<code>completed</code>/<code>success</code>. A relative
<code>DELETE</code> write-back whose only success signal is a &ldquo;Deleted!&rdquo;/&ldquo;Removed!&rdquo; toast — no <code>resp.ok</code>/status
check — is now flagged at error severity like its save-flow equivalent, since under Cowork it resolves
non-ok against Cowork&rsquo;s own origin and the false confirmation is identical.</p>
</li>
</ul>
<h3 id="documentation">Documentation</h3>
<ul>
<li><strong>Documented an <code>analyze-skill --runtime</code> recipe for agent-generated artifacts.</strong>
<code>analyze-skill --runtime &lt;run-dir&gt;/work/session/mnt/outputs</code> confirms interactive-artifact write-backs in
HTML the agent <em>generates during a run</em> — content the source-only static scan can&rsquo;t see until a run has
happened. Notes the tier-specific output paths and the microvm/replay caveats.</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs: analyze-skill &ndash;runtime recipe for agent-generated run-time artifacts by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/51">https://github.com/yaniv-golan/cowork-harness/pull/51</a></li>
<li>fix: microvm workspace false-green + make microvm outputs observable (#52, complete) by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/54">https://github.com/yaniv-golan/cowork-harness/pull/54</a></li>
<li>test: remove redundant jsdom &ndash;runtime spawn (real fix for the CI timeout flake) by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/55">https://github.com/yaniv-golan/cowork-harness/pull/55</a></li>
<li>release: 1.2.0 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/56">https://github.com/yaniv-golan/cowork-harness/pull/56</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.2.0">https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.2.0</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/hol-codex-plugin-scanner/</link><pubDate>Sat, 18 Jul 2026 22:48:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.514.
This action is used across all versions by 12 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the security and quality checks of AI plugins across different coding environments (Codex, Claude, Gemini, OpenCode) by emitting structured reports. It helps identify potential security issues, code readability concerns, and runtime readiness, while staying aligned with the main scanner release train. The action supports various execution modes and output formats, making it versatile for developers to integrate into their workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.514</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>12</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the security and quality checks of AI plugins across different coding environments (Codex, Claude, Gemini, OpenCode) by emitting structured reports. It helps identify potential security issues, code readability concerns, and runtime readiness, while staying aligned with the main scanner release train. The action supports various execution modes and output formats, making it versatile for developers to integrate into their workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.514">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.514</a></p>
]]></content:encoded></item><item><title>Supply Chain Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/supply-chain-guard/</link><pubDate>Sat, 18 Jul 2026 22:47:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/supply-chain-guard/</guid><description>Version updated for https://github.com/homeofe/supply-chain-guard to version v5.17.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary
Supply-chain-guard is an open-source supply-chain security scanner that detects malware campaigns and fake AI tool repos across various ecosystems, including npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, Terraform, VS Code extensions, GitHub Actions, and repositories. It uses a combination of threat indicators and automated analysis to provide a comprehensive view of the security posture in your software supply chain.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/homeofe/supply-chain-guard">https://github.com/homeofe/supply-chain-guard</a></strong> to version <strong>v5.17.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/supply-chain-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary</strong></p>
<p>Supply-chain-guard is an open-source supply-chain security scanner that detects malware campaigns and fake AI tool repos across various ecosystems, including npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, Terraform, VS Code extensions, GitHub Actions, and repositories. It uses a combination of threat indicators and automated analysis to provide a comprehensive view of the security posture in your software supply chain.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="5174---2026-07-18">[5.17.4] - 2026-07-18</h2>
<p><strong>Fix: <code>scan --format json</code> and risk-history reported a stale tool version (v5.2.0)</strong></p>
<h3 id="fixed">Fixed</h3>
<ul>
<li><code>src/scanner.ts</code> hardcoded <code>TOOL_VERSION = &quot;5.2.0&quot;</code>, so <code>ScanReport.tool</code> (emitted
verbatim by the JSON reporter) and the persisted <code>.scg-history/</code> risk entries reported
<code>supply-chain-guard v5.2.0</code>, while every other surface (text header, SARIF, SBOM, HTML
footer, GitLab) correctly used reporter.ts&rsquo;s own version. Corrected to the release version.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><code>check:version-sync</code> now also covers <code>src/scanner.ts</code>, so <code>TOOL_VERSION</code> can never drift
undetected again - the root cause was that the gate did not include scanner.ts.</li>
</ul>
]]></content:encoded></item><item><title>droast — Dockerfile linter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/droast-dockerfile-linter/</link><pubDate>Sat, 18 Jul 2026 22:45:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/droast-dockerfile-linter/</guid><description>Version updated for https://github.com/immanuwell/dockerfile-roast to version 1.4.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action droast-dockerfile-linter automates Dockerfile linting by identifying and reporting bad practices, providing feedback in a non-polite manner. It supports various parsing capabilities, including handling heredocs, parser directives, shell forms, BuildKit flags, Windows paths, PowerShell, and custom ignore files to ensure accurate detection of issues.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/immanuwell/dockerfile-roast">https://github.com/immanuwell/dockerfile-roast</a></strong> to version <strong>1.4.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/droast-dockerfile-linter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>droast-dockerfile-linter</code> automates Dockerfile linting by identifying and reporting bad practices, providing feedback in a non-polite manner. It supports various parsing capabilities, including handling heredocs, parser directives, shell forms, BuildKit flags, Windows paths, PowerShell, and custom ignore files to ensure accurate detection of issues.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>chore: release version 1.4.2 (e3e9589)</li>
<li>feat: publish crates.io packages for release tags (b6a8870)</li>
<li>fix: prepare version 1.4.1 for Cargo installation (43e49e4)</li>
<li>chore: update the Docker metadata action runtime (650622f)</li>
<li>fix: publish Docker images for amd64 and arm64 (6597993)</li>
<li>feat: support explicit configuration file paths (ccb62bc)</li>
<li>fix: parse apt assume-yes options and package pins correctly (f2799d4)</li>
<li>fix: recognize apt-get distclean as package-list cleanup (ecd341d)</li>
<li>fix: avoid matching prefixed package managers as npm (362e8ef)</li>
<li>fix: parse FROM options and inherited stage state correctly (6b42247)</li>
</ul>
]]></content:encoded></item><item><title>cibuild-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/cibuild-action/</link><pubDate>Sat, 18 Jul 2026 22:44:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/cibuild-action/</guid><description>Version updated for https://github.com/invarnhq/cibuild to version v2.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The cibuild action automates the setup and configuration of CI/CD pipelines for iOS and Android projects using YAML files. It provides an interactive wizard or auto-creation feature to generate a ready-to-use GitHub Actions workflow, which is fully non-interactive and works with AI agents and scripts. The action also supports importing existing pipeline YAML files and allows customization by editing the generated pipeline files.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/invarnhq/cibuild">https://github.com/invarnhq/cibuild</a></strong> to version <strong>v2.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cibuild-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The cibuild action automates the setup and configuration of CI/CD pipelines for iOS and Android projects using YAML files. It provides an interactive wizard or auto-creation feature to generate a ready-to-use GitHub Actions workflow, which is fully non-interactive and works with AI agents and scripts. The action also supports importing existing pipeline YAML files and allows customization by editing the generated pipeline files.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release v2.4.0</p>
]]></content:encoded></item><item><title>Invigil — Product Quality Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/invigil-product-quality-gate/</link><pubDate>Sat, 18 Jul 2026 22:43:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/invigil-product-quality-gate/</guid><description>Version updated for https://github.com/invigil/invigil to version v1.6.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Invigil is a CI quality gate that evaluates an open-source project against product-quality guidelines, not just code style. It checks whether the published artifact boots quickly and legibly, ensuring cold-start users can easily use and contribute to the project. Invigil provides detailed feedback on what’s wrong, why it matters, and how to fix it in CI. The tool covers gaps left by existing tools like linters and dependabot, focusing on legibility and error hygiene.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/invigil/invigil">https://github.com/invigil/invigil</a></strong> to version <strong>v1.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/invigil-product-quality-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Invigil is a CI quality gate that evaluates an open-source project against product-quality guidelines, not just code style. It checks whether the published artifact boots quickly and legibly, ensuring cold-start users can easily use and contribute to the project. Invigil provides detailed feedback on what&rsquo;s wrong, why it matters, and how to fix it in CI. The tool covers gaps left by existing tools like linters and dependabot, focusing on legibility and error hygiene.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/invigil/invigil/compare/v1.5.1...v1.6.0">https://github.com/invigil/invigil/compare/v1.5.1...v1.6.0</a></p>
]]></content:encoded></item><item><title>Agent Guard Secret Guardrails</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/agent-guard-secret-guardrails/</link><pubDate>Sat, 18 Jul 2026 22:42:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/agent-guard-secret-guardrails/</guid><description>Version updated for https://github.com/JeongJaeSoon/agent-guard to version v2.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Guard is a guardrail for AI coding agents (Claude Code, Codex) to prevent accidental exposure of secrets before they are read or written. It uses gitleaks for detection and plain shell scripts for integration. By running at the agent’s tool boundary, it blocks common ways an agent can accidentally expose secrets and provides defense in depth by also performing commit- or CI-time scanning.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/JeongJaeSoon/agent-guard">https://github.com/JeongJaeSoon/agent-guard</a></strong> to version <strong>v2.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-guard-secret-guardrails">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Agent Guard is a guardrail for AI coding agents (Claude Code, Codex) to prevent accidental exposure of secrets before they are read or written. It uses gitleaks for detection and plain shell scripts for integration. By running at the agent&rsquo;s tool boundary, it blocks common ways an agent can accidentally expose secrets and provides defense in depth by also performing commit- or CI-time scanning.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: add self-contained managed bootstrap by @JeongJaeSoon in <a href="https://github.com/JeongJaeSoon/agent-guard/pull/119">https://github.com/JeongJaeSoon/agent-guard/pull/119</a></li>
<li>release: v2.2.0 by @github-actions[bot] in <a href="https://github.com/JeongJaeSoon/agent-guard/pull/120">https://github.com/JeongJaeSoon/agent-guard/pull/120</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/JeongJaeSoon/agent-guard/compare/v2.1.0...v2.2.0">https://github.com/JeongJaeSoon/agent-guard/compare/v2.1.0...v2.2.0</a></p>
]]></content:encoded></item><item><title>jPipe Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/jpipe-runner/</link><pubDate>Sat, 18 Jul 2026 22:41:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/jpipe-runner/</guid><description>Version updated for https://github.com/jpipe-mcscert/jpipe-runner to version v3.5.3.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary A Justification Runner designed for jPipe, which automates template variable definitions, library loading, diagram selection, output file specification, dry run validation, and debug logging for jPipe workflows. It supports command-line interface usage with various options like variable definition, diagram selection, output file path, and more.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jpipe-mcscert/jpipe-runner">https://github.com/jpipe-mcscert/jpipe-runner</a></strong> to version <strong>v3.5.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jpipe-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>A Justification Runner designed for jPipe, which automates template variable definitions, library loading, diagram selection, output file specification, dry run validation, and debug logging for jPipe workflows. It supports command-line interface usage with various options like variable definition, diagram selection, output file path, and more.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Merge pull request #100 from jpipe-mcscert/dev (493d054)</li>
<li>release: bump version to 3.5.3 (6168133)</li>
<li>fix(release): stop shipping changelog placeholder to PPA; bump actions to Node 24 (74d2d24)</li>
<li>Merge pull request #99 from jpipe-mcscert/dev (b129268)</li>
<li>fix(release): address Copilot review on PR #99 (244a5e5)</li>
<li>release: bump version to 3.5.2 (ff67b74)</li>
<li>ci(release): overhaul release pipeline to mirror jpipe-compiler (ce7df05)</li>
<li>Merge pull request #98 from jpipe-mcscert/hotfix/ppa-3.5.1 (11777c3)</li>
<li>fix(ppa): validate retry tunables and skip sleep after final attempt (e32453d)</li>
<li>release: 3.5.1 — add PPA distros, harden PPA upload, complete 3.5.0 publish (683d2d9)</li>
</ul>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/neurolink-ai/</link><pubDate>Sat, 18 Jul 2026 22:40:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v9.93.1.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is a universal AI integration platform that provides a TypeScript-first way to integrate with 30+ AI providers and 100+ models. It offers single, consistent APIs, support for edge-first execution, continuous streaming architectures, and enterprise features such as Redis memory and multi-provider failover.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v9.93.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>NeuroLink is a universal AI integration platform that provides a TypeScript-first way to integrate with 30+ AI providers and 100+ models. It offers single, consistent APIs, support for edge-first execution, continuous streaming architectures, and enterprise features such as Redis memory and multi-provider failover.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="9931-2026-07-18"><a href="https://github.com/juspay/neurolink/compare/v9.93.0...v9.93.1">9.93.1</a> (2026-07-18)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(proxy):</strong>  complete reliability and analysis hardening (<a href="https://github.com/juspay/neurolink/commit/d91da31ec1233704ce5093fe6d5167517f04387c">d91da31</a>)</li>
</ul>
]]></content:encoded></item><item><title>kramlipi CI Repair</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/kramlipi-ci-repair/</link><pubDate>Sat, 18 Jul 2026 22:39:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/kramlipi-ci-repair/</guid><description>Version updated for https://github.com/kramlipi/code-agent-action to version v0.1.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, kramlipi/code-agent-action, automates CI verification and repair processes by running a specified command (verify-cmd) to check the status of a workflow run. It ensures that the build is green before proceeding with further tasks or generating a draft pull request if specified. The action supports various expert modes for different types of fixes, such as bug-fixing, code-review, and testing intelligence. It also manages secrets for authentication and licensing with options for free CI to paid upgrades via license API.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kramlipi/code-agent-action">https://github.com/kramlipi/code-agent-action</a></strong> to version <strong>v0.1.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kramlipi-ci-repair">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>kramlipi/code-agent-action</code>, automates CI verification and repair processes by running a specified command (<code>verify-cmd</code>) to check the status of a workflow run. It ensures that the build is green before proceeding with further tasks or generating a draft pull request if specified. The action supports various expert modes for different types of fixes, such as bug-fixing, code-review, and testing intelligence. It also manages secrets for authentication and licensing with options for free CI to paid upgrades via license API.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="kramlipi-ci-repair-v014">kramlipi CI Repair v0.1.4</h2>
<p>Verify-gated CI repair for GitHub Actions.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">kramlipi/code-agent-action@v0.1.4</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">expert</span>: <span style="color:#ae81ff">bug-fix</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">verify-cmd</span>: <span style="color:#ae81ff">pytest -q</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">publish</span>: <span style="color:#66d9ef">true</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">env</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">GEMINI_API_KEY</span>: <span style="color:#ae81ff">${{ secrets.GEMINI_API_KEY }}</span>
</span></span></code></pre></div><p>The Solution: A Senior Engineer Agent in Your CI Pipeline
kramlipi CI Repair doesn&rsquo;t just comment on problems; it actively solves them. It steps into your workflow exactly like a seasoned team lead to accelerate development and guarantee code quality.</p>
<p>Auto-Fixes Broken Tests: When a build fails, the agent jumps into the workspace, diagnoses the failure, and iteratively rewrites the code until your test suite passes successfully.</p>
<p>Improves Code Coverage: It doesn&rsquo;t just patch the bug; it proactively writes new test cases to cover the edge cases it uncovers, preventing future regressions.</p>
<p>Senior-Level Code Reviews: It provides deep, meaningful review comments on your Merge Requests (MRs) to catch design flaws early, keeping your main branches pristine and development fast.</p>
<p>Delivers Ready-to-Merge PRs: Once the agent successfully turns the build green, it packages the fix into a clean draft PR. Your team only reviews work that is already verified.</p>
<p>How it Differs from the Noise
Not an IDE Distraction: It stays out of your way, running asynchronously in the background only when your pipeline needs it.</p>
<p>No Comment Spam: Every PR comment is structured like a precise, senior engineering code review—actionable and context-aware.</p>
<p>Zero Data Lock-in: We don’t ask you to &ldquo;upload your monorepo&rdquo; to a third-party cloud. The product source stays private, and execution happens safely inside your ecosystem. You use your own AI model Gemini, Claude etc.</p>
<p>Built on absolute trust
Hard Boundaries: The agent is explicitly blocked from editing .github/workflows—it will never &ldquo;fake&rdquo; a green build.</p>
<p>Complete Security Control: Customer-hosted, running via a public binary release with Bring-Your-Own-LLM (BYO LLM) API keys.</p>
<p>Links
Get Started in 2 Minutes: <a href="https://kramlipi.github.io/get-started/">kramlipi.github.io/get-started</a>
Website: <a href="https://www.kramlipi.com/">https://www.kramlipi.com/</a></p>
]]></content:encoded></item><item><title>HoverStare</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/hoverstare/</link><pubDate>Sat, 18 Jul 2026 22:38:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/hoverstare/</guid><description>Version updated for https://github.com/liuchong/hoverstare to version v0.0.7.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary HoverStare is an AI code review tool for GitHub that reads your repository like a human reviewer before making suggestions. It uses multi-pass voting and a verifier to ensure high signal, low noise. The action provides precise inline comments with line number validation and incremental reviews, while being fail-open by design.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/liuchong/hoverstare">https://github.com/liuchong/hoverstare</a></strong> to version <strong>v0.0.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hoverstare">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>HoverStare is an AI code review tool for GitHub that reads your repository like a human reviewer before making suggestions. It uses multi-pass voting and a verifier to ensure high signal, low noise. The action provides precise inline comments with line number validation and incremental reviews, while being fail-open by design.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/liuchong/hoverstare/compare/v0.0.6...v0.0.7">https://github.com/liuchong/hoverstare/compare/v0.0.6...v0.0.7</a></p>
]]></content:encoded></item><item><title>guardmarly</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/guardmarly/</link><pubDate>Sat, 18 Jul 2026 22:36:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/guardmarly/</guid><description>Version updated for https://github.com/mattybellx/Guardmarly to version v6.5.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Guardmarly is a free SAST tool that automates the detection of authorization bugs such as IDOR, missing access controls, and privilege escalation. It maps HTTP routes to database queries and checks for missing auth guards, tracing data flow from routes to sinks to flag security vulnerabilities. Guardmarly provides detailed reports in text, JSON, and SARIF formats and supports multiple programming languages and CWEs, including 5 languages and 35+ CWE types.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mattybellx/Guardmarly">https://github.com/mattybellx/Guardmarly</a></strong> to version <strong>v6.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/guardmarly">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Guardmarly is a free SAST tool that automates the detection of authorization bugs such as IDOR, missing access controls, and privilege escalation. It maps HTTP routes to database queries and checks for missing auth guards, tracing data flow from routes to sinks to flag security vulnerabilities. Guardmarly provides detailed reports in text, JSON, and SARIF formats and supports multiple programming languages and CWEs, including 5 languages and 35+ CWE types.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="what-is-new-in-v650">What is new in v6.5.0</h2>
<ul>
<li>VS Code v1.2.0: gutter dots, findings quick-pick, scan spinner, auto CLI detection</li>
<li>Webapp: live scan counter</li>
<li>CI: auto-publish on push, pipeline reference docs</li>
</ul>
]]></content:encoded></item><item><title>Affected Code Owners</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/affected-code-owners/</link><pubDate>Sat, 18 Jul 2026 22:35:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/affected-code-owners/</guid><description>Version updated for https://github.com/meddevo/affected-codeowners to version v2.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action affected-codeowners determines which code owners are affected by changes in a pull request based on the repository’s CODEOWNERS file. It parses the file to generate lists of individual and grouped code owners, addressing known limitations related to pattern escaping and negation. The action outputs JSON-formatted lists of affected owners for both individuals and groups, aiding in tracking which contributors need attention.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/meddevo/affected-codeowners">https://github.com/meddevo/affected-codeowners</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/affected-code-owners">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>affected-codeowners</code> determines which code owners are affected by changes in a pull request based on the repository&rsquo;s <code>CODEOWNERS</code> file. It parses the file to generate lists of individual and grouped code owners, addressing known limitations related to pattern escaping and negation. The action outputs JSON-formatted lists of affected owners for both individuals and groups, aiding in tracking which contributors need attention.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat!: migrate action runtime to node24 by @joh-klein in <a href="https://github.com/meddevo/affected-codeowners/pull/24">https://github.com/meddevo/affected-codeowners/pull/24</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@joh-klein made their first contribution in <a href="https://github.com/meddevo/affected-codeowners/pull/24">https://github.com/meddevo/affected-codeowners/pull/24</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/meddevo/affected-codeowners/compare/v1...v2.0.0">https://github.com/meddevo/affected-codeowners/compare/v1...v2.0.0</a></p>
]]></content:encoded></item><item><title>Run AER Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/run-aer-tests/</link><pubDate>Sat, 18 Jul 2026 22:33:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/run-aer-tests/</guid><description>Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.19.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The aer action is a tool to locally execute and test Salesforce Apex code. It supports running tests, executing anonymous Apex, and debugging Apex in an interactive debugger through CLI or CI. It mimics the Salesforce runtime environment locally, without requiring an org or deploy. The action can be installed as a Homebrew package, npm plugin, VS Code extension, or downloaded manually.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/octoberswimmer/aer-dist">https://github.com/octoberswimmer/aer-dist</a></strong> to version <strong>v1.2.19</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-aer-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>The aer action is a tool to locally execute and test Salesforce Apex code. It supports running tests, executing anonymous Apex, and debugging Apex in an interactive debugger through CLI or CI. It mimics the Salesforce runtime environment locally, without requiring an org or deploy. The action can be installed as a Homebrew package, npm plugin, VS Code extension, or downloaded manually.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Version v1.2.19</p>
<ul>
<li>
<p>Throw Illegal Assignment When SObject.put Stores Non-String In Text Field</p>
</li>
<li>
<p>Include Inactive Record Types In getRecordTypeInfos Describe Results</p>
</li>
<li>
<p>Defer Polymorphic FK Validation Until Bootstrap Copy Completes</p>
</li>
<li>
<p>Report Duplicate Results Per Active DuplicateRule In findDuplicates</p>
</li>
<li>
<p>Auto-Calculate Contract EndDate From StartDate And ContractTerm</p>
</li>
<li>
<p>Copy Missing Standard Field Mappings In Database.convertLead</p>
</li>
<li>
<p>Scope Record Type Picklist Defaults To The Record&rsquo;s Record Type</p>
</li>
<li>
<p>Reject Share Inserts Targeting An Inactive User</p>
</li>
<li>
<p>Support MFLOOR And MCEILING Formula Functions</p>
</li>
<li>
<p>Support Method Calls On Enum Results Of Binary Expressions</p>
</li>
<li>
<p>Evaluate TEXT(NULL) As Empty String In Formula Evaluator</p>
</li>
</ul>
]]></content:encoded></item><item><title>Automatic Semantic Releases</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/automatic-semantic-releases/</link><pubDate>Sat, 18 Jul 2026 22:32:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/automatic-semantic-releases/</guid><description>Version updated for https://github.com/oliversalzburg/action-automatic-semantic-releases to version v3.2.0.
This action is used across all versions by 16 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically creates semantic releases based on versioning in code. It supports tagged builds, version management, and development builds with customizable release settings. The action uses the release-version.cjs script to generate versions and can be configured to create draft or prerelease releases.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/oliversalzburg/action-automatic-semantic-releases">https://github.com/oliversalzburg/action-automatic-semantic-releases</a></strong> to version <strong>v3.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>16</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/automatic-semantic-releases">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically creates semantic releases based on versioning in code. It supports tagged builds, version management, and development builds with customizable release settings. The action uses the <code>release-version.cjs</code> script to generate versions and can be configured to create draft or prerelease releases.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="chores-72-unlisted">Chores (7/+2 unlisted)</h2>
<ul>
<li>Allow scripts (<a href="https://github.com/oliversalzburg/action-automatic-semantic-releases/commit/a131075569e554752c5a661cd69833674166d47f">Oliver Salzburg</a>)</li>
<li>Rebuild entrypoint (<a href="https://github.com/oliversalzburg/action-automatic-semantic-releases/commit/0e935f00881d8b00bd8bdf901744cdd06669c173">Oliver Salzburg</a>)
<sup>2 similar commits not listed: 50ceac5c70a877ff96ea8e8b256830f8d3deec42, c3212b4657f8b203a4dca6512fa5ce93d03521d7</sup></li>
<li>Update locks (<a href="https://github.com/oliversalzburg/action-automatic-semantic-releases/commit/3455452dcde4321007d1345c59cc3f3db68133c3">Oliver Salzburg</a>)</li>
<li>Version bump 3.2.0 (<a href="https://github.com/oliversalzburg/action-automatic-semantic-releases/commit/9c5dab74293788d5fd1d3cae6f18b3bd7839c4b8">Oliver Salzburg</a>)</li>
<li><strong>deps-dev</strong>: bump esbuild from 0.27.3 to 0.28.1 <a href="https://github.com/oliversalzburg/action-automatic-semantic-releases/pull/245">#245</a> (<a href="https://github.com/oliversalzburg/action-automatic-semantic-releases/commit/e5c0634af48374e2b64958d126c2fbbff148ced5">dependabot[bot]</a>)</li>
<li><strong>deps-dev</strong>: bump fast-uri from 3.1.0 to 3.1.2 <a href="https://github.com/oliversalzburg/action-automatic-semantic-releases/pull/242">#242</a> (<a href="https://github.com/oliversalzburg/action-automatic-semantic-releases/commit/75a0db0fcacfc7844a11678b608b640f7c34588b">dependabot[bot]</a>)</li>
<li><strong>deps-dev</strong>: bump simple-git from 3.33.0 to 3.36.0 <a href="https://github.com/oliversalzburg/action-automatic-semantic-releases/pull/243">#243</a> (<a href="https://github.com/oliversalzburg/action-automatic-semantic-releases/commit/78d62fb8448d27e966a97f927ef773bcda2a9655">dependabot[bot]</a>)</li>
</ul>
<h2 id="features-1">Features (1)</h2>
<ul>
<li>Support Dependabot&rsquo;s <code>deps-dev</code> (<a href="https://github.com/oliversalzburg/action-automatic-semantic-releases/commit/6ec1d4c60625c6c419a82766c5a1ee50edc75898">Oliver Salzburg</a>)</li>
</ul>
<h2 id="dependency-changes">Dependency Changes</h2>
<details>
<summary>Chores (2)</summary>
<ul>
<li><strong>deps</strong>: bump qs and express <a href="https://github.com/oliversalzburg/action-automatic-semantic-releases/pull/244">#244</a> (<a href="https://github.com/oliversalzburg/action-automatic-semantic-releases/commit/8b1e62b9089fee2967f00270adbc81b78dd85510">dependabot[bot]</a>)</li>
<li><strong>deps</strong>: bump undici from 6.24.1 to 6.27.0 <a href="https://github.com/oliversalzburg/action-automatic-semantic-releases/pull/246">#246</a> (<a href="https://github.com/oliversalzburg/action-automatic-semantic-releases/commit/26b2d32547d456ac8e9affce292344690ed80c36">dependabot[bot]</a>)</li>
</ul>
</details>
]]></content:encoded></item><item><title>Install omnipackage</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/install-omnipackage/</link><pubDate>Sat, 18 Jul 2026 22:31:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/install-omnipackage/</guid><description>Version updated for https://github.com/omnipackage/omnipackage-rs to version v0.1.17.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action installs and configures the OmniPackage CLI for building RPM, DEB, and Arch packages. It automates the process of packaging software into these formats using a specified channel (stable or master). The action is designed to be used in workflows on Ubuntu runners, automatically detecting the CPU architecture.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/omnipackage/omnipackage-rs">https://github.com/omnipackage/omnipackage-rs</a></strong> to version <strong>v0.1.17</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-omnipackage">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action installs and configures the OmniPackage CLI for building RPM, DEB, and Arch packages. It automates the process of packaging software into these formats using a specified channel (stable or master). The action is designed to be used in workflows on Ubuntu runners, automatically detecting the CPU architecture.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix dowload url retained package (3aa801f)</li>
<li>gh market color to green (3b8aba2)</li>
<li>set next versions 0.1.17 (9aaa991)</li>
<li>add github action (cff437a)</li>
<li>fix fedora 41 (dbea940)</li>
<li>pin rust 1.95 (49f56ca)</li>
<li>cargo update (ce6c454)</li>
<li>add retry to s3 operations (c5f4219)</li>
<li>remove badge border (7cc8b9e)</li>
<li>add install.sh and install.json (#6) (b92554d)</li>
</ul>
]]></content:encoded></item><item><title>GitHub Change Risk</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/github-change-risk/</link><pubDate>Sat, 18 Jul 2026 22:30:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/github-change-risk/</guid><description>Version updated for https://github.com/orangevakaris/github-change-risk to version v1.5.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action checks for risks in changes between two commits without running the repository’s code, providing deterministic risk signals and aggregate reports. It supports free and paid per-file reports, is opt-in for commenting on pull requests, and requires API access to function.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/orangevakaris/github-change-risk">https://github.com/orangevakaris/github-change-risk</a></strong> to version <strong>v1.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-change-risk">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action checks for risks in changes between two commits without running the repository&rsquo;s code, providing deterministic risk signals and aggregate reports. It supports free and paid per-file reports, is opt-in for commenting on pull requests, and requires API access to function.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Extends GitHub-hosted runner retries for transient API connectivity interruptions.</p>
]]></content:encoded></item><item><title>Self-hosted Repository Visuals</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/self-hosted-repository-visuals/</link><pubDate>Sat, 18 Jul 2026 22:29:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/self-hosted-repository-visuals/</guid><description>Version updated for https://github.com/overtrue/repo-visuals-action to version v1.3.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action generates star history charts and contributor walls from GitHub’s API without using third-party rendering services, providing customizable themes and offline SVGs with embedded avatar images. It supports multiple chart types (area, line, glow) and various themes, including classic and gradient styles, with a focus on determinism and offline capabilities for local rendering.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/overtrue/repo-visuals-action">https://github.com/overtrue/repo-visuals-action</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/self-hosted-repository-visuals">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action generates star history charts and contributor walls from GitHub&rsquo;s API without using third-party rendering services, providing customizable themes and offline SVGs with embedded avatar images. It supports multiple chart types (area, line, glow) and various themes, including classic and gradient styles, with a focus on determinism and offline capabilities for local rendering.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Backward-compatible feature release. Output filenames and existing <code>chart-style</code> values are unchanged, so workflows pinned to <code>v1</code> pick up the new look automatically on their next run.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>9 chart themes</strong> (was 3): <code>classic</code>, <code>minimal</code>, <code>gradient</code>, <code>midnight</code>, <code>sunset</code>, <code>ocean</code>, <code>forest</code>, <code>flame</code>, <code>mono</code>.</li>
<li><strong>Chart variants</strong> — <code>area</code>, <code>line</code>, <code>glow</code> selectable per theme with the new <code>chart-variant</code> input (9 × 3 combinations).</li>
<li><strong>Redesigned chart</strong> — dashboard-style header with the current star total, smooth monotone-cubic trend line, dashed gridlines, hairline card border, and a footer showing the tracked date range. The old endpoint label that collided with the top axis is gone.</li>
<li><strong>Contributor wall styling</strong> — configurable columns, avatar size, spacing, outer padding, and avatar shape (<code>circle</code>, <code>squircle</code>, <code>square</code>), plus top-three leaderboard highlighting and a &ldquo;led by&rdquo; header.</li>
<li><strong>Color and title overrides</strong> — <code>background-color(-dark)</code>, <code>accent-color(-dark)</code>, <code>chart-title</code>, <code>contributors-title</code>. All color inputs are hex-validated.</li>
</ul>
<h2 id="new-inputs">New inputs</h2>
<p><code>chart-variant</code>, <code>chart-title</code>, <code>smooth</code>, <code>background-color</code>, <code>background-color-dark</code>, <code>accent-color</code>, <code>accent-color-dark</code>, <code>contributors-title</code>, <code>contributors-columns</code>, <code>avatar-size</code>, <code>avatar-gap</code>, <code>avatar-shape</code>, <code>padding</code>.</p>
<p>See the <a href="https://github.com/overtrue/repo-visuals-action/blob/v1.3.0/README.md">README</a> for the full theme gallery and inputs table.</p>
<p><strong>Full changelog</strong>: <a href="https://github.com/overtrue/repo-visuals-action/compare/v1.2.1...v1.3.0">https://github.com/overtrue/repo-visuals-action/compare/v1.2.1...v1.3.0</a></p>
]]></content:encoded></item><item><title>PR Explainer AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/pr-explainer-ai/</link><pubDate>Sat, 18 Jul 2026 22:27:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/pr-explainer-ai/</guid><description>Version updated for https://github.com/rafaeltorresng/pr-explainer-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary PR Explainer AI is a GitHub Action that automates the creation of interactive HTML artifacts for pull requests. It helps reviewers understand pull requests by providing context, technical intuition, visual diagrams, code walkthroughs, and quizzes, making the knowledge durable and easy to revisit. The action supports multiple languages and limits large changes to avoid model issues.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rafaeltorresng/pr-explainer-action">https://github.com/rafaeltorresng/pr-explainer-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pr-explainer-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>PR Explainer AI is a GitHub Action that automates the creation of interactive HTML artifacts for pull requests. It helps reviewers understand pull requests by providing context, technical intuition, visual diagrams, code walkthroughs, and quizzes, making the knowledge durable and easy to revisit. The action supports multiple languages and limits large changes to avoid model issues.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new">What&rsquo;s new</h2>
<ul>
<li>The generated prompt now includes the Pull Request description (when the author wrote one), alongside the existing PR title, number, and diff. The model can use stated intent as context while still deferring to the diff as source of truth when the two disagree.</li>
</ul>
<h2 id="details">Details</h2>
<ul>
<li>Extracted <code>pull_request.body</code> from the GitHub event payload and threaded it into the user prompt as a clearly labeled &ldquo;Pull Request description&rdquo; section (English and pt-BR), placed after the title/number and before the diff block.</li>
<li>Section is fully omitted when the PR has no description or it is empty/whitespace-only — behavior for PRs without a description is unchanged.</li>
<li>No length cap applied to the description text (diff remains capped at 40,000 characters).</li>
<li>Updated both prompt files&rsquo; &ldquo;source of truth&rdquo; instruction so the model treats the description as author intent, not verified fact, and favors the diff on conflicts.</li>
<li>Added unit test coverage for the new prompt section (present/absent/whitespace-only, both languages) and verified end-to-end with a real event payload and mocked model response.</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/rafaeltorresng/pr-explainer-action/compare/v1.0.6...v1.1.0">https://github.com/rafaeltorresng/pr-explainer-action/compare/v1.0.6...v1.1.0</a></p>
]]></content:encoded></item><item><title>ForgeProof Verify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/forgeproof-verify/</link><pubDate>Sat, 18 Jul 2026 22:26:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/forgeproof-verify/</guid><description>Version updated for https://github.com/ryanjmichie-git/forgeproof-verify to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, forgeproof-verify, automates the verification of ForgeProof .rpack provenance bundles on pull requests. It ensures that the bundles are tamper-proof and integrates with CI to ensure complete integrity and completeness of sealed provenance chains and artifacts within the checkout. The action posts a human-readable audit report as a PR comment and writes it to the job summary, helping to maintain the veracity of AI-generated code in open-source projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ryanjmichie-git/forgeproof-verify">https://github.com/ryanjmichie-git/forgeproof-verify</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/forgeproof-verify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>forgeproof-verify</code>, automates the verification of <a href="https://github.com/ryanjmichie-git/forgeproof-plugin">ForgeProof</a> <code>.rpack</code> provenance bundles on pull requests. It ensures that the bundles are tamper-proof and integrates with CI to ensure complete integrity and completeness of sealed provenance chains and artifacts within the checkout. The action posts a human-readable audit report as a PR comment and writes it to the job summary, helping to maintain the veracity of AI-generated code in open-source projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Re-vendors the ForgeProof engine to plugin <strong>v1.2.2</strong>. Closes a signature
malleability gap: a whitespace-only trailer (newline/space/tab) appended to a
valid signature previously verified green (<code>ssh-keygen -Y verify</code> ignores
trailing bytes, and the canonical check <code>strip()</code>&rsquo;d before validating). The
vendored verifier now turns any such change red.</p>
<ul>
<li>New <code>signature-whitespace</code> tamper-matrix case (green on the old engine, red now).</li>
<li>Also carries v1.2.2&rsquo;s clean-error hardening (non-string digest, deeply nested JSON).</li>
</ul>
<p>The floating <code>v1</code> tag now points here, so <code>uses: ryanjmichie-git/forgeproof-verify@v1</code> picks up the fix automatically.</p>
]]></content:encoded></item><item><title>Argus PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/argus-pr-review/</link><pubDate>Sat, 18 Jul 2026 22:25:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/argus-pr-review/</guid><description>Version updated for https://github.com/sibinms/argus to version v1.2.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Argus is an AI code review tool that optimizes for recall by running multiple specialized AI reviewers in parallel. It uses an evidence-based curator to verify findings before posting review comments on pull requests, helping developers identify more real bugs while keeping false positives manageable. The action supports various LLM providers and allows users to create custom lenses using Markdown.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sibinms/argus">https://github.com/sibinms/argus</a></strong> to version <strong>v1.2.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/argus-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Argus is an AI code review tool that optimizes for recall by running multiple specialized AI reviewers in parallel. It uses an evidence-based curator to verify findings before posting review comments on pull requests, helping developers identify more real bugs while keeping false positives manageable. The action supports various LLM providers and allows users to create custom lenses using Markdown.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Pin the Action to this tag:</p>
<pre><code>- uses: sibinms/argus@v1.2.3
</code></pre>
<h2 id="readme-restructure">README restructure</h2>
<p>The previous README buried multi-provider usage across five different sections (a Quick Start footnote, a &ldquo;Why use Argus&rdquo; bullet, a Features table row, a Configuration paragraph, a Data privacy paragraph) and read as one long wall of text.</p>
<ul>
<li><strong>Quick Start now shows three copy-paste GitHub Action blocks</strong> — Anthropic, OpenAI, and Gemini — right up front, each ready to paste with the right env var and a pointer to the matching model string.</li>
<li><strong>Everything long is now a real collapsed <code>&lt;details&gt;</code></strong>: install troubleshooting, data privacy, &ldquo;Why use Argus,&rdquo; &ldquo;How it works,&rdquo; measuring recall, the full CI breakdown, and design notes. The page you land on is short; the reference material is one click away.</li>
<li>Table of Contents trimmed to only what stays visible.</li>
</ul>
<p>No changes to the review pipeline itself — this is purely a documentation restructure.</p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/bernstein-multi-agent-orchestration/</link><pubDate>Sat, 18 Jul 2026 22:24:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.7.1.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bernstein is a deterministic orchestrator for CLI coding agents, scheduling tasks using plain Python to ensure reproducibility. It records every artifact write in an always-on lineage spine and replay journal, providing audit logs with receipts for offline verification.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.7.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Bernstein is a deterministic orchestrator for CLI coding agents, scheduling tasks using plain Python to ensure reproducibility. It records every artifact write in an always-on lineage spine and replay journal, providing audit logs with receipts for offline verification.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v371">v3.7.1</h1>
<p>Security and integrity hardening. Every item below is a confirmed defect with a regression test that fails on the pre-fix code, not a speculative hardening.</p>
<p>Each fix was reproduced against the shipped code before it was written, and independently reviewed afterwards by reviewers whose brief was to run the same input against the previous release and report anything that got worse. Several fixes were rejected on that basis and held back rather than shipped; they are listed at the end.</p>
<h2 id="behaviour-changes-read-before-upgrading">Behaviour changes (read before upgrading)</h2>
<ul>
<li><strong><code>mission define</code> now refuses a phase that declares no gate tasks.</strong> A phase is a verification gate plus a budget envelope; one with an empty gate had nothing to verify and projected <code>passed</code> on no evidence at all. The check runs at define time, so existing ledgers are untouched: no recorded mission changes its verdict or its hash. If you have a spec declaring a gateless phase, <code>mission define</code> now rejects it and says why.</li>
<li><strong>A tampered mission ledger reports as unverified rather than not-found.</strong> The declared mission id sits in a row no hash covers, so it cannot on its own justify a not-found; only a chain that verifies has earned the right to say the mission does not exist. The HTTP route and <code>mission verify</code> now apply one shared rule, so a torn chain reads as <code>unverified</code> on both, instead of a 404 on one and a projection on the other.</li>
<li><strong><code>bernstein approve</code> and <code>bernstein reject</code> refuse identifiers outside <code>[A-Za-z0-9._-]{1,64}</code>.</strong> The bound matches the rule the rest of the tree already used. An earlier draft of this change capped at 59, which would have stranded ordinary descriptive backlog ids: such a task could post artifacts, because the artifact surface accepted the id, but could never be approved or rejected.</li>
<li><strong><code>ConnectionDocument.secret_name</code> is deprecated, not removed.</strong> The field is now <code>broker_ref</code>. <code>secret_name</code> keeps working as a deprecated alias on the constructor, on attribute reads, and on <code>create_document</code> and <code>rotate_document</code>, emitting a warning and forwarding; supplying both spellings with different values raises. No code change is required to take this patch. The serialised form and the signed preimage are unchanged, so existing signatures and chain digests still verify.</li>
</ul>
<h2 id="fixed">Fixed</h2>
<h3 id="path-containment-across-the-ledger-journals-and-artifact-store">Path containment across the ledger, journals, and artifact store</h3>
<p>Path traversal was reachable from HTTP route parameters in the work ledger, replay journal, SLA store, and artifact store. One pre-existing containment check guarded nothing: it resolved the path, tested containment on that throwaway value, then used the original unchecked path for filesystem access.</p>
<p>Every construction of the affected journal paths, for both task journals and run journals, now goes through one barrier shared by the writer and the readers. That sharing is the point: a local copy of the same check was found in the MCP server, already drifted from the original. A test now scans for journal paths built from an identifier and fails on any construction that bypasses the barrier, so a new reader is covered by construction rather than by memory.</p>
<p>Identifiers are bounded by encoded byte length rather than character count, so an over-long identifier is refused by the barrier and read as absent instead of surfacing as a filesystem error from a deeper layer. A capacity refusal is a distinct exception type from a containment violation, so readers can degrade on the first without ever swallowing the second.</p>
<h3 id="identifier-validation-before-the-filesystem-is-addressed">Identifier validation before the filesystem is addressed</h3>
<p>Stored SLA contracts and artifact rows now validate their identifiers before deriving a path, and the CLI and HTTP surfaces report a not-found rather than an internal error when one is rejected. Validation is lexical and runs first, so a hostile identifier never reaches path resolution; resolution still happens for well-formed ids, because it is the only thing that catches a run directory that is a symlink out of the runs root.</p>
<p>Also fixed here: log injection through unsanitised values, clear-text storage of sensitive material, a super-linear-backtracking regex in the adapter version scan (adversarial input took 14.7s against a 0.5s budget), and clear-text transport origins now required to be TLS or loopback-pinned.</p>
<h3 id="cache-engine-traversal-claim-race-and-torn-eviction">Cache engine: traversal, claim race, and torn eviction</h3>
<p>Verified against the shipped code before the fix: <code>cache evict ../../../../pwned</code> wrote its recall report outside the cache directory; a 16-thread cold start produced two or three claim winners in nine of twenty runs, meaning duplicate agent spawns; an interrupted transitive revocation left the root tombstoned while its children still served. The recall report path is now resolved and contained first, so an unsafe key is refused before the tombstone journal, the audit chain, or the filesystem is touched.</p>
<h3 id="suspend-and-resume-receipt-binding-and-approval-gating">Suspend and resume: receipt binding and approval gating</h3>
<p>The resume path took the latest receipt for a task rather than the one bound to the selected suspend row, never validated receipt identity before a release or resume mutation, enforced approval only in the CLI so a library caller could resume an approval-gated park with no decision at all, interpolated <code>task_id</code> straight into an approval filename, and accepted incomplete or unrelated continuity proofs.</p>
<p>The fix is one definition rather than four patches: a single predicate decides what counts as settled, one scope covers every suspend receipt rather than only the most recent park, chain and journal are both consulted so removing a terminal audit entry cannot re-arm an approval, and one implementation builds every approvals path. Reverting any single call site to its own construction fails the test that asserts they agree.</p>
<h3 id="mission-phases-gate-binding-and-a-host-independent-projection">Mission phases: gate binding, and a host-independent projection</h3>
<p>A phase could project as passed without the receipt binding its declared gate: the evidence check compared a receipt&rsquo;s own task ids against its own hash list and never consulted the declared gate, so a receipt for an unrelated task satisfied the phase. Four sibling bypasses existed alongside it. A pass now requires the declared gate set to match, equal lengths, the stored hash to equal the recomputed hash, and the bundles to still hash as recorded.</p>
<p>Sealing a phase receipt had routed its hash through a redaction helper that reads the host&rsquo;s home directory and process-global state, so the same ledger could project <code>passed</code> on one machine and <code>unverified</code> on another, and an offline verifier on a second host could not recompute the attested value. The self-consistency check that introduced that dependence has been removed rather than repaired: an attacker who rewrites a chain entry recomputes the hash too, so it only ever caught accidental corruption that the chain walk already catches, with a clearer verdict. <code>receipt_hash()</code> is a pure function of the receipt&rsquo;s fields again, verified byte-identical to the previous release across seven ledger shapes and across differing home directories. A separate normalisation fixes negative zero, which serialises as a distinct token and had moved the status hash for any ledger that recorded one.</p>
<h3 id="audit-query-now-reads-the-same-segments-the-verifier-does">Audit query now reads the same segments the verifier does</h3>
<p><code>verify()</code> has replayed archived segments for some time; <code>query()</code> read only live ones, and the lineage projection uses <code>query()</code>. The two therefore disagreed about what exists, and an operator running ordinary audit-log retention was told a definition-lineage link was broken when nothing was broken. Every release until now made some accusation about an archived-but-honest record; nothing is wrong with such a record, so the correct output is silence.</p>
<p>The projection now reads archived segments too. Undecodable bytes still raise rather than being replaced: an invalid byte in an audit segment is evidence, and a reader that quietly substitutes a placeholder would return a record that does not match what is on disk while the verifier chokes on the same bytes.</p>
<h2 id="held-back">Held back</h2>
<p>Five changes were reviewed, found to introduce defects of their own, and moved to the next minor release rather than shipped here. They are not lost; each is tracked with its findings.</p>
<p>Two of them could not fit a patch release at all: a fail-closed rule that turned ordinary audit-log retention into a permanent refusal, and a journal seal that no production path emitted, which left an unsealed run indistinguishable from an unfinished one. One was correct but expensive: reading every segment you authenticate is right, and doing it took a per-gate operation from 0.3ms to 688ms on a large chain, which needs an index rather than a patch. The remaining two had headline fixes that did not hold under review.</p>
<p>Holding them back is the point of reviewing at all.</p>
<h2 id="code-scanning">Code-scanning</h2>
<p>The open-alert set was worked to disposition rather than to a number: real defects fixed with regression tests, and coercions that pin canonical serialisation (a <code>bool</code> is an <code>int</code> subclass, and <code>int</code> and <code>float</code> serialise differently) dismissed as false positives with a documented rationale, because removing them would change hash inputs and break byte-identical replay.</p>
]]></content:encoded></item><item><title>gw - Go workspaces</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/gw-go-workspaces/</link><pubDate>Sat, 18 Jul 2026 22:23:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/gw-go-workspaces/</guid><description>Version updated for https://github.com/Toyz/gw to version v0.11.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary gw is a tool designed to streamline and automate Go monorepo management. It automates the creation, synchronization, and verification of a go.work file across multiple modules, ensuring consistent dependency versions and streamlined workflows. The main functionalities include bootstraping, linting, running commands in parallel, generating documentation, and analyzing module dependencies to identify changes affecting the project as a whole.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Toyz/gw">https://github.com/Toyz/gw</a></strong> to version <strong>v0.11.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gw-go-workspaces">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>gw</code> is a tool designed to streamline and automate Go monorepo management. It automates the creation, synchronization, and verification of a <code>go.work</code> file across multiple modules, ensuring consistent dependency versions and streamlined workflows. The main functionalities include bootstraping, linting, running commands in parallel, generating documentation, and analyzing module dependencies to identify changes affecting the project as a whole.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Toyz/gw/compare/v0...v0.11.0">https://github.com/Toyz/gw/compare/v0...v0.11.0</a></p>
]]></content:encoded></item><item><title>EcoTrace Carbon Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/ecotrace-carbon-gate/</link><pubDate>Sat, 18 Jul 2026 22:21:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/ecotrace-carbon-gate/</guid><description>Version updated for https://github.com/Zwony/ecotrace to version core-v1.4.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary EcoTrace is a lightweight library designed to measure the carbon footprint of Python applications in real-time. It provides features such as pausing and resuming tracking, side-by-side run comparisons, webhook integrations, filtered CSV exporting, log maintenance commands, and access to session metrics programmatically. The action automates energy and emissions instrumentation without requiring configuration files or background services.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Zwony/ecotrace">https://github.com/Zwony/ecotrace</a></strong> to version <strong>core-v1.4.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ecotrace-carbon-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>EcoTrace is a lightweight library designed to measure the carbon footprint of Python applications in real-time. It provides features such as pausing and resuming tracking, side-by-side run comparisons, webhook integrations, filtered CSV exporting, log maintenance commands, and access to session metrics programmatically. The action automates energy and emissions instrumentation without requiring configuration files or background services.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="release-notes--v141">Release Notes — v1.4.1</h1>
<p><strong>Released:</strong> 2026-07-18<br>
<strong>Type:</strong> Patch Release — 7 bug fixes, zero breaking changes</p>
<hr>
<h2 id="summary">Summary</h2>
<p>v1.4.1 is a patch release addressing multiple edge-case bugs, linter/static analysis warnings, and dynamic versioning issues identified in v1.4.0. It improves exception safety in code blocks, normalizes GPU reports, and resolves unresolved import warnings in environments without optional web dependencies installed.</p>
<hr>
<h2 id="resolved-issues--bug-fixes">Resolved Issues &amp; Bug Fixes</h2>
<h3 id="1-exception-safety-in-track_block">1. Exception Safety in <code>track_block()</code></h3>
<p>Restructured the <code>track_block()</code> context manager using a <code>try/finally</code> block. This ensures that session duration and carbon metrics are cleanly calculated and logged even if the wrapped code blocks raise user exceptions, aligning it with the robust exception-handling design of <code>measure()</code>.</p>
<h3 id="2-gpu-chart-data-normalization">2. GPU Chart Data Normalization</h3>
<p>Normalized the <code>_gpu_samples</code> structure inside the core engine&rsquo;s PDF generator (<code>generate_pdf_report</code>). The core continuous hardware monitor tracks metrics using 3-tuples <code>(timestamp, utilization, power)</code>. The PDF reporting module now filters and maps these to 2-tuples <code>(timestamp, utilization)</code> before rendering to prevent visual plotting and parsing errors.</p>
<h3 id="3-django-middleware-renaming">3. Django Middleware Renaming</h3>
<p>Renamed the middleware class defined in <code>middleware/django.py</code> from <code>EcoTraceMiddleware</code> to <code>EcoTraceDjangoMiddleware</code> to perfectly reflect the migration guidelines documented in v1.1.2. A backward-compatible alias <code>EcoTraceMiddleware</code> is preserved at module scope to prevent integration breakage.</p>
<h3 id="4-dynamic-dashboard-versioning">4. Dynamic Dashboard Versioning</h3>
<p>Replaced the hardcoded version in the live dashboard HTML footer. It now dynamically injects the package&rsquo;s current version (e.g. <code>v1.4.1</code>) retrieved directly from metadata at request resolution.</p>
<h3 id="5-format-aware-export-filenames">5. Format-Aware Export Filenames</h3>
<p>The CLI <code>ecotrace export</code> command now determines the default output filename according to the selected format. Specifying <code>--csv</code> automatically defaults to <code>ecotrace_export.csv</code> rather than confusingly writing CSV data to <code>ecotrace_report.json</code>.</p>
<h3 id="6-dynamic-web-imports-no-static-warnings">6. Dynamic Web Imports (No Static Warnings)</h3>
<p>Refactored <code>middleware/django.py</code> to lazily and dynamically load optional dependencies (<code>django</code> and <code>asgiref</code>) using <code>importlib</code>. This removes critical &lsquo;Unresolved Import&rsquo; red alerts inside IDEs and static analyzers for developers using EcoTrace without standard web framework libraries in their environment.</p>
<h3 id="7-corrected-gpu-energy-accumulation">7. Corrected GPU Energy Accumulation</h3>
<p>Initialized the <code>total_energy_kwh</code> property inside the main engine constructor. This permits cumulative GPU/ML tracking contexts to correctly increment the total session energy metrics across consecutive training run boundaries.</p>
<hr>
<h2 id="upgrade-instructions">Upgrade Instructions</h2>
<p>This is a non-breaking patch release. Upgrade via pip:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install --upgrade ecotrace
</span></span></code></pre></div>]]></content:encoded></item><item><title>Sparda MCP</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/sparda-mcp/</link><pubDate>Sat, 18 Jul 2026 22:20:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/sparda-mcp/</guid><description>Version updated for https://github.com/zyx77550/sparda to version v0.64.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SPARDA is a tool that compiles backend behavior into a graph, enabling automated validation and testing of web applications. It provides a way to ensure that your application’s logic remains consistent and free from errors without relying on external APIs or tools. The compiled behavior graph can be used by AI agents to automate tests, debug issues, and prevent breaking changes during deployments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zyx77550/sparda">https://github.com/zyx77550/sparda</a></strong> to version <strong>v0.64.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sparda-mcp">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SPARDA is a tool that compiles backend behavior into a graph, enabling automated validation and testing of web applications. It provides a way to ensure that your application&rsquo;s logic remains consistent and free from errors without relying on external APIs or tools. The compiled behavior graph can be used by AI agents to automate tests, debug issues, and prevent breaking changes during deployments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/zyx77550/sparda/compare/v0.63.0...v0.64.0">https://github.com/zyx77550/sparda/compare/v0.63.0...v0.64.0</a></p>
]]></content:encoded></item><item><title>efaimo</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/efaimo/</link><pubDate>Sat, 18 Jul 2026 14:40:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/efaimo/</guid><description>Version updated for https://github.com/efaimo-ai/efaimo to version v0.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The efaimo action is a tool designed to audit and validate Agent Skills and MCP servers. It checks the context budget, trigger quality, linting errors, and migration diffs against the 2026-07-28 spec. Additionally, it provides a way to measure whether a skill improves task completion using A/B testing with LLM judges. The tool is useful for developers to ensure that their agent’s skills are well-formed, efficient, and effective.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/efaimo-ai/efaimo">https://github.com/efaimo-ai/efaimo</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/efaimo">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The efaimo action is a tool designed to audit and validate Agent Skills and MCP servers. It checks the context budget, trigger quality, linting errors, and migration diffs against the 2026-07-28 spec. Additionally, it provides a way to measure whether a skill improves task completion using A/B testing with LLM judges. The tool is useful for developers to ensure that their agent&rsquo;s skills are well-formed, efficient, and effective.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release. One CLI that audits what your agent loads: MCP servers and Agent Skills.</p>
<ul>
<li><code>efaimo weigh</code>: context-window cost of MCP tool definitions (stdio, remote, or a whole client config) and of Agent Skills, in three serializations, with an optional <code>--anthropic</code> exact Claude count. Per-tool numbers plus a block-framing line reconcile exactly with the total. CI budget gates (<code>--out</code>/<code>--diff</code>/<code>--max-tokens</code>/<code>--allow-increase</code>) and a badge.</li>
<li><code>efaimo check --mcp</code>: a quality grade (descriptions, schemas, annotations, cost) plus a separate ungraded 2026-07-28 migration diff, each item naming its SEP. Speaks both the legacy handshake and bare stateless requests, so 2026-07-28 servers audit fine.</li>
<li><code>efaimo check --skill</code>: lints Agent Skills against the agentskills.io spec, per-skill grades over a folder, plus a reproducible Skills Quality Index (pinned-commit corpus).</li>
<li><code>efaimo test</code> (experimental): with/without-skill A/B trials with an LLM judge; dry-run by default, opt-in <code>--live</code>.</li>
<li><code>efaimo mcp</code>: a read-only MCP server exposing the skill checks to an agent.</li>
</ul>
<p>Install: <code>npx efaimo</code> or <code>npm i -D efaimo</code>. Node 22+. Apache-2.0.</p>
<p>Full changelog: <a href="https://github.com/efaimo-ai/efaimo/blob/main/CHANGELOG.md">https://github.com/efaimo-ai/efaimo/blob/main/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>rust-star-history</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/rust-star-history/</link><pubDate>Sat, 18 Jul 2026 14:39:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/rust-star-history/</guid><description>Version updated for https://github.com/Flux159/rust-star-history to version v1.1.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The rust-star-history GitHub Action generates self-hosted star history SVG charts for any GitHub repository. It solves the problem of broken star-history.com embeds and automates tasks such as generating, updating, and embedding static star history charts directly in a repository’s README.md or other markdown files. The action provides features like a single self-contained binary with no external dependencies, adaptive y-axis ticks, and multi-repo comparison options to enhance visual representation of the chart.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Flux159/rust-star-history">https://github.com/Flux159/rust-star-history</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rust-star-history">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>rust-star-history</code> GitHub Action generates self-hosted star history SVG charts for any GitHub repository. It solves the problem of broken star-history.com embeds and automates tasks such as generating, updating, and embedding static star history charts directly in a repository&rsquo;s README.md or other markdown files. The action provides features like a single self-contained binary with no external dependencies, adaptive y-axis ticks, and multi-repo comparison options to enhance visual representation of the chart.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Download release assets from the CDN and fail hard when missing by @Flux159 in <a href="https://github.com/Flux159/rust-star-history/pull/14">https://github.com/Flux159/rust-star-history/pull/14</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Flux159/rust-star-history/compare/v1.1.0...v1.1.1">https://github.com/Flux159/rust-star-history/compare/v1.1.0...v1.1.1</a></p>
]]></content:encoded></item><item><title>Invigil — Product Quality Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/invigil-product-quality-gate/</link><pubDate>Sat, 18 Jul 2026 14:38:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/invigil-product-quality-gate/</guid><description>Version updated for https://github.com/invigil/invigil to version v1.3.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Invigil is a CI quality gate that checks the product-quality of an open-source project against a specified doctrine. It ensures that projects are easy to use and boot in 10 minutes, provide actionable error messages, and verify published artifacts through daily machine verification. Invigil grades projects based on seven Gates (G1-G7) representing different levels of legibility and user experience, providing clear feedback for developers and ensuring the project is accessible to a wide range of users.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/invigil/invigil">https://github.com/invigil/invigil</a></strong> to version <strong>v1.3.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/invigil-product-quality-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Invigil is a CI quality gate that checks the product-quality of an open-source project against a specified doctrine. It ensures that projects are easy to use and boot in 10 minutes, provide actionable error messages, and verify published artifacts through daily machine verification. Invigil grades projects based on seven Gates (G1-G7) representing different levels of legibility and user experience, providing clear feedback for developers and ensuring the project is accessible to a wide range of users.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/invigil/invigil/compare/v1.3.1...v1.3.2">https://github.com/invigil/invigil/compare/v1.3.1...v1.3.2</a></p>
]]></content:encoded></item><item><title>jk-neospec</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/jk-neospec/</link><pubDate>Sat, 18 Jul 2026 14:37:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/jk-neospec/</guid><description>Version updated for https://github.com/jedi-knights/neospec to version v0.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary neospec is a self-contained test runner and coverage tool for Neovim plugins and distributions. It manages its own Neovim binary, runs tests in isolated environments, instruments Lua coverage via debug.sethook, and generates reports in LCOV, Cobertura XML, JUnit XML, and color console summary formats.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jedi-knights/neospec">https://github.com/jedi-knights/neospec</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jk-neospec">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>neospec is a self-contained test runner and coverage tool for Neovim plugins and distributions. It manages its own Neovim binary, runs tests in isolated environments, instruments Lua coverage via <code>debug.sethook</code>, and generates reports in LCOV, Cobertura XML, JUnit XML, and color console summary formats.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
]]></content:encoded></item><item><title>Agent Guard Secret Guardrails</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/agent-guard-secret-guardrails/</link><pubDate>Sat, 18 Jul 2026 14:35:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/agent-guard-secret-guardrails/</guid><description>Version updated for https://github.com/JeongJaeSoon/agent-guard to version v2.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Guard is a real-time guardrail that blocks AI coding agents from accidentally exposing secrets, such as reading .env files or writing secret-like values. It uses gitleaks for detection and provides shell scripts for integration into the agent’s tool boundary. The action helps prevent leaks before they occur by blocking sensitive file access and providing defense in depth with commit/CI scanning.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/JeongJaeSoon/agent-guard">https://github.com/JeongJaeSoon/agent-guard</a></strong> to version <strong>v2.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-guard-secret-guardrails">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Agent Guard is a real-time guardrail that blocks AI coding agents from accidentally exposing secrets, such as reading <code>.env</code> files or writing secret-like values. It uses gitleaks for detection and provides shell scripts for integration into the agent&rsquo;s tool boundary. The action helps prevent leaks before they occur by blocking sensitive file access and providing defense in depth with commit/CI scanning.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci: bump openai/codex-action from 1.9 to 1.11 by @dependabot[bot] in <a href="https://github.com/JeongJaeSoon/agent-guard/pull/107">https://github.com/JeongJaeSoon/agent-guard/pull/107</a></li>
<li>ci: bump hashgraph-online/ai-plugin-scanner-action from 1.2.286 to 1.2.512 by @dependabot[bot] in <a href="https://github.com/JeongJaeSoon/agent-guard/pull/111">https://github.com/JeongJaeSoon/agent-guard/pull/111</a></li>
<li>Lead Quick Start with Claude Code and Codex by @JeongJaeSoon in <a href="https://github.com/JeongJaeSoon/agent-guard/pull/54">https://github.com/JeongJaeSoon/agent-guard/pull/54</a></li>
<li>docs: prepare Claude marketplace submission review by @JeongJaeSoon in <a href="https://github.com/JeongJaeSoon/agent-guard/pull/115">https://github.com/JeongJaeSoon/agent-guard/pull/115</a></li>
<li>docs: pin community submission source by @JeongJaeSoon in <a href="https://github.com/JeongJaeSoon/agent-guard/pull/116">https://github.com/JeongJaeSoon/agent-guard/pull/116</a></li>
<li>feat: add managed deployment for Claude Code and Codex by @JeongJaeSoon in <a href="https://github.com/JeongJaeSoon/agent-guard/pull/117">https://github.com/JeongJaeSoon/agent-guard/pull/117</a></li>
<li>release: v2.1.0 by @github-actions[bot] in <a href="https://github.com/JeongJaeSoon/agent-guard/pull/118">https://github.com/JeongJaeSoon/agent-guard/pull/118</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/JeongJaeSoon/agent-guard/compare/v2.0.1...v2.1.0">https://github.com/JeongJaeSoon/agent-guard/compare/v2.0.1...v2.1.0</a></p>
]]></content:encoded></item><item><title>slopscore-lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/slopscore-lint/</link><pubDate>Sat, 18 Jul 2026 14:34:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/slopscore-lint/</guid><description>Version updated for https://github.com/jman4162/slopscore to version v0.8.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary slopscore is an AI-slop linter that measures the density of formulaic, generic, low-specificity, and over-polished writing patterns in text. It reports per-dimension scores and evidence spans to help identify and fix these patterns, nudging writers toward clearer and more specific prose.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jman4162/slopscore">https://github.com/jman4162/slopscore</a></strong> to version <strong>v0.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/slopscore-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>slopscore</code> is an AI-slop linter that measures the density of formulaic, generic, low-specificity, and over-polished writing patterns in text. It reports per-dimension scores and evidence spans to help identify and fix these patterns, nudging writers toward clearer and more specific prose.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Two new detection axes, both conservative by default.</p>
<h2 id="insight_signaling--a-new-dimension"><code>insight_signaling</code> — a new dimension</h2>
<p>Pseudo-profundity tells that announce insight rather than contain it: &ldquo;load-bearing assumption&rdquo;, &ldquo;doing the real work&rdquo;, &ldquo;the crux of the issue&rdquo;, &ldquo;pressure-test the claim&rdquo;. Context-gated (literal &ldquo;load-bearing wall&rdquo; is not flagged) and mostly low/medium severity — density, not existence, is the tell. Distinct from the WP:AILEGACY puffery in <code>significance_inflation</code>. Rules-only (excluded from the ML <code>FEATURE_ORDER</code>), so no model retrain. Also adds antithesis variants to <code>parallelism</code> (&ldquo;not merely X but Y&rdquo;, &ldquo;less about X, more about Y&rdquo;, the non-&lsquo;it&rsquo; em-dash form, &ldquo;both/and&rdquo;).</p>
<h2 id="expanded-weasel_attribution--the-fake-evidence-axis">Expanded <code>weasel_attribution</code> — the &ldquo;fake evidence&rdquo; axis</h2>
<p>Impersonal-passive attribution (&ldquo;it is widely believed&rdquo;, &ldquo;sources say&rdquo;), unearned-certainty reasoning smells (&ldquo;Clearly,&rdquo;, &ldquo;needless to say&rdquo;, &ldquo;it goes without saying&rdquo;), and hedge+vague-adjective (&ldquo;somewhat successful&rdquo;). Scored by default, high-precision.</p>
<h2 id="new---broad-flag-also-toolslopscore-broad">New <code>--broad</code> flag (also <code>[tool.slopscore] broad</code>)</h2>
<p>An opt-in tier of higher-false-positive rules, off by default: rationalist/essayist jargon for <code>insight_signaling</code> (steelman, first principles) and bare quantifiers/hedges/intensifiers for <code>weasel_attribution</code> (many/very/may). Kept off the default score because those bare words have no discriminative power on the ESL/simple-English fairness slices — <code>--broad</code> is a self-editing highlighter, not an accusation. Deliberately excludes the hedges <code>human_writing_signals</code> rewards.</p>
<p>The JSON report gains an <code>insight_signaling</code> key in <code>dimensions</code>; <code>SCHEMA_VERSION</code> is 0.8.0. Fairness gate stays 0% on the plain/non-native slices with the default rules.</p>
<p>Full changelog: <a href="https://github.com/jman4162/slopscore/blob/main/CHANGELOG.md">https://github.com/jman4162/slopscore/blob/main/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/neurolink-ai/</link><pubDate>Sat, 18 Jul 2026 14:33:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v9.93.0.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is the unified AI integration platform that unifies 30+ AI providers and models under one consistent API. It provides a practical, TypeScript-first way to integrate AI into any application with features like multi-provider failover, intelligent routing, and edge-first execution for cost optimization.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v9.93.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>NeuroLink is the unified AI integration platform that unifies 30+ AI providers and models under one consistent API. It provides a practical, TypeScript-first way to integrate AI into any application with features like multi-provider failover, intelligent routing, and edge-first execution for cost optimization.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="9930-2026-07-18"><a href="https://github.com/juspay/neurolink/compare/v9.92.3...v9.93.0">9.93.0</a> (2026-07-18)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>(proxy):</strong>  add compatibility telemetry foundation (<a href="https://github.com/juspay/neurolink/commit/e303c7c8044329baef3cb9e226da1363b63e118d">e303c7c</a>)</li>
</ul>
]]></content:encoded></item><item><title>SupaPulse — Supabase keep-alive</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/supapulse-supabase-keep-alive/</link><pubDate>Sat, 18 Jul 2026 14:32:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/supapulse-supabase-keep-alive/</guid><description>Version updated for https://github.com/Karanjoshi128/supapulse to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action SupaPulse keeps a Supabase free-tier project from pausing by proving each ping actually reached Postgres, sending a random nonce with the ping and expecting it to be echoed back within two timestamps. If the check fails, it exits non-zero, triggering a red run in GitHub Actions that emails the user about the failure. The action also warns users about expiring anon keys and public repositories being disabled by GitHub.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Karanjoshi128/supapulse">https://github.com/Karanjoshi128/supapulse</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/supapulse-supabase-keep-alive">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action SupaPulse keeps a Supabase free-tier project from pausing by proving each ping actually reached Postgres, sending a random nonce with the ping and expecting it to be echoed back within two timestamps. If the check fails, it exits non-zero, triggering a red run in GitHub Actions that emails the user about the failure. The action also warns users about expiring anon keys and public repositories being disabled by GitHub.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="supapulse-v100">SupaPulse v1.0.0</h2>
<p>A Supabase keep-alive GitHub Action that <strong>proves the ping actually reached Postgres</strong>, and fails loudly when it stops working.</p>
<h3 id="why">Why</h3>
<p>Supabase free-tier projects pause after about a week of inactivity, and restoring is a manual dashboard click. Most keep-alives report success even when they failed - one pings an endpoint that never touches the database, one swallows its own errors and exits green. This one refuses to.</p>
<h3 id="what-it-does">What it does</h3>
<ul>
<li><strong>Provable ping</strong> - a random nonce round-trips through Postgres, so a cached <code>200 OK</code> can&rsquo;t fake success.</li>
<li><strong>Fails red</strong> on any failure, so a dead keep-alive emails you.</li>
<li><strong>Refuses <code>service_role</code>/PAT keys</strong>; warns before your anon key expires and before GitHub&rsquo;s 60-day public-repo disable.</li>
<li><strong>Zero dependencies</strong> - the whole action is one auditable file.</li>
<li>Optional degraded <code>select</code> mode for projects that skip the SQL.</li>
</ul>
<h3 id="usage">Usage</h3>
<pre><code>- uses: Karanjoshi128/supapulse@v1
  with:
    anon-key: ${{ secrets.SUPABASE_ANON_KEY }}
</code></pre>
<p>Run <code>sql/supapulse.sql</code> once per project first. Full setup in the README.</p>
]]></content:encoded></item><item><title>HoverStare</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/hoverstare/</link><pubDate>Sat, 18 Jul 2026 14:31:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/hoverstare/</guid><description>Version updated for https://github.com/liuchong/hoverstare to version v0.0.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary HoverStare is an AI code review bot that reads a GitHub repository like a human reviewer would. It uses Rust and runs as a single static binary as a GitHub Action. HoverStare reviews PRs incrementally, validates inline comments against the real diff, and tracks findings across commits until they are fixed. It also provides multi-pass voting and a verifier to ensure high signal and low noise in its findings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/liuchong/hoverstare">https://github.com/liuchong/hoverstare</a></strong> to version <strong>v0.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hoverstare">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>HoverStare is an AI code review bot that reads a GitHub repository like a human reviewer would. It uses Rust and runs as a single static binary as a GitHub Action. HoverStare reviews PRs incrementally, validates inline comments against the real diff, and tracks findings across commits until they are fixed. It also provides multi-pass voting and a verifier to ensure high signal and low noise in its findings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/liuchong/hoverstare/compare/v0...v0.0.4">https://github.com/liuchong/hoverstare/compare/v0...v0.0.4</a></p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/liuchong/hoverstare/compare/v0...v0.0.4">https://github.com/liuchong/hoverstare/compare/v0...v0.0.4</a></p>
]]></content:encoded></item><item><title>Auth Route Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/auth-route-guard/</link><pubDate>Sat, 18 Jul 2026 14:30:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/auth-route-guard/</guid><description>Version updated for https://github.com/mateuszingano/airlock-auth to version v0.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Auth Route Guard is a GitHub Action that scans Next.js projects to prevent server secrets from being exposed and provides warnings on unauthenticated mutations and webhooks. It flags potential security issues by checking NEXT_PUBLIC_* variables, mutating route handlers without auth checks, and webhook routes without signature verification. The action ensures build failure for critical findings and provides warnings for further review.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mateuszingano/airlock-auth">https://github.com/mateuszingano/airlock-auth</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/auth-route-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Auth Route Guard is a GitHub Action that scans Next.js projects to prevent server secrets from being exposed and provides warnings on unauthenticated mutations and webhooks. It flags potential security issues by checking <code>NEXT_PUBLIC_*</code> variables, mutating route handlers without auth checks, and webhook routes without signature verification. The action ensures build failure for critical findings and provides warnings for further review.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release. <code>uses: mateuszingano/airlock-auth@v1</code> now resolves. The action runs <code>npx airlock-auth</code> (published on npm).</p>
]]></content:encoded></item><item><title>move-test-gen coverage check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/move-test-gen-coverage-check/</link><pubDate>Sat, 18 Jul 2026 14:29:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/move-test-gen-coverage-check/</guid><description>Version updated for https://github.com/mehvetero/move-test-gen to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Move Test Gen is a GitHub Action that generates comprehensive edge-case test suites for Sui Move functions, covering various scenarios such as boundary values, arithmetic edges, access control, state machine, and economic considerations. It automates the creation of #[test] and #[expected_failure] functions to ensure robust testing of Move contracts. The tool outputs a .move file targeting sui move test, making it easy to verify that tests are complete and compile correctly.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mehvetero/move-test-gen">https://github.com/mehvetero/move-test-gen</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/move-test-gen-coverage-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Move Test Gen is a GitHub Action that generates comprehensive edge-case test suites for Sui Move functions, covering various scenarios such as boundary values, arithmetic edges, access control, state machine, and economic considerations. It automates the creation of <code>#[test]</code> and <code>#[expected_failure]</code> functions to ensure robust testing of Move contracts. The tool outputs a <code>.move</code> file targeting <code>sui move test</code>, making it easy to verify that tests are complete and compile correctly.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new">What&rsquo;s new</h2>
<h3 id="github-action-zero-install-ci-for-move-repos">GitHub Action (zero-install CI for Move repos)</h3>
<p>Any Sui Move repo can now add coverage checking to their PR workflow in 6 lines:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">mehvetero/move-test-gen@v1.1.1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">sources</span>: <span style="color:#ae81ff">sources</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">tests</span>: <span style="color:#ae81ff">tests</span>
</span></span></code></pre></div><ul>
<li><strong>Layer 1 (PR gate):</strong> assert pairing — no sui needed, runs in seconds</li>
<li><strong>Layer 2 (nightly):</strong> mutation testing — needs sui CLI, catches weak tests</li>
<li><code>--scope</code> option for target-only mutation (skip dependency libraries)</li>
</ul>
<h3 id="honesty-channel-v110">Honesty channel (v1.1.0)</h3>
<ul>
<li>Gate confesses &ldquo;undecidable&rdquo; instead of blaming the suite for equivalent mutants</li>
<li>Mutual-redundancy probe: measured evidence, not pattern-matching</li>
<li><code>signed_having_learned</code> field in adjudication records</li>
</ul>
<h3 id="eval-lab--3-campaigns-complete">Eval lab — 3 campaigns complete</h3>
<ul>
<li><strong>Campaign 1:</strong> 6 fixture scenarios, 53/53 mutants killed</li>
<li><strong>Campaign 2:</strong> gate honesty — planted equivalents confessed in all rounds</li>
<li><strong>Campaign 3:</strong> real protocol (Interest Protocol SuiTears) — fund 3/3, oracle 21/22</li>
</ul>
<p>Full records: <a href="eval/RESULTS.md">eval/RESULTS.md</a></p>
<h3 id="infrastructure">Infrastructure</h3>
<ul>
<li>CI: gate-selftest (7 cases) + action-selftest (dogfood) on every push</li>
<li>MIT License with SuiTears attribution</li>
<li>Pinned release tags (no live-branch references in docs)</li>
<li>Marketplace: eye/purple</li>
</ul>
<hr>
<p>Methodology borrowed from <a href="https://github.com/TheColliery">HetCreep / TheColliery</a>. Full lineage in the record.Thanks @HetCreep.</p>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/totem-shield/</link><pubDate>Sat, 18 Jul 2026 14:27:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.101.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Totem is a file-based toolkit that helps developers maintain project rules and lessons by using plain markdown lessons, a queryable knowledge index derived from them, and compiled lint rules. It provides a deterministic zero-LLM linter to enforce these rules, ensuring that architectural mistakes are caught before they become problems.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.101.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Totem is a file-based toolkit that helps developers maintain project rules and lessons by using plain markdown lessons, a queryable knowledge index derived from them, and compiled lint rules. It provides a deterministic zero-LLM linter to enforce these rules, ensuring that architectural mistakes are caught before they become problems.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>Agent Done Or Not</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/agent-done-or-not/</link><pubDate>Sat, 18 Jul 2026 14:26:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/agent-done-or-not/</guid><description>Version updated for https://github.com/mohamedzhioua/agent-done-or-not to version v0.13.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, agent-done-or-not, ensures that AI coding agents verify tasks before declaring success. It captures every check with a tamper-evident receipt (command + exit code + SHA-256 hash of the output) and blocks the agent from finishing until the most recent check is fresh and passing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mohamedzhioua/agent-done-or-not">https://github.com/mohamedzhioua/agent-done-or-not</a></strong> to version <strong>v0.13.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-done-or-not">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, agent-done-or-not, ensures that AI coding agents verify tasks before declaring success. It captures every check with a tamper-evident receipt (command + exit code + SHA-256 hash of the output) and blocks the agent from finishing until the most recent check is fresh and passing.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="0130--2026-07-18">[0.13.0] — 2026-07-18</h2>
<p>The PR Receipts release. Adds a <code>review-pr</code> subcommand (and Action <code>mode: review-pr</code>) that re-executes an AI-authored PR&rsquo;s claimed checks. Additive — no
change to existing subcommands or the receipt format.</p>
<h3 id="added">Added</h3>
<ul>
<li><strong><code>review-pr</code> subcommand</strong> (<code>done-gate.sh review-pr</code> / <code>done-gate.ps1 review-pr</code>), with <code>--body &lt;file|-&gt;</code>, <code>--commits [--base &lt;ref&gt;]</code>, and <code>--json</code>.
Parses a PR description&rsquo;s testable claims (&ldquo;tests pass&rdquo;, &ldquo;lint clean&rdquo;, &ldquo;build
succeeds&rdquo;), auto-resolves the project&rsquo;s REAL commands from its manifests
(<code>package.json</code>, <code>pyproject.toml</code>, <code>go.mod</code> — three ecosystems for v1),
re-executes them, and prints a receipt splitting claims into <strong>RE-EXECUTED</strong>,
<strong>ASSERTED</strong> (recognized but no re-executable command), and <strong>UNPARSED</strong>. Never
the word &ldquo;VERIFIED&rdquo;: a green re-run proves the command passed, not that the PR
is correct. Exits non-zero if a re-executed claim fails. The re-run command is
resolved only from the manifests — never from PR text — so a PR cannot inject a
command.</li>
<li><strong>Action <code>mode: review-pr</code></strong> (&ldquo;PR Receipts&rdquo;) with a <code>pr-body</code> input, a
documented untrusted-PR trust model (CI-only, <code>pull_request</code> not
<code>pull_request_target</code>, no secrets), and job-summary + sticky-PR-comment output.</li>
<li><strong><code>docs/pr-receipts.md</code></strong> — the PR Receipts page: how it works, usage, the trust
model, and a ready-to-use GitHub Action recipe.</li>
</ul>
]]></content:encoded></item><item><title>Star History Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/star-history-action/</link><pubDate>Sat, 18 Jul 2026 14:25:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/star-history-action/</guid><description>Version updated for https://github.com/narayann7/star-history-action to version v1.0.4.
This action is used across all versions by 8 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Star History Action automates the process of displaying a self-updating star history chart in your own repository’s README. It solves the problem of rendering star-history.com badges on restricted endpoints and provides an alternative method using GitHub Actions and Node.js to render charts based on your own access token. The action runs in your CI, commits the rendered chart into your repo, and updates the README with a static image, ensuring that it only refreshes when there are actual changes to the stargazers data.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/narayann7/star-history-action">https://github.com/narayann7/star-history-action</a></strong> to version <strong>v1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/star-history-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Star History Action automates the process of displaying a self-updating star history chart in your own repository&rsquo;s README. It solves the problem of rendering star-history.com badges on restricted endpoints and provides an alternative method using GitHub Actions and Node.js to render charts based on your own access token. The action runs in your CI, commits the rendered chart into your repo, and updates the README with a static image, ensuring that it only refreshes when there are actual changes to the stargazers data.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li>A GitHub API rate-limit or access <strong>403 while refreshing an already-committed chart no longer fails the workflow.</strong> When a chart already exists, the run keeps it, logs a warning, and exits cleanly, then refreshes on the next run once the limit resets. Retrying alone could not cover this: the automatic Actions token&rsquo;s primary limit (1000 requests/hour per repo) resets up to an hour out, far beyond the retry wait cap. The first run with no chart yet still fails loudly, since a 403 there usually means the token cannot read the target repo.</li>
<li>The dogfood <code>watch</code> workflow now sets <code>concurrency: cancel-in-progress: true</code>, so a <strong>burst of stars collapses into a single refresh</strong> instead of queuing one run per star. Each render spends ~40 API requests; without collapsing, a star burst drained the per-repo hourly quota and made later runs 403.</li>
</ul>
<h3 id="documentation">Documentation</h3>
<ul>
<li>Condensed the README and added a <strong>Rate limits</strong> section covering the per-repo 1000/hour Actions-token cap, the 5000/hour PAT cap, and the burst failure mode.</li>
</ul>
<p>The vendored star-history renderer is unchanged.</p>
<p><strong>Full changelog:</strong> <a href="https://github.com/narayann7/star-history-action/compare/v1.0.3...v1.0.4">https://github.com/narayann7/star-history-action/compare/v1.0.3...v1.0.4</a></p>
]]></content:encoded></item><item><title>Changelog Bot Runner Nyaomaru</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/changelog-bot-runner-nyaomaru/</link><pubDate>Sat, 18 Jul 2026 14:24:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/changelog-bot-runner-nyaomaru/</guid><description>Version updated for https://github.com/nyaomaru/changelog-bot to version v0.6.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The @nyaomaru/changelog-bot GitHub Action automates the creation of a polished changelog entry based on commit history, release notes, and optionally uses AI to generate summaries. It provides automated storytelling capabilities, can open PRs with the updated changelog, handles duplicate versions safely, and works as a CI-native action or reusable workflow.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nyaomaru/changelog-bot">https://github.com/nyaomaru/changelog-bot</a></strong> to version <strong>v0.6.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/changelog-bot-runner-nyaomaru">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>@nyaomaru/changelog-bot</code> GitHub Action automates the creation of a polished changelog entry based on commit history, release notes, and optionally uses AI to generate summaries. It provides automated storytelling capabilities, can open PRs with the updated changelog, handles duplicate versions safely, and works as a CI-native action or reusable workflow.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs(changelog): 0.6.5 by @github-actions[bot] in <a href="https://github.com/nyaomaru/changelog-bot/pull/162">https://github.com/nyaomaru/changelog-bot/pull/162</a></li>
<li>refactor: separate changelog run concerns by @nyaomaru in <a href="https://github.com/nyaomaru/changelog-bot/pull/163">https://github.com/nyaomaru/changelog-bot/pull/163</a></li>
<li>Release: 0.6.6 by @github-actions[bot] in <a href="https://github.com/nyaomaru/changelog-bot/pull/164">https://github.com/nyaomaru/changelog-bot/pull/164</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nyaomaru/changelog-bot/compare/v0...v0.6.6">https://github.com/nyaomaru/changelog-bot/compare/v0...v0.6.6</a></p>
]]></content:encoded></item><item><title>phi.ag - Setup Binaryen</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/phi.ag-setup-binaryen/</link><pubDate>Sat, 18 Jul 2026 14:23:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/phi.ag-setup-binaryen/</guid><description>Version updated for https://github.com/phi-ag/setup-binaryen to version v1.0.10.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The phi-ag/setup-binaryen GitHub Action sets up the Binaryen toolchain, which is a compiler for WebAssembly. It automates the process of downloading and configuring Binaryen to streamline development workflows related to WebAssembly compilation and optimization tasks. The action supports specifying a specific version of Binaryen if needed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/phi-ag/setup-binaryen">https://github.com/phi-ag/setup-binaryen</a></strong> to version <strong>v1.0.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/phi-ag-setup-binaryen">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>phi-ag/setup-binaryen</code> GitHub Action sets up the <a href="https://github.com/WebAssembly/binaryen">Binaryen</a> toolchain, which is a compiler for WebAssembly. It automates the process of downloading and configuring Binaryen to streamline development workflows related to WebAssembly compilation and optimization tasks. The action supports specifying a specific version of Binaryen if needed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1010-2026-07-16"><a href="https://github.com/phi-ag/setup-binaryen/compare/v1.0.9...v1.0.10">1.0.10</a> (2026-07-16)</h2>
<h3 id="miscellaneous-chores">Miscellaneous Chores</h3>
<ul>
<li><strong>deps:</strong> update actions/checkout action to v7 (<a href="https://github.com/phi-ag/setup-binaryen/commit/535e73a49271a775432af7585c1edd276ce106a9">535e73a</a>)</li>
<li><strong>deps:</strong> update actions/checkout digest to df4cb1c (<a href="https://github.com/phi-ag/setup-binaryen/commit/1fafd4c5c35ecfdaf1f7984d043dfdc29aebdbcf">1fafd4c</a>)</li>
<li><strong>deps:</strong> update dependency binaryen to v131 (<a href="https://github.com/phi-ag/setup-binaryen/commit/88ff5748eb5e1d4ed946ab1427f235c1cb8a1d94">88ff574</a>)</li>
</ul>
]]></content:encoded></item><item><title>Postman Onboarding AWS Spec Discovery</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/postman-onboarding-aws-spec-discovery/</link><pubDate>Sat, 18 Jul 2026 14:23:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/postman-onboarding-aws-spec-discovery/</guid><description>Version updated for https://github.com/postman-cs/postman-aws-spec-discovery-action to version v2.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the discovery and export of API specifications from AWS services using only the existing AWS credentials. It helps in creating a source-of-truth specification for Postman onboarding, which can be used to generate deterministic collections, OpenAPI-backed contract checks, smoke tests, mocks, monitors, repo artifacts, and CI runs. The action supports various AWS providers, including API Gateway, AppSync, SNS, EventBridge, Lambda, SSM, etc., and uses IAM permissions for authorization.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-aws-spec-discovery-action">https://github.com/postman-cs/postman-aws-spec-discovery-action</a></strong> to version <strong>v2.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-aws-spec-discovery">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the discovery and export of API specifications from AWS services using only the existing AWS credentials. It helps in creating a source-of-truth specification for Postman onboarding, which can be used to generate deterministic collections, OpenAPI-backed contract checks, smoke tests, mocks, monitors, repo artifacts, and CI runs. The action supports various AWS providers, including API Gateway, AppSync, SNS, EventBridge, Lambda, SSM, etc., and uses IAM permissions for authorization.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>test(discovery): prove contract-control wires against live API Gateway by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/39">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/39</a></li>
<li>v2.1.0: ambiguity outputs, local CDK/SAM artifact probe, additive REST enrichment by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/41">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/41</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/compare/v2.0.3...v2.1.0">https://github.com/postman-cs/postman-aws-spec-discovery-action/compare/v2.0.3...v2.1.0</a></p>
]]></content:encoded></item><item><title>memi design CI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/memi-design-ci/</link><pubDate>Sat, 18 Jul 2026 14:22:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/memi-design-ci/</guid><description>Version updated for https://github.com/sarveshsea/memi to version v2.6.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: memi is a CLI tool that automates design QA for coding agents. It audits real interfaces, remembers design systems, and prevents UI regressions before merge. The action provides features like finding accessibility issues, loading design-system context, enforcing design CI checks, building SwiftUI interfaces, and generating compact briefs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sarveshsea/memi">https://github.com/sarveshsea/memi</a></strong> to version <strong>v2.6.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/memi-design-ci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong> memi is a CLI tool that automates design QA for coding agents. It audits real interfaces, remembers design systems, and prevents UI regressions before merge. The action provides features like finding accessibility issues, loading design-system context, enforcing design CI checks, building SwiftUI interfaces, and generating compact briefs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: ship warning-free 2.6.1 installs (#70) (c2a8a6b)</li>
<li>feat: add Apple platform design CI (#69) (c9cfa1f)</li>
<li>docs: record hosted Smithery MCP release (#68) (127871b)</li>
<li>docs: record marketplace submissions (#67) (1b38cc5)</li>
<li>ci: move action runtime pins to Node 24 (#66) (26a47f6)</li>
<li>docs: connect focused distribution surfaces (#65) (01c1eb2)</li>
<li>feat: expand design CI distribution surfaces (#64) (b56836c)</li>
<li>fix: advertise Smithery runtime discovery (#63) (b00511b)</li>
<li>fix: ship executable MCPB entry point (#62) (628331d)</li>
<li>Merge pull request #61 from sarveshsea/codex/design-skills-integration (67a5d66)</li>
</ul>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/agentauditkit-mcp-security-scan/</link><pubDate>Sat, 18 Jul 2026 14:20:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.50.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentAuditKit automates security scans for AI agents, providing a fully offline and deterministic solution to identify misconfigurations, hardcoded secrets, tool poisoning, and other threats. It produces auditor-ready evidence packs in SARIF format and PDF reports mapped to 13 frameworks, ensuring compliance with EU AI Act, SOC 2, ISO standards, and regional regulations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.50</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AgentAuditKit automates security scans for AI agents, providing a fully offline and deterministic solution to identify misconfigurations, hardcoded secrets, tool poisoning, and other threats. It produces auditor-ready evidence packs in SARIF format and PDF reports mapped to 13 frameworks, ensuring compliance with EU AI Act, SOC 2, ISO standards, and regional regulations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.50
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.50
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.50</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs: single-source rule count + retire unbounded 48h CVE-SLA claim by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/432">https://github.com/sattyamjjain/agent-audit-kit/pull/432</a></li>
<li>feat(rules): AAK-OAUTH-007 RFC 8707 resource indicators + reconcile July rules to ratified MCP 2026-07-28 by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/443">https://github.com/sattyamjjain/agent-audit-kit/pull/443</a></li>
<li>fix(rules): 2026-07-13..15 MCP CVE backlog — 7 version-pin rules (247→254) by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/444">https://github.com/sattyamjjain/agent-audit-kit/pull/444</a></li>
<li>fix(rules): 2026-07-15..17 MCP CVE wave — 7 version-pin rules (254→261) by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/469">https://github.com/sattyamjjain/agent-audit-kit/pull/469</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.49...v0.3.50">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.49...v0.3.50</a></p>
]]></content:encoded></item><item><title>Argus PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/argus-pr-review/</link><pubDate>Sat, 18 Jul 2026 14:19:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/argus-pr-review/</guid><description>Version updated for https://github.com/sibinms/argus to version v1.2.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Argus is an AI PR reviewer that uses multiple narrow lenses to suggest potential issues and one curator to decide which ones are real. It automates the detection of bugs and security vulnerabilities in pull requests by analyzing them with various models from Anthropic, OpenAI, or other providers. The action integrates seamlessly into GitHub workflows for automated review without requiring separate configuration steps after initial setup.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sibinms/argus">https://github.com/sibinms/argus</a></strong> to version <strong>v1.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/argus-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Argus is an AI PR reviewer that uses multiple narrow lenses to suggest potential issues and one curator to decide which ones are real. It automates the detection of bugs and security vulnerabilities in pull requests by analyzing them with various models from Anthropic, OpenAI, or other providers. The action integrates seamlessly into GitHub workflows for automated review without requiring separate configuration steps after initial setup.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Pin the Action to this tag:</p>
<pre><code>- uses: sibinms/argus@v1.2.2
</code></pre>
<h2 id="bug-fix">Bug fix</h2>
<p>The README told CLI users to <code>pip install argus-review</code>. That name is already registered on PyPI by a completely unrelated project (&ldquo;Local multi-agent technical deliberation tool&rdquo;) — the command would have silently installed someone else&rsquo;s tool. We were never actually published there.</p>
<p>Fixes:</p>
<ul>
<li>Renamed the distribution from <code>argus-review</code> to <strong><code>argus-pr-review</code></strong> (matches the Marketplace listing slug, confirmed available on PyPI for when this does get published).</li>
<li>Until then, the README&rsquo;s CLI Quick Start installs straight from this tagged commit: <code>pip install &quot;git+https://github.com/sibinms/argus.git@v1.2.2&quot;</code>.</li>
<li>Added a troubleshooting note for a Rust/<code>maturin</code> build error some environments hit installing litellm&rsquo;s <code>tokenizers</code> dependency from source (<code>--only-binary=:all:</code> works around it).</li>
</ul>
<p>No changes to the review pipeline itself.</p>
]]></content:encoded></item><item><title>Pipr Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/pipr-review/</link><pubDate>Sat, 18 Jul 2026 14:18:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/pipr-review/</guid><description>Version updated for https://github.com/somus/pipr to version v0.4.3.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Pipr is a GitHub Action and CLI tool that automates AI code reviews across various code hosts. It loads configuration from .pipr/config.ts, builds a deterministic Diff Manifest, runs Pi for structured output, validates findings against commentable ranges, and publishes Main Review Comments and capped Inline Review Comments. Supported delivery targets include GitHub, GitLab, Azure DevOps Services, and Bitbucket Cloud. The runtime owns diff modeling, Pi execution, structured output validation, stale-head checks, and comment publishing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somus/pipr">https://github.com/somus/pipr</a></strong> to version <strong>v0.4.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pipr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Pipr is a GitHub Action and CLI tool that automates AI code reviews across various code hosts. It loads configuration from <code>.pipr/config.ts</code>, builds a deterministic Diff Manifest, runs Pi for structured output, validates findings against commentable ranges, and publishes Main Review Comments and capped Inline Review Comments. Supported delivery targets include GitHub, GitLab, Azure DevOps Services, and Bitbucket Cloud. The runtime owns diff modeling, Pi execution, structured output validation, stale-head checks, and comment publishing.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="043-2026-07-18"><a href="https://github.com/somus/pipr/compare/v0.4.2...v0.4.3">0.4.3</a> (2026-07-18)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>config:</strong> collapse dogfood inline rationales (<a href="https://github.com/somus/pipr/issues/93">#93</a>) (<a href="https://github.com/somus/pipr/commit/9b646b55d8da223e9f5bb7709d82296adacf6a5d">9b646b5</a>)</li>
<li><strong>runtime:</strong> pre-exclude discarded diff content (<a href="https://github.com/somus/pipr/issues/95">#95</a>) (<a href="https://github.com/somus/pipr/commit/8847418249b59841d42227eaf4d513828a834de0">8847418</a>)</li>
</ul>
]]></content:encoded></item><item><title>Graveyard Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/graveyard-check/</link><pubDate>Sat, 18 Jul 2026 14:17:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/graveyard-check/</guid><description>Version updated for https://github.com/TahaKotwal12/graveyard-check to version v0.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Graveyard Check is a GitHub Action that helps identify and recommend replacements for abandoned or at-risk dependencies in various ecosystems, such as npm, PyPI, and Go modules. It scans project lockfiles to determine if packages have been deprecated or not updated in a while, and suggests suitable alternatives. The tool supports multiple lockfile formats and can be used as a CI gate to ensure that only maintained versions are used.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TahaKotwal12/graveyard-check">https://github.com/TahaKotwal12/graveyard-check</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/graveyard-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Graveyard Check is a GitHub Action that helps identify and recommend replacements for abandoned or at-risk dependencies in various ecosystems, such as npm, PyPI, and Go modules. It scans project lockfiles to determine if packages have been deprecated or not updated in a while, and suggests suitable alternatives. The tool supports multiple lockfile formats and can be used as a CI gate to ensure that only maintained versions are used.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Fix formatting in App component by removing unnecessary whitespace in the feature display section for improved code cleanliness. (bb468bf)</li>
<li>Upgrade to version 0.3.0, adding support for pnpm and Yarn lockfiles alongside npm. Update README and App component to reflect new features and clarify ecosystem support. Enhance error messages for lockfile detection and improve overall documentation. (a2c7572)</li>
<li>Add Checker component for package verification and update App layout to include a new section for checking packages. Enhance package.json with yaml dependency and update Vercel configuration for rewrites. Introduce checker logic in new lib files for npm and PyPI support. (57b46d7)</li>
<li>Add SECURITY.md to outline the security policy for reporting vulnerabilities and update CONTRIBUTING.md to direct users to report issues privately. This enhances project security and clarifies contributor responsibilities. (ffccb8a)</li>
<li>Add CODE_OF_CONDUCT.md to establish community standards and expectations for behavior. Update CONTRIBUTING.md to reference the new Code of Conduct, ensuring contributors are aware of the guidelines for participation. (c6924a2)</li>
<li>Update CONTRIBUTING.md and README.md for clarity on ecosystem support; add support for PyPI in the CLI. Bump version to 0.2.0 and enhance error handling for package checks. Introduce new successor records for Python packages in the dataset. (4b773fd)</li>
<li>Add GitHub contribution templates and issue bootstrap script. (de88857)</li>
<li>Refactor command display in App component: update CLI commands to use &rsquo;npm i graveyard-check&rsquo; and reorganize layout for better user experience. Modify section titles for clarity. (0125547)</li>
<li>Update package.json files: change repository URL format in root package.json and add dependencies and devDependencies in website package.json for improved project structure and functionality. (d5e67a2)</li>
<li>Rename project from &lsquo;Lifeboat&rsquo; to &lsquo;Graveyard Check&rsquo;, updating all relevant files and references. Modify action.yml, README, and documentation to reflect the new name and functionality. Add website structure for marketing and documentation. Update CLI commands and error messages accordingly. (deebb75)</li>
</ul>
]]></content:encoded></item><item><title>Keep Node Current</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/keep-node-current/</link><pubDate>Sat, 18 Jul 2026 14:15:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/keep-node-current/</guid><description>Version updated for https://github.com/TimothyJones/github-action-keep-node-current to version v1.0.2.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action keeps Node.js versions in sync across repositories by fetching the latest release schedule and adjusting CI configurations, .nvmrc, and package.json files to reflect active LTS majors. It automates the process of updating matrices, single-version pins, and engine version declarations, ensuring compatibility with the official Node.js release schedule.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TimothyJones/github-action-keep-node-current">https://github.com/TimothyJones/github-action-keep-node-current</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/keep-node-current">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action keeps Node.js versions in sync across repositories by fetching the latest release schedule and adjusting CI configurations, <code>.nvmrc</code>, and <code>package.json</code> files to reflect active LTS majors. It automates the process of updating matrices, single-version pins, and engine version declarations, ensuring compatibility with the official Node.js release schedule.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Bug fix: pushing could fail with <code>Duplicate header: &quot;Authorization&quot;</code> when <code>actions/checkout</code> had persisted more than one credential header. The action now clears all persisted <code>extraheader</code> entries and authenticates with a single one from the supplied token.</p>
<p>Recommended for all users. <code>@v1</code> now points here.</p>
]]></content:encoded></item><item><title>Setup Tombi</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/setup-tombi/</link><pubDate>Sat, 18 Jul 2026 14:14:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/setup-tombi/</guid><description>Version updated for https://github.com/tombi-toml/setup-tombi to version v1.2.2.
This action is used across all versions by 137 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up Tombi, a configuration management tool, in your GitHub Actions workflow. It allows you to install specific versions of Tombi or resolve versions from lock files, with options for checksum verification and cache behavior control.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tombi-toml/setup-tombi">https://github.com/tombi-toml/setup-tombi</a></strong> to version <strong>v1.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>137</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-tombi">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up Tombi, a configuration management tool, in your GitHub Actions workflow. It allows you to install specific versions of Tombi or resolve versions from lock files, with options for checksum verification and cache behavior control.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This setup-tombi release matches <a href="https://github.com/tombi-toml/tombi/releases/tag/v1.2.2">tombi v1.2.2</a>.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/tombi-toml/setup-tombi/compare/v1...v1.2.2">https://github.com/tombi-toml/setup-tombi/compare/v1...v1.2.2</a></p>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/vibgrate-scan/</link><pubDate>Sat, 18 Jul 2026 14:12:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.718.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action @vibgrate/cli is designed to analyze local codebases, providing insights such as a deterministic code graph and a drift score. It automates tasks like generating drift scores, building code graphs, and answering questions about the codebase. The action runs locally on the user’s machine without requiring any API keys or network connections, focusing on improving productivity for AI coding agents by offering local intelligence and documentation tools.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.718.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>@vibgrate/cli</code> is designed to analyze local codebases, providing insights such as a deterministic code graph and a drift score. It automates tasks like generating drift scores, building code graphs, and answering questions about the codebase. The action runs locally on the user&rsquo;s machine without requiring any API keys or network connections, focusing on improving productivity for AI coding agents by offering local intelligence and documentation tools.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20267182">Vibgrate CLI 2026.718.2</h1>
<p><em>Released 2026-07-18</em></p>
<p>This release of the Vibgrate CLI includes new commands for system diagnostics and enhanced security features. It also improves guidance for AI assistants and updates telemetry settings.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="new">New</h3>
<ul>
<li>A new vg doctor command provides a read-only overview of your setup, including configuration, credentials, and server launch details.</li>
<li>vg serve now respects the DO_NOT_TRACK standard, ensuring no data is uploaded even with &ndash;share-stats.</li>
<li>vg serve &ndash;http now blocks requests from non-local origins to enhance security against DNS rebinding.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>The library-docs tools now offer clearer guidance for AI assistants, emphasizing the importance of version-correct documentation.</li>
</ul>
<h3 id="security">Security</h3>
<ul>
<li>Patched the semantic-embedding backend to use node-tar 7.5.8+, addressing high-severity vulnerabilities.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.717.1, interleaved on one runner against the pinned corpus (157 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>19053 count</td>
          <td>19053 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>7791 count</td>
          <td>7791 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.98 ratio</td>
          <td>0.98 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>604.10 ms</td>
          <td>603.20 ms</td>
      </tr>
  </tbody>
</table>
<p>No regressions against the previous release.</p>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.718.2">https://vibgrate.com/changelog/cli/2026.718.2</a></p>
]]></content:encoded></item><item><title>Symfony Security Auditor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/symfony-security-auditor/</link><pubDate>Sat, 18 Jul 2026 14:11:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/symfony-security-auditor/</guid><description>Version updated for https://github.com/vinceAmstoutz/symfony-security-auditor to version 1.16.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is an AI-powered security auditor designed for Symfony applications. It uses multi-agent techniques to identify application-level flaws that traditional static analysis tools (PHPStan, Psalm) miss. The Auditor runs alongside other SAST tools and dependency scanners to provide a comprehensive security audit experience. The auditor can be used standalone as a CLI tool or integrated into a Symfony app via a bundle.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vinceAmstoutz/symfony-security-auditor">https://github.com/vinceAmstoutz/symfony-security-auditor</a></strong> to version <strong>1.16.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/symfony-security-auditor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is an AI-powered security auditor designed for Symfony applications. It uses multi-agent techniques to identify application-level flaws that traditional static analysis tools (PHPStan, Psalm) miss. The Auditor runs alongside other SAST tools and dependency scanners to provide a comprehensive security audit experience. The auditor can be used standalone as a CLI tool or integrated into a Symfony app via a bundle.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(standalone): add a self-update command by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/166">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/166</a></li>
<li>chore(deps): update mcp/sdk requirement from ^0.6.0 to ^0.7.0 by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/167">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/167</a></li>
<li>fix(standalone): restore Windows binary build by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/168">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/168</a></li>
<li>ci: retry apt installs by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/169">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/169</a></li>
<li>ci: hide the macOS tap-trust warnings by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/170">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/170</a></li>
<li>ci: add a Launchpad fallback for apt by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/171">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/171</a></li>
<li>feat(scan): add an HTTP trust-boundary attacker skill by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/172">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/172</a></li>
<li>feat(ci): add standalone mode and outputs to the GitHub Action by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/173">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/173</a></li>
<li>feat(pipeline): controllers on voter changes in diff mode by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/174">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/174</a></li>
<li>feat(scan): add five security misconfiguration audits by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/175">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/175</a></li>
<li>feat(scan): parse sarif code flows into taint paths by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/176">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/176</a></li>
<li>feat(agent): add cross-run reviewer triage memory by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/177">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/177</a></li>
<li>docs(ci): add a sticky PR-comment recipe for the summary by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/178">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/178</a></li>
<li>chore(deps): update symfony/ai-bundle from ^0.10 to ^0.11 by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/179">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/179</a></li>
<li>feat(scan): audit LDAP, admin panels and Mercure by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/180">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/180</a></li>
<li>feat(llm): add MiniMax provider support by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/181">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/181</a></li>
<li>feat(llm): expose finish reasons and retry 5xx errors by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/183">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/183</a></li>
<li>fix: resolve audit vulnerabilities, triage, and CI defects by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/184">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/184</a></li>
<li>chore: enforce slow tests in CI by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/185">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/185</a></li>
<li>ci: add zizmor GitHub Actions security scanning by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/186">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/186</a></li>
<li>fix: 1.16.0 pre-release fixes by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/188">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/188</a></li>
<li>chore: release 1.16.0 by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/189">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/189</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/compare/1.15.0...1.16.0">https://github.com/vinceAmstoutz/symfony-security-auditor/compare/1.15.0...1.16.0</a></p>
]]></content:encoded></item><item><title>hide-comment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/hide-comment/</link><pubDate>Sat, 18 Jul 2026 07:04:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/hide-comment/</guid><description>Version updated for https://github.com/int128/hide-comment-action to version v1.66.0.
This action is used across all versions by 231 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action hides (minimizes) comments in a pull request, providing flexibility through various filtering conditions and allowing the user to hide comments by issue number or GitHub token.
What’s Changed uses: int128/hide-comment-action@8cd375395d4b1630f8b70d17b802501a15d32561 # v1.66.0 What’s Changed chore(deps): update dependency @biomejs/biome to v2.5.2 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1651 chore(deps): update int128/release-typescript-action action to v1.75.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1653 chore(deps): update int128/update-generated-files-action action to v2.100.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1654 chore(deps): update int128/wait-for-workflows-action action to v1.86.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1655 chore(deps): lock file maintenance by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1656 chore(deps): update int128/update-generated-files-action action to v2.101.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1657 chore(deps): update pnpm to v11.10.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1658 chore(deps): update dependency @types/node to v24.13.3 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1660 chore(deps): update dependency @biomejs/biome to v2.5.3 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1659 chore(deps): update dependency vitest to v4.1.10 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1661 chore(deps): update pnpm to v11.11.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1662 chore(deps): lock file maintenance by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1664 Full Changelog: https://github.com/int128/hide-comment-action/compare/v1.65.0...v1.66.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/int128/hide-comment-action">https://github.com/int128/hide-comment-action</a></strong> to version <strong>v1.66.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>231</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hide-comment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action hides (minimizes) comments in a pull request, providing flexibility through various filtering conditions and allowing the user to hide comments by issue number or GitHub token.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">uses</span>: <span style="color:#ae81ff">int128/hide-comment-action@8cd375395d4b1630f8b70d17b802501a15d32561</span> <span style="color:#75715e"># v1.66.0</span>
</span></span></code></pre></div><h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): update dependency @biomejs/biome to v2.5.2 by @renovate[bot] in <a href="https://github.com/int128/hide-comment-action/pull/1651">https://github.com/int128/hide-comment-action/pull/1651</a></li>
<li>chore(deps): update int128/release-typescript-action action to v1.75.0 by @renovate[bot] in <a href="https://github.com/int128/hide-comment-action/pull/1653">https://github.com/int128/hide-comment-action/pull/1653</a></li>
<li>chore(deps): update int128/update-generated-files-action action to v2.100.0 by @renovate[bot] in <a href="https://github.com/int128/hide-comment-action/pull/1654">https://github.com/int128/hide-comment-action/pull/1654</a></li>
<li>chore(deps): update int128/wait-for-workflows-action action to v1.86.0 by @renovate[bot] in <a href="https://github.com/int128/hide-comment-action/pull/1655">https://github.com/int128/hide-comment-action/pull/1655</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/int128/hide-comment-action/pull/1656">https://github.com/int128/hide-comment-action/pull/1656</a></li>
<li>chore(deps): update int128/update-generated-files-action action to v2.101.0 by @renovate[bot] in <a href="https://github.com/int128/hide-comment-action/pull/1657">https://github.com/int128/hide-comment-action/pull/1657</a></li>
<li>chore(deps): update pnpm to v11.10.0 by @renovate[bot] in <a href="https://github.com/int128/hide-comment-action/pull/1658">https://github.com/int128/hide-comment-action/pull/1658</a></li>
<li>chore(deps): update dependency @types/node to v24.13.3 by @renovate[bot] in <a href="https://github.com/int128/hide-comment-action/pull/1660">https://github.com/int128/hide-comment-action/pull/1660</a></li>
<li>chore(deps): update dependency @biomejs/biome to v2.5.3 by @renovate[bot] in <a href="https://github.com/int128/hide-comment-action/pull/1659">https://github.com/int128/hide-comment-action/pull/1659</a></li>
<li>chore(deps): update dependency vitest to v4.1.10 by @renovate[bot] in <a href="https://github.com/int128/hide-comment-action/pull/1661">https://github.com/int128/hide-comment-action/pull/1661</a></li>
<li>chore(deps): update pnpm to v11.11.0 by @renovate[bot] in <a href="https://github.com/int128/hide-comment-action/pull/1662">https://github.com/int128/hide-comment-action/pull/1662</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/int128/hide-comment-action/pull/1664">https://github.com/int128/hide-comment-action/pull/1664</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/int128/hide-comment-action/compare/v1.65.0...v1.66.0">https://github.com/int128/hide-comment-action/compare/v1.65.0...v1.66.0</a></p>
]]></content:encoded></item><item><title>Official Junie GitHub Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/official-junie-github-action/</link><pubDate>Sat, 18 Jul 2026 07:03:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/official-junie-github-action/</guid><description>Version updated for https://github.com/JetBrains/junie-github-action to version v1.5.10.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 38 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates JetBrains’ AI coding agent Junie into your workflows to automate code changes, issue resolution, PR management, and inline reviews. It helps developers interactively with their codebase through comments in issues, PRs, and CI/CD pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/JetBrains/junie-github-action">https://github.com/JetBrains/junie-github-action</a></strong> to version <strong>v1.5.10</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>38</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/official-junie-github-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates JetBrains&rsquo; AI coding agent Junie into your workflows to automate code changes, issue resolution, PR management, and inline reviews. It helps developers interactively with their codebase through comments in issues, PRs, and CI/CD pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>[Junie]: Update Junie CLI Version to 2285.5 in Files by @mashan555 in <a href="https://github.com/JetBrains/junie-github-action/pull/181">https://github.com/JetBrains/junie-github-action/pull/181</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/JetBrains/junie-github-action/compare/v1...v1.5.10">https://github.com/JetBrains/junie-github-action/compare/v1...v1.5.10</a></p>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/totem-shield/</link><pubDate>Sat, 18 Jul 2026 07:02:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.101.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Totem is a file-based toolkit that provides deterministic, offline linting and a queryable knowledge index derived from plain markdown lessons. It keeps project rules and context in the repository itself, ensuring architectural integrity survives PRs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.101.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Totem is a file-based toolkit that provides deterministic, offline linting and a queryable knowledge index derived from plain markdown lessons. It keeps project rules and context in the repository itself, ensuring architectural integrity survives PRs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>Agent Done Or Not</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/agent-done-or-not/</link><pubDate>Sat, 18 Jul 2026 07:01:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/agent-done-or-not/</guid><description>Version updated for https://github.com/mohamedzhioua/agent-done-or-not to version v0.12.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The agent-done-or-not action ensures that an AI code agent doesn’t declare a task as complete without running checks first. It records each check’s evidence (command, exit code, and SHA-256 hash) and blocks the agent from finishing until it has a fresh, passing check. This helps prevent agents from making false claims of completion and ensures that tasks are completed reliably.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mohamedzhioua/agent-done-or-not">https://github.com/mohamedzhioua/agent-done-or-not</a></strong> to version <strong>v0.12.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-done-or-not">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The agent-done-or-not action ensures that an AI code agent doesn&rsquo;t declare a task as complete without running checks first. It records each check&rsquo;s evidence (command, exit code, and SHA-256 hash) and blocks the agent from finishing until it has a fresh, passing check. This helps prevent agents from making false claims of completion and ensures that tasks are completed reliably.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="0120--2026-07-18">[0.12.0] — 2026-07-18</h2>
<p>The claim-audit release. Adds a new <code>audit</code> subcommand that diffs what an agent
<strong>claimed</strong> against the content-hashed <strong>receipts</strong> of what it actually ran.
Additive — no change to <code>capture</code>, <code>assert</code>, <code>verify</code>, <code>show</code>, or the receipt
format.</p>
<h3 id="added">Added</h3>
<ul>
<li><strong><code>audit</code> subcommand</strong> (<code>done-gate.sh audit</code> / <code>done-gate.ps1 audit</code>), with
<code>--transcript &lt;file|-&gt;</code>, <code>--run</code>, and <code>--json</code>. Extracts an agent&rsquo;s claims from
two sources: structured markers (<code>&lt;agent-done:claim label=… exit=… sha256=… /&gt;</code>)
and a conservative transcript heuristic fallback (tagged <code>inferred</code>, never
silently upgraded). Per-claim verdicts: <strong>BACKED</strong>, <strong>UNBACKED</strong> (asserted,
never run), <strong>MISREPORTED</strong> (claimed exit 0, recorded non-zero),
<strong>INTEGRITY_MISMATCH</strong> (claimed hash ≠ recorded hash), and <strong>UNPARSED</strong>
(claim-shaped text with no bindable label — reported, never counted as backed).
Never the word &ldquo;TAMPERED&rdquo;: a hash proves a mismatch, not who caused it. Only
execution receipts can back a claim. Exits non-zero on any unbacked,
misreported, or integrity-mismatched claim. Human table + <code>--json</code>; coverage
(marker vs inferred, unparsed count) is always reported.</li>
<li><strong><code>subagent-audit.sh</code> / <code>subagent-audit.ps1</code></strong> — a SubagentStop hook that audits
a subagent&rsquo;s summary before the parent trusts it. Blocks (exit 2) only on a real
finding and <strong>fails open</strong> on an ambiguous payload or missing ledger, so it
never wedges a session. Loop-guarded via <code>stop_hook_active</code>; escape hatch
<code>AGENT_DONE_OFF=1</code>.</li>
<li><strong><code>docs/markers.md</code></strong> — the paste-ready claim-marker contract and agent
instruction snippet, plus the SubagentStop hook wiring.</li>
</ul>
]]></content:encoded></item><item><title>Aether Deploy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/aether-deploy/</link><pubDate>Sat, 18 Jul 2026 07:00:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/aether-deploy/</guid><description>Version updated for https://github.com/Monoradioactivo/aetherpush-deploy-action to version v0.3.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the process of releasing React Native over-the-air updates using the Aether platform. It wraps the @aetherpush/cli release commands, providing features like deployment to different platforms and targeting specific binary versions. The action supports both release and release-react commands, handling various inputs such as app name, command, rollout percentage, and more, while outputting relevant metadata for further integration into CI workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Monoradioactivo/aetherpush-deploy-action">https://github.com/Monoradioactivo/aetherpush-deploy-action</a></strong> to version <strong>v0.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aether-deploy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action automates the process of releasing React Native over-the-air updates using the Aether platform. It wraps the @aetherpush/cli release commands, providing features like deployment to different platforms and targeting specific binary versions. The action supports both <code>release</code> and <code>release-react</code> commands, handling various inputs such as app name, command, rollout percentage, and more, while outputting relevant metadata for further integration into CI workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="031-2026-07-07"><a href="https://github.com/Monoradioactivo/aetherpush-deploy-action/compare/v0.3.0...v0.3.1">0.3.1</a> (2026-07-07)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>bundle @aetherpush/cli 0.3.2 (<a href="https://github.com/Monoradioactivo/aetherpush-deploy-action/issues/10">#10</a>) (<a href="https://github.com/Monoradioactivo/aetherpush-deploy-action/commit/2e4da31a23815ada7eadf5e2814d7ad7d690d67d">2e4da31</a>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs: full README with usage examples by @Monoradioactivo in <a href="https://github.com/Monoradioactivo/aetherpush-deploy-action/pull/9">https://github.com/Monoradioactivo/aetherpush-deploy-action/pull/9</a></li>
<li>fix: bundle @aetherpush/cli 0.3.2 by @Monoradioactivo in <a href="https://github.com/Monoradioactivo/aetherpush-deploy-action/pull/10">https://github.com/Monoradioactivo/aetherpush-deploy-action/pull/10</a></li>
<li>chore(main): release 0.3.1 by @aetherpush-release-bot[bot] in <a href="https://github.com/Monoradioactivo/aetherpush-deploy-action/pull/11">https://github.com/Monoradioactivo/aetherpush-deploy-action/pull/11</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Monoradioactivo/aetherpush-deploy-action/compare/v0.3.0...v0.3.1">https://github.com/Monoradioactivo/aetherpush-deploy-action/compare/v0.3.0...v0.3.1</a></p>
]]></content:encoded></item><item><title>Kaniscope AI Code Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/kaniscope-ai-code-review/</link><pubDate>Sat, 18 Jul 2026 06:59:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/kaniscope-ai-code-review/</guid><description>Version updated for https://github.com/nhatvu148/kaniscope-action to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Kaniscope, automates AI code reviews by using an OpenRouter model to generate comments on pull requests. It posts line-anchored inline reviews and a summary comment, helping developers identify issues without blocking merges or edits. The action runs on a small Docker container and is cost-effective due to its integration with OpenRouter, which uses models like moonshotai/kimi-k2-0905 for cheaper reviews.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nhatvu148/kaniscope-action">https://github.com/nhatvu148/kaniscope-action</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kaniscope-ai-code-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, Kaniscope, automates AI code reviews by using an OpenRouter model to generate comments on pull requests. It posts line-anchored inline reviews and a summary comment, helping developers identify issues without blocking merges or edits. The action runs on a small Docker container and is cost-effective due to its integration with OpenRouter, which uses models like <code>moonshotai/kimi-k2-0905</code> for cheaper reviews.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nhatvu148/kaniscope-action/commits/v0.1.1">https://github.com/nhatvu148/kaniscope-action/commits/v0.1.1</a></p>
]]></content:encoded></item><item><title>Quick OCP</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/quick-ocp/</link><pubDate>Sat, 18 Jul 2026 06:57:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/quick-ocp/</guid><description>Version updated for https://github.com/palmsoftware/quick-ocp to version v1.0.0.
This action is used across all versions by 14 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
This GitHub Action uses OpenShift Local to quickly deploy an OCP (OpenShift Container Platform) cluster on a GitHub Actions runner. It supports specific versions and configurations, including memory allocation, disk size, and operator readiness checks. The action also includes connectivity requirements and options for preloading images into the cluster registry.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/palmsoftware/quick-ocp">https://github.com/palmsoftware/quick-ocp</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>14</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/quick-ocp">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>This GitHub Action uses OpenShift Local to quickly deploy an OCP (OpenShift Container Platform) cluster on a GitHub Actions runner. It supports specific versions and configurations, including memory allocation, disk size, and operator readiness checks. The action also includes connectivity requirements and options for preloading images into the cluster registry.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: add set -e to 3 scripts missing it by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/94">https://github.com/palmsoftware/quick-ocp/pull/94</a></li>
<li>fix: align version validation regex to 4.18+ by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/95">https://github.com/palmsoftware/quick-ocp/pull/95</a></li>
<li>feat: add setup-duration output for deployment timing by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/96">https://github.com/palmsoftware/quick-ocp/pull/96</a></li>
<li>feat: add kubeconfig-path output by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/97">https://github.com/palmsoftware/quick-ocp/pull/97</a></li>
<li>feat: add configurable operator wait timeout by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/98">https://github.com/palmsoftware/quick-ocp/pull/98</a></li>
<li>feat: validate numeric inputs before CRC configuration by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/99">https://github.com/palmsoftware/quick-ocp/pull/99</a></li>
<li>feat: add bundle cache hit/miss output by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/100">https://github.com/palmsoftware/quick-ocp/pull/100</a></li>
<li>feat: expand connectivity check to include GitHub API by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/101">https://github.com/palmsoftware/quick-ocp/pull/101</a></li>
<li>feat: add shellcheck to Makefile and CI, fix all findings by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/102">https://github.com/palmsoftware/quick-ocp/pull/102</a></li>
<li>feat: add nightly tests for cluster-monitoring and preload-images by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/103">https://github.com/palmsoftware/quick-ocp/pull/103</a></li>
<li>feat: add proxy configuration support by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/104">https://github.com/palmsoftware/quick-ocp/pull/104</a></li>
<li>fix: add diagnostic output on operator wait timeout by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/105">https://github.com/palmsoftware/quick-ocp/pull/105</a></li>
<li>fix: add diagnostic context on CRC start final failure by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/106">https://github.com/palmsoftware/quick-ocp/pull/106</a></li>
<li>feat: add log grouping for verbose action steps by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/107">https://github.com/palmsoftware/quick-ocp/pull/107</a></li>
<li>fix: improve nightly test reliability with better retry logic and diagnostics by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/108">https://github.com/palmsoftware/quick-ocp/pull/108</a></li>
<li>fix: prevent broken pipe from bypassing CRC start retry logic by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/109">https://github.com/palmsoftware/quick-ocp/pull/109</a></li>
<li>security: pin GitHub Actions to commit SHAs by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/110">https://github.com/palmsoftware/quick-ocp/pull/110</a></li>
<li>security: add SHA256 checksum verification for CRC download by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/111">https://github.com/palmsoftware/quick-ocp/pull/111</a></li>
<li>fix: authenticate GitHub API calls to avoid rate limiting by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/112">https://github.com/palmsoftware/quick-ocp/pull/112</a></li>
<li>perf: consolidate duplicate package installation by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/113">https://github.com/palmsoftware/quick-ocp/pull/113</a></li>
<li>docs: document enableClusterMonitoring resource impact by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/114">https://github.com/palmsoftware/quick-ocp/pull/114</a></li>
<li>docs: add preloadImages usage example to README by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/115">https://github.com/palmsoftware/quick-ocp/pull/115</a></li>
<li>docs: add troubleshooting section to README by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/116">https://github.com/palmsoftware/quick-ocp/pull/116</a></li>
<li>Prepare for v1.0.0 release by @sebrandon1 in <a href="https://github.com/palmsoftware/quick-ocp/pull/117">https://github.com/palmsoftware/quick-ocp/pull/117</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/palmsoftware/quick-ocp/compare/v0...v1.0.0">https://github.com/palmsoftware/quick-ocp/compare/v0...v1.0.0</a></p>
]]></content:encoded></item><item><title>Postman API Onboarding</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/postman-api-onboarding/</link><pubDate>Sat, 18 Jul 2026 06:56:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/postman-api-onboarding/</guid><description>Version updated for https://github.com/postman-cs/postman-api-onboarding-action to version v2.0.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman API Onboarding action automates the process of setting up a new API repository by bootstrapping a workspace, uploading an OpenAPI specification, generating collections and scripts, and running tests. It helps ensure that the project is compliant with standards and practices by linking to Postman Insights and enforcing contract assertions through built-in smoke and contract runs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-api-onboarding-action">https://github.com/postman-cs/postman-api-onboarding-action</a></strong> to version <strong>v2.0.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-api-onboarding">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman API Onboarding action automates the process of setting up a new API repository by bootstrapping a workspace, uploading an OpenAPI specification, generating collections and scripts, and running tests. It helps ensure that the project is compliant with standards and practices by linking to Postman Insights and enforcing contract assertions through built-in smoke and contract runs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): bump the actions group with 2 updates by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/71">https://github.com/postman-cs/postman-api-onboarding-action/pull/71</a></li>
<li>chore(deps-dev): bump the npm-minor-patch group with 2 updates by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/72">https://github.com/postman-cs/postman-api-onboarding-action/pull/72</a></li>
<li>Pin bootstrap v2.9.9 in the composite action by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/73">https://github.com/postman-cs/postman-api-onboarding-action/pull/73</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-api-onboarding-action/compare/v2...v2.0.6">https://github.com/postman-cs/postman-api-onboarding-action/compare/v2...v2.0.6</a></p>
]]></content:encoded></item><item><title>Postman Onboarding AWS Spec Discovery</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/postman-onboarding-aws-spec-discovery/</link><pubDate>Sat, 18 Jul 2026 06:55:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/postman-onboarding-aws-spec-discovery/</guid><description>Version updated for https://github.com/postman-cs/postman-aws-spec-discovery-action to version v2.0.3.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the discovery and export of API specs from AWS services using your existing AWS credentials. It solves the problem of setting up a source-of-truth spec hub for Postman onboarding by automatically detecting providers, resolving specs if they exist locally, and exporting them to Postman. The action supports various AWS services like API Gateway, AppSync, SNS, EventBridge, Lambda, SSM, etc., and can be used in a CI/CD workflow without requiring GitHub tokens.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-aws-spec-discovery-action">https://github.com/postman-cs/postman-aws-spec-discovery-action</a></strong> to version <strong>v2.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-aws-spec-discovery">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the discovery and export of API specs from AWS services using your existing AWS credentials. It solves the problem of setting up a source-of-truth spec hub for Postman onboarding by automatically detecting providers, resolving specs if they exist locally, and exporting them to Postman. The action supports various AWS services like API Gateway, AppSync, SNS, EventBridge, Lambda, SSM, etc., and can be used in a CI/CD workflow without requiring GitHub tokens.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(ci): fast-loop e2e tune-up (P1/P5) by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/31">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/31</a></li>
<li>test(ci): complete deterministic fast-loop gates by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/33">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/33</a></li>
<li>fix(ci): assert rebuilt dist has no drift by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/34">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/34</a></li>
<li>chore(deps): bump the actions group with 3 updates by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/35">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/35</a></li>
<li>chore(deps): bump the npm-minor-patch group with 21 updates by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/36">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/36</a></li>
<li>feat(discovery): audit API Gateway schema coverage by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/37">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/37</a></li>
<li>test(discovery): retain live contract audit proof by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/38">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/38</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/compare/v2...v2.0.3">https://github.com/postman-cs/postman-aws-spec-discovery-action/compare/v2...v2.0.3</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Workspace Bootstrap</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/postman-onboarding-workspace-bootstrap/</link><pubDate>Sat, 18 Jul 2026 06:54:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/postman-onboarding-workspace-bootstrap/</guid><description>Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.9.9.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman Onboarding: Workspace Bootstrap action creates a Postman workspace from an OpenAPI specification, generating baseline, smoke, and contract collections. It automates the process of setting up a comprehensive test suite using RFC-based assertions and supports various protocols like gRPC, SOAP, GraphQL, AsyncAPI, and MCP. The action provides executable contract tests and enforces adherence to industry standards.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-bootstrap-action">https://github.com/postman-cs/postman-bootstrap-action</a></strong> to version <strong>v2.9.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-workspace-bootstrap">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman Onboarding: Workspace Bootstrap action creates a Postman workspace from an OpenAPI specification, generating baseline, smoke, and contract collections. It automates the process of setting up a comprehensive test suite using RFC-based assertions and supports various protocols like gRPC, SOAP, GraphQL, AsyncAPI, and MCP. The action provides executable contract tests and enforces adherence to industry standards.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(bootstrap): preserve undocumented response bodies by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/95">https://github.com/postman-cs/postman-bootstrap-action/pull/95</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.9.9">https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.9.9</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Repo Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/postman-onboarding-repo-sync/</link><pubDate>Sat, 18 Jul 2026 06:53:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/postman-onboarding-repo-sync/</guid><description>Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.1.7.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of exporting Postman collections and environments into a repository and setting up CI, mock servers, and monitors. It helps streamline the setup of API development environments by integrating with Postman’s APIs and GitHub actions to manage configurations efficiently. The action supports various inputs for customizing the sync process, including workspace IDs, collection IDs, environment settings, and more.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-repo-sync-action">https://github.com/postman-cs/postman-repo-sync-action</a></strong> to version <strong>v2.1.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-repo-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of exporting Postman collections and environments into a repository and setting up CI, mock servers, and monitors. It helps streamline the setup of API development environments by integrating with Postman&rsquo;s APIs and GitHub actions to manage configurations efficiently. The action supports various inputs for customizing the sync process, including workspace IDs, collection IDs, environment settings, and more.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v2...v2.1.7">https://github.com/postman-cs/postman-repo-sync-action/compare/v2...v2.1.7</a></p>
]]></content:encoded></item><item><title>Pipeline Pling</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/pipeline-pling/</link><pubDate>Sat, 18 Jul 2026 06:52:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/pipeline-pling/</guid><description>Version updated for https://github.com/Qbox-project/pipeline-pling to version v1.2.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Pipeline Pling is an action that automates the creation of readable Discord notifications from GitHub pushes, providing features such as customizable appearance, branch filtering, privacy controls, and retry mechanisms. It integrates with Discord’s webhook system to deliver push notifications directly to a specified channel.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Qbox-project/pipeline-pling">https://github.com/Qbox-project/pipeline-pling</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pipeline-pling">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Pipeline Pling is an action that automates the creation of readable Discord notifications from GitHub pushes, providing features such as customizable appearance, branch filtering, privacy controls, and retry mechanisms. It integrates with Discord&rsquo;s webhook system to deliver push notifications directly to a specified channel.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(deps): update GitHub Actions clients by @pushkart2 in <a href="https://github.com/Qbox-project/pipeline-pling/pull/2">https://github.com/Qbox-project/pipeline-pling/pull/2</a></li>
<li>feat: add customization options from issue #1 by @ChatDisabled in <a href="https://github.com/Qbox-project/pipeline-pling/pull/3">https://github.com/Qbox-project/pipeline-pling/pull/3</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@pushkart2 made their first contribution in <a href="https://github.com/Qbox-project/pipeline-pling/pull/2">https://github.com/Qbox-project/pipeline-pling/pull/2</a></li>
<li>@ChatDisabled made their first contribution in <a href="https://github.com/Qbox-project/pipeline-pling/pull/3">https://github.com/Qbox-project/pipeline-pling/pull/3</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Qbox-project/pipeline-pling/compare/v1.1.0...v1.2.0">https://github.com/Qbox-project/pipeline-pling/compare/v1.1.0...v1.2.0</a></p>
]]></content:encoded></item><item><title>Remyx Outrider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/remyx-outrider/</link><pubDate>Sat, 18 Jul 2026 06:51:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/remyx-outrider/</guid><description>Version updated for https://github.com/remyxai/outrider to version v1.7.34.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of validating and comparing new machine learning methods against existing codebases. It schedules runs weekly or allows for ad-hoc dispatches based on user inputs, providing self-review notes, issues, and a selection narrative in the step summary. The action uses pluggable model backends like Anthropic Opus and z.ai GLM-5.2 to evaluate candidates, with options for branch-only mode and cost considerations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remyxai/outrider">https://github.com/remyxai/outrider</a></strong> to version <strong>v1.7.34</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/remyx-outrider">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of validating and comparing new machine learning methods against existing codebases. It schedules runs weekly or allows for ad-hoc dispatches based on user inputs, providing self-review notes, issues, and a selection narrative in the step summary. The action uses pluggable model backends like Anthropic Opus and z.ai GLM-5.2 to evaluate candidates, with options for branch-only mode and cost considerations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="new">New</h2>
<p><strong>AI-agent scaffolding</strong> (<a href="https://github.com/remyxai/outrider/pull/99">PR #99</a>) — the meta-layer around the codebase so future AI-agent sessions load context on entry instead of re-deriving it. Score under <a href="https://github.com/paladini/harness-score">paladini/harness-score</a>: <strong>L0 → L2 · 70%</strong>.</p>
<p>Landed:</p>
<ul>
<li><code>AGENTS.md</code> at repo root — architecture, build &amp; test, backend routing, chain phases, release conventions, guardrails.</li>
<li>Scoped rules per code area — <code>.github/instructions/*.instructions.md</code> for <code>src/run.py</code>, <code>tests/</code>, <code>action.yml</code>.</li>
<li>Two Claude Code skills — <code>outrider-experimentation</code> (user-facing field guide: dispatch patterns, log parsing, coordination checks, fidelity audit reading) and <code>remyxai-cli</code> (CLI context).</li>
<li><code>/release</code> slash command codifying the tag → push → <code>gh release create</code> → v1-move sequence.</li>
<li>Hooks — <code>PreToolUse</code> Bash gate (denies force-push main, <code>--no-verify</code>, destructive <code>rm -rf</code>, <code>git reset --hard main</code>) and <code>PostToolUse</code> reminders after <code>src/run.py</code> / <code>action.yml</code> / <code>docs/</code> edits.</li>
</ul>
<h2 id="fixed">Fixed</h2>
<p><strong>docs term drift</strong> — <code>docs/customization.md</code> referenced <code>pin-method</code> as if it were a real action input; the actual input is <code>search-method</code>. Fixed so the docs match <code>action.yml</code> and the <code>Unexpected input(s) 'pin-method'</code> warning stops appearing on smoke workflows generated from the doc&rsquo;s example shape.</p>
<h2 id="compatibility">Compatibility</h2>
<p>Backward-compatible. No runtime code changes; scaffolding is entirely additive. <code>remyxai/outrider@v1</code> now points to v1.7.34.</p>
]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/rumdl-action/</link><pubDate>Sat, 18 Jul 2026 06:50:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.35.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary
rumdl is a high-performance Markdown linter and formatter built in Rust. It aims to improve the linting experience by offering speed, numerous lint rules covering common Markdown issues, automatic formatting with fixable violations, zero dependencies, highly configurable via TOML, support for multiple Markdown flavors, and various installation options for different platforms including Rust, Python, npm, pip, uv, mise, Nix, Termux User Repository (TUR), Arch Linux, and standalone binaries.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.35</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary</strong></p>
<p>rumdl is a high-performance Markdown linter and formatter built in Rust. It aims to improve the linting experience by offering speed, numerous lint rules covering common Markdown issues, automatic formatting with fixable violations, zero dependencies, highly configurable via TOML, support for multiple Markdown flavors, and various installation options for different platforms including Rust, Python, npm, pip, uv, mise, Nix, Termux User Repository (TUR), Arch Linux, and standalone binaries.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>cli</strong>: honor &ndash;deny-config-warnings on the stdin path (<a href="https://github.com/rvben/rumdl/commit/0f93ca5187176e459bbbae4a43a8468983ae8176">0f93ca5</a>)</li>
<li><strong>cli</strong>: make &ndash;deny-config-warnings cover inline disable-comment rule names (<a href="https://github.com/rvben/rumdl/commit/96d75f56b5f114983ec1163413d779f48a2ad8e7">96d75f5</a>)</li>
<li><strong>cli</strong>: add &ndash;deny-config-warnings for config-file and CLI-flag problems (<a href="https://github.com/rvben/rumdl/commit/5045daf52e13d0e308740df7253177f24411a0e7">5045daf</a>)</li>
<li><strong>reflow</strong>: support breaking within emphasis spans (<a href="https://github.com/rvben/rumdl/commit/2e8bded170f917ab00deef193aa5996a301c3bd4">2e8bded</a>)</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>reflow</strong>: preserve non-breaking spaces and the space before French double punctuation (<a href="https://github.com/rvben/rumdl/commit/f66021f067713fa28b481a457cb99b3dc7a7804b">f66021f</a>)</li>
<li><strong>cli</strong>: walk directory arguments even when file paths are also passed (<a href="https://github.com/rvben/rumdl/commit/d058273dd177eb0d41059215c21cb1e598a3ab18">d058273</a>)</li>
<li><strong>lsp</strong>: honor line anchors in goto-definition (<a href="https://github.com/rvben/rumdl/commit/17a21e796f6f18ef1abf88e7b64d2a7f33647987">17a21e7</a>)</li>
<li><strong>md077</strong>: attribute middle-level continuation lines to their own list item (<a href="https://github.com/rvben/rumdl/commit/c73763ba2e0149548703e8733346967e1eca1d28">c73763b</a>)</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.35/rumdl-v0.2.35-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.35-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.35/rumdl-v0.2.35-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.35/rumdl-v0.2.35-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.35-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.35/rumdl-v0.2.35-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.35/rumdl-v0.2.35-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.35-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.35/rumdl-v0.2.35-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.35/rumdl-v0.2.35-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.35-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.35/rumdl-v0.2.35-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.35/rumdl-v0.2.35-x86_64-apple-darwin.tar.gz">rumdl-v0.2.35-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.35/rumdl-v0.2.35-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.35/rumdl-v0.2.35-aarch64-apple-darwin.tar.gz">rumdl-v0.2.35-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.35/rumdl-v0.2.35-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.35/rumdl-v0.2.35-x86_64-pc-windows-msvc.zip">rumdl-v0.2.35-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.35/rumdl-v0.2.35-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>ForgeProof Verify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/forgeproof-verify/</link><pubDate>Sat, 18 Jul 2026 06:48:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/forgeproof-verify/</guid><description>Version updated for https://github.com/ryanjmichie-git/forgeproof-verify to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the verification of ForgeProof .rpack bundles in pull requests. It checks that the bundle’s root digest, signature, provenance chain, and all recorded artifacts are intact, ensuring AI-generated code remains secure. The action posts a human-readable audit report as a PR comment if enabled, and fails the check on tampering or missing evidence.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ryanjmichie-git/forgeproof-verify">https://github.com/ryanjmichie-git/forgeproof-verify</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/forgeproof-verify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the verification of ForgeProof <code>.rpack</code> bundles in pull requests. It checks that the bundle&rsquo;s root digest, signature, provenance chain, and all recorded artifacts are intact, ensuring AI-generated code remains secure. The action posts a human-readable audit report as a PR comment if enabled, and fails the check on tampering or missing evidence.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Re-vendors the ForgeProof engine to plugin <strong>v1.2.1</strong>, which closes an unsigned-bundle forgery: stripping a bundle&rsquo;s signature and resealing the keyless public <code>root_digest</code> previously verified green, so a tampered PR could pass this Action&rsquo;s check. The vendored verifier now rejects any bundle without a valid signature.</p>
<ul>
<li><code>verifier/forgeproof.py</code> → plugin v1.2.1 (sha256 <code>008470c3…</code>); <code>verifier/UPSTREAM</code> re-pinned to <code>ref=v1.2.1</code>. <code>sync-check</code> green.</li>
<li>New <code>signature-removed</code> tamper-matrix case (strip signature + reseal digest → red). Green on the old engine, red now — guards the fix.</li>
</ul>
<p>The floating <code>v1</code> tag now points here, so <code>uses: ryanjmichie-git/forgeproof-verify@v1</code> picks up the fix automatically.</p>
]]></content:encoded></item><item><title>nix init</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/nix-init/</link><pubDate>Sat, 18 Jul 2026 06:47:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/nix-init/</guid><description>Version updated for https://github.com/spotdemo4/nix-init to version v1.59.0.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action initializes a Nix-based repository by automating several key tasks such as setting up Git user configurations, installing Nix from a cache, and applying configuration settings from a flake. It also provides options for creating a GitHub App token and using caching with niks3. The action runs efficiently in less than one minute and works across self-hosted and managed runners like GitHub Actions, Gitea, and Forgejo.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spotdemo4/nix-init">https://github.com/spotdemo4/nix-init</a></strong> to version <strong>v1.59.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nix-init">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action initializes a Nix-based repository by automating several key tasks such as setting up Git user configurations, installing Nix from a cache, and applying configuration settings from a flake. It also provides options for creating a GitHub App token and using caching with <code>niks3</code>. The action runs efficiently in less than one minute and works across self-hosted and managed runners like GitHub Actions, Gitea, and Forgejo.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update cachix/install-nix-action action to v31.11.0 (#164) (41c29115426f53d0a85dafd40f47441d9ada0e36)</li>
<li>bump: v1.58.0 -&gt; v1.59.0 (c0437e8d7de78564b4c3a1db710f43ce407e509b)</li>
<li>chore(deps): update github actions to v1.58.0 (#163) (0482a4f731ec935cf88f924e83dde212d32920aa)</li>
</ul>
]]></content:encoded></item><item><title>GitGalaxy Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/gitgalaxy-scanner/</link><pubDate>Sat, 18 Jul 2026 06:46:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/gitgalaxy-scanner/</guid><description>Version updated for https://github.com/squid-protocol/gitgalaxy to version v2.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GitGalaxy is a tool that provides a comprehensive macro-level view of software architectures across the entire repository. It automates the process of understanding the network dependencies and identifying local folder constraints, mapping out the exact flow of information across different languages and tasks. This allows for more efficient DevSecOps operations by providing detailed insights into codebase risks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/squid-protocol/gitgalaxy">https://github.com/squid-protocol/gitgalaxy</a></strong> to version <strong>v2.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gitgalaxy-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>GitGalaxy is a tool that provides a comprehensive macro-level view of software architectures across the entire repository. It automates the process of understanding the network dependencies and identifying local folder constraints, mapping out the exact flow of information across different languages and tasks. This allows for more efficient DevSecOps operations by providing detailed insights into codebase risks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="gitgalaxy-v240-planetary-scale-cd-integration">GitGalaxy v2.4.0: Planetary Scale CD Integration</h1>
<p>GitGalaxy v2.4.0 is focused on ecosystem integration and community outreach. Our primary goal with this milestone is to make GitGalaxy deployable in the vast majority of corporate DevSecOps environments in under 5 minutes. This means meeting developers where they already work by deploying our tool across GitLab, Azure DevOps, and Bitbucket, alongside our existing GitHub distribution.</p>
<p>In short: GitGalaxy is now natively integrated into the security dashboards of GitHub, GitLab, Azure, and Bitbucket.</p>
<p>GitHub remains our active development hub. From there, automated workflows push read-only clones to the other platforms, triggering GitGalaxy as a native CI security gate in each ecosystem whenever code is pushed. Repositories on external sites have been strictly locked down to funnel all active development and contributions back to GitHub.</p>
<h3 id="the-deploy-anywhere-cicd-matrix">The &ldquo;Deploy Anywhere&rdquo; CI/CD Matrix</h3>
<ul>
<li><strong>What we did:</strong> Engineered and validated plug-and-play pipeline templates for Azure DevOps, GitLab CI, Bitbucket Pipelines, and GitHub Actions. This includes custom utilities, like a native Bitbucket Code Insights REST integration, to publish inline PR annotations. We also resolved pipeline regressions by fixing YAML syntax failures and Azure basic authentication parsing errors.</li>
<li><strong>What this allows:</strong> This removes the guesswork from wiring GitGalaxy into your infrastructure. DevOps engineers can simply copy our pre-built YAML templates into their repositories to deploy GitGalaxy as a native security gate. For example, if a developer pushes risky code on Bitbucket, our new REST utility will overlay a warning directly onto the relevant line of code in the Pull Request view.</li>
</ul>
<h3 id="universal-sarif-exporting--native-dashboards">Universal SARIF Exporting &amp; Native Dashboards</h3>
<ul>
<li><strong>What we did:</strong> Built the Universal SARIF Exporter and implemented alert sanitization algorithms that zero out threat arrays for ignored paths.</li>
<li><strong>What this allows:</strong> GitGalaxy now automatically translates its calculated risk indicators (derived from raw regular expression keyword hit distributions) into industry-standard SARIF payloads. Your security findings will populate directly inside native UI dashboards like GitHub Advanced Security and GitLab Ultimate. The new sanitization rules also significantly reduce ghost alerts, keeping your dashboard focused on actionable threats.</li>
</ul>
<h3 id="cli-quality-gating">CLI Quality Gating</h3>
<ul>
<li><strong>What we did:</strong> Injected new systemic threat gating parameters (such as <code>max_system_threat</code>) directly into the core orchestrator and worked to reduce false-positive security signatures across the core internal SAST engines.</li>
<li><strong>What this allows:</strong> You can configure CI/CD pipelines to explicitly fail and block a merge if the structural risk exceeds customized thresholds. The CLI output is also cleaner, giving developers immediate and clear feedback in their terminal when a build fails.</li>
</ul>
<h3 id="air-gapped-reliability--core-upgrades">Air-Gapped Reliability &amp; Core Upgrades</h3>
<ul>
<li><strong>What we did:</strong> Implemented configuration file support via <code>.galaxyscope.yaml</code> to enforce global repository scanning rules and patched supply chain firewall bypasses. We enforced explicit zero-dependency mode fallbacks and hardened the Python execution environment by bumping core dependencies (CodeQL to 4.37.0, pytest to 9.1.1, and tiktoken to 0.13.0).</li>
<li><strong>What this allows:</strong> GitGalaxy is hardened for sterile environments. The zero-dependency fallback ensures the engine can execute inside air-gapped CI/CD runners without internet access. Security teams can also mandate directory exclusions and custom risk policies across massive monorepos using a single <code>.galaxyscope.yaml</code> file.</li>
</ul>
]]></content:encoded></item><item><title>gw - Go workspaces</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/gw-go-workspaces/</link><pubDate>Sat, 18 Jul 2026 06:45:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/gw-go-workspaces/</guid><description>Version updated for https://github.com/Toyz/gw to version v0.10.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The gw GitHub Action is a tool designed for managing Go monorepos by automating tasks such as generating and maintaining a unified go.work file, ensuring consistent dependency versions across modules, running commands in each module, and linting dependencies. It helps streamline the workflow of multi-module Go projects, reducing manual effort and improving collaboration among developers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Toyz/gw">https://github.com/Toyz/gw</a></strong> to version <strong>v0.10.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gw-go-workspaces">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>gw</code> GitHub Action is a tool designed for managing Go monorepos by automating tasks such as generating and maintaining a unified <code>go.work</code> file, ensuring consistent dependency versions across modules, running commands in each module, and linting dependencies. It helps streamline the workflow of multi-module Go projects, reducing manual effort and improving collaboration among developers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Toyz/gw/compare/v0...v0.10.2">https://github.com/Toyz/gw/compare/v0...v0.10.2</a></p>
]]></content:encoded></item><item><title>BlissOS-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/blissos-vm/</link><pubDate>Sat, 18 Jul 2026 06:44:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/blissos-vm/</guid><description>Version updated for https://github.com/vmactions/blissos-vm to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the setup and execution of continuous integration (CI) workflows on BlissOS, a high-performance Android device OS. It simplifies the process of building and testing applications on BlissOS by handling the complex configuration and setup required to run CI in BlissOS environments. The action supports multiple releases and architectures and can be used with different sync methods to share code between the host and VM.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/blissos-vm">https://github.com/vmactions/blissos-vm</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/blissos-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the setup and execution of continuous integration (CI) workflows on BlissOS, a high-performance Android device OS. It simplifies the process of building and testing applications on BlissOS by handling the complex configuration and setup required to run CI in BlissOS environments. The action supports multiple releases and architectures and can be used with different sync methods to share code between the host and VM.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The prepare step (installing packages etc.) normally runs on every build. With cache-after-prepare: true, the action shuts the VM down cleanly after prepare has finished, caches the prepared VM image, and boots the VM again before run. Later runs with the same prepare script restore the prepared image, skip prepare entirely, and start directly at run</p>
<p><a href="https://github.com/vmactions/blissos-vm#10-cache-the-vm-image-after-prepare">https://github.com/vmactions/blissos-vm#10-cache-the-vm-image-after-prepare</a></p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/blissos-vm/compare/v1...v1.0.1">https://github.com/vmactions/blissos-vm/compare/v1...v1.0.1</a></p>
]]></content:encoded></item><item><title>GhostBSD-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/ghostbsd-vm/</link><pubDate>Sat, 18 Jul 2026 06:43:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/ghostbsd-vm/</guid><description>Version updated for https://github.com/vmactions/ghostbsd-vm to version v1.0.2.
This action is used across all versions by 27 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action vmactions/ghostbsd-vm enables running CI in GhostBSD, a popular BSD distribution. It automates the process of setting up and managing virtual machines for testing or deployment tasks specific to GhostBSD. The action allows users to run commands and tests within a GhostBSD environment, with options to share files via rsync, sshfs, nfs, or scp, sync working directories, and more.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/ghostbsd-vm">https://github.com/vmactions/ghostbsd-vm</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>27</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ghostbsd-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>vmactions/ghostbsd-vm</code> enables running CI in GhostBSD, a popular BSD distribution. It automates the process of setting up and managing virtual machines for testing or deployment tasks specific to GhostBSD. The action allows users to run commands and tests within a GhostBSD environment, with options to share files via rsync, sshfs, nfs, or scp, sync working directories, and more.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The prepare step (installing packages etc.) normally runs on every build. With cache-after-prepare: true, the action shuts the VM down cleanly after prepare has finished, caches the prepared VM image, and boots the VM again before run. Later runs with the same prepare script restore the prepared image, skip prepare entirely, and start directly at run</p>
<p><a href="https://github.com/vmactions/ghostbsd-vm#10-cache-the-vm-image-after-prepare">https://github.com/vmactions/ghostbsd-vm#10-cache-the-vm-image-after-prepare</a></p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/ghostbsd-vm/compare/v1...v1.0.2">https://github.com/vmactions/ghostbsd-vm/compare/v1...v1.0.2</a></p>
]]></content:encoded></item><item><title>Haiku-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/haiku-vm/</link><pubDate>Sat, 18 Jul 2026 06:42:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/haiku-vm/</guid><description>Version updated for https://github.com/vmactions/haiku-vm to version v1.1.3.
This action is used across all versions by 52 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the setup of a CI environment on Haiku, providing features such as AI-based workflow creation, automatic selection of compatible releases and architectures, SSHFS, NFS, or SCP code synchronization, and NAT port forwarding between the host runner and the VM. It simplifies the process of running tests and building projects on Haiku by handling many common setup tasks automatically.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/haiku-vm">https://github.com/vmactions/haiku-vm</a></strong> to version <strong>v1.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>52</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/haiku-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the setup of a CI environment on Haiku, providing features such as AI-based workflow creation, automatic selection of compatible releases and architectures, SSHFS, NFS, or SCP code synchronization, and NAT port forwarding between the host runner and the VM. It simplifies the process of running tests and building projects on Haiku by handling many common setup tasks automatically.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The prepare step (installing packages etc.) normally runs on every build. With cache-after-prepare: true, the action shuts the VM down cleanly after prepare has finished, caches the prepared VM image, and boots the VM again before run. Later runs with the same prepare script restore the prepared image, skip prepare entirely, and start directly at run</p>
<p><a href="https://github.com/vmactions/haiku-vm#10-cache-the-vm-image-after-prepare">https://github.com/vmactions/haiku-vm#10-cache-the-vm-image-after-prepare</a></p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/haiku-vm/compare/v1...v1.1.3">https://github.com/vmactions/haiku-vm/compare/v1...v1.1.3</a></p>
]]></content:encoded></item><item><title>MidnightBSD-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/midnightbsd-vm/</link><pubDate>Sat, 18 Jul 2026 06:40:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/midnightbsd-vm/</guid><description>Version updated for https://github.com/vmactions/midnightbsd-vm to version v1.0.4.
This action is used across all versions by 34 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action vmactions/midnightbsd-vm is designed to run CI on MidnightBSD. It automates the setup and execution of tests on this popular BSD distribution by managing the environment, copying files, and running commands within a VM. The action supports various releases and architectures, including x86_64, and can be configured to use different synchronization methods like rsync, sshfs, or nfs. It also allows for passing environment variables and customizing the shell used during execution.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/midnightbsd-vm">https://github.com/vmactions/midnightbsd-vm</a></strong> to version <strong>v1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>34</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/midnightbsd-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>vmactions/midnightbsd-vm</code> is designed to run CI on MidnightBSD. It automates the setup and execution of tests on this popular BSD distribution by managing the environment, copying files, and running commands within a VM. The action supports various releases and architectures, including x86_64, and can be configured to use different synchronization methods like <code>rsync</code>, <code>sshfs</code>, or <code>nfs</code>. It also allows for passing environment variables and customizing the shell used during execution.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The prepare step (installing packages etc.) normally runs on every build. With cache-after-prepare: true, the action shuts the VM down cleanly after prepare has finished, caches the prepared VM image, and boots the VM again before run. Later runs with the same prepare script restore the prepared image, skip prepare entirely, and start directly at run</p>
<p><a href="https://github.com/vmactions/midnightbsd-vm#10-cache-the-vm-image-after-prepare">https://github.com/vmactions/midnightbsd-vm#10-cache-the-vm-image-after-prepare</a></p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/midnightbsd-vm/compare/v1...v1.0.4">https://github.com/vmactions/midnightbsd-vm/compare/v1...v1.0.4</a></p>
]]></content:encoded></item><item><title>OpenIndiana-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/openindiana-vm/</link><pubDate>Sat, 18 Jul 2026 06:39:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/openindiana-vm/</guid><description>Version updated for https://github.com/vmactions/openindiana-vm to version v1.1.4.
This action is used across all versions by 61 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, vmactions/openindiana-vm, automates CI testing on OpenIndiana systems. It allows users to run their CI workflows in an OpenIndiana virtual machine and is particularly useful for ensuring compatibility with 64-bit x86_64 architecture environments. The action supports various release versions of OpenIndiana, including fresh and build environments, and includes features such as environment variable forwarding, command execution, file synchronization, and directory mounting to facilitate seamless CI testing across different OSes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/openindiana-vm">https://github.com/vmactions/openindiana-vm</a></strong> to version <strong>v1.1.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>61</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/openindiana-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>vmactions/openindiana-vm</code>, automates CI testing on OpenIndiana systems. It allows users to run their CI workflows in an OpenIndiana virtual machine and is particularly useful for ensuring compatibility with 64-bit x86_64 architecture environments. The action supports various release versions of OpenIndiana, including fresh and build environments, and includes features such as environment variable forwarding, command execution, file synchronization, and directory mounting to facilitate seamless CI testing across different OSes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The prepare step (installing packages etc.) normally runs on every build. With cache-after-prepare: true, the action shuts the VM down cleanly after prepare has finished, caches the prepared VM image, and boots the VM again before run. Later runs with the same prepare script restore the prepared image, skip prepare entirely, and start directly at run</p>
<p><a href="https://github.com/vmactions/openindiana-vm#10-cache-the-vm-image-after-prepare">https://github.com/vmactions/openindiana-vm#10-cache-the-vm-image-after-prepare</a></p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/openindiana-vm/compare/v1...v1.1.4">https://github.com/vmactions/openindiana-vm/compare/v1...v1.1.4</a></p>
]]></content:encoded></item><item><title>Tribblix-vm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/tribblix-vm/</link><pubDate>Sat, 18 Jul 2026 06:38:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/tribblix-vm/</guid><description>Version updated for https://github.com/vmactions/tribblix-vm to version v1.0.3.
This action is used across all versions by 27 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Run GitHub CI in Tribblix action is designed to enable running CI workflows on the Tribblix operating system. It provides an AI-ready feature that automatically generates the necessary GitHub Actions YAML configuration based on user input, handling tasks such as setting up toolchains, installing dependencies, and managing environment variables. Key capabilities include support for various VM releases, different architectures, and methods of code synchronization (e.g., rsync, sshfs, nfs). The action simplifies the process of setting up CI pipelines in Tribblix by automating common setup tasks and reducing the need to manually configure each pipeline.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vmactions/tribblix-vm">https://github.com/vmactions/tribblix-vm</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>27</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tribblix-vm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>Run GitHub CI in Tribblix</code> action is designed to enable running CI workflows on the Tribblix operating system. It provides an AI-ready feature that automatically generates the necessary GitHub Actions YAML configuration based on user input, handling tasks such as setting up toolchains, installing dependencies, and managing environment variables. Key capabilities include support for various VM releases, different architectures, and methods of code synchronization (e.g., rsync, sshfs, nfs). The action simplifies the process of setting up CI pipelines in Tribblix by automating common setup tasks and reducing the need to manually configure each pipeline.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The prepare step (installing packages etc.) normally runs on every build. With cache-after-prepare: true, the action shuts the VM down cleanly after prepare has finished, caches the prepared VM image, and boots the VM again before run. Later runs with the same prepare script restore the prepared image, skip prepare entirely, and start directly at run</p>
<p><a href="https://github.com/vmactions/tribblix-vm#10-cache-the-vm-image-after-prepare">https://github.com/vmactions/tribblix-vm#10-cache-the-vm-image-after-prepare</a></p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vmactions/tribblix-vm/compare/v1...v1.0.3">https://github.com/vmactions/tribblix-vm/compare/v1...v1.0.3</a></p>
]]></content:encoded></item><item><title>Legion Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/legion-runner/</link><pubDate>Sat, 18 Jul 2026 06:36:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/legion-runner/</guid><description>Version updated for https://github.com/Wraith-security/Legion_runner to version v1.0.42.
This action is used across all versions by 8 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Legion Runner is an open-source action that secures GitHub Actions by monitoring and blocking outbound connections based on allowlists. It records processes associated with outbound traffic and detects file tampering during job execution. The Action runs locally without dependencies and can be used to enhance the security of CI pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Wraith-security/Legion_runner">https://github.com/Wraith-security/Legion_runner</a></strong> to version <strong>v1.0.42</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/legion-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Legion Runner is an open-source action that secures GitHub Actions by monitoring and blocking outbound connections based on allowlists. It records processes associated with outbound traffic and detects file tampering during job execution. The Action runs locally without dependencies and can be used to enhance the security of CI pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Feature/production by @OpenSource-For-Freedom in <a href="https://github.com/Wraith-security/Legion_runner/pull/54">https://github.com/Wraith-security/Legion_runner/pull/54</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Wraith-security/Legion_runner/compare/v1...v1.0.42">https://github.com/Wraith-security/Legion_runner/compare/v1...v1.0.42</a></p>
]]></content:encoded></item><item><title>Sparda MCP</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/sparda-mcp/</link><pubDate>Sat, 18 Jul 2026 06:35:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/18/sparda-mcp/</guid><description>Version updated for https://github.com/zyx77550/sparda to version v0.63.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SPARDA is a compiler that transforms backend behaviors into an abstract, mathematical graph. It helps ensure that all tools (linters, debuggers, deploy gates) can reason about the application’s behavior at compile time, improving efficiency and reducing runtime dependencies. With SPARDA, developers can verify, prove, and execute their applications without exposing them to AI agents or external APIs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zyx77550/sparda">https://github.com/zyx77550/sparda</a></strong> to version <strong>v0.63.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sparda-mcp">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SPARDA is a compiler that transforms backend behaviors into an abstract, mathematical graph. It helps ensure that all tools (linters, debuggers, deploy gates) can reason about the application&rsquo;s behavior at compile time, improving efficiency and reducing runtime dependencies. With SPARDA, developers can verify, prove, and execute their applications without exposing them to AI agents or external APIs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Update to v0.63.0 - sparda_prove live MCP tool.</p>
]]></content:encoded></item><item><title>SDD Validate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/sdd-validate/</link><pubDate>Fri, 17 Jul 2026 22:49:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/sdd-validate/</guid><description>Version updated for https://github.com/juanklagos/spec-driven-development-template to version v1.5.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Spec-Driven Development Template is a practical approach to software development using AI agents. It helps teams plan and validate their projects by writing clear specifications before code creation, ensuring that decisions are documented and traceable. The action automates tasks such as validating spec structures and enforcing rules through an enforcement script. The template provides educational resources for both non-technical founders and technical developers, offering a unified workflow for applying SDD in real projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juanklagos/spec-driven-development-template">https://github.com/juanklagos/spec-driven-development-template</a></strong> to version <strong>v1.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sdd-validate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Spec-Driven Development Template is a practical approach to software development using AI agents. It helps teams plan and validate their projects by writing clear specifications before code creation, ensuring that decisions are documented and traceable. The action automates tasks such as validating spec structures and enforcing rules through an enforcement script. The template provides educational resources for both non-technical founders and technical developers, offering a unified workflow for applying SDD in real projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The biggest release so far — the template becomes an interactive, bilingual SDD school + toolkit:</p>
<ul>
<li>🎛️ <code>/sdd:*</code> slash commands for Claude Code (help, new, spec, gate, close, <strong>tutor</strong>) + Copilot prompt files + portable Agent Skill</li>
<li>🔌 Installable as a plugin: <code>/plugin marketplace add juanklagos/spec-driven-development-template</code></li>
<li>✅ GitHub Action: enforce &ldquo;no code before approved spec&rdquo; in any CI (<code>uses: juanklagos/spec-driven-development-template@v1.5.0</code>)</li>
<li>📖 Docs site with EN/ES search and level badges: <a href="https://juanklagos.github.io/spec-driven-development-template/">https://juanklagos.github.io/spec-driven-development-template/</a></li>
<li>🎓 Interactive course (GitHub Skills format): <a href="https://github.com/juanklagos/aprende-sdd">https://github.com/juanklagos/aprende-sdd</a></li>
<li>📊 SDD dashboard on the MCP HTTP transport, EARS notation, llms.txt, Codespaces devcontainer, auto-generated demo GIF</li>
<li>🔬 Fresh 2026 state-of-the-art research: guide 50</li>
</ul>
<p>Full details in the <a href="https://github.com/juanklagos/spec-driven-development-template/blob/main/CHANGELOG.md">CHANGELOG</a>.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/juanklagos/spec-driven-development-template/compare/v1.4.1...v.1.5.0">https://github.com/juanklagos/spec-driven-development-template/compare/v1.4.1...v.1.5.0</a></p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/neurolink-ai/</link><pubDate>Fri, 17 Jul 2026 22:47:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v9.92.2.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is a universal AI integration platform that simplifies the process of integrating various AI providers into applications. It provides a consistent API across 30+ models and supports a wide range of tools and modalities like text-to-speech, image generation, and music creation. The action automates tasks such as stream processing and intelligent routing, making it easier to integrate AI into various applications efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v9.92.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>NeuroLink is a universal AI integration platform that simplifies the process of integrating various AI providers into applications. It provides a consistent API across 30+ models and supports a wide range of tools and modalities like text-to-speech, image generation, and music creation. The action automates tasks such as stream processing and intelligent routing, making it easier to integrate AI into various applications efficiently.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="9922-2026-07-17"><a href="https://github.com/juspay/neurolink/compare/v9.92.1...v9.92.2">9.92.2</a> (2026-07-17)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(sagemaker):</strong>  fix tool/tool-choice format crash on AI SDK&rsquo;s flat tool shape (<a href="https://github.com/juspay/neurolink/commit/344d628f44fb5a00c0862cc346f51afca8e7473c">344d628</a>)</li>
</ul>
]]></content:encoded></item><item><title>setup-jemalloc</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/setup-jemalloc/</link><pubDate>Fri, 17 Jul 2026 22:46:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/setup-jemalloc/</guid><description>Version updated for https://github.com/kaeawc/setup-jemalloc to version v0.0.5.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action downloads and installs jemalloc, which replaces the default malloc to free up memory left unusable by fragmentation. It supports Linux platforms but requires building with arm64e architecture for macOS and is not supported on Windows. The action ensures atomic installation and idempotence, allowing it to be safely invoked multiple times within a job without interference.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kaeawc/setup-jemalloc">https://github.com/kaeawc/setup-jemalloc</a></strong> to version <strong>v0.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-jemalloc">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action downloads and installs jemalloc, which replaces the default malloc to free up memory left unusable by fragmentation. It supports Linux platforms but requires building with arm64e architecture for macOS and is not supported on Windows. The action ensures atomic installation and idempotence, allowing it to be safely invoked multiple times within a job without interference.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-since-v004">What&rsquo;s changed since v0.0.4</h2>
<ul>
<li><strong>Removed unreachable macOS/Windows dead code</strong> from the Linux-gated action steps (#8, #10): dropped the <code>elif macOS</code>/<code>elif Windows</code> branches that could never execute, the no-op &ldquo;Pacman Tool Setup&rdquo; step, and the orphaned <code>before_install.sh</code>.</li>
<li><strong>Small efficiency cleanups</strong>: no longer re-copies the multi-MB library to <code>/tmp</code> on every cache-hit invocation (staging now happens only on the cache-miss install path), quieter <code>tar xf</code> extraction, and the downloaded tarball is cleaned up after build.</li>
</ul>
<p>No consumer-facing behavior change from v0.0.4 — the same steps run in the same order on Linux, and the cache key is unchanged. This tag simply ensures the published release reflects <code>main</code> including the post-v0.0.4 cleanup.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/kaeawc/setup-jemalloc/compare/v0.0.4...v0.0.5">https://github.com/kaeawc/setup-jemalloc/compare/v0.0.4...v0.0.5</a></p>
]]></content:encoded></item><item><title>Kusari Ingest</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/kusari-ingest/</link><pubDate>Fri, 17 Jul 2026 22:46:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/kusari-ingest/</guid><description>Version updated for https://github.com/kusaridev/kusari-ingest to version v4.5.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The kusari-ingest GitHub Action automates the process of ingesting various artifacts (SBOMs, SLSA attestations) into the Kusari Platform. This action simplifies the integration with Kusari by handling authentication credentials and providing options to generate an SBOM from source or a container image. The action also captures ingestion results and automatically maps components if required, enhancing ease of use for developers and DevOps teams in integrating automated security measures within their workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kusaridev/kusari-ingest">https://github.com/kusaridev/kusari-ingest</a></strong> to version <strong>v4.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kusari-ingest">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The kusari-ingest GitHub Action automates the process of ingesting various artifacts (SBOMs, SLSA attestations) into the Kusari Platform. This action simplifies the integration with Kusari by handling authentication credentials and providing options to generate an SBOM from source or a container image. The action also captures ingestion results and automatically maps components if required, enhancing ease of use for developers and DevOps teams in integrating automated security measures within their workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Update kusari-cli to v2.8.2 by @nchelluri in <a href="https://github.com/kusaridev/kusari-ingest/pull/38">https://github.com/kusaridev/kusari-ingest/pull/38</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/kusaridev/kusari-ingest/compare/v4.4.0...v4.5.0">https://github.com/kusaridev/kusari-ingest/compare/v4.4.0...v4.5.0</a></p>
]]></content:encoded></item><item><title>OctoSTS</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/octosts/</link><pubDate>Fri, 17 Jul 2026 22:45:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/octosts/</guid><description>Version updated for https://github.com/launchdarkly/octosts-action to version v1.4.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 1 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action described in the README facilitates the exchange of a workflow’s identity token for a GitHub token using an OctoSTS service. It automates the process of federating a GitHub repository with a trusted third-party, providing a secure and seamless authentication mechanism without the need to manually generate or manage tokens. This action simplifies the integration of external services into GitHub workflows by automatically managing access permissions based on configured trust policies.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/launchdarkly/octosts-action">https://github.com/launchdarkly/octosts-action</a></strong> to version <strong>v1.4.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>1</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/octosts">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action described in the README facilitates the exchange of a workflow&rsquo;s identity token for a GitHub token using an OctoSTS service. It automates the process of federating a GitHub repository with a trusted third-party, providing a secure and seamless authentication mechanism without the need to manually generate or manage tokens. This action simplifies the integration of external services into GitHub workflows by automatically managing access permissions based on configured trust policies.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Work around bug in octokit by @BehnH in <a href="https://github.com/launchdarkly/octosts-action/pull/9">https://github.com/launchdarkly/octosts-action/pull/9</a></li>
<li>Bump undici from 7.20.0 to 7.24.0 by @dependabot[bot] in <a href="https://github.com/launchdarkly/octosts-action/pull/10">https://github.com/launchdarkly/octosts-action/pull/10</a></li>
<li>chore: [SEC-7924] pin third-party GitHub Actions to commit SHAs by @pkaeding in <a href="https://github.com/launchdarkly/octosts-action/pull/11">https://github.com/launchdarkly/octosts-action/pull/11</a></li>
<li>Update SECURITY.md to reflect bug bounty program by @kparkinson-ld in <a href="https://github.com/launchdarkly/octosts-action/pull/12">https://github.com/launchdarkly/octosts-action/pull/12</a></li>
<li>fix: remediate high &amp; critical Dependabot and Wiz vulnerabilities by @pkaeding in <a href="https://github.com/launchdarkly/octosts-action/pull/13">https://github.com/launchdarkly/octosts-action/pull/13</a></li>
<li>Switch CODEOWNERS to team-cloud-engineering by @Jrc356 in <a href="https://github.com/launchdarkly/octosts-action/pull/16">https://github.com/launchdarkly/octosts-action/pull/16</a></li>
<li>Bump undici from 7.24.0 to 7.28.0 in the npm_and_yarn group across 1 directory by @dependabot[bot] in <a href="https://github.com/launchdarkly/octosts-action/pull/15">https://github.com/launchdarkly/octosts-action/pull/15</a></li>
<li>fix: Exclude the workflow&rsquo;s own repo from configure-git auth by @BehnH in <a href="https://github.com/launchdarkly/octosts-action/pull/17">https://github.com/launchdarkly/octosts-action/pull/17</a></li>
<li>Fix publishing workflow for major tags by @BehnH in <a href="https://github.com/launchdarkly/octosts-action/pull/19">https://github.com/launchdarkly/octosts-action/pull/19</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/launchdarkly/octosts-action/pull/10">https://github.com/launchdarkly/octosts-action/pull/10</a></li>
<li>@pkaeding made their first contribution in <a href="https://github.com/launchdarkly/octosts-action/pull/11">https://github.com/launchdarkly/octosts-action/pull/11</a></li>
<li>@kparkinson-ld made their first contribution in <a href="https://github.com/launchdarkly/octosts-action/pull/12">https://github.com/launchdarkly/octosts-action/pull/12</a></li>
<li>@Jrc356 made their first contribution in <a href="https://github.com/launchdarkly/octosts-action/pull/16">https://github.com/launchdarkly/octosts-action/pull/16</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/launchdarkly/octosts-action/compare/v1...v1.4.0">https://github.com/launchdarkly/octosts-action/compare/v1...v1.4.0</a></p>
]]></content:encoded></item><item><title>E2E Self-Heal</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/e2e-self-heal/</link><pubDate>Fri, 17 Jul 2026 22:44:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/e2e-self-heal/</guid><description>Version updated for https://github.com/Lee-Dongwook/E2E-Self-Heal to version v0.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary A self-healing engine that uses AI to automatically repair broken Playwright E2E tests by diagnosing and patching failing selectors, ensuring tests remain resilient to UI changes. The tool can operate in two modes: auto-heal (re-running the test until it passes) or review (diagnosing why a selector broke and suggesting source-level fixes as inline PR comments). It resolves selectors against the live DOM and checks if each patch resolves to exactly one element before running the test again.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Lee-Dongwook/E2E-Self-Heal">https://github.com/Lee-Dongwook/E2E-Self-Heal</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/e2e-self-heal">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>A self-healing engine that uses AI to automatically repair broken Playwright E2E tests by diagnosing and patching failing selectors, ensuring tests remain resilient to UI changes. The tool can operate in two modes: auto-heal (re-running the test until it passes) or review (diagnosing why a selector broke and suggesting source-level fixes as inline PR comments). It resolves selectors against the live DOM and checks if each patch resolves to exactly one element before running the test again.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>chore(release): 0.4.0</p>
<p>Multi-provider LLM support (OpenAI, Anthropic, Ollama alongside NVIDIA NIM)
via a provider-agnostic LangChain-backed client abstraction.</p>
<p>Co-Authored-By: Claude Opus 4.8 (1M context) <a href="mailto:noreply@anthropic.com">noreply@anthropic.com</a></p>
]]></content:encoded></item><item><title>Lingo.Dev AI Localization</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/lingo.dev-ai-localization/</link><pubDate>Fri, 17 Jul 2026 22:43:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/lingo.dev-ai-localization/</guid><description>Version updated for https://github.com/lingodotdev/lingo.dev to version lingo.dev@0.138.2.
This action is used across all versions by 104 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Lingo GitHub Action automates the continuous localization of text across repositories using the Lingo.dev platform. It simplifies the process of translating content, ensuring consistent and high-quality translations with features like AI-assisted setup and integration with existing translation engines. This action streamlines the localization workflow by automatically handling changes in text files and ensures that only necessary updates are processed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lingodotdev/lingo.dev">https://github.com/lingodotdev/lingo.dev</a></strong> to version <strong><a href="mailto:lingo.dev@0.138.2">lingo.dev@0.138.2</a></strong>.</p>
<ul>
<li>This action is used across all versions by <strong>104</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lingo-dev-ai-localization">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Lingo GitHub Action automates the continuous localization of text across repositories using the Lingo.dev platform. It simplifies the process of translating content, ensuring consistent and high-quality translations with features like AI-assisted setup and integration with existing translation engines. This action streamlines the localization workflow by automatically handling changes in text files and ensures that only necessary updates are processed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="patch-changes">Patch Changes</h3>
<ul>
<li><a href="https://github.com/lingodotdev/lingo.dev/pull/2169">#2169</a> <a href="https://github.com/lingodotdev/lingo.dev/commit/14b34e7868670b6e56a1abddfba3987309afb3fc"><code>14b34e7</code></a> Thanks <a href="https://github.com/cherkanovart">@cherkanovart</a>! - Fix Biome formatter silently skipping files when <code>biome.jsonc</code> uses a grit <code>plugins</code> entry (or any section the bundled Biome can&rsquo;t apply). Previously <code>applyConfiguration</code> threw on such keys, formatting was disabled for the whole file, and the project&rsquo;s configured quote style was dropped — files got committed reformatted to defaults on every run. The <code>plugins</code> key is now excluded before applying config, and any remaining unsupported/unknown section falls back to formatter-only settings so formatting still runs.</li>
</ul>
]]></content:encoded></item><item><title>Blast Radius verify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/blast-radius-verify/</link><pubDate>Fri, 17 Jul 2026 22:42:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/blast-radius-verify/</guid><description>Version updated for https://github.com/Lockelamoree/Blast_Radius to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Blast Radius is a browser-based game designed to help developers practice making safe approval decisions around AI code agents. It offers 20 pre-defined scenarios, a deterministic gate system, and the ability to track action outcomes and evidence with receipts. The application supports multiple browsers and can be run locally or hosted on a server.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Lockelamoree/Blast_Radius">https://github.com/Lockelamoree/Blast_Radius</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/blast-radius-verify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Blast Radius is a browser-based game designed to help developers practice making safe approval decisions around AI code agents. It offers 20 pre-defined scenarios, a deterministic gate system, and the ability to track action outcomes and evidence with receipts. The application supports multiple browsers and can be run locally or hosted on a server.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>A deterministic, offline GitHub Action for teams supervising AI coding agents.
I have designend this project tp help new and upcoming developers with the safe and fun use of ai agents like codex.</p>
<p>This tools help with the gating and decision making process of what commands an agent should actually run on the machine.</p>
<ul>
<li>Gate-verify scenario drafts (<code>scenarios:</code>) against the production Blast Radius correctness gate — exact, safe to require.</li>
<li>Screen a PR diff (<code>diff-base:</code>) for known agent-security red flags: secret reads, unapproved egress, remote-code pipes, and more. This half is a deterministic keyword heuristic, not a proof of safety — start with <code>fail-on: never</code> (advisory) and tighten to <code>sandbox</code>/<code>reject</code> once you trust it.</li>
</ul>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Lockelamoree/Blast_Radius@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">scenarios</span>: <span style="color:#e6db74">&#34;scenarios/*.json&#34;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">diff-base</span>: <span style="color:#ae81ff">${{ github.event.pull_request.base.sha }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">never</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>tofu-garnish</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/tofu-garnish/</link><pubDate>Fri, 17 Jul 2026 22:41:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/tofu-garnish/</guid><description>Version updated for https://github.com/lowlydba/tofu-garnish to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: This GitHub Action automates the process of publishing OpenTofu/Terraform outputs as a static HTML page on GitHub Pages. It provides a user-friendly interface to view and filter Tofu output data, with sensitive information masked automatically. The action is dependency-free, supports structure-aware HTML rendering, and can handle multiple workspaces or tenants efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lowlydba/tofu-garnish">https://github.com/lowlydba/tofu-garnish</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tofu-garnish">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong> This GitHub Action automates the process of publishing OpenTofu/Terraform outputs as a static HTML page on GitHub Pages. It provides a user-friendly interface to view and filter Tofu output data, with sensitive information masked automatically. The action is dependency-free, supports structure-aware HTML rendering, and can handle multiple workspaces or tenants efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li><a href="docs">BUG</a> Balance hero SVG horizontal margins by @lowlydba in <a href="https://github.com/lowlydba/tofu-garnish/pull/6">https://github.com/lowlydba/tofu-garnish/pull/6</a></li>
<li>[BUG] Render scalar lists as unordered bullets instead of numbered list by @lowlydba in <a href="https://github.com/lowlydba/tofu-garnish/pull/7">https://github.com/lowlydba/tofu-garnish/pull/7</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/lowlydba/tofu-garnish/compare/v1.1.0...v1.1.1">https://github.com/lowlydba/tofu-garnish/compare/v1.1.0...v1.1.1</a></p>
]]></content:encoded></item><item><title>Pipelock Agent Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/pipelock-agent-security-scan/</link><pubDate>Fri, 17 Jul 2026 22:40:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/pipelock-agent-security-scan/</guid><description>Version updated for https://github.com/luckyPipewrench/pipelock to version v3.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Pipelock is an open-source AI-driven firewall designed to monitor and secure AI agents by inspecting mediated network traffic. It identifies potential threats such as secret exfiltration, prompt injection, and SSRF, emitting mediator-signed action receipts that third parties can verify outside the agent runtime. This helps ensure the integrity of data transmitted between AI agents and networks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/luckyPipewrench/pipelock">https://github.com/luckyPipewrench/pipelock</a></strong> to version <strong>v3.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pipelock-agent-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Pipelock is an open-source AI-driven firewall designed to monitor and secure AI agents by inspecting mediated network traffic. It identifies potential threats such as secret exfiltration, prompt injection, and SSRF, emitting mediator-signed action receipts that third parties can verify outside the agent runtime. This helps ensure the integrity of data transmitted between AI agents and networks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<h3 id="-bug-fixes">🐛 Bug Fixes</h3>
<ul>
<li>45002497bcdd89722fe06bd05f22673be6edd537 fix(contain): narrow credential guard watches (#1008)</li>
<li>a48d545cc398cca28131c64b6c9544519c0bf074 fix(coveragecert): fail closed when no trusted signer is supplied (#1014)</li>
</ul>
<h3 id="-dependencies">📦 Dependencies</h3>
<ul>
<li>3747656b2ebc8c08ec53774150da838d48b56da7 chore(deps): update dependency setuptools to v83 [security] (#1007)</li>
</ul>
<h3 id="other-changes">Other Changes</h3>
<ul>
<li>7a6f866752605215d2ee820eb10132d464626d49 Add MCP tool-policy example with verify script (#1006)</li>
<li>e0536c4187cdd2611af72c1d5c270a6abc8b5ce1 Add fetch proxy SSRF example with verify script (#1005)</li>
<li>913a051b75094e87c9522ea1d479b07862fc80c4 Add kill switch example with verify script (#1004)</li>
<li>c0715e6b49232e633cd519a382994994285b7e50 Fail closed when replay verification is unpinned (#1016)</li>
<li>8c5ab23ffa59de4c25920fe86c81d4f3bcf6bb58 Fix A2A forward request-body scanning (#1013)</li>
<li>990725b86e7b1c3301b0317ba3df65c1c9274423 Harden security trust boundaries and parser semantics (#1010)</li>
<li>371893f0084ed693c1f69adf6da81c269e84aeff Make executable config examples fail closed in CI (#1011)</li>
<li>51b21d45393afe02cabca54bda8a1324ffb7418e Make startup validation honest and accelerate releases (#1012)</li>
<li>39e93b452e9589a9ba812f09e42c2382c44fac86 chore(ci): fail CI when a shipped config example cannot start (#1009)</li>
<li>ecbe637d64c2d07367bdb38ad5b83632ef2a0454 chore(release): reconcile v3.2.0 changelog, chart version, and broken instructions (#1017)</li>
<li>3850edb71b054f2ee505c7dc4747ec2101bb8f3d chore(release): set v3.2.0 changelog date to the tag date (2026-07-17) (#1019)</li>
<li>ca1eb9a99ea2a388147f89c2376f33cb435bcdea chore(release): stamp v3.2.0 date and add release-readiness gate (#1018)</li>
</ul>
<hr>
<p>📚 Docs: <a href="https://pipelab.org">https://pipelab.org</a>  •  💬 Community: <a href="https://discord.gg/badNfhGKTc">https://discord.gg/badNfhGKTc</a></p>
<p>Pipelock is an open-source agent firewall. Come poke holes in it.</p>
]]></content:encoded></item><item><title>Airlock Migration Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/airlock-migration-guard/</link><pubDate>Fri, 17 Jul 2026 22:38:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/airlock-migration-guard/</guid><description>Version updated for https://github.com/mateuszingano/airlock-migrate to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: Migration Guard is a GitHub Action designed to prevent Supabase/Postgres migration scripts from introducing data leaks or breaking authentication by checking for certain conditions such as tables without RLS, disabled RLS, permissive policies, and dropped policies/triggers. It helps identify potential issues before they reach production, ensuring the integrity of the database schema and security measures are maintained.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mateuszingano/airlock-migrate">https://github.com/mateuszingano/airlock-migrate</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/airlock-migration-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong>
Migration Guard is a GitHub Action designed to prevent Supabase/Postgres migration scripts from introducing data leaks or breaking authentication by checking for certain conditions such as tables without RLS, disabled RLS, permissive policies, and dropped policies/triggers. It helps identify potential issues before they reach production, ensuring the integrity of the database schema and security measures are maintained.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release. <code>uses: mateuszingano/airlock-migrate@v1</code> now resolves. The action runs <code>npx airlock-migrate</code> (published on npm).</p>
]]></content:encoded></item><item><title>ansede-static</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/ansede-static/</link><pubDate>Fri, 17 Jul 2026 22:37:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/ansede-static/</guid><description>Version updated for https://github.com/mattybellx/Ansede to version v6.5.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Ansede is a free static analysis tool that automatically detects authorization bugs like IDOR, missing access controls, and privilege escalation. It performs cross-function analysis to trace data flow from HTTP routes to database queries or other sensitive sinks without relying on network connections or API keys. Ansede is designed to catch these security flaws before attackers do, offering a 100% CVE recall rate across multiple programming languages.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mattybellx/Ansede">https://github.com/mattybellx/Ansede</a></strong> to version <strong>v6.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ansede-static">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Ansede is a free static analysis tool that automatically detects authorization bugs like IDOR, missing access controls, and privilege escalation. It performs cross-function analysis to trace data flow from HTTP routes to database queries or other sensitive sinks without relying on network connections or API keys. Ansede is designed to catch these security flaws before attackers do, offering a 100% CVE recall rate across multiple programming languages.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="630--2026-07-13">[6.3.0] — 2026-07-13</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>CWE-639 IDOR Detection</strong> — World-first among open-source SAST tools. Detects
Insecure Direct Object Reference patterns across Express/DAO (JS), Django ORM
(Python), Flask-SQLAlchemy (Python), and Spring Boot JPA (Java). Identifies route
parameters used in database queries without session/ownership verification.</li>
<li><strong>Variable propagation in fallback detectors</strong> — All three language analyzers
(JS, Python, Java) now trace taint through variable assignments, enabling detection
of patterns like <code>const x = req.query.file</code> → <code>fs.readFile(x)</code>.</li>
<li><strong>Struts2/Spring parameter binding detection</strong> — Java fallback now recognizes
implicit taint sources from framework parameter binding (setters, <code>@RequestParam</code>,
<code>@PathVariable</code>) in addition to explicit <code>getParameter()</code> calls.</li>
<li><strong>Django ORM <code>.raw()</code> propagation</strong> — Multi-hop taint tracing through string
concatenation assignments: <code>name = request.GET.get('q')</code> → <code>sql = &quot;SELECT...&quot; + name</code>
→ <code>Model.objects.raw(sql)</code>.</li>
</ul>
<h3 id="improved">Improved</h3>
<ul>
<li><strong>Known-vulnerability detection: 88.6% → 91.4%</strong> across 4 test applications
(NodeGoat, goof, pygoat, dvja) covering 35 CWE instances.</li>
<li><strong>Production noise: 0.04 findings/kLOC</strong> — Verified across 16 real production
repositories (366,638 LOC). Scanner correctly identifies well-written production
code as clean.</li>
<li><strong>Python fallback cap</strong> — Increased from 20 to 25 with injection CWE prioritization
to prevent CWE-89/CWE-78 truncation.</li>
<li><strong>Java <code>Runtime.exec()</code> pattern</strong> — Now matches <code>runtime.exec(command)</code> where
<code>command</code> is a variable, not just chained <code>.exec(var + &quot;...&quot;)</code>.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>Confidence pipeline bug</strong> — <code>pattern-rust</code> analysis kind now recognized as
structural evidence, preventing false demotion of legitimate findings.</li>
<li><strong>Paren-location bug</strong> — <code>_arg_contains_taint</code> now correctly locates the opening
parenthesis in regex-matched sink patterns across all three language fallbacks.</li>
<li><strong>SQLAlchemy parameterized query FP</strong> — <code>.execute(text(...), {'key': var})</code> now
correctly identified as safe (parameterized).</li>
<li><strong>CWE-22 method-call FP</strong> — <code>f.read()</code>, <code>obj.write()</code> patterns no longer flagged
as path traversal.</li>
<li><strong>Python CWE-22 secure_filename guard</strong> — Files using <code>werkzeug.utils.secure_filename</code>
are now correctly excluded from path traversal detection.</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li>1,215 tests passing (96.4%)</li>
<li>CVE recall: 100% (164/164 across 5 languages)</li>
<li>16-repo production benchmark: 0.04 findings/kLOC average</li>
</ul>
]]></content:encoded></item><item><title>GHGen Workflow Analyzer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/ghgen-workflow-analyzer/</link><pubDate>Fri, 17 Jul 2026 22:36:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/ghgen-workflow-analyzer/</guid><description>Version updated for https://github.com/nigelhorne/App-GHGen to version v6.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GHGen Workflow Analyzer is a GitHub Action that automates the process of generating, analyzing, and optimizing CI workflows. It automatically detects project types and generates workflows with caching, security, concurrency, and best practices built-in. It also analyzes existing workflows for performance bottlenecks, outdated actions, missing security permissions, and wasted CI minutes, and applies safe, intelligent fixes or opens a clean pull request with improvements.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nigelhorne/App-GHGen">https://github.com/nigelhorne/App-GHGen</a></strong> to version <strong>v6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ghgen-workflow-analyzer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>GHGen Workflow Analyzer is a GitHub Action that automates the process of generating, analyzing, and optimizing CI workflows. It automatically detects project types and generates workflows with caching, security, concurrency, and best practices built-in. It also analyzes existing workflows for performance bottlenecks, outdated actions, missing security permissions, and wasted CI minutes, and applies safe, intelligent fixes or opens a clean pull request with improvements.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<pre><code>[ Bug Fixes ]
- Approved https://github.com/nigelhorne/App-GHGen/pull/6
  Missing unescaped $ failed to interpolate variable into double-quoted string
  Thanks to https://github.com/chromatic
- Fixed enable_linter_unused having no effect when set to 1 via the non-interactive code
  path. The POD Params::Validate block (default =&gt; 0) is documentation only; the actual
  runtime default was the // 0 on the assignment line (line 286). Changed to // 1.

[ New Features ]
- Added Perl syntax linting step to generated workflows (enable_linter, default: on)
  Uses shell: perl {0} so it runs cross-platform without OS-specific branching.
  Searches lib/ and bin/, uses do $file with a stub @INC handler for every .pm file,
  and covers every matrix cell (all OS × Perl version combinations).
  No extra CPAN dependencies required.
- Added unused-variable check (enable_linter_unused, default: on). The check is embedded
  inside the lint step and runs PERL5OPT=-Mwarnings::unused prove -lr t/ so variable
  lifetimes are exercised at runtime (perl -c is compile-only and cannot detect unused
  vars). Gated on RUNNER_OS == Linux and continue-on-error: true.
- Added import-hygiene check (enable_perlimports, default: on). Installs App::perlimports
  and runs perlimports --lint across all .pm files under lib/. Scoped to latest Perl +
  ubuntu-latest; continue-on-error: true so it is advisory rather than blocking.
- Both enable_linter_unused and enable_perlimports are exposed in the interactive
  --customize prompt for Perl workflows under the &quot;Code Quality Tools&quot; heading.
- Regression test added in t/pull_6.t for the PR #6 cost-display bug fix.
- Tests added/extended in t/linter.t covering presence/absence, ordering, and
  platform-gating of all lint-stage steps.
- Added t/extended_tests.t: 99 branch-coverage tests targeting uncovered paths across all
  8 modules (Analyzer, CostEstimator, Detector, Fixer, Generator, Interactive,
  PerlCustomizer, Reporter). Flags Analyzer::has_deployment_steps as dead code (defined
  but not exported and not called from analyze_workflow).

[ CI Matrix ]
- Default Perl matrix is now 5.36, 5.38, 5.40, 5.42 (max_perl_version bumped from
  5.40 to 5.42). Perl::Critic, perlimports, and coverage steps are now gated on
  5.42 (always the latest version in the matrix).
- Perl 5.44 added to the known-versions table as an opt-in. Projects wanting to test
  against 5.44 before it becomes the default can pass max_perl_version =&gt; '5.44' to
  generate_custom_perl_workflow, or set perl_versions explicitly. No code change
  needed on the caller's side.
- POD for generate_custom_perl_workflow updated: max_perl_version default corrected to
  5.42, opt-in examples for 5.44 added under the max_perl_version item.
</code></pre>
]]></content:encoded></item><item><title>Run AER Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/run-aer-tests/</link><pubDate>Fri, 17 Jul 2026 22:35:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/run-aer-tests/</guid><description>Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.18.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates running Apex unit tests and executing anonymous Apex code locally without needing an org or sandbox environment. It provides local execution of SOQL, DML, and test data, supports triggers, validation rules, flows, governor limits, and the standard library, with a focus on behavior similar to Salesforce’s Apex runtime. The action can be used in CI/CD pipelines for continuous testing and development.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/octoberswimmer/aer-dist">https://github.com/octoberswimmer/aer-dist</a></strong> to version <strong>v1.2.18</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-aer-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates running Apex unit tests and executing anonymous Apex code locally without needing an org or sandbox environment. It provides local execution of SOQL, DML, and test data, supports triggers, validation rules, flows, governor limits, and the standard library, with a focus on behavior similar to Salesforce&rsquo;s Apex runtime. The action can be used in CI/CD pipelines for continuous testing and development.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Version v1.2.18</p>
<ul>
<li>
<p>Resolve Bare Custom Names Only Via The Executing Namespace</p>
</li>
<li>
<p>Fix Protected Custom Metadata Visibility Across Namespaces And Warm Caches</p>
</li>
<li>
<p>Hard-delete Share Records Instead Of Soft-deleting Them</p>
</li>
<li>
<p>Canonicalize Package SObject Names, Workflow Rules, And Flows At Load</p>
</li>
<li>
<p>Run Record-Triggered Flows In exec And Load Full Sources In exec &ndash;debug</p>
</li>
<li>
<p>Accept Uppercase Escape Letters In String Literals</p>
</li>
<li>
<p>Run Packaged Flows In aer server And Register Them For Flow.Interview</p>
</li>
</ul>
]]></content:encoded></item><item><title>Prowler Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/prowler-security-scan/</link><pubDate>Fri, 17 Jul 2026 22:33:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/prowler-security-scan/</guid><description>Version updated for https://github.com/prowler-cloud/prowler to version 5.35.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Purpose: Prowler is an Open Source Cloud Security Platform designed to automate security and compliance in any cloud environment. It offers a wide range of security checks, remediation guides, and compliance frameworks to help organizations ensure their cloud resources are secure and compliant.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/prowler-cloud/prowler">https://github.com/prowler-cloud/prowler</a></strong> to version <strong>5.35.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/prowler-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Purpose</strong>: <strong>Prowler</strong> is an Open Source Cloud Security Platform designed to automate security and compliance in any cloud environment. It offers a wide range of security checks, remediation guides, and compliance frameworks to help organizations ensure their cloud resources are secure and compliant.</p>
<p><strong>Functionality</strong>: The action automates the scanning and reporting of security findings for AWS accounts using Prowler, which can be used to identify potential vulnerabilities, misconfigurations, and non-compliance issues in your cloud environment. This helps in maintaining a secure and compliant cloud infrastructure by providing real-time monitoring and actionable insights.</p>
<p><strong>Key Capabilities</strong>: The action provides features such as customizable scanning options, integration with CI/CD pipelines, email notifications for security findings, and detailed reports that help organizations identify and address security risks quickly.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="-new-features-to-highlight-in-this-version">✨ New features to highlight in this version</h1>
<p>Enjoy them all now for free at <a href="https://cloud.prowler.com">https://cloud.prowler.com</a></p>
<h2 id="-lighthouse-ai---side-chat">💬 Lighthouse AI - Side Chat</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Private Cloud</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>Lighthouse AI now lives in a side panel you can open from anywhere in the app. Ask about the findings you are looking at without leaving the page, and expand to the full-page chat at any time: your draft, messages, and streaming response come along. Finding and resource details share the same panel, with tabs to switch between Details and Lighthouse AI.</p>
<img width="1664" height="995" alt="lighthouse-ai-side-chat" src="https://github.com/user-attachments/assets/1da5d894-6f12-44a7-ab91-adb24c4e65ee" />
<p>Read more in our <a href="https://docs.prowler.com/getting-started/products/prowler-cloud-lighthouse#side-panel">Lighthouse AI documentation</a>.</p>
<h2 id="-lighthouse-ai---take-action">🤖 Lighthouse AI - Take Action</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Private Cloud</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>Lighthouse AI is no longer read-only. Ask it to do things and it will: connect or remove providers, trigger a scan, schedule daily scans, update scan settings, and manage your mutelist and mute rules, straight from the chat. Every action is gated by RBAC: Lighthouse can only do what the user asking could do themselves.</p>
<p>Read more in our <a href="https://docs.prowler.com/getting-started/products/prowler-cloud-lighthouse#capabilities">Lighthouse AI capabilities</a>.</p>
<h2 id="-one-step-aws-organizations-onboarding">☁️ One-step AWS Organizations onboarding</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Private Cloud</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>Onboarding an entire AWS Organization is now a single step. One CloudFormation quick-create link deploys the management account role and a service-managed StackSet that rolls the role out to every member account, replacing the manual StackSet console setup. Target the whole organization or a specific Organizational Unit or Root ID, and deploy from the management account or a delegated administrator. The S3 integration quick-create link also pre-fills the bucket owner account ID, preventing a stack validation error.</p>
<img width="1167" height="1205" alt="aws-orgs-wizard" src="https://github.com/user-attachments/assets/1bf6a192-fb2b-4bf9-94ba-4fc4fcc400c6" />
<p>Built on the full-organization CloudFormation template contributed by @jchrisfarris — thanks!</p>
<p>Read more in our <a href="https://docs.prowler.com/user-guide/tutorials/prowler-cloud-aws-organizations">AWS Organizations documentation</a>.</p>
<h2 id="-scan-configurations-exclude-checks-and-services">🎯 Scan configurations: exclude checks and services</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Private Cloud</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>Scan configurations now accept <code>excluded_checks</code> and <code>excluded_services</code> to narrow the execution scope. Skip individual checks or entire services per provider, and the scan does not run them at all: less noise, faster scans, and no findings you would mute anyway.</p>
<p>Read more in our <a href="https://docs.prowler.com/user-guide/tutorials/prowler-app-scan-configuration#limiting-the-scan-scope">Scan Configuration documentation</a>.</p>
<h2 id="-redesigned-sidebar-navigation">🧭 Redesigned sidebar navigation</h2>
<p>The sidebar was redesigned around how you actually work: grouped sections for security, settings, and help, a Home/Chat switch at the top, collapsible configuration entries, clearer active states, and a responsive mobile overlay.</p>
<img width="255" height="961" alt="new-menu" src="https://github.com/user-attachments/assets/6f2eb33d-d01f-4f28-b6fd-71f6cae2f510" />
<h2 id="-prowler-mcp-tools-renamed-to-prowler_">🔌 Prowler MCP tools renamed to <code>prowler_*</code></h2>
<p>Core Prowler tools in Prowler MCP moved from the <code>prowler_app_*</code> prefix to the shorter <code>prowler_*</code> namespace, and the MCP documentation was restructured around it. Legacy <code>prowler_app_*</code> names keep working in Lighthouse AI, so existing setups are not broken.</p>
<p>Read more in our <a href="https://docs.prowler.com/getting-started/basic-usage/prowler-mcp-tools">Prowler MCP tools reference</a>.</p>
<h2 id="-security">🔐 Security</h2>
<ul>
<li>Jira integration credentials now only accept bare Atlassian site names (letters, numbers, and hyphens), and Jira tenant information requests validate site names and no longer follow redirects.</li>
<li>Social account linking now requires a verified matching email from both the identity provider and the existing user account, and account connection notification emails are disabled.</li>
<li>13 advisories reported by <code>pnpm audit</code> on the UI (3 high, 9 moderate, 1 low) are resolved with patched versions of <code>hono</code>, <code>ws</code>, <code>vite</code>, <code>dompurify</code>, <code>js-yaml</code>, <code>@opentelemetry/core</code>, and <code>@babel/core</code>, including <code>hono</code> CVE-2026-59896.</li>
</ul>
<h2 id="-external-contributors">🙌 External Contributors</h2>
<p>No external contributors in this release.</p>
<p>Special mention to @jchrisfarris, whose full-organization CloudFormation template from v5.34.0 powers the new one-step AWS Organizations onboarding <a href="https://github.com/prowler-cloud/prowler/pull/10403">(#10403)</a>.</p>
<hr>
<h2 id="ui">UI</h2>
<h3 id="-changed">🔄 Changed</h3>
<ul>
<li>AWS Organizations onboarding now deploys the management account role and the member-account StackSet from a single CloudFormation stack, replacing the manual StackSet console step <a href="https://github.com/prowler-cloud/prowler/pull/11927">(#11927)</a></li>
<li>Dynamic providers can now be renamed and deleted from the Providers table <a href="https://github.com/prowler-cloud/prowler/pull/11957">(#11957)</a></li>
<li>Sidebar navigation with grouped sections, clearer active states, and a responsive mobile overlay <a href="https://github.com/prowler-cloud/prowler/pull/11994">(#11994)</a></li>
<li>Core Prowler tools in Lighthouse use the <code>prowler_*</code> namespace while preserving legacy <code>prowler_app_*</code> compatibility <a href="https://github.com/prowler-cloud/prowler/pull/12017">(#12017)</a></li>
</ul>
<h3 id="-fixed">🐞 Fixed</h3>
<ul>
<li>The AWS S3 integration CloudFormation quick-create link now sets the bucket owner account ID, preventing a stack validation error when S3 integration is enabled <a href="https://github.com/prowler-cloud/prowler/pull/11927">(#11927)</a></li>
<li><code>Scan ID</code> filter on the Findings page now shows the active scan when opening findings from a scan&rsquo;s <code>View Findings</code> action <a href="https://github.com/prowler-cloud/prowler/pull/11997">(#11997)</a></li>
</ul>
<h3 id="-security-1">🔐 Security</h3>
<ul>
<li><code>js-yaml</code> to 4.3.0, <code>@sentry/nextjs</code> to 10.65.0 with <code>import-in-the-middle</code> 3.3.1, and transitive <code>hono</code>, <code>dompurify</code>, <code>ws</code>, <code>vite</code>, <code>@babel/core</code> and <code>@opentelemetry/core</code> to patched versions, resolving 13 npm audit advisories (3 high, 9 moderate, 1 low) plus <code>hono</code> CVE-2026-59896, published on NVD but not yet in the npm audit feed <a href="https://github.com/prowler-cloud/prowler/pull/12029">(#12029)</a></li>
</ul>
<h2 id="api">API</h2>
<h3 id="-fixed-1">🐞 Fixed</h3>
<ul>
<li><code>attack-paths-scan-perform</code> Celery tasks now use the configurable long-task time limits instead of the six-hour defaults <a href="https://github.com/prowler-cloud/prowler/pull/12009">(#12009)</a></li>
<li>Attack Paths scans handle provider deletion races cleanly, detect stale tasks after 16 hours, use backend-specific graph synchronization batches, and report exhausted Neptune write retries with the original database error <a href="https://github.com/prowler-cloud/prowler/pull/12019">(#12019)</a></li>
</ul>
<h3 id="-security-2">🔐 Security</h3>
<ul>
<li>Jira integration credentials only accept bare Atlassian site names containing letters, numbers, and hyphens <a href="https://github.com/prowler-cloud/prowler/pull/12012">(#12012)</a></li>
<li>Social account linking requires a verified matching email from both the identity provider and the existing user account without sending account connection notifications <a href="https://github.com/prowler-cloud/prowler/pull/12013">(#12013)</a></li>
</ul>
<h2 id="sdk">SDK</h2>
<h3 id="-added">🚀 Added</h3>
<ul>
<li><code>excluded_checks</code> and <code>excluded_services</code> in scan configurations to narrow the execution scope <a href="https://github.com/prowler-cloud/prowler/pull/12028">(#12028)</a></li>
</ul>
<h3 id="-security-3">🔐 Security</h3>
<ul>
<li>Jira tenant information requests validate site names and do not follow redirects <a href="https://github.com/prowler-cloud/prowler/pull/12012">(#12012)</a></li>
</ul>
<h2 id="mcp">MCP</h2>
<h3 id="-changed-1">🔄 Changed</h3>
<ul>
<li>Core Prowler tool namespace from the <code>prowler_app_*</code> prefix to <code>prowler_*</code> <a href="https://github.com/prowler-cloud/prowler/pull/12017">(#12017)</a></li>
</ul>
]]></content:encoded></item><item><title>Generate Roq Site</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/generate-roq-site/</link><pubDate>Fri, 17 Jul 2026 22:32:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/generate-roq-site/</guid><description>Version updated for https://github.com/quarkiverse/quarkus-roq to version 2.1.6.
This action is used across all versions by 77 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Roq is a free static site generator built with Java and Quarkus that simplifies the process of creating websites and blogs. It automatically generates HTML files from templates and articles, and offers extensions like Roq Data and Roq FrontMatter for enhanced content management. The GitHub Action integration allows users to deploy their sites directly through Actions, while standalone usage provides flexibility for developers who want to use Quarkus Roq’s features without additional setup.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/quarkiverse/quarkus-roq">https://github.com/quarkiverse/quarkus-roq</a></strong> to version <strong>2.1.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>77</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/generate-roq-site">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Roq is a free static site generator built with Java and Quarkus that simplifies the process of creating websites and blogs. It automatically generates HTML files from templates and articles, and offers extensions like Roq Data and Roq FrontMatter for enhanced content management. The GitHub Action integration allows users to deploy their sites directly through Actions, while standalone usage provides flexibility for developers who want to use Quarkus Roq&rsquo;s features without additional setup.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add tutorial blog posts by @ia3andy in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1036">https://github.com/quarkiverse/quarkus-roq/pull/1036</a></li>
<li>Publish comments tutorials by @ia3andy in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1065">https://github.com/quarkiverse/quarkus-roq/pull/1065</a></li>
<li>Fix bunch of issues from #1068 by @ia3andy in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1071">https://github.com/quarkiverse/quarkus-roq/pull/1071</a></li>
<li>Bump com.fasterxml.jackson.dataformat:jackson-dataformat-yaml from 2.18.2 to 2.22.0 by @dependabot[bot] in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1061">https://github.com/quarkiverse/quarkus-roq/pull/1061</a></li>
<li>Bump quarkus-barcode.version from 1.1.0 to 1.2.0 by @dependabot[bot] in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1060">https://github.com/quarkiverse/quarkus-roq/pull/1060</a></li>
<li>Add variable, filter, file location, and config tables to migration docs by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1045">https://github.com/quarkiverse/quarkus-roq/pull/1045</a></li>
<li>Bump io.vertx:vertx-dependencies from 5.1.2 to 5.1.3 by @dependabot[bot] in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1002">https://github.com/quarkiverse/quarkus-roq/pull/1002</a></li>
<li>Bump org.mvnpm.at.mvnpm:tiptap from 3.23.5 to 3.27.1 by @dependabot[bot] in <a href="https://github.com/quarkiverse/quarkus-roq/pull/999">https://github.com/quarkiverse/quarkus-roq/pull/999</a></li>
<li>Bump actions/checkout from 6 to 7 by @dependabot[bot] in <a href="https://github.com/quarkiverse/quarkus-roq/pull/992">https://github.com/quarkiverse/quarkus-roq/pull/992</a></li>
<li>Bump actions/checkout from 6 to 7 in /.github/workflows by @dependabot[bot] in <a href="https://github.com/quarkiverse/quarkus-roq/pull/993">https://github.com/quarkiverse/quarkus-roq/pull/993</a></li>
<li>Handle null dateStyle in style() extension, default to medium by @ia3andy in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1073">https://github.com/quarkiverse/quarkus-roq/pull/1073</a></li>
<li>feat: implement draft detection for substring paths by @matheusandre1 in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1034">https://github.com/quarkiverse/quarkus-roq/pull/1034</a></li>
<li>Bump com.fasterxml.jackson.dataformat:jackson-dataformat-yaml from 2.22.0 to 2.22.1 by @dependabot[bot] in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1077">https://github.com/quarkiverse/quarkus-roq/pull/1077</a></li>
<li>Bump io.vertx:vertx-dependencies from 5.1.3 to 5.1.4 by @dependabot[bot] in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1075">https://github.com/quarkiverse/quarkus-roq/pull/1075</a></li>
<li>Bump org.mvnpm.at.mvnpm:tiptap from 3.27.1 to 3.27.3 by @dependabot[bot] in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1076">https://github.com/quarkiverse/quarkus-roq/pull/1076</a></li>
<li>Update Liquid-to-Qute converter to handle more cases by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1044">https://github.com/quarkiverse/quarkus-roq/pull/1044</a></li>
<li>Expose resolved layout in page.data when it comes from defaults by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1082">https://github.com/quarkiverse/quarkus-roq/pull/1082</a></li>
<li>Bump io.vertx:vertx-dependencies from 5.1.4 to 5.1.5 by @dependabot[bot] in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1085">https://github.com/quarkiverse/quarkus-roq/pull/1085</a></li>
<li>Bump org.mvnpm.at.mvnpm:tiptap from 3.27.3 to 3.27.4 by @dependabot[bot] in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1084">https://github.com/quarkiverse/quarkus-roq/pull/1084</a></li>
<li>Bump org.bouncycastle:bcpkix-jdk18on from 1.84 to 1.85 by @dependabot[bot] in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1081">https://github.com/quarkiverse/quarkus-roq/pull/1081</a></li>
<li>Fix unbalanced quote in aliases plugin redirect template by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1078">https://github.com/quarkiverse/quarkus-roq/pull/1078</a></li>
<li>Add editor section to advanced documentation by @omatheusmesmo in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1066">https://github.com/quarkiverse/quarkus-roq/pull/1066</a></li>
<li>feat: add default layout support for collections and implement related tests by @matheusandre1 in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1030">https://github.com/quarkiverse/quarkus-roq/pull/1030</a></li>
<li>Fix duplicates in Site.allPages caused by tagging collections by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1087">https://github.com/quarkiverse/quarkus-roq/pull/1087</a></li>
<li>feat: Add RSS feed support in roq-base theme layout by @matheusandre1 in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1062">https://github.com/quarkiverse/quarkus-roq/pull/1062</a></li>
<li>Add doc for new tagging api, preserve order in collections by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1088">https://github.com/quarkiverse/quarkus-roq/pull/1088</a></li>
<li>docs: document that {#rss} is included by base theme and all built-in themes by @ia3andy in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1090">https://github.com/quarkiverse/quarkus-roq/pull/1090</a></li>
<li>Fix linktree theme: dedicated layouts, codestart cleanup, tutorial rewrite by @ia3andy in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1072">https://github.com/quarkiverse/quarkus-roq/pull/1072</a></li>
<li>fix: improve Lunr search ranking and add URL to results by @ia3andy in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1092">https://github.com/quarkiverse/quarkus-roq/pull/1092</a></li>
<li>fix: root pages rank above sections in search by @ia3andy in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1093">https://github.com/quarkiverse/quarkus-roq/pull/1093</a></li>
<li>Convert tags to lowercase (when configured to do so) in tags aggregation by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1094">https://github.com/quarkiverse/quarkus-roq/pull/1094</a></li>
<li>fix: use LazyValue with Arc to access tagging lowercase config by @ia3andy in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1096">https://github.com/quarkiverse/quarkus-roq/pull/1096</a></li>
<li>Bump org.mvnpm.at.fortawesome:fontawesome-free from 7.3.0 to 7.3.1 by @dependabot[bot] in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1095">https://github.com/quarkiverse/quarkus-roq/pull/1095</a></li>
<li>Enable alt expression syntax in codestarts and update docs by @ia3andy in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1097">https://github.com/quarkiverse/quarkus-roq/pull/1097</a></li>
<li>Bump current version to 2.1.6 by @ia3andy in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1098">https://github.com/quarkiverse/quarkus-roq/pull/1098</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/quarkiverse/quarkus-roq/compare/2.1.5...2.1.6">https://github.com/quarkiverse/quarkus-roq/compare/2.1.5...2.1.6</a></p>
]]></content:encoded></item><item><title>latexindent-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/latexindent-action/</link><pubDate>Fri, 17 Jul 2026 22:31:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/latexindent-action/</guid><description>Version updated for https://github.com/quentin-rodriguez/latexindent-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The LaTeXindent-action is a GitHub Action that checks or applies latexindent formatting on .tex files, using a custom configuration file and additional options. It provides flexibility in configuring the action via a YAML file and allows passing extra arguments to latexindent. The summary explains its purpose, functionality, and how it solves problems related to LaTeX formatting automation in GitHub workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/quentin-rodriguez/latexindent-action">https://github.com/quentin-rodriguez/latexindent-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/latexindent-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The LaTeXindent-action is a GitHub Action that checks or applies <code>latexindent</code> formatting on <code>.tex</code> files, using a custom configuration file and additional options. It provides flexibility in configuring the action via a YAML file and allows passing extra arguments to <code>latexindent</code>. The summary explains its purpose, functionality, and how it solves problems related to LaTeX formatting automation in GitHub workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): bump actions/checkout from 6 to 7 by @dependabot[bot] in <a href="https://github.com/quentin-rodriguez/latexindent-action/pull/1">https://github.com/quentin-rodriguez/latexindent-action/pull/1</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/quentin-rodriguez/latexindent-action/pull/1">https://github.com/quentin-rodriguez/latexindent-action/pull/1</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/quentin-rodriguez/latexindent-action/commits/v1.0.0">https://github.com/quentin-rodriguez/latexindent-action/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>setup-openapi</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/setup-openapi/</link><pubDate>Fri, 17 Jul 2026 22:30:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/setup-openapi/</guid><description>Version updated for https://github.com/remarkablemark/setup-openapi to version v1.1.10.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the setup of a workflow for generating OpenAPI clients using the OpenAPI Generator CLI. It installs Java, caches the CLI by version, and exposes the binary for use in subsequent steps in a GitHub Actions workflow. The action is designed to help developers quickly set up their workflows to generate code from OpenAPI specifications.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remarkablemark/setup-openapi">https://github.com/remarkablemark/setup-openapi</a></strong> to version <strong>v1.1.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-openapi">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the setup of a workflow for generating OpenAPI clients using the OpenAPI Generator CLI. It installs Java, caches the CLI by version, and exposes the binary for use in subsequent steps in a GitHub Actions workflow. The action is designed to help developers quickly set up their workflows to generate code from OpenAPI specifications.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1110-2026-07-17"><a href="https://github.com/remarkablemark/setup-openapi/compare/v1.1.9...v1.1.10">1.1.10</a> (2026-07-17)</h2>
<h3 id="build-system">Build System</h3>
<ul>
<li><strong>deps:</strong> bump actions/setup-java from 5.5.0 to 5.6.0 (<a href="https://github.com/remarkablemark/setup-openapi/issues/30">#30</a>) (<a href="https://github.com/remarkablemark/setup-openapi/commit/e008e049b97f39d93ac16937b34e831138de540c">e008e04</a>)</li>
</ul>
]]></content:encoded></item><item><title>Publish APKs to esper.io</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/publish-apks-to-esper.io/</link><pubDate>Fri, 17 Jul 2026 22:28:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/publish-apks-to-esper.io/</guid><description>Version updated for https://github.com/ryanoboril/action-esper.io-upload-multi to version 2.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of uploading one or more APK files to esper.io using their API. It requires specifying the Esper.io Enterprise ID, API Key, and tenant name, along with the folder containing APK files to upload. The action also allows for optional release comments to be applied to each uploaded APK version. The result data from the upload operation is available as an output.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ryanoboril/action-esper.io-upload-multi">https://github.com/ryanoboril/action-esper.io-upload-multi</a></strong> to version <strong>2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/publish-apks-to-esper-io">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of uploading one or more APK files to esper.io using their API. It requires specifying the Esper.io Enterprise ID, API Key, and tenant name, along with the folder containing APK files to upload. The action also allows for optional release comments to be applied to each uploaded APK version. The result data from the upload operation is available as an output.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release notes are now provided to uploaded apps based on the latest commit</p>
]]></content:encoded></item><item><title>Pipr Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/pipr-review/</link><pubDate>Fri, 17 Jul 2026 22:28:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/pipr-review/</guid><description>Version updated for https://github.com/somus/pipr to version v0.4.2.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Pipr is a code-owned AI review action that automates structured, provider-neutral reviews across popular code hosts (GitHub, GitLab.com, Azure DevOps Services, and Bitbucket Cloud). It uses a TypeScript configuration file to define review workflows and integrates with various code hosting providers through adapters. The tool runs AI-driven reviews, validates findings, and publishes comments in GitHub pull requests.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somus/pipr">https://github.com/somus/pipr</a></strong> to version <strong>v0.4.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pipr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Pipr is a code-owned AI review action that automates structured, provider-neutral reviews across popular code hosts (GitHub, GitLab.com, Azure DevOps Services, and Bitbucket Cloud). It uses a TypeScript configuration file to define review workflows and integrates with various code hosting providers through adapters. The tool runs AI-driven reviews, validates findings, and publishes comments in GitHub pull requests.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="042-2026-07-17"><a href="https://github.com/somus/pipr/compare/v0.4.1...v0.4.2">0.4.2</a> (2026-07-17)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>runtime:</strong> apply review policy to custom schemas (<a href="https://github.com/somus/pipr/issues/89">#89</a>) (<a href="https://github.com/somus/pipr/commit/bd134bf5a2d6ac7eba6e8e74823e3145a09fd21a">bd134bf</a>)</li>
<li>suppress resolved findings across heads (<a href="https://github.com/somus/pipr/issues/88">#88</a>) (<a href="https://github.com/somus/pipr/commit/63cf68fe8b8cdc3bb353a8eee1b6dbe7d5482eb6">63cf68f</a>)</li>
</ul>
]]></content:encoded></item><item><title>runward gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/runward-gate/</link><pubDate>Fri, 17 Jul 2026 22:27:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/runward-gate/</guid><description>Version updated for https://github.com/stranxik/runward to version v0.19.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Runward is an agent delivery framework that automates the entire mission from framing to handover, addressing architecture problems in agentic systems by providing structured delivery and governance. It supports various input sources like specs, OpenSpecs, and prototypes and offers six gated phases: Frame, Spec Kit, OpenSpec, Brownfield, Floor, Evolution on Evidence, Governance, and Handover. Runward ensures that agentic systems are built, tested, and delivered with resilience and autonomy, making them robust against unpredictable outputs and complex environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stranxik/runward">https://github.com/stranxik/runward</a></strong> to version <strong>v0.19.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/runward-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Runward is an agent delivery framework that automates the entire mission from framing to handover, addressing architecture problems in agentic systems by providing structured delivery and governance. It supports various input sources like specs, OpenSpecs, and prototypes and offers six gated phases: Frame, Spec Kit, OpenSpec, Brownfield, Floor, Evolution on Evidence, Governance, and Handover. Runward ensures that agentic systems are built, tested, and delivered with resilience and autonomy, making them robust against unpredictable outputs and complex environments.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Making &ldquo;an AI agent can discover, install and operate runward with no human at the keyboard&rdquo; true — without leaning on a detection layer that can only ever be partial (<a href="docs/adr/ADR-0030-agent-operates-runward-neutral-baseline-best-effort-detection.md">ADR-0030</a>).</p>
<ul>
<li><strong>Neutral baseline by default.</strong> <code>init</code> with no explicit <code>--tools</code> writes only the vendor-neutral core (<code>AGENTS.md</code> + <code>.agents/skills/</code>); <code>--yes</code> no longer defaults to the <code>claude</code> profile and the wizard pre-checks nothing. No harness is privileged — a channel is an opt-in the operator adds afterward. Closes a standing vendor-neutrality breach.</li>
<li><strong><code>runward wire</code> — best-effort harness detection.</strong> Detects the AI harness running the command via a verified runtime signal (<code>CLAUDECODE</code> for Claude Code and Cowork, <code>GEMINI_CLI</code>, <code>CURSOR_AGENT</code>), falling back to a config-file marker, then <code>undetermined</code>. It recommends the matching auto-trigger channel and points at the inert sample — it never wires anything (<code>wires:false</code> invariant, <a href="docs/adr/ADR-0012-the-gate-as-a-port-with-harness-adapters.md">ADR-0012</a>) and never prompts, so an agent run never hangs. On <code>undetermined</code>, the doctrine (AGENTS.md + the plugin SKILL.md) tells the agent to <em>ask</em> the operator which tool they use rather than guess.</li>
<li><strong><code>check --json</code> — a machine contract.</strong> A stable, deterministic JSON verdict (current gate, deliverable states, conformance gaps) so an agent drives on data, not scraped text. Hook output is routed to stderr under <code>--json</code> so a subprocess can&rsquo;t corrupt the object.</li>
<li><strong>Hardened non-interactivity.</strong> <code>isNonInteractive()</code> also returns true when stdin is not a TTY or <code>CI</code> is set — an autonomous run never hangs on a prompt it cannot answer.</li>
<li><strong>Guards.</strong> New unit tests for detection (signal precedence, per-family config detection, <code>undetermined</code>, the <code>wires:false</code> invariant) and smoke assertions for <code>wire --json</code> and <code>check --json[ --strict]</code>. Self-gate strict green; 65 unit tests.</li>
</ul>
]]></content:encoded></item><item><title>Setup Tombi</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/setup-tombi/</link><pubDate>Fri, 17 Jul 2026 22:25:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/setup-tombi/</guid><description>Version updated for https://github.com/tombi-toml/setup-tombi to version v1.2.1.
This action is used across all versions by 137 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up Tombi, a dependency manager for Rust projects, in your GitHub Actions workflow. It allows users to install specific versions of Tombi or resolve dependencies from lock files, and it provides options for caching the installation for faster future runs. The action supports various checksum verification methods for ensuring the integrity of downloaded binaries.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tombi-toml/setup-tombi">https://github.com/tombi-toml/setup-tombi</a></strong> to version <strong>v1.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>137</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-tombi">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up Tombi, a dependency manager for Rust projects, in your GitHub Actions workflow. It allows users to install specific versions of Tombi or resolve dependencies from lock files, and it provides options for caching the installation for faster future runs. The action supports various checksum verification methods for ensuring the integrity of downloaded binaries.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This setup-tombi release matches <a href="https://github.com/tombi-toml/tombi/releases/tag/v1.2.1">tombi v1.2.1</a>.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/tombi-toml/setup-tombi/compare/v1...v1.2.1">https://github.com/tombi-toml/setup-tombi/compare/v1...v1.2.1</a></p>
]]></content:encoded></item><item><title>Setup Upwarden</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/setup-upwarden/</link><pubDate>Fri, 17 Jul 2026 22:23:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/setup-upwarden/</guid><description>Version updated for https://github.com/upwarden-io/setup-upwarden to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The setup-upwarden action provides a simple and secure way to authenticate and attribute package manager dependencies in CI pipelines. It uses the user’s OIDC identity to mint a short-lived token, ensuring that each dependency fetch is authenticated and attributed, and can be policy-enforced. The action is highly configurable with options for different ecosystems (npm, pip, maven) and supports both GitHub and non-GitHub environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/upwarden-io/setup-upwarden">https://github.com/upwarden-io/setup-upwarden</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-upwarden">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The setup-upwarden action provides a simple and secure way to authenticate and attribute package manager dependencies in CI pipelines. It uses the user&rsquo;s OIDC identity to mint a short-lived token, ensuring that each dependency fetch is authenticated and attributed, and can be policy-enforced. The action is highly configurable with options for different ecosystems (npm, pip, maven) and supports both GitHub and non-GitHub environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Patch release — no behavior change.</p>
<ul>
<li><strong>Branding:</strong> Marketplace icon updated to shield / green.</li>
<li><strong>Docs:</strong> corrected README (accurate two-mode auth model; keyless-primary), and the provenance section now states only what is true (immutable release + tag protection) with the OCI attestation flagged as coming.</li>
<li><strong>action.yml:</strong> keyless (Mode C) comments corrected — keyless is live + primary in prod.</li>
</ul>
<p><code>uses: upwarden-io/setup-upwarden@v1</code> (moving) or <code>@v1.0.1</code> (immutable).</p>
]]></content:encoded></item><item><title>Agent Lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/agent-lint/</link><pubDate>Fri, 17 Jul 2026 22:22:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/agent-lint/</guid><description>Version updated for https://github.com/zhupanov/agent-lint to version v3.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Lint is a Rust-based linter designed to validate various configurations related to Claude Code, Cursor, and Codex. It checks for compliance with specific lint rules across multiple categories such as Manifest, Hooks, Skills, Agents, Prompt Content, Claude Rules, Output Styles, Settings, Hygiene, Email, User Config, MCP, Codex, Slack, Docs, Markdown Structure, Link/import integrity, and more. The action supports both Basic mode (for standard configuration validation) and Plugin mode (which runs the full rule suite when a .claude-plugin/ directory is present). Agent Lint is configurable through agent-lint.toml to suppress or downgrade rules. It offers integration options via GitHub Actions and pre-commit, with cross-platform binaries available for macOS, Linux x86_64/aarch64, and macOS aarch64.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zhupanov/agent-lint">https://github.com/zhupanov/agent-lint</a></strong> to version <strong>v3.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Agent Lint is a Rust-based linter designed to validate various configurations related to Claude Code, Cursor, and Codex. It checks for compliance with specific lint rules across multiple categories such as Manifest, Hooks, Skills, Agents, Prompt Content, Claude Rules, Output Styles, Settings, Hygiene, Email, User Config, MCP, Codex, Slack, Docs, Markdown Structure, Link/import integrity, and more. The action supports both Basic mode (for standard configuration validation) and Plugin mode (which runs the full rule suite when a <code>.claude-plugin/</code> directory is present). Agent Lint is configurable through <code>agent-lint.toml</code> to suppress or downgrade rules. It offers integration options via GitHub Actions and pre-commit, with cross-platform binaries available for macOS, Linux x86_64/aarch64, and macOS aarch64.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Document release admin merge procedure by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/188">https://github.com/zhupanov/agent-lint/pull/188</a></li>
<li>Add config-only per-file rule suppression overrides by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/190">https://github.com/zhupanov/agent-lint/pull/190</a></li>
<li>Release v3.0.1 by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/191">https://github.com/zhupanov/agent-lint/pull/191</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/zhupanov/agent-lint/compare/v3...v3.0.1">https://github.com/zhupanov/agent-lint/compare/v3...v3.0.1</a></p>
]]></content:encoded></item><item><title>Sparda MCP</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/sparda-mcp/</link><pubDate>Fri, 17 Jul 2026 22:21:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/sparda-mcp/</guid><description>Version updated for https://github.com/zyx77550/sparda to version v0.58.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SPARDA is a tool that compiles backend behavior into a graph, enabling tools to reason about and verify applications. It helps in identifying and fixing issues by compiling routes, database queries, and state mutations into a single, language-agnostic graph, which can then be verified and replayed without running the actual application.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zyx77550/sparda">https://github.com/zyx77550/sparda</a></strong> to version <strong>v0.58.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sparda-mcp">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SPARDA is a tool that compiles backend behavior into a graph, enabling tools to reason about and verify applications. It helps in identifying and fixing issues by compiling routes, database queries, and state mutations into a single, language-agnostic graph, which can then be verified and replayed without running the actual application.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix(action): satisfy github marketplace limits (d79b6d3)</li>
<li>release: v0.58.0 (cd2db1c)</li>
<li>fix(publish): bump server.json version to 0.32.0 (5c8b5c9)</li>
<li>fix(publish): bump server.json version to 0.30.0 for mcp registry (e463ccb)</li>
<li>feat(core): release v0.30.0 (Blindspot ledger, Directus, UI rewrite) (e862904)</li>
<li>docs: update public README and SKILL with v0.26.0 metrics (3f74d5d)</li>
<li>chore: redesign dossier.js HTML output to premium standards (17b036c)</li>
<li>chore: bump server.json version to 0.26.0 (d4551b4)</li>
<li>chore: sync HQ to public (v0.26.0) (8a04a45)</li>
<li>Merge pull request #23 from zyx77550/sync/registry-bump (39a9cf7)</li>
</ul>
]]></content:encoded></item><item><title>cibuild-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/cibuild-action/</link><pubDate>Fri, 17 Jul 2026 15:04:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/cibuild-action/</guid><description>Version updated for https://github.com/invarnhq/cibuild to version v2.3.8.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The cibuild action automates the setup of CI/CD pipelines for iOS and Android projects on GitHub. It provides interactive and non-interactive setup options, including auto-detection of platform and project type. The action generates a YAML-based pipeline with recommended defaults or allows users to customize it using an interactive wizard. Users can run the generated pipeline locally or remotely after validation. It supports adding secrets for environment variables and key management, and provides utilities for uploading secrets to GitHub environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/invarnhq/cibuild">https://github.com/invarnhq/cibuild</a></strong> to version <strong>v2.3.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cibuild-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The cibuild action automates the setup of CI/CD pipelines for iOS and Android projects on GitHub. It provides interactive and non-interactive setup options, including auto-detection of platform and project type. The action generates a YAML-based pipeline with recommended defaults or allows users to customize it using an interactive wizard. Users can run the generated pipeline locally or remotely after validation. It supports adding secrets for environment variables and key management, and provides utilities for uploading secrets to GitHub environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release v2.3.8</p>
]]></content:encoded></item><item><title>Agent Guard Secret Guardrails</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/agent-guard-secret-guardrails/</link><pubDate>Fri, 17 Jul 2026 15:03:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/agent-guard-secret-guardrails/</guid><description>Version updated for https://github.com/JeongJaeSoon/agent-guard to version v2.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Guard is a deterministic guardrail designed to prevent AI coding agents from accidentally exposing sensitive information, such as .env files containing private keys or credentials. It monitors the agent’s interactions with these files at runtime and blocks them if they attempt to read or write sensitive data before it can be used. This tool helps in real-time detection of potential leaks by using gitleaks for scanning and plain shell scripts for integration, ensuring defense-in-depth security measures are implemented.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/JeongJaeSoon/agent-guard">https://github.com/JeongJaeSoon/agent-guard</a></strong> to version <strong>v2.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-guard-secret-guardrails">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Agent Guard is a deterministic guardrail designed to prevent AI coding agents from accidentally exposing sensitive information, such as <code>.env</code> files containing private keys or credentials. It monitors the agent&rsquo;s interactions with these files at runtime and blocks them if they attempt to read or write sensitive data before it can be used. This tool helps in real-time detection of potential leaks by using gitleaks for scanning and plain shell scripts for integration, ensuring defense-in-depth security measures are implemented.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(hooks): scan NotebookEdit cell content for secrets and PII by @JeongJaeSoon in <a href="https://github.com/JeongJaeSoon/agent-guard/pull/113">https://github.com/JeongJaeSoon/agent-guard/pull/113</a></li>
<li>chore(release): v2.0.1 by @JeongJaeSoon in <a href="https://github.com/JeongJaeSoon/agent-guard/pull/114">https://github.com/JeongJaeSoon/agent-guard/pull/114</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/JeongJaeSoon/agent-guard/compare/v2.0.0...v2.0.1">https://github.com/JeongJaeSoon/agent-guard/compare/v2.0.0...v2.0.1</a></p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/neurolink-ai/</link><pubDate>Fri, 17 Jul 2026 15:02:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v9.92.0.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is an AI integration platform that provides a unified API to integrate 30+ AI providers and models. It offers features like switching providers with a single parameter change, leveraging built-in tools, deploying with enterprise features, optimizing costs automatically, and using the professional CLI or TypeScript SDK. The platform supports edge-first execution and continuous streaming architectures for practical and universally available AI.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v9.92.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>NeuroLink is an AI integration platform that provides a unified API to integrate 30+ AI providers and models. It offers features like switching providers with a single parameter change, leveraging built-in tools, deploying with enterprise features, optimizing costs automatically, and using the professional CLI or TypeScript SDK. The platform supports edge-first execution and continuous streaming architectures for practical and universally available AI.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="9920-2026-07-17"><a href="https://github.com/juspay/neurolink/compare/v9.91.1...v9.92.0">9.92.0</a> (2026-07-17)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>(proxy):</strong>  hot-reload routing configuration (<a href="https://github.com/juspay/neurolink/commit/de31a3cac77326d49c5211099238a852b9623dda">de31a3c</a>)</li>
</ul>
]]></content:encoded></item><item><title>Threatify Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/threatify-scan/</link><pubDate>Fri, 17 Jul 2026 15:01:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/threatify-scan/</guid><description>Version updated for https://github.com/kamranhasan/Threatify to version 0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Threatify is a static analysis tool that generates a capability graph from an AI agent’s configuration and identifies potential attack paths. It helps in detecting hidden vulnerabilities such as LETHAL_TRIFECTA and ATTACK_PATHs, which can be used for exfiltration or unauthorized access. The tool runs offline, analyzing the configuration file alone without relying on external APIs or network calls.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kamranhasan/Threatify">https://github.com/kamranhasan/Threatify</a></strong> to version <strong>0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/threatify-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Threatify is a static analysis tool that generates a capability graph from an AI agent&rsquo;s configuration and identifies potential attack paths. It helps in detecting hidden vulnerabilities such as LETHAL_TRIFECTA and ATTACK_PATHs, which can be used for exfiltration or unauthorized access. The tool runs offline, analyzing the configuration file alone without relying on external APIs or network calls.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Scans AI agent configs on every PR and blocks merges that introduce a new reachable exfiltration or privileged-action path.</p>
]]></content:encoded></item><item><title>Lint package.json</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/lint-package.json/</link><pubDate>Fri, 17 Jul 2026 15:00:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/lint-package.json/</guid><description>Version updated for https://github.com/kirkeaton/action-publint to version v2.0.20.
This action is used across all versions by 13 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action action-publint automates the linting of a package.json file to detect packaging errors using Publint. It helps identify issues related to dependencies, metadata, and version management that could affect how your project is published. The action provides flexibility in setting the logging level and the path to the package directory for custom configurations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kirkeaton/action-publint">https://github.com/kirkeaton/action-publint</a></strong> to version <strong>v2.0.20</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>13</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lint-package-json">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>action-publint</code> automates the linting of a package.json file to detect packaging errors using Publint. It helps identify issues related to dependencies, metadata, and version management that could affect how your project is published. The action provides flexibility in setting the logging level and the path to the package directory for custom configurations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="2020-2026-07-17"><a href="https://github.com/kirkeaton/action-publint/compare/v2.0.19...v2.0.20">2.0.20</a> (2026-07-17)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> lock file maintenance (<a href="https://github.com/kirkeaton/action-publint/issues/261">#261</a>) (<a href="https://github.com/kirkeaton/action-publint/commit/7d016f859ab1635756d4f4e2e653cf9a72af4a6f">7d016f8</a>)</li>
</ul>
]]></content:encoded></item><item><title>Landsafe — Postgres migration safety</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/landsafe-postgres-migration-safety/</link><pubDate>Fri, 17 Jul 2026 15:00:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/landsafe-postgres-migration-safety/</guid><description>Version updated for https://github.com/landsafe-dev/action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Landsafe GitHub Action checks PostgreSQL migration safety by analyzing the diff between two database schemas and identifying potential issues such as blocking index builds, full-table rewrites, and data loss. The action verifies these risks without connecting to or interacting with the actual database, ensuring that developers are aware of potential production impacts before merging migrations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/landsafe-dev/action">https://github.com/landsafe-dev/action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/landsafe-postgres-migration-safety">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Landsafe GitHub Action checks PostgreSQL migration safety by analyzing the diff between two database schemas and identifying potential issues such as blocking index builds, full-table rewrites, and data loss. The action verifies these risks without connecting to or interacting with the actual database, ensuring that developers are aware of potential production impacts before merging migrations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release.</p>
<p>Landsafe reads the SQL in your pull request and tells you which lock each migration takes, what that lock blocks, and how long it will hold — before it merges.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">landsafe-dev/action@v1</span>
</span></span></code></pre></div><p><strong>28 rules</strong>, every one version-aware: PG 11&rsquo;s fast <code>ADD COLUMN ... DEFAULT</code>, PG 12&rsquo;s scan-free <code>SET NOT NULL</code> via a valid CHECK, <code>REINDEX CONCURRENTLY</code>, <code>DETACH PARTITION CONCURRENTLY</code> in 14. It knows <code>DEFAULT 'free'</code> is catalog-only and <code>DEFAULT gen_random_uuid()</code> rewrites all 48 million rows, and it will only wake you up for the second one.</p>
<p><strong>What&rsquo;s in it</strong></p>
<ul>
<li>Sticky PR comment — updated in place, never spammed. Lock profile, what it blocks, the safe path.</li>
<li>Advisory about merging, honest about signalling: the check goes red on a critical by default, and you can merge straight through it. It never holds a required status and never blocks a merge. <code>fail-on: never</code> to silence it.</li>
<li><code>mode: digest</code> — a weekly cross-repo rollup answering the question a single PR comment can&rsquo;t: which PRs merged with criticals unresolved. It reads the payloads Landsafe already wrote into your own PR comments, via your own token. If it can&rsquo;t read a repo, it says so and marks the counts a lower bound.</li>
<li>Org-wide policy enforcement via the license: repos can tighten the fail threshold, never loosen it.</li>
<li><code>npx landsafe check --json</code> and <code>npx landsafe init</code> for AI agents writing migrations.</li>
</ul>
<p><strong>Why you can audit it rather than trust it</strong></p>
<p>The engine has zero dependencies — its only import anywhere is <code>node:crypto</code>. No telemetry, no phone-home, no licensing server: verification is offline Ed25519 against a public key compiled in. No LLM in the analysis path — explicit rules over documented Postgres lock semantics, so the same migration always produces the same answer. <code>src/</code> and the tests are published next to <code>dist/</code>.</p>
<p>Pin a commit SHA rather than trusting me, as you should with any third-party Action.</p>
<p><strong>Limits</strong></p>
<p>Postgres only. It reads <code>.sql</code> — Rails/Django/Prisma migrations written in Ruby/Python/TypeScript aren&rsquo;t analyzed, only the SQL they generate. And it&rsquo;s brand new.</p>
<p>Free tier is the whole detection engine on unlimited repos and developers. Pro ($79/mo) adds ready-to-paste zero-downtime rewrites and impact estimated against your real table sizes. Business ($299/mo) adds the digest, org policy, and cross-repo dashboard. Details at <a href="https://landsafe.dev">landsafe.dev</a>.</p>
]]></content:encoded></item><item><title>Git Velocity Analyser</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/git-velocity-analyser/</link><pubDate>Fri, 17 Jul 2026 14:59:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/git-velocity-analyser/</guid><description>Version updated for https://github.com/lukaszraczylo/git-velocity to version v1.0.12.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Git Velocity is a GitHub Action that analyzes your Git repositories and generates a gamified dashboard showing developer velocity metrics. It helps track contributions, automates code review processes, and provides achievements to motivate team members in their development efforts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lukaszraczylo/git-velocity">https://github.com/lukaszraczylo/git-velocity</a></strong> to version <strong>v1.0.12</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/git-velocity-analyser">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Git Velocity is a GitHub Action that analyzes your Git repositories and generates a gamified dashboard showing developer velocity metrics. It helps track contributions, automates code review processes, and provides achievements to motivate team members in their development efforts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
]]></content:encoded></item><item><title>lgtmaybe</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/lgtmaybe/</link><pubDate>Fri, 17 Jul 2026 14:57:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/lgtmaybe/</guid><description>Version updated for https://github.com/MattJColes/lgtmaybe to version lgtmaybe-v0.12.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The lgtmaybe GitHub Action reviews pull requests by analyzing code changes and surrounding lines from the file, detecting logic and correctness bugs, security vulnerabilities, missing or weak tests, outdated code, performance regressions, unnecessary complexity, intent, and ponytail. It uses a language model to generate inline review comments and summaries, reducing the need for static keys and improving safety.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MattJColes/lgtmaybe">https://github.com/MattJColes/lgtmaybe</a></strong> to version <strong>lgtmaybe-v0.12.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lgtmaybe">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The lgtmaybe GitHub Action reviews pull requests by analyzing code changes and surrounding lines from the file, detecting logic and correctness bugs, security vulnerabilities, missing or weak tests, outdated code, performance regressions, unnecessary complexity, intent, and ponytail. It uses a language model to generate inline review comments and summaries, reducing the need for static keys and improving safety.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="0121-2026-07-17"><a href="https://github.com/MattJColes/lgtmaybe/compare/lgtmaybe-v0.12.0...lgtmaybe-v0.12.1">0.12.1</a> (2026-07-17)</h2>
<h3 id="performance-improvements">Performance Improvements</h3>
<ul>
<li>cut redundant work in the pipeline and trim prompt token waste (<a href="https://github.com/MattJColes/lgtmaybe/issues/185">#185</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/c2ebd970301cfff63335c1ac4be0d39156d06084">c2ebd97</a>)</li>
</ul>
]]></content:encoded></item><item><title>Code Guard PR Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/code-guard-pr-scanner/</link><pubDate>Fri, 17 Jul 2026 14:56:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/code-guard-pr-scanner/</guid><description>Version updated for https://github.com/mlawsonking/code-guard-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action mlawsonking/code-guard-action scans code changes in pull requests for security bugs using a deterministic rule engine, flagging them inline on the diff and posting findings as annotations. It automates the process of catching high-frequency vulnerabilities such as command injection, SQL injection, SSRF, hardcoded secrets/API keys, weak crypto, unsafe deserialization, disabled TLS verification, and XSS. The action runs on added lines in each PR, checks them with a deterministic rule engine, and posts findings inline on the “Files changed” tab. It can be configured to fail the check based on the worst verdict level or not at all.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mlawsonking/code-guard-action">https://github.com/mlawsonking/code-guard-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/code-guard-pr-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>mlawsonking/code-guard-action</code> scans code changes in pull requests for security bugs using a deterministic rule engine, flagging them inline on the diff and posting findings as annotations. It automates the process of catching high-frequency vulnerabilities such as command injection, SQL injection, SSRF, hardcoded secrets/API keys, weak crypto, unsafe deserialization, disabled TLS verification, and XSS. The action runs on added lines in each PR, checks them with a deterministic rule engine, and posts findings inline on the &ldquo;Files changed&rdquo; tab. It can be configured to fail the check based on the worst verdict level or not at all.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Deterministic security scan for pull requests. Code Guard checks the added lines of your PR diff and posts inline annotations on the exact lines, with a single pass / review / block verdict. No LLM, so the results are consistent and there is nothing to hallucinate.</p>
<p><strong>Checks:</strong> command and code injection, SSRF, hardcoded secrets, weak crypto, unsafe deserialization, disabled TLS verification, and reflected XSS.</p>
<p><strong>Usage</strong> - add <code>.github/workflows/code-guard.yml</code>:</p>
<pre tabindex="0"><code>name: Code Guard
on: pull_request
permissions:
  contents: read
  pull-requests: read
jobs:
  scan:
    runs-on: ubuntu-latest
    steps:
      - uses: mlawsonking/code-guard-action@v1
        with:
          fail-on: block   # block | review | never
</code></pre><p><strong>Inputs:</strong> <code>fail-on</code> (default <code>block</code>), <code>api</code> (override only if you self-host).
<strong>Outputs:</strong> <code>verdict</code> (pass/review/block), <code>findings</code> (count).</p>
<p>Your code is not stored; the diff is scanned and discarded. Uses a free hosted API; self-host by pointing <code>api</code> at your own deployment.</p>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/totem-shield/</link><pubDate>Fri, 17 Jul 2026 14:56:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.100.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Totem is a file-based toolkit that integrates AI coding agents, provides a queryable knowledge index, and enforces lint rules to maintain architectural integrity in projects. It uses deterministic zero-LLM linting and avoids network calls by storing lessons and lint configurations locally.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.100.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Totem is a file-based toolkit that integrates AI coding agents, provides a queryable knowledge index, and enforces lint rules to maintain architectural integrity in projects. It uses deterministic zero-LLM linting and avoids network calls by storing lessons and lint configurations locally.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>AI Harness Doctor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/ai-harness-doctor/</link><pubDate>Fri, 17 Jul 2026 14:55:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/ai-harness-doctor/</guid><description>Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v1.13.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Harness Doctor is a GitHub Action designed to audit and consolidate AGENTS.md, CLAUDE.md, and related harness files in repositories. It helps developers identify and correct inconsistencies, ensuring that the agent’s documentation remains accurate, up-to-date, and secure. The tool also measures whether the resulting harness improves agent answers by comparing before- and after-performance metrics.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NieZhuZhu/ai-harness-doctor">https://github.com/NieZhuZhu/ai-harness-doctor</a></strong> to version <strong>v1.13.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-harness-doctor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AI Harness Doctor is a GitHub Action designed to audit and consolidate <code>AGENTS.md</code>, <code>CLAUDE.md</code>, and related harness files in repositories. It helps developers identify and correct inconsistencies, ensuring that the agent&rsquo;s documentation remains accurate, up-to-date, and secure. The tool also measures whether the resulting harness improves agent answers by comparing before- and after-performance metrics.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(cli): add &ndash;version flag to report the installed version by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/261">https://github.com/NieZhuZhu/ai-harness-doctor/pull/261</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NieZhuZhu/ai-harness-doctor/compare/v1...v1.13.0">https://github.com/NieZhuZhu/ai-harness-doctor/compare/v1...v1.13.0</a></p>
]]></content:encoded></item><item><title>Zablo — zero-knowledge secrets</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/zablo-zero-knowledge-secrets/</link><pubDate>Fri, 17 Jul 2026 14:53:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/zablo-zero-knowledge-secrets/</guid><description>Version updated for https://github.com/r2l332/zablo-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action fetches zero-knowledge secrets from a Zablo server and injects them into your GitHub Actions workflow using an OIDC token, without storing any sensitive information in public repositories. It supports both static API keys and OIDC federation methods to access the secrets securely. The action is designed for use with workflows that require deployment or configuration tasks that involve sensitive data like database URLs, Stripe keys, and Redis passwords.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/r2l332/zablo-action">https://github.com/r2l332/zablo-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zablo-zero-knowledge-secrets">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action fetches zero-knowledge secrets from a Zablo server and injects them into your GitHub Actions workflow using an OIDC token, without storing any sensitive information in public repositories. It supports both static API keys and OIDC federation methods to access the secrets securely. The action is designed for use with workflows that require deployment or configuration tasks that involve sensitive data like database URLs, Stripe keys, and Redis passwords.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release of the <strong>Zablo GitHub Action</strong> — inject zero-knowledge secrets into any workflow without storing a long-lived API key in <code>Settings → Secrets</code>.</p>
<h2 id="-what-you-get">✨ What you get</h2>
<ul>
<li><strong>OIDC federation by default</strong> — the runner mints a GitHub ID token, Zablo exchanges it for a short-lived <code>vks_…</code> session. No long-lived credentials in GitHub Secrets. Only the client-side passphrase needs to be stored.</li>
<li><strong>Static API key fallback</strong> for environments without OIDC.</li>
<li><strong>Install-only mode</strong> — omit <code>secrets:</code> to just install the CLI and drive it yourself.</li>
<li><strong>Automatic log masking</strong> — every fetched value is passed to <code>::add-mask::</code> line-by-line, so multi-line values like PEM keys stay redacted in the log.</li>
<li><strong>Multi-line-safe env export</strong> — random EOF markers written to <code>$GITHUB_ENV</code> so certificates, JSON blobs, and any value with newlines round-trips cleanly.</li>
<li><strong>Composite action</strong> — pure bash + <code>pipx</code>. No Docker pull, no Node runtime. Cold start is roughly a second.</li>
<li><strong>Pinnable CLI version</strong> — default is <code>latest</code>; pin with <code>version: 0.4.0</code> for reproducible builds.</li>
</ul>
<h2 id="-quickstart">🚀 Quickstart</h2>
<pre><code>permissions:
  id-token: write
  contents: read

jobs:
  deploy:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: r2l332/zablo-action@v1
        with:
          api-url: https://zablo.example.com
          passphrase: ${{ secrets.ZABLO_PASSPHRASE }}
          secrets: |
            DATABASE_URL=prod/db/url
            STRIPE_KEY=prod/stripe/live
            REDIS_PASSWORD=prod/redis/pw
      - run: ./deploy.sh
</code></pre>
<p>The four secrets are now available as <code>$DATABASE_URL</code> etc. — decrypted on the runner, masked in the log, gone when the job ends.</p>
<h2 id="-inputs">📦 Inputs</h2>
<table>
  <thead>
      <tr>
          <th>Name</th>
          <th>Required</th>
          <th>Default</th>
          <th>Description</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>api-url</code></td>
          <td>✅</td>
          <td>—</td>
          <td>Zablo server URL</td>
      </tr>
      <tr>
          <td><code>passphrase</code></td>
          <td>✅ if <code>secrets</code> set</td>
          <td>—</td>
          <td>Client-side encryption passphrase (from <code>secrets.ZABLO_PASSPHRASE</code>)</td>
      </tr>
      <tr>
          <td><code>secrets</code></td>
          <td></td>
          <td>—</td>
          <td>Multiline <code>NAME=path</code> list</td>
      </tr>
      <tr>
          <td><code>api-key</code></td>
          <td></td>
          <td>—</td>
          <td>Static <code>vk_…</code> key (if unset, action uses OIDC)</td>
      </tr>
      <tr>
          <td><code>audience</code></td>
          <td></td>
          <td><code>zablo.io</code></td>
          <td>OIDC audience</td>
      </tr>
      <tr>
          <td><code>version</code></td>
          <td></td>
          <td><code>latest</code></td>
          <td>zablo-cli version to install</td>
      </tr>
  </tbody>
</table>
<h2 id="-what-was-tested">🧪 What was tested</h2>
<ul>
<li>Install-only + version-pin flows verified via <a href=".github/workflows/test.yml"><code>.github/workflows/test.yml</code></a> on Ubuntu latest</li>
<li>End-to-end fetch + <code>$GITHUB_ENV</code> injection verified against a local Zablo server</li>
<li>Line-by-line masking verified against a multi-line PEM value</li>
</ul>
<h2 id="-security">🔒 Security</h2>
<ul>
<li>Passphrase never sent to the Zablo server (AES-256-GCM key derived locally on the runner, Argon2id KDF).</li>
<li>Session token is short-lived (~1 hour by default) — replay window is bounded.</li>
<li>Pin to a SHA in production: <code>uses: r2l332/zablo-action@abc1234</code></li>
</ul>
<h2 id="-docs">📚 Docs</h2>
<ul>
<li>CLI reference: <a href="https://pypi.org/project/zablo-cli/">https://pypi.org/project/zablo-cli/</a></li>
<li>Zablo platform + <code>USAGE.md</code>: <a href="https://github.com/r2l332/zablo">https://github.com/r2l332/zablo</a></li>
<li>Full example workflow: <a href="examples/deploy.yml"><code>examples/deploy.yml</code></a></li>
</ul>
<h2 id="requires">Requires</h2>
<ul>
<li>A running Zablo server (OSS, self-hosted; deploy with the included Bicep / azd — see <code>docs/DEPLOY.md</code>)</li>
<li>Python 3 on the runner (present on all <code>ubuntu-*</code> and <code>macos-*</code> GitHub-hosted runners by default)</li>
</ul>
]]></content:encoded></item><item><title>raviqqe/muffy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/raviqqe/muffy/</link><pubDate>Fri, 17 Jul 2026 14:52:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/raviqqe/muffy/</guid><description>Version updated for https://github.com/raviqqe/muffy to version v0.3.14.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Muffy GitHub Action automates the process of validating static websites by running Muffet, a static website validator. It solves the problem of checking website validity and provides key capabilities for ensuring that HTML and CSS are correctly formatted and that links work as expected.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/raviqqe/muffy">https://github.com/raviqqe/muffy</a></strong> to version <strong>v0.3.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/raviqqe-muffy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Muffy GitHub Action automates the process of validating static websites by running Muffet, a static website validator. It solves the problem of checking website validity and provides key capabilities for ensuring that HTML and CSS are correctly formatted and that links work as expected.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>74d15a2643350fa5ba6b8e1dc6b77529c6b8d238 Bump version (#1082)</li>
<li>c4804a7e524f02c9e3cae260231714e4882ca9b7 Fix robots.txt on redirects (#1081)</li>
<li>ca544375467651cd2d31838f93bc4307d66dd339 Flush output before table (#1080)</li>
<li>c3c3fae940154951e9ebfb4d88d561a63c156a10 Emoji in text format (#1079)</li>
<li>34d35002708b44194ecd67754f719943d9b46bec Bump rust-toolchain from 1.97.0 to 1.97.1 (#1077)</li>
<li>995eb84433f139cfb432acdec1cc60d9742eded7 Bump astro from 7.0.9 to 7.1.0 in /doc in the astro group (#1075)</li>
<li>017052d7e13046ed80c77d871437acc273b2cd23 Bump tokio from 1.52.3 to 1.52.4 (#1074)</li>
<li>eb9a870de6c3ba7357515960bbd3dd845905d18e Bump regex from 1.13.0 to 1.13.1 (#1073)</li>
<li>dd7f91502384fc7eaf89f72c8b369a8779be98d3 Bump clap from 4.6.1 to 4.6.2 (#1072)</li>
</ul>
]]></content:encoded></item><item><title>Remyx Outrider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/remyx-outrider/</link><pubDate>Fri, 17 Jul 2026 14:52:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/remyx-outrider/</guid><description>Version updated for https://github.com/remyxai/outrider to version v1.7.33.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Outrider, automates the process of validating and comparing new methods against an organization’s existing codebase. It uses Anthropic Opus or z.ai GLM-5.2 as model backends to evaluate arXiv methods (or design-doc leads) against real call sites, providing a self-review and issue routing feature. It supports branch-only mode and avoids duplicate work by not re-recommending papers once they have been referenced. The action is designed to streamline the integration of new models into production environments while ensuring compliance with code review metrics.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remyxai/outrider">https://github.com/remyxai/outrider</a></strong> to version <strong>v1.7.33</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/remyx-outrider">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, Outrider, automates the process of validating and comparing new methods against an organization&rsquo;s existing codebase. It uses Anthropic Opus or z.ai GLM-5.2 as model backends to evaluate arXiv methods (or design-doc leads) against real call sites, providing a self-review and issue routing feature. It supports branch-only mode and avoids duplicate work by not re-recommending papers once they have been referenced. The action is designed to streamline the integration of new models into production environments while ensuring compliance with code review metrics.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="fixed">Fixed</h2>
<p><strong>Refinement chain short-circuited when fidelity audit couldn&rsquo;t run</strong> (<a href="https://github.com/remyxai/outrider/pull/98">PR #98</a>) — the chain (fidelity → convention → test) treated `fidelity_skipped_*` statuses the same as actual audit failures, cancelling convention (PR-body rewrite) and test (pytest gate) even when the PR itself was unchanged.</p>
<p>Root cause: a single &ldquo;starts with `fidelity_audited`&rdquo; gate at chain entry. Skipping the audit because the paper&rsquo;s reference URL doesn&rsquo;t back-reference the arxiv (`fidelity_skipped_reference_mismatch`) leaves the PR fine, but convention + test never fired.</p>
<p>New taxonomy: chain continues on any `fidelity_skipped_<em>` <strong>except</strong> `fidelity_skipped_no_pr` (nothing to work on). Short-circuits stay on `fidelity_failed_</em>` (audit crashed → conservative, investigation warranted).</p>
<h2 id="compatibility">Compatibility</h2>
<p>Existing `fidelity_audited*` semantics unchanged. Only behavioral change is the three `fidelity_skipped_*` (no_reference, not_bot, reference_mismatch) now run convention + test where they previously short-circuited. No API-input or workflow-YAML changes.</p>
<p>The `remyxai/outrider@v1` action tag now points to v1.7.33.</p>
]]></content:encoded></item><item><title>RabbitMQ Publish</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/rabbitmq-publish/</link><pubDate>Fri, 17 Jul 2026 14:51:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/rabbitmq-publish/</guid><description>Version updated for https://github.com/rikkaneko/rabbitmq-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The RabbitMQ Publish Action automates the process of publishing UTF-8 payloads to a RabbitMQ or AMQP exchange or queue using GitHub Actions. It supports both username/password and mTLS certificate authentication, as well as newline-separated key=value AMQP headers and optional consumer acknowledgement through RabbitMQ direct reply-to. The action is configured via inputs and requires secrets for sensitive data storage.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rikkaneko/rabbitmq-action">https://github.com/rikkaneko/rabbitmq-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rabbitmq-publish">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The RabbitMQ Publish Action automates the process of publishing UTF-8 payloads to a RabbitMQ or AMQP exchange or queue using GitHub Actions. It supports both username/password and mTLS certificate authentication, as well as newline-separated <code>key=value</code> AMQP headers and optional consumer acknowledgement through RabbitMQ direct reply-to. The action is configured via inputs and requires secrets for sensitive data storage.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Major release v1</p>
]]></content:encoded></item><item><title>ForgeProof Verify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/forgeproof-verify/</link><pubDate>Fri, 17 Jul 2026 14:50:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/forgeproof-verify/</guid><description>Version updated for https://github.com/ryanjmichie-git/forgeproof-verify to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the verification of ForgeProof .rpack bundles in pull requests. It ensures that AI-generated code is properly sealed into provenance bundles and checks their integrity and completeness, failing the check on tampering. The action posts a human-readable audit report as a PR comment and writes the same report to the job summary. It supports glob patterns for bundle paths and options to control strictness and require bundle presence.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ryanjmichie-git/forgeproof-verify">https://github.com/ryanjmichie-git/forgeproof-verify</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/forgeproof-verify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the verification of ForgeProof <code>.rpack</code> bundles in pull requests. It ensures that AI-generated code is properly sealed into provenance bundles and checks their integrity and completeness, failing the check on tampering. The action posts a human-readable audit report as a PR comment and writes the same report to the job summary. It supports glob patterns for bundle paths and options to control strictness and require bundle presence.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial release: a stdlib-only composite action that verifies ForgeProof <code>.rpack</code>
provenance bundles (Ed25519-signed, SHA-256 hash-chained audit trails for
AI-generated code) on pull requests.</p>
<ul>
<li><strong>Strict by default</strong> — tamper <em>or</em> missing evidence turns the check red
(<code>strict</code> and <code>require-bundle</code> default to true); every input fails closed.</li>
<li><strong>Audit report where you need it</strong> — written to the job summary and upserted
as a single PR comment that updates in place.</li>
<li><strong>Fork-safe</strong> — on fork PRs the report goes to the job summary;
<code>pull_request_target</code> is deliberately unsupported.</li>
<li><strong>Vendored verifier</strong> with a hash sync-check against the pinned upstream
plugin release, so drift fails CI.</li>
<li>Proven by a 13-job CI matrix across Ubuntu/macOS/Windows, including a
4-way tamper matrix.</li>
</ul>
<p>Pair it with a required-status ruleset to block merging tampered PRs — see the
<a href="https://github.com/ryanjmichie-git/forgeproof-plugin/blob/main/docs/branch-protection.md">branch-protection recipe</a>.</p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/bernstein-multi-agent-orchestration/</link><pubDate>Fri, 17 Jul 2026 14:49:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.7.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bernstein orchestrates a crew of CLI coding agents to execute tasks in parallel against a single goal using deterministic scheduling. It provides an HMAC-signed audit chain with bearer-token authentication, signed agent cards, and per-artefact lineage recording.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Bernstein orchestrates a crew of CLI coding agents to execute tasks in parallel against a single goal using deterministic scheduling. It provides an HMAC-signed audit chain with bearer-token authentication, signed agent cards, and per-artefact lineage recording.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v370">v3.7.0</h1>
<p>Released 2026-07-17.</p>
<h2 id="theme">Theme</h2>
<p>v3.7.0 opens the orchestrator beyond coding agents and turns its determinism and audit chain into standard, independently verifiable receipts. The through-line: any agent, any artifact, and every result provable offline.</p>
<h2 id="highlights">Highlights</h2>
<h3 id="verifiable-receipts-in-standard-formats">Verifiable receipts, in standard formats</h3>
<ul>
<li><strong>Export the audit chain as standard verifiable receipts (#2617).</strong> Projects an HMAC audit-chain range into COSE_Sign1, in-toto attestation, and a transparency-log-style signed receipt, each re-verifiable offline by a standard verifier with zero Bernstein imports. Tampering with a chain entry breaks the receipt exactly as it breaks the chain.</li>
<li><strong>Per-goal SLA contracts (#2618).</strong> Signed violation receipts, lineage-anchored freshness, and ledger-projected error budgets: a breach is a signed, offline-verifiable receipt, not just a log line.</li>
</ul>
<h3 id="universalization-non-coding-agents-as-first-class">Universalization: non-coding agents as first-class</h3>
<ul>
<li><strong>Browser and computer-use adapter (#2621).</strong> A new adapter family fronts autonomous browser and computer-use agents. Every action is a content-addressed lineage anchor; the action sequence replays deterministically and a divergence surfaces as a hash mismatch at the exact action index.</li>
<li><strong>Research activity worker (#2630).</strong> Non-coding research runs land as artifacts whose every citation is an offline-resolvable lineage anchor, so a report reconstructs from the chain alone.</li>
</ul>
<h3 id="durable-resilient-execution">Durable, resilient execution</h3>
<ul>
<li><strong>Durable task suspend and resume (#2616).</strong> A task waiting on a human or external event parks with an attested receipt that releases the seat, sandbox, and budget envelope; resume reconstructs byte-identically from the receipt.</li>
<li><strong>Cache policy engine (#2625).</strong> Composable content-addressed key recipes, repo-drift expiry, claim-based fleet dedup with a signed duplicate-of receipt, and lineage-propagated eviction. Two operators derive byte-identical cache keys and verdicts.</li>
<li><strong>Lineage-attested failure receipts in recovery (#2628).</strong> An <code>on_fail</code> recovery task now carries a lineage-attested failure receipt, so why-it-failed and what-recovered are a single verifiable edge.</li>
</ul>
<h3 id="fleet-and-deployment">Fleet and deployment</h3>
<ul>
<li><strong>Named sandbox pools (#2547).</strong> Chain-projected pool manifests, governed overrides with capability and egress ceilings, and signed worker enrolment. Two hosts holding the same manifest compute a byte-identical effective-manifest hash; a widening override is refused with a chained receipt and no sandbox is created.</li>
<li><strong>Sovereign deployment profile (#2629).</strong> A signed residency posture attestation anchored in the audit chain; posture drift at spawn is a signed, offline-verifiable refusal rather than a silent misconfiguration.</li>
<li><strong>Mission timeline and signed daily digests (#2510).</strong> A mission screen backed by signed daily progress digests, each a verifiable projection of the day&rsquo;s chain.</li>
</ul>
<h2 id="security">Security</h2>
<p>Hardening from coordinated disclosure (all fixed and merged):</p>
<ul>
<li><strong>Memory provenance on the spawned-agent prompt path (#2624).</strong> The cross-adapter memory-poisoning invariant is now enforced where the spawned-agent prompt is built, not only in the opt-in query path.</li>
<li><strong>Sandbox scope enforcement (#2622).</strong> <code>scope_enforcement</code> is no longer auto-relaxed for a sandbox backend that cannot demonstrate a task-scoped mount.</li>
<li><strong>Newsletter endpoint (bernstein.run).</strong> <code>POST /api/notify</code> now returns a uniform response regardless of prior subscription state, closing a subscriber-membership oracle.</li>
</ul>
<p>The disclosure policy was also corrected (#2623, #2627, #2634): the prior SECURITY.md advertised a paid bug bounty with no budget behind it. It is replaced with an honest recognition-only coordinated-disclosure policy, and the sovereign profile now attests egress truthfully at spawn time.</p>
<h2 id="acknowledgments">Acknowledgments</h2>
<p>Thanks to the researchers who reported the issues above through coordinated disclosure:</p>
<ul>
<li><strong>Dmitriy Filatov (Malder)</strong> (@Malder-coder) for the memory-provenance and sandbox scope-enforcement reports.</li>
<li><strong>Gaurav Popalghat</strong> (<a href="https://www.linkedin.com/in/noobx/">https://www.linkedin.com/in/noobx/</a>) for the newsletter subscriber-enumeration report.</li>
</ul>
]]></content:encoded></item><item><title>Console CensorChecker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/console-censorchecker/</link><pubDate>Fri, 17 Jul 2026 14:47:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/console-censorchecker/</guid><description>Version updated for https://github.com/SpaceTimee/Console-CensorChecker to version 1.1.4.52.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: Console-CensorChecker is a PowerShell-based tcping batch probing and review detection script for checking network censorship status. It provides tools to check Tcping latency and service availability, with options to automate tasks through PowerShell scripts, modules, or GitHub Actions. The tool is suitable for any platform and can be used to monitor and review network services without bypassing censorship devices.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SpaceTimee/Console-CensorChecker">https://github.com/SpaceTimee/Console-CensorChecker</a></strong> to version <strong>1.1.4.52</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/console-censorchecker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary</strong>: Console-CensorChecker is a PowerShell-based tcping batch probing and review detection script for checking network censorship status. It provides tools to check Tcping latency and service availability, with options to automate tasks through PowerShell scripts, modules, or GitHub Actions. The tool is suitable for any platform and can be used to monitor and review network services without bypassing censorship devices.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ol>
<li>添加 Invoke-Check -mcp stdio MCP 服务支持</li>
<li>添加 -browser 参数</li>
<li>添加 -targets 单文件路径作为 Target.txt 支持</li>
<li>添加 Action 输入 BROWSER</li>
<li>添加 Action TARGETS 单文件路径支持</li>
<li>修改 Action 引号风格与路径处理</li>
</ol>
]]></content:encoded></item><item><title>gw - Go workspaces</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/gw-go-workspaces/</link><pubDate>Fri, 17 Jul 2026 14:47:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/gw-go-workspaces/</guid><description>Version updated for https://github.com/Toyz/gw to version v0.8.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The gw GitHub Action automates and simplifies working with Go workspaces by generating, maintaining, and linting dependencies across multiple modules. It allows users to run commands, sync dependencies, check linting issues, and manage module configurations efficiently. The action handles tasks like moving replace directives, syncing use sets, and verifying release contracts in a multi-module environment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Toyz/gw">https://github.com/Toyz/gw</a></strong> to version <strong>v0.8.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gw-go-workspaces">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>gw</code> GitHub Action automates and simplifies working with Go workspaces by generating, maintaining, and linting dependencies across multiple modules. It allows users to run commands, sync dependencies, check linting issues, and manage module configurations efficiently. The action handles tasks like moving replace directives, syncing use sets, and verifying release contracts in a multi-module environment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Toyz/gw/compare/v0.8.1...v0.8.2">https://github.com/Toyz/gw/compare/v0.8.1...v0.8.2</a></p>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/vibgrate-scan/</link><pubDate>Fri, 17 Jul 2026 14:45:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.715.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, @vibgrate/cli, automates local codebase intelligence and analysis tasks for AI coding agents. It provides a deterministic code graph with call trees, import paths, impact surfaces, dependency facts, and a drift score to assess how far behind the codebase is from current standards and best practices. The action runs on your machine without relying on external APIs or network calls, ensuring no data leaves your repository unless explicitly pushed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.715.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>@vibgrate/cli</code>, automates local codebase intelligence and analysis tasks for AI coding agents. It provides a deterministic code graph with call trees, import paths, impact surfaces, dependency facts, and a drift score to assess how far behind the codebase is from current standards and best practices. The action runs on your machine without relying on external APIs or network calls, ensuring no data leaves your repository unless explicitly pushed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20267151">Vibgrate CLI 2026.715.1</h1>
<p><em>Released 2026-07-15</em></p>
<p>This release of the Vibgrate CLI includes enhancements to database schema detection and improvements in code analysis accuracy. Users can expect better handling of various database formats and improved recognition of dependencies in code.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="new">New</h3>
<ul>
<li>Extended database schema detection to also read raw SQL migrations, SQL Server database projects, Drizzle, and TypeORM, tagging each detected table with its source.</li>
</ul>
<h3 id="improved">Improved</h3>
<ul>
<li>Improved code-search accuracy across all supported languages, especially for short, generated, or non-Latin symbol names.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Code graph analysis now recognizes Spring-style constructor/field dependency injection in Java and correctly attributes XCTest cases to the Swift classes they construct, even across different source directories.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.711.2, interleaved on one runner against the pinned corpus (157 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>18986 count</td>
          <td>18986 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>7660 count</td>
          <td>7660 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.97 ratio</td>
          <td>0.98 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>596.10 ms</td>
          <td>598.40 ms</td>
      </tr>
  </tbody>
</table>
<p>2 regression(s) — published, not omitted:</p>
<ul>
<li>Response size p95 (est. tokens): 246 → 247 (0.4%)</li>
<li>Locate top-1 — java: 0.97 → 0.96 (-1.1%)</li>
</ul>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.715.1">https://vibgrate.com/changelog/cli/2026.715.1</a></p>
]]></content:encoded></item><item><title>Derive Ruby versions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/derive-ruby-versions/</link><pubDate>Fri, 17 Jul 2026 14:44:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/derive-ruby-versions/</guid><description>Version updated for https://github.com/voxpupuli/ruby-version to version 2.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Ruby version determination GitHub Action reads a gemspec to determine the compatible Ruby versions for your testing matrix. It provides an output of compatible versions that can be used in CI pipelines to automate the process of setting up Ruby environments based on the specified requirements. The action supports Ruby versions from 2.4 to 4.0 and maintains a static list of compatible versions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/voxpupuli/ruby-version">https://github.com/voxpupuli/ruby-version</a></strong> to version <strong>2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/derive-ruby-versions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Ruby version determination GitHub Action reads a gemspec to determine the compatible Ruby versions for your testing matrix. It provides an output of compatible versions that can be used in CI pipelines to automate the process of setting up Ruby environments based on the specified requirements. The action supports Ruby versions from 2.4 to 4.0 and maintains a static list of compatible versions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at 2.0.0 -->
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="new-features-">New Features 🎉</h3>
<ul>
<li>Add Ruby 4.0 support by @bastelfreak in <a href="https://github.com/voxpupuli/ruby-version/pull/7">https://github.com/voxpupuli/ruby-version/pull/7</a></li>
<li>CI: pin external workflows &amp; Add GitHub Release config by @bastelfreak in <a href="https://github.com/voxpupuli/ruby-version/pull/12">https://github.com/voxpupuli/ruby-version/pull/12</a></li>
</ul>
<h3 id="other-changes">Other Changes</h3>
<ul>
<li>document Ruby 4.0 support by @bastelfreak in <a href="https://github.com/voxpupuli/ruby-version/pull/8">https://github.com/voxpupuli/ruby-version/pull/8</a></li>
<li>CI: Add dependabot configuration by @bastelfreak in <a href="https://github.com/voxpupuli/ruby-version/pull/9">https://github.com/voxpupuli/ruby-version/pull/9</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/voxpupuli/ruby-version/pull/10">https://github.com/voxpupuli/ruby-version/pull/10</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/voxpupuli/ruby-version/compare/1.0.1...2.0.0">https://github.com/voxpupuli/ruby-version/compare/1.0.1...2.0.0</a></p>
]]></content:encoded></item><item><title>WAF++ PASS Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/waf-pass-scan/</link><pubDate>Fri, 17 Jul 2026 14:44:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/waf-pass-scan/</guid><description>Version updated for https://github.com/WAF2p/wafpass-action to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The WAF++ PASS GitHub Action automates the execution of WAF++ scans on IaC files in a repository and pushes the results to a specified WAF++ server endpoint. It supports various IaC frameworks like Terraform, Bicep, CDK, and Pulumi. The action handles both bearer token and API key authentication for secure communication with the server. It also provides output parameters such as run_id, score, and findings_count to help users track the scan’s status and results.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/WAF2p/wafpass-action">https://github.com/WAF2p/wafpass-action</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/waf-pass-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The WAF++ PASS GitHub Action automates the execution of WAF++ scans on IaC files in a repository and pushes the results to a specified WAF++ server endpoint. It supports various IaC frameworks like Terraform, Bicep, CDK, and Pulumi. The action handles both bearer token and API key authentication for secure communication with the server. It also provides output parameters such as <code>run_id</code>, <code>score</code>, and <code>findings_count</code> to help users track the scan&rsquo;s status and results.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Run WAF++ PASS scans directly from GitHub Actions and push the results to your WAF++ server.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>One-step scan &amp; push</strong> — installs the <code>wafpass</code> CLI, runs the scan, and POSTs the JSON result to <code>POST /runs</code>.</li>
<li><strong>CI/CD-native runs</strong> — every run is automatically marked as <code>run: { is_cicd: true }</code> with <code>triggered_by: github-actions</code>.</li>
<li><strong>Flexible authentication</strong> — use a Bearer token (<code>api_token</code>) or an API key (<code>api_key</code>).</li>
<li><strong>Configurable failure policies</strong> — fail on <code>fail</code>, <code>skip</code>, <code>any</code>, or by severity (<code>low</code>, <code>medium</code>, <code>high</code>, <code>critical</code>), or use <code>never</code>.</li>
<li><strong>Multi-cloud / monorepo ready</strong> — scan multiple space-separated paths in a single step.</li>
<li><strong>Optional extras</strong> — Terraform plan change overview, source upload for dashboard diff previews, and server-fetched controls.</li>
</ul>
<h2 id="quick-start">Quick start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">name</span>: <span style="color:#ae81ff">Run WAF++ PASS</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">WAF2p/wafpass-action@v0.1.0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">server_url</span>: <span style="color:#ae81ff">https://wafpass.example.com</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">api_key</span>: <span style="color:#ae81ff">${{ secrets.WAFPASS_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">scan_path</span>: <span style="color:#ae81ff">./infra</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail_on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><p>Outputs</p>
<ul>
<li>run_id — UUID of the created run on the WAF++ server</li>
<li>score — overall compliance score</li>
<li>findings_count — number of findings returned by the scan</li>
</ul>
]]></content:encoded></item><item><title>Feishu Notification</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/feishu-notification/</link><pubDate>Fri, 17 Jul 2026 14:42:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/feishu-notification/</guid><description>Version updated for https://github.com/Waybox-AI/feishu-notification to version v1.0.21.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sends interactive card notifications to a Feishu (Lark) group chat when pull request events occur in your repository, providing notifications on PR opened, new commits pushed, and merged into the main branch. It skips closed PRs or those not merged into main.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Waybox-AI/feishu-notification">https://github.com/Waybox-AI/feishu-notification</a></strong> to version <strong>v1.0.21</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/feishu-notification">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sends interactive card notifications to a Feishu (Lark) group chat when pull request events occur in your repository, providing notifications on PR opened, new commits pushed, and merged into the <code>main</code> branch. It skips closed PRs or those not merged into <code>main</code>.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Waybox-AI/feishu-notification/compare/v1.0.20...v1.0.21">https://github.com/Waybox-AI/feishu-notification/compare/v1.0.20...v1.0.21</a></p>
]]></content:encoded></item><item><title>Kimi Code Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/kimi-code-action/</link><pubDate>Fri, 17 Jul 2026 14:40:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/kimi-code-action/</guid><description>Version updated for https://github.com/xuwenhao/kimi-code-action to version v0.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates code review and implementation tasks in pull requests and issues using the kimi-code CLI. It detects which mode to run based on events like comments or mentions of @kimi. Features include automatic mode detection, interactive code assistance, code review, code implementation, progress tracking, commit signing, session resume, and security hardening. The action runs entirely on GitHub runners with minimal external calls.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/xuwenhao/kimi-code-action">https://github.com/xuwenhao/kimi-code-action</a></strong> to version <strong>v0.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kimi-code-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates code review and implementation tasks in pull requests and issues using the kimi-code CLI. It detects which mode to run based on events like comments or mentions of <code>@kimi</code>. Features include automatic mode detection, interactive code assistance, code review, code implementation, progress tracking, commit signing, session resume, and security hardening. The action runs entirely on GitHub runners with minimal external calls.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release of <strong>kimi-code-action</strong> — agentic GitHub automation driven by the
<a href="https://github.com/MoonshotAI/kimi-code">Kimi Code CLI</a>, forked from
<a href="https://github.com/anthropics/claude-code-action">claude-code-action</a> (MIT, see NOTICE).</p>
<h2 id="what-it-does">What it does</h2>
<ul>
<li><strong>@kimi mentions</strong> — mention <code>@kimi</code> in issues, PR comments, or reviews; the agent
answers questions, implements changes, and pushes branches</li>
<li><strong>PR auto-review</strong> — tracked review comment with live checkboxes, plus inline comments
on exact diff lines (<code>track_progress: true</code>)</li>
<li><strong>Custom automation</strong> — any prompt on <code>workflow_dispatch</code> / <code>schedule</code> / <code>workflow_run</code>
(issue triage, CI failure analysis, …)</li>
<li><strong>Commit signing</strong> (GitHub API or SSH key), sticky comments, <code>session_id</code> resume</li>
<li><strong>Security hardening inherited from upstream</strong> — write-permission checks, content
sanitization, TOCTOU filtering, config restore from the base branch, restricted
git-push, default deny rules for <code>.github/workflows</code> and force-pushes</li>
</ul>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">xuwenhao/kimi-code-action@v0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">kimi_api_key</span>: <span style="color:#ae81ff">${{ secrets.KIMI_API_KEY }}</span>
</span></span></code></pre></div><h2 id="requirements">Requirements</h2>
<ul>
<li><code>KIMI_API_KEY</code> secret — Kimi Code subscribers create keys in the Kimi Code Console
(Console › API Keys); Open Platform keys work via <code>kimi_platform: open-cn|open-intl</code></li>
<li>Default model <code>k3</code> requires a Moderato plan or above; set <code>kimi_model: kimi-for-coding</code>
on lower plans</li>
</ul>
<h2 id="differences-from-upstream">Differences from upstream</h2>
<ul>
<li>Runs <code>kimi -p</code> with stream-json parsing; CLI config injected via a generated
<code>KIMI_CODE_HOME</code> (permission rules + <code>mcp.json</code>)</li>
<li>Not supported: OIDC App-token exchange, WIF/Bedrock/Vertex/Foundry,
<code>allowed_non_write_users</code>, structured output (<code>--json-schema</code>), plugins</li>
<li><code>kimi_args</code> maps Claude-style flags to kimi equivalents (<code>--allowedTools</code>,
<code>--max-turns</code>, <code>--mcp-config</code>, <code>--append-system-prompt</code>)</li>
</ul>
<p>Verified end-to-end on real runners: @kimi replies, tracked PR reviews, inline comments.
(base) ➜  ~ cat /tmp/kimi-code-action-v0.0.1-release-notes.md
First public release of <strong>kimi-code-action</strong> — agentic GitHub automation driven by the
<a href="https://github.com/MoonshotAI/kimi-code">Kimi Code CLI</a>, forked from
<a href="https://github.com/anthropics/claude-code-action">claude-code-action</a> (MIT, see NOTICE).</p>
<h2 id="what-it-does-1">What it does</h2>
<ul>
<li><strong>@kimi mentions</strong> — mention <code>@kimi</code> in issues, PR comments, or reviews; the agent
answers questions, implements changes, and pushes branches</li>
<li><strong>PR auto-review</strong> — tracked review comment with live checkboxes, plus inline comments
on exact diff lines (<code>track_progress: true</code>)</li>
<li><strong>Custom automation</strong> — any prompt on <code>workflow_dispatch</code> / <code>schedule</code> / <code>workflow_run</code>
(issue triage, CI failure analysis, …)</li>
<li><strong>Commit signing</strong> (GitHub API or SSH key), sticky comments, <code>session_id</code> resume</li>
<li><strong>Security hardening inherited from upstream</strong> — write-permission checks, content
sanitization, TOCTOU filtering, config restore from the base branch, restricted
git-push, default deny rules for <code>.github/workflows</code> and force-pushes</li>
</ul>
<h2 id="usage-1">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">xuwenhao/kimi-code-action@v0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">kimi_api_key</span>: <span style="color:#ae81ff">${{ secrets.KIMI_API_KEY }}</span>
</span></span></code></pre></div><h2 id="requirements-1">Requirements</h2>
<ul>
<li><code>KIMI_API_KEY</code> secret — Kimi Code subscribers create keys in the Kimi Code Console
(Console › API Keys); Open Platform keys work via <code>kimi_platform: open-cn|open-intl</code></li>
<li>Default model <code>k3</code> requires a Moderato plan or above; set <code>kimi_model: kimi-for-coding</code>
on lower plans</li>
</ul>
<h2 id="differences-from-upstream-1">Differences from upstream</h2>
<ul>
<li>Runs <code>kimi -p</code> with stream-json parsing; CLI config injected via a generated
<code>KIMI_CODE_HOME</code> (permission rules + <code>mcp.json</code>)</li>
<li>Not supported: OIDC App-token exchange, WIF/Bedrock/Vertex/Foundry,
<code>allowed_non_write_users</code>, structured output (<code>--json-schema</code>), plugins</li>
<li><code>kimi_args</code> maps Claude-style flags to kimi equivalents (<code>--allowedTools</code>,
<code>--max-turns</code>, <code>--mcp-config</code>, <code>--append-system-prompt</code>)</li>
</ul>
<p>Verified end-to-end on real runners: @kimi replies, tracked PR reviews, inline comments.</p>
]]></content:encoded></item><item><title>Kover Report Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/kover-report-action/</link><pubDate>Fri, 17 Jul 2026 14:39:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/kover-report-action/</guid><description>Version updated for https://github.com/yshrsmz/kover-report-action to version v3.1.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Kover Report Action is a GitHub Action designed to generate and report code coverage from Kover XML reports in Kotlin/Android projects using multi-module support. It supports various discovery methods and customizable thresholds, enabling easy integration into CI/CD workflows. The action also provides automatic PR comments for coverage results with trend indicators and allows exporting coverage data for further use.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yshrsmz/kover-report-action">https://github.com/yshrsmz/kover-report-action</a></strong> to version <strong>v3.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kover-report-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Kover Report Action is a GitHub Action designed to generate and report code coverage from Kover XML reports in Kotlin/Android projects using multi-module support. It supports various discovery methods and customizable thresholds, enabling easy integration into CI/CD workflows. The action also provides automatic PR comments for coverage results with trend indicators and allows exporting coverage data for further use.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>v3.1.2: PR #139 - fix(deps): update dependency @actions/tool-cache to v4</p>
]]></content:encoded></item><item><title>Agent Lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/agent-lint/</link><pubDate>Fri, 17 Jul 2026 14:38:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/agent-lint/</guid><description>Version updated for https://github.com/zhupanov/agent-lint to version v2.7.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Lint is a versatile linter for Claude Code, Cursor, and Codex configurations. It checks for various issues related to manifest files, hook paths, skill frontmatter, agent fields, prompt content, Claude rules, output styles, settings, hygiene, email format, user configuration, MCP server setup, Codex configuration, Cursor rules, and Cursor skills. The tool supports both Basic and Plugin modes based on the presence of .claude-plugin/ in the repository, and it provides a GitHub Action for easy integration into CI pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zhupanov/agent-lint">https://github.com/zhupanov/agent-lint</a></strong> to version <strong>v2.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Agent Lint is a versatile linter for Claude Code, Cursor, and Codex configurations. It checks for various issues related to manifest files, hook paths, skill frontmatter, agent fields, prompt content, Claude rules, output styles, settings, hygiene, email format, user configuration, MCP server setup, Codex configuration, Cursor rules, and Cursor skills. The tool supports both Basic and Plugin modes based on the presence of <code>.claude-plugin/</code> in the repository, and it provides a GitHub Action for easy integration into CI pipelines.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bootstrap agent-lint configuration and CI by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/167">https://github.com/zhupanov/agent-lint/pull/167</a></li>
<li>Verify documented rules have implementations by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/170">https://github.com/zhupanov/agent-lint/pull/170</a></li>
<li>Complete S021/G009/D004/S062 parity for remaining generic larch linters by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/171">https://github.com/zhupanov/agent-lint/pull/171</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/zhupanov/agent-lint/compare/v2.6.0...v2.7.0">https://github.com/zhupanov/agent-lint/compare/v2.6.0...v2.7.0</a></p>
]]></content:encoded></item><item><title>Draugr Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/draugr-security-scan/</link><pubDate>Fri, 17 Jul 2026 07:04:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/draugr-security-scan/</guid><description>Version updated for https://github.com/draugr-dev/draugr to version v0.20.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Draugr, automates developer-first security scanning of applications. It uses a single descriptor file (draugr.saga.yaml) to declare software components and dependencies, enabling the orchestration of various security controls such as image scanning with Trivy, secret detection with Gitleaks, and source code analysis with Semgrep. Draugr normalizes results to SARIF format for easy integration into continuous integration pipelines, allowing developers to prioritize and gate scans based on criticality levels.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/draugr-dev/draugr">https://github.com/draugr-dev/draugr</a></strong> to version <strong>v0.20.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/draugr-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, Draugr, automates developer-first security scanning of applications. It uses a single descriptor file (<code>draugr.saga.yaml</code>) to declare software components and dependencies, enabling the orchestration of various security controls such as image scanning with Trivy, secret detection with Gitleaks, and source code analysis with Semgrep. Draugr normalizes results to SARIF format for easy integration into continuous integration pipelines, allowing developers to prioritize and gate scans based on criticality levels.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong><code>draugr diff &lt;base.sarif&gt; &lt;head.sarif&gt;</code></strong> — compare two scans and classify every finding as
<strong>new / fixed / unchanged</strong>, with a delta by severity and priority. The headline use case is a
PR&rsquo;s security impact vs its base branch. Adds a <strong>differential gate</strong> (<code>--fail-on-new</code> /
<code>--fail-on-new-priority</code>) that fails a build only for findings the change <em>introduces</em>, not the
pre-existing backlog — so gating stays adoptable. Renders as <code>console</code>, <code>markdown</code> (a ready-made
MR comment), or <code>json</code>. Findings are matched line-insensitively, so carried-over findings that
merely moved lines aren&rsquo;t reported as fixed + new.</li>
<li><strong>Two more <code>draugr scan --format</code> outputs.</strong> <code>html</code> renders a self-contained, browser-viewable
report (inline CSS, no assets) you can publish as a build artifact; <code>junit</code> emits JUnit XML so
CI systems (GitLab, Jenkins, Azure DevOps…) surface findings in their native test-results panel
— one <code>&lt;testsuite&gt;</code> per control, one failing <code>&lt;testcase&gt;</code> per finding. Both plug into the same
Reporter interface as <code>console</code>/<code>markdown</code>/<code>json</code>/<code>sarif</code>.</li>
</ul>
]]></content:encoded></item><item><title>Semantic Version Release</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/semantic-version-release/</link><pubDate>Fri, 17 Jul 2026 07:03:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/semantic-version-release/</guid><description>Version updated for https://github.com/EasyDesk/action-semver-release to version v1.1.8.
This action is used across all versions by 67 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of updating major and minor version tags when a release is triggered, creating corresponding GitHub releases, and handling semantic versioning to ensure version consistency. It supports handling conditional execution based on version format, making it suitable for projects that require precise version management and tagging practices.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/EasyDesk/action-semver-release">https://github.com/EasyDesk/action-semver-release</a></strong> to version <strong>v1.1.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>67</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/semantic-version-release">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of updating major and minor version tags when a release is triggered, creating corresponding GitHub releases, and handling semantic versioning to ensure version consistency. It supports handling conditional execution based on version format, making it suitable for projects that require precise version management and tagging practices.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/EasyDesk/action-semver-release/compare/v1.1.7...v1.1.8">https://github.com/EasyDesk/action-semver-release/compare/v1.1.7...v1.1.8</a></p>
]]></content:encoded></item><item><title>Pitwall k6 Report</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/pitwall-k6-report/</link><pubDate>Fri, 17 Jul 2026 07:02:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/pitwall-k6-report/</guid><description>Version updated for https://github.com/florin-stefan/pitwall-k6 to version 0.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Pitwall-k6, automates the process of generating and serving a comprehensive HTML report from k6 load test results. It parses various output formats (raw JSON stream, summary files) to reconstruct detailed metrics including thresholds, checks, and pass/fail verdicts. The generated report includes charts for trends across runs and a glossary of key metrics. Users can easily serve the report locally or directly in their web applications, making it accessible without additional backend infrastructure.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/florin-stefan/pitwall-k6">https://github.com/florin-stefan/pitwall-k6</a></strong> to version <strong>0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pitwall-k6-report">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, Pitwall-k6, automates the process of generating and serving a comprehensive HTML report from k6 load test results. It parses various output formats (raw JSON stream, summary files) to reconstruct detailed metrics including thresholds, checks, and pass/fail verdicts. The generated report includes charts for trends across runs and a glossary of key metrics. Users can easily serve the report locally or directly in their web applications, making it accessible without additional backend infrastructure.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The first public release of <strong>Pitwall</strong> — a complete, portable HTML report for <a href="https://k6.io">k6</a> load tests. Point it at the output k6 already produces and get a static site with the full metrics breakdown, pass/fail verdicts, trend charts across runs, and a plain-language glossary. No backend, no CDN calls, no telemetry — host the folder anywhere.</p>
<p><img src="https://raw.githubusercontent.com/florin-stefan/pitwall-k6/main/.github/assets/pitwall-report.png" alt="Pitwall report overview"></p>
<p>🔗 <strong><a href="https://florin-stefan.github.io/pitwall-k6/">View a live sample report</a></strong></p>
<h2 id="use-it-as-a-github-action">Use it as a GitHub Action</h2>
<p>Run k6 first (e.g. with <code>grafana/setup-k6-action</code>), then:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">florin-stefan/pitwall-k6@v0.3.0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">results</span>: <span style="color:#ae81ff">results.json summary.json</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">name</span>: <span style="color:#ae81ff">checkout flow</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">run-id</span>: <span style="color:#ae81ff">${{ github.run_number }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on-thresholds</span>: <span style="color:#66d9ef">true</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/upload-artifact@v4</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">if</span>: <span style="color:#ae81ff">always()</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">name</span>: <span style="color:#ae81ff">pitwall-report</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">path</span>: <span style="color:#ae81ff">pitwall-report</span>
</span></span></code></pre></div><p>The action installs Pitwall, generates the report, appends a run summary (verdict, headline stats, thresholds, slowest endpoints) to the job summary page, and — with <code>fail-on-thresholds</code> — gates the job on breached thresholds <em>after</em> the report is written, so a red build still has the full report as an artifact.</p>
<h2 id="use-it-as-a-cli">Use it as a CLI</h2>
<pre tabindex="0"><code>k6 run --out json=results.json script.js
pitwall serve results.json
</code></pre><p>Works with the raw <code>--out json=</code> stream (plain or gzipped), a <code>handleSummary()</code> export, a <code>--summary-export=</code> file, or any combination — formats are auto-detected.</p>
<h2 id="highlights-in-030">Highlights in 0.3.0</h2>
<ul>
<li><strong><code>pitwall diff &lt;baseline&gt; &lt;current&gt;</code></strong> — compare two runs: headline deltas, per-endpoint p95 changes, new/removed endpoints. <code>--fail-on-p95 &lt;pct&gt;</code> and <code>--fail-on-error-rate &lt;points&gt;</code> turn it into a CI regression gate that catches <em>drift</em> before it breaches a threshold; <code>--md</code> writes the comparison as PR-ready markdown.</li>
<li><strong>GitHub Action</strong> (this listing) with threshold gating and automatic job summaries.</li>
<li><strong>Multi-run trend history</strong> — every <code>generate</code> appends to a small history file; the Trends page charts p95, error rate, throughput, and checks across your last runs, and the overview shows run-over-run deltas.</li>
<li><strong>CI on Node 18/20/22</strong> (Linux + Windows), plus a security policy, contributing guide, and issue templates.</li>
</ul>
<h2 id="docs">Docs</h2>
<ul>
<li><a href="https://github.com/florin-stefan/pitwall-k6/blob/main/docs/beginners-guide.md">Beginner&rsquo;s guide</a> — from installing Node and k6 to reading your first report</li>
<li><a href="https://github.com/florin-stefan/pitwall-k6/blob/main/docs/commands.md">Command reference</a> — every command, flag, and exit code</li>
<li><a href="https://github.com/florin-stefan/pitwall-k6/blob/main/docs/features.md">Feature guide</a> — every report page, history, CI gating, hosting</li>
<li><a href="https://github.com/florin-stefan/pitwall-k6/blob/main/CHANGELOG.md">Changelog</a> · <a href="https://github.com/florin-stefan/pitwall-k6/blob/main/SECURITY.md">Security policy</a></li>
</ul>
<hr>
<p><strong>Requirements:</strong> Node ≥ 18 for the CLI; the action runs on any standard GitHub-hosted runner. npm package publication is coming — until then, the action is fully self-contained, and the CLI works from a clone (<code>npm install &amp;&amp; npm link</code>).</p>
]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/ai-plugin-scanner/</link><pubDate>Fri, 17 Jul 2026 07:01:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.509.
This action is used across all versions by 19 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action automates the security, publishability, runtime readiness, and trust signal verification of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems. It emits structured reports, SARIF, policy results, and submission metadata while staying aligned with the main scanner release train. The default install path uses an exact PyPI release, verifies its provenance against hol-guard, and only then installs it. Advanced distribution paths are available when needed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.509</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>19</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action automates the security, publishability, runtime readiness, and trust signal verification of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems. It emits structured reports, SARIF, policy results, and submission metadata while staying aligned with the main scanner release train. The default install path uses an exact PyPI release, verifies its provenance against <code>hol-guard</code>, and only then installs it. Advanced distribution paths are available when needed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/5fb1369318ac81ae4f8fb0a9c0a7a7721f20080c">https://github.com/hashgraph-online/hol-guard/tree/5fb1369318ac81ae4f8fb0a9c0a7a7721f20080c</a> with plugin-scanner 2.0.1111.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.508...v1.2.509">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.508...v1.2.509</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/hol-codex-plugin-scanner/</link><pubDate>Fri, 17 Jul 2026 07:00:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.509.
This action is used across all versions by 12 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the scanning of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems. It checks for security, publishability, runtime readiness, and trust signals, emitting structured reports, SARIF, policy results, and submission metadata. The action stays aligned to the main scanner release train and can be used in workflows by specifying paths and execution modes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.509</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>12</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action automates the scanning of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems. It checks for security, publishability, runtime readiness, and trust signals, emitting structured reports, SARIF, policy results, and submission metadata. The action stays aligned to the main scanner release train and can be used in workflows by specifying paths and execution modes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.509">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.509</a></p>
]]></content:encoded></item><item><title>action-tag-release-build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/action-tag-release-build/</link><pubDate>Fri, 17 Jul 2026 06:59:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/action-tag-release-build/</guid><description>Version updated for https://github.com/heronlabs/action-tag-release-build to version v6.0.7.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action “tag-release-build” automates the process of bumping the version number, creating a tag, updating a CHANGELOG, and optionally publishing a release in GitLab CI/CD pipelines. It uses semantic versioning based on commit messages to determine the type of update (major, minor, or patch). The action supports syncing the updated version with package.json files and Claude Code plugin files for easy integration into existing projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/heronlabs/action-tag-release-build">https://github.com/heronlabs/action-tag-release-build</a></strong> to version <strong>v6.0.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/action-tag-release-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action &ldquo;tag-release-build&rdquo; automates the process of bumping the version number, creating a tag, updating a CHANGELOG, and optionally publishing a release in GitLab CI/CD pipelines. It uses semantic versioning based on commit messages to determine the type of update (major, minor, or patch). The action supports syncing the updated version with package.json files and Claude Code plugin files for easy integration into existing projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>[skip ci] bump v6.0.7 (4f529d9)</li>
<li>ci: remove redundant cache, restructure job DAG (#40) (9cea684)</li>
<li>[skip ci] bump v6.0.6 (2ca8be8)</li>
<li>fix: Replace stdout.write with stderr outside CLI (#39) (9297e26)</li>
<li>[skip ci] bump v6.0.5 (7b0f39c)</li>
<li>chore: Remove version comments, bump pnpm to 11.13.1 (#38) (b02bfe0)</li>
<li>[skip ci] bump v6.0.4 (dbe67f5)</li>
<li>chore(deps-dev): bump the npm group across 1 directory with 2 updates (#35) (f8a8b9f)</li>
<li>[skip ci] bump v6.0.3 (9f2e0f2)</li>
<li>chore(deps): bump actions/setup-node (#36) (69a2407)</li>
</ul>
]]></content:encoded></item><item><title>Agentic Workflow Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/agentic-workflow-guard/</link><pubDate>Fri, 17 Jul 2026 06:58:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/agentic-workflow-guard/</guid><description>Version updated for https://github.com/jinyounghub/agentic-workflow-guard to version v0.2.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action agentic-workflow-guard is a static analyzer designed to detect and prevent AI-agent-specific vulnerabilities in GitHub Actions workflows. It focuses on identifying potential risks where untrusted event data, such as issue bodies, PR comments, branch names, or commit messages, are passed into AI agent prompts, potentially leading to write permissions, scripts, release commands, or secrets being executed with elevated privileges. This action helps ensure the security of CI/CD pipelines by monitoring for these high-risk patterns without requiring access to API keys or sending sensitive workflow content to external models.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jinyounghub/agentic-workflow-guard">https://github.com/jinyounghub/agentic-workflow-guard</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentic-workflow-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>agentic-workflow-guard</code> is a static analyzer designed to detect and prevent AI-agent-specific vulnerabilities in GitHub Actions workflows. It focuses on identifying potential risks where untrusted event data, such as issue bodies, PR comments, branch names, or commit messages, are passed into AI agent prompts, potentially leading to write permissions, scripts, release commands, or secrets being executed with elevated privileges. This action helps ensure the security of CI/CD pipelines by monitoring for these high-risk patterns without requiring access to API keys or sending sensitive workflow content to external models.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s changed</h2>
<ul>
<li>Added a 30-second advisory GitHub Action quick start near the top of the README.</li>
<li>Added a real synthetic report preview plus direct links to the successful demo run and Marketplace listing.</li>
<li>Declared the Action&rsquo;s <code>report-path</code>, <code>findings</code>, and severity-count outputs in <code>action.yml</code>.</li>
<li>Added metadata coverage so declared outputs stay aligned with the runtime.</li>
<li>Stabilized the committed baseline fixture test across Windows path aliases.</li>
</ul>
<h2 id="install">Install</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npm install --save-dev @jin0/agentic-workflow-guard@0.2.1
</span></span></code></pre></div><p>GitHub Actions users can continue using <code>jinyounghub/agentic-workflow-guard@v0</code>, which now points to this release.</p>
<p><strong>Full changelog:</strong> <a href="https://github.com/jinyounghub/agentic-workflow-guard/compare/v0.2.0...v0.2.1">https://github.com/jinyounghub/agentic-workflow-guard/compare/v0.2.0...v0.2.1</a></p>
]]></content:encoded></item><item><title>setup-jemalloc</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/setup-jemalloc/</link><pubDate>Fri, 17 Jul 2026 06:57:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/setup-jemalloc/</guid><description>Version updated for https://github.com/kaeawc/setup-jemalloc to version v0.0.4.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action downloads, installs, and caches jemalloc, replacing the default malloc to free up unused native memory due to fragmentation. It supports Linux but requires arm64e target architecture on macOS. The action can be invoked multiple times within a job without affecting existing processes, ensuring atomic installations and idempotency.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kaeawc/setup-jemalloc">https://github.com/kaeawc/setup-jemalloc</a></strong> to version <strong>v0.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-jemalloc">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action downloads, installs, and caches jemalloc, replacing the default malloc to free up unused native memory due to fragmentation. It supports Linux but requires arm64e target architecture on macOS. The action can be invoked multiple times within a job without affecting existing processes, ensuring atomic installations and idempotency.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="bug-fixes">Bug fixes</h2>
<ul>
<li><strong>Fixed SIGSEGV (exit code 139) when the action is invoked more than once in the same job</strong> (#5, #6). The relocate step previously overwrote <code>/usr/local/lib/libjemalloc.so.2</code> in place with <code>cp</code> — but on a second invocation that library is already <code>LD_PRELOAD</code>&rsquo;d into the running <code>cp</code>, and truncating a live-mmap&rsquo;d shared object crashed it before the workload ran. The install is now <strong>atomic</strong> (temp file + <code>rename(2)</code>, so live mappings keep the old inode) and <strong>idempotent</strong> (skips entirely when the destination already matches). The action is now safe to invoke multiple times per job.</li>
</ul>
<h2 id="internals">Internals</h2>
<ul>
<li>Relocate logic extracted into <code>scripts/linux/relocate.sh</code> / <code>scripts/mac/relocate.sh</code> with dependency-free unit tests (<code>tests/relocate_test.sh</code>).</li>
<li>New CI jobs: shellcheck + unit tests, and a <code>linux_double_invocation</code> regression job that invokes the action twice in one job and asserts the first invocation&rsquo;s jemalloc-preloaded process survives the second.</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/kaeawc/setup-jemalloc/compare/v0.0.3...v0.0.4">https://github.com/kaeawc/setup-jemalloc/compare/v0.0.3...v0.0.4</a></p>
]]></content:encoded></item><item><title>16 Eyes</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/16-eyes/</link><pubDate>Fri, 17 Jul 2026 06:56:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/16-eyes/</guid><description>Version updated for https://github.com/kigiela/16-eyes to version v1.1.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
This GitHub Action is designed to perform security audits on code repositories using AI-driven tools. It provides a comprehensive, multi-agent approach to identify and verify security issues across an entire repository or specific changes in a pull request. The action profiles the repository’s architecture and design before automating the scanning process with tailored lenses that check for vulnerabilities, ensuring robust and skeptical review processes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kigiela/16-eyes">https://github.com/kigiela/16-eyes</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/16-eyes">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>This GitHub Action is designed to perform security audits on code repositories using AI-driven tools. It provides a comprehensive, multi-agent approach to identify and verify security issues across an entire repository or specific changes in a pull request. The action profiles the repository&rsquo;s architecture and design before automating the scanning process with tailored lenses that check for vulnerabilities, ensuring robust and skeptical review processes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: shorten action.yml description to fit GitHub Marketplace&rsquo;s 125-char limit by @kigiela in <a href="https://github.com/kigiela/16-eyes/pull/16">https://github.com/kigiela/16-eyes/pull/16</a></li>
<li>chore: bump version to 1.1.1 by @kigiela in <a href="https://github.com/kigiela/16-eyes/pull/17">https://github.com/kigiela/16-eyes/pull/17</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/kigiela/16-eyes/compare/v1.1.0...v1.1.1">https://github.com/kigiela/16-eyes/compare/v1.1.0...v1.1.1</a></p>
]]></content:encoded></item><item><title>Setup runner cli</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/setup-runner-cli/</link><pubDate>Fri, 17 Jul 2026 06:55:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/setup-runner-cli/</guid><description>Version updated for https://github.com/kjanat/runner to version v0.20.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary runner is an action designed to help developers quickly identify and run commands across multiple task runners and package managers within their projects. It provides a tab completion feature that suggests available tasks and packages, reducing the need to remember specific command structures or configurations for different repositories. This tool enhances efficiency by automating the process of selecting the correct runner and command for executing tasks, making it easier to manage and run project-related commands without manual configuration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kjanat/runner">https://github.com/kjanat/runner</a></strong> to version <strong>v0.20.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-runner-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>runner</strong> is an action designed to help developers quickly identify and run commands across multiple task runners and package managers within their projects. It provides a tab completion feature that suggests available tasks and packages, reducing the need to remember specific command structures or configurations for different repositories. This tool enhances efficiency by automating the process of selecting the correct runner and command for executing tasks, making it easier to manage and run project-related commands without manual configuration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><code>[install].on_collision</code> (<code>RUNNER_INSTALL_ON_COLLISION</code>) decides what
<code>runner install</code> does when two detected package managers write the same
directory. <code>&quot;resolve&quot;</code> (the default) installs with the PM already resolved
for that ecosystem (lockfile, <code>packageManager</code>, <code>[pm].node</code>) and skips the
other, printing which one it skipped; <code>&quot;error&quot;</code> refuses to pick and exits 2.
Under <code>&quot;resolve&quot;</code>, naming both writers in <code>[install].pms</code> still runs both;
<code>&quot;error&quot;</code> refuses the collision even when both writers are explicitly named.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>Package managers that write the same install directory no longer install
concurrently. <code>bun install</code> and <code>deno install</code> over one <code>node_modules/</code> now
run one after another; managers with their own directories (cargo, uv, go)
still overlap.</li>
<li>The install-dir collision warning is confined to <code>runner install</code> and
<code>doctor</code>, the surfaces that can act on it. It was reaching <code>run</code>, <code>list</code>,
<code>info</code>, and every nested runner process, none of which install anything.
<code>doctor</code> also reports the install plan (which PM installs a shared directory,
and which is shadowed) as a <code>conflicts[]</code> entry alongside duplicate task
names.</li>
<li>Detection warnings are printed once per project, not once per runner process.
A <code>package.json</code> script that calls <code>runner</code> again (<code>&quot;fmt&quot;: &quot;runner run lint:fix fmt:dprint&quot;</code>) no longer repeats its parent&rsquo;s warnings.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Deno counts as a <code>node_modules</code> writer in any project with a <code>package.json</code>,
not only one that sets <code>nodeModulesDir</code> explicitly. Deno&rsquo;s documented default
for a <code>package.json</code> project is the manual <code>node_modules</code> mode, so
<code>deno install</code> was writing the same tree as bun/npm/pnpm/yarn while runner
reported no collision at all.</li>
<li>Two node lockfiles in one directory are settled by which one git tracks
before falling back to the fixed <code>bun &gt; pnpm &gt; yarn &gt; npm</code> preference. A
project that commits <code>bun.lock</code> and gitignores <code>package-lock.json</code> is a bun
project, whichever way the preference order happens to point. Committed
status is the signal, not ignore status: a gitignored lockfile is ambiguous
(it can mean &ldquo;we never commit lockfiles&rdquo;, which is evidence the manager <em>is</em>
used). One lockfile still answers by itself, and no git process is spawned
unless a directory holds two or more.</li>
<li>A prerelease package-manager build (<code>bun@1.3.0-canary</code>) satisfies a
<code>devEngines</code> range like <code>&gt;=1.2</code> instead of reporting a version mismatch.
Semver excludes prereleases from ranges that don&rsquo;t name one, which is correct
for a dependency solver and wrong for a &ldquo;is the installed tool new enough&rdquo;
check.</li>
<li><code>runner install</code> no longer orphans a running package manager when waiting on
another one fails.</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(install): resolve install-dir collisions by @kjanat in <a href="https://github.com/kjanat/runner/pull/88">https://github.com/kjanat/runner/pull/88</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/kjanat/runner/compare/v0.19.1...v0.20.0">https://github.com/kjanat/runner/compare/v0.19.1...v0.20.0</a></p>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/totem-shield/</link><pubDate>Fri, 17 Jul 2026 06:54:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.99.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Totem is a GitHub Action that enhances AI coding agents by providing a file-based toolkit. It helps prevent common mistakes and architectural issues by enforcing clear rules and lessons through plain text markdown files. The action includes a queryable knowledge index and a zero-LLM linter to ensure deterministic code, enhancing the integrity of project architecture and reducing the need for frequent re-explaining between sessions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.99.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Totem is a GitHub Action that enhances AI coding agents by providing a file-based toolkit. It helps prevent common mistakes and architectural issues by enforcing clear rules and lessons through plain text markdown files. The action includes a queryable knowledge index and a zero-LLM linter to ensure deterministic code, enhancing the integrity of project architecture and reducing the need for frequent re-explaining between sessions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>AI Harness Doctor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/ai-harness-doctor/</link><pubDate>Fri, 17 Jul 2026 06:53:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/ai-harness-doctor/</guid><description>Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v1.11.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Harness Doctor is an automated tool designed to audit AI harnesses and provide insights into their consistency, security, and efficacy. It helps in consolidating scattered instructions into a single AGENTS.md file and ensuring that all related files are kept small pointers. The tool also measures the improvement in agent answers after consolidation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NieZhuZhu/ai-harness-doctor">https://github.com/NieZhuZhu/ai-harness-doctor</a></strong> to version <strong>v1.11.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-harness-doctor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AI Harness Doctor is an automated tool designed to audit AI harnesses and provide insights into their consistency, security, and efficacy. It helps in consolidating scattered instructions into a single <code>AGENTS.md</code> file and ensuring that all related files are kept small pointers. The tool also measures the improvement in agent answers after consolidation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs(plans): plan LLM-judge unparseable-output fallback (Plan 043) by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/211">https://github.com/NieZhuZhu/ai-harness-doctor/pull/211</a></li>
<li>fix(eval): fall back to keyword judge on unparseable LLM output (Plan 043) by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/212">https://github.com/NieZhuZhu/ai-harness-doctor/pull/212</a></li>
<li>docs(plans): plan installer incomplete-transaction recovery (Plan 044) by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/213">https://github.com/NieZhuZhu/ai-harness-doctor/pull/213</a></li>
<li>fix(cli): recover journal-less installer transactions (Plan 044) by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/214">https://github.com/NieZhuZhu/ai-harness-doctor/pull/214</a></li>
<li>docs(plans): single-source scoped eval lockfile facts (Plan 045) by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/215">https://github.com/NieZhuZhu/ai-harness-doctor/pull/215</a></li>
<li>fix(eval): single-source scoped lockfile facts (Plan 045) by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/216">https://github.com/NieZhuZhu/ai-harness-doctor/pull/216</a></li>
<li>docs(plans): mark Plan 045 done by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/217">https://github.com/NieZhuZhu/ai-harness-doctor/pull/217</a></li>
<li>docs(plans): Action quality outputs and Job Summary (Plan 046) by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/218">https://github.com/NieZhuZhu/ai-harness-doctor/pull/218</a></li>
<li>feat(action): quality outputs and Job Summary (Plan 046) by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/219">https://github.com/NieZhuZhu/ai-harness-doctor/pull/219</a></li>
<li>docs(plans): close the baseline debt lifecycle (Plan 047) by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/220">https://github.com/NieZhuZhu/ai-harness-doctor/pull/220</a></li>
<li>feat(baseline): new/known/resolved lifecycle and safe pruning (Plan 047) by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/221">https://github.com/NieZhuZhu/ai-harness-doctor/pull/221</a></li>
<li>docs(plans): truthful Action reporting for baseline maintenance (Plan 048) by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/222">https://github.com/NieZhuZhu/ai-harness-doctor/pull/222</a></li>
<li>feat(action): truthful baseline maintenance reporting (Plan 048) by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/223">https://github.com/NieZhuZhu/ai-harness-doctor/pull/223</a></li>
<li>docs(agents): consolidate Plans 046-048 maintenance contracts by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/224">https://github.com/NieZhuZhu/ai-harness-doctor/pull/224</a></li>
<li>docs(readme): improve readability and add four languages by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/225">https://github.com/NieZhuZhu/ai-harness-doctor/pull/225</a></li>
<li>docs(plans): redact hook secrets from all reports (Plan 049) by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/226">https://github.com/NieZhuZhu/ai-harness-doctor/pull/226</a></li>
<li>fix(scan): redact hook credentials from every report surface (Plan 049) by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/227">https://github.com/NieZhuZhu/ai-harness-doctor/pull/227</a></li>
<li>docs(plans): harden LLM judge endpoint trust (Plan 050) by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/228">https://github.com/NieZhuZhu/ai-harness-doctor/pull/228</a></li>
<li>fix(eval): keep LLM judge credentials on trusted endpoints (Plan 050) by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/229">https://github.com/NieZhuZhu/ai-harness-doctor/pull/229</a></li>
<li>docs(plans): redact credentials from eval artifacts (Plan 051) by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/230">https://github.com/NieZhuZhu/ai-harness-doctor/pull/230</a></li>
<li>fix(eval): redact credentials from persisted artifacts by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/231">https://github.com/NieZhuZhu/ai-harness-doctor/pull/231</a></li>
<li>docs(plans): close Plan 051 by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/232">https://github.com/NieZhuZhu/ai-harness-doctor/pull/232</a></li>
<li>docs(plans): honor gitignored runtime paths (Plan 052) by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/233">https://github.com/NieZhuZhu/ai-harness-doctor/pull/233</a></li>
<li>fix(paths): honor repository gitignore for runtime paths by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/234">https://github.com/NieZhuZhu/ai-harness-doctor/pull/234</a></li>
<li>docs(plans): close Plan 052 by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/235">https://github.com/NieZhuZhu/ai-harness-doctor/pull/235</a></li>
<li>docs(plans): resolve nested package ancestors (Plan 053) by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/236">https://github.com/NieZhuZhu/ai-harness-doctor/pull/236</a></li>
<li>fix(drift): resolve nested facts through package ancestors by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/237">https://github.com/NieZhuZhu/ai-harness-doctor/pull/237</a></li>
<li>docs(plans): close Plan 053 by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/238">https://github.com/NieZhuZhu/ai-harness-doctor/pull/238</a></li>
<li>docs(plans): add structured Action args (Plan 054) by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/239">https://github.com/NieZhuZhu/ai-harness-doctor/pull/239</a></li>
<li>feat(action): add structured extra arguments by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/240">https://github.com/NieZhuZhu/ai-harness-doctor/pull/240</a></li>
<li>docs(plans): close Plan 054 by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/241">https://github.com/NieZhuZhu/ai-harness-doctor/pull/241</a></li>
<li>docs(agents): record Plans 052-054 maintenance contracts by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/242">https://github.com/NieZhuZhu/ai-harness-doctor/pull/242</a></li>
<li>chore(release): v1.11.0 by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/243">https://github.com/NieZhuZhu/ai-harness-doctor/pull/243</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NieZhuZhu/ai-harness-doctor/compare/v1.10.0...v1.11.0">https://github.com/NieZhuZhu/ai-harness-doctor/compare/v1.10.0...v1.11.0</a></p>
]]></content:encoded></item><item><title>Run AER Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/run-aer-tests/</link><pubDate>Fri, 17 Jul 2026 06:51:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/run-aer-tests/</guid><description>Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.17.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The aer GitHub Action runs Apex and unit tests locally without requiring an org or deployment. It supports running Apex code, executing anonymous code, stepping through Apex in an interactive debugger, and simulating Salesforce governor limits, standard library features, and testing framework capabilities.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/octoberswimmer/aer-dist">https://github.com/octoberswimmer/aer-dist</a></strong> to version <strong>v1.2.17</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-aer-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The aer GitHub Action runs Apex and unit tests locally without requiring an org or deployment. It supports running Apex code, executing anonymous code, stepping through Apex in an interactive debugger, and simulating Salesforce governor limits, standard library features, and testing framework capabilities.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Version v1.2.17</p>
<ul>
<li>
<p>Report Error When Overriding A Non-virtual, Non-abstract Method</p>
</li>
<li>
<p>Push Call-Stack Frames For Implicitly Invoked Method Bodies</p>
</li>
<li>
<p>Report Account.Name As Nillable When Person Accounts Is Enabled</p>
</li>
<li>
<p>Select The Most Specific Matching Method Overload</p>
</li>
<li>
<p>Allow Cross-namespace Calls Through Builtin Global Interfaces</p>
</li>
<li>
<p>Deduplicate Custom Metadata Records And Show Them In Package Listings</p>
</li>
<li>
<p>Scope Protected Custom Metadata Records To Their Owning Namespace</p>
</li>
<li>
<p>Render Tracked Non-string Field Values As Text In History Rows</p>
</li>
<li>
<p>Derive Custom Metadata Record NamespacePrefix From The Record, Not The Type</p>
</li>
<li>
<p>Resolve Lookup Filter Field References To Namespaced Columns</p>
</li>
<li>
<p>Keep Multi-line If Condition Locals In Scope With Break Or Continue</p>
</li>
<li>
<p>Namespace Packaged Permission Records And Keep Same-Name Rows Distinct</p>
</li>
<li>
<p>Skip Stale FieldPermissions Rows When Loading User Permissions</p>
</li>
<li>
<p>Test Packaged Custom Metadata Is Returned Once From exec Queries</p>
</li>
<li>
<p>Enable Person Accounts When Lookup Filters Reference Person Contact Fields</p>
</li>
</ul>
]]></content:encoded></item><item><title>pgrls — Postgres RLS linter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/pgrls-postgres-rls-linter/</link><pubDate>Fri, 17 Jul 2026 06:50:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/pgrls-postgres-rls-linter/</guid><description>Version updated for https://github.com/pgrls/pgrls-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action pgrls-action automates the use of the static analyzer pgrls to detect and prevent Row-Level Security bugs in PostgreSQL databases. It supports two modes: linting a live database’s RLS state or serving as a pull-request gate that checks for regressions and new issues in schema changes without requiring a running database.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pgrls/pgrls-action">https://github.com/pgrls/pgrls-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pgrls-postgres-rls-linter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>pgrls-action</code> automates the use of the static analyzer <code>pgrls</code> to detect and prevent Row-Level Security bugs in PostgreSQL databases. It supports two modes: linting a live database&rsquo;s RLS state or serving as a pull-request gate that checks for regressions and new issues in schema changes without requiring a running database.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Adds <strong><code>mode: pr</code></strong> — a DB-free base↔head RLS regression gate — beside the existing live-DB <code>mode: lint</code> (unchanged, fully back-compatible).</p>
<p>On a <code>pull_request</code>, it snapshots your migrations directory at the base and head <strong>offline</strong> (a detached <code>git worktree</code> + <code>pgrls snapshot --migrations</code> — no database, no Docker), then runs <code>pgrls pr</code>:</p>
<ul>
<li><strong>diff (base → head)</strong> — a policy this PR <em>loosened</em> is Z3-proven <code>dangerous</code> and fails the check</li>
<li><strong>lint (head)</strong> — a new RLS finding in the changed schema</li>
</ul>
<p>Either crossing its threshold fails the check, and a sticky review comment is posted with the report.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>: { <span style="color:#f92672">fetch-depth</span>: <span style="color:#ae81ff">0</span> }   <span style="color:#75715e"># the base revision must be reachable</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">pgrls/pgrls-action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">mode</span>: <span style="color:#ae81ff">pr</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">migrations</span>: <span style="color:#ae81ff">supabase/migrations</span>
</span></span></code></pre></div><p>Requires <strong>pgrls &gt;= 0.50.0</strong> (auto-installed). Catalog copy refreshed to <strong>67 rules</strong>.</p>
<p>Verified in CI on a real runner: installs pgrls from PyPI, asserts <code>pgrls pr</code> + <code>snapshot --migrations</code> exist, passes a clean head, and fails a Z3-verified loosening.</p>
]]></content:encoded></item><item><title>Postman Onboarding Workspace Bootstrap</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/postman-onboarding-workspace-bootstrap/</link><pubDate>Fri, 17 Jul 2026 06:49:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/postman-onboarding-workspace-bootstrap/</guid><description>Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.9.5.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the creation of a Postman workspace by importing an OpenAPI specification. It generates baseline, smoke, and contract collections with executable tests covering various protocols (OpenAPI, gRPC, SOAP, GraphQL, AsyncAPI, MCP). The action simplifies the setup process for new projects and integrates seamlessly with other Postman CI/CD actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-bootstrap-action">https://github.com/postman-cs/postman-bootstrap-action</a></strong> to version <strong>v2.9.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-workspace-bootstrap">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the creation of a Postman workspace by importing an OpenAPI specification. It generates baseline, smoke, and contract collections with executable tests covering various protocols (OpenAPI, gRPC, SOAP, GraphQL, AsyncAPI, MCP). The action simplifies the setup process for new projects and integrates seamlessly with other Postman CI/CD actions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: branch-aware collection markers + credential-free publish-gate by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/87">https://github.com/postman-cs/postman-bootstrap-action/pull/87</a></li>
<li>fix: preserve legacy OpenAPI null schemas by @sean-riney in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/89">https://github.com/postman-cs/postman-bootstrap-action/pull/89</a></li>
<li>chore(release): v2.9.5 by @sean-riney in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/92">https://github.com/postman-cs/postman-bootstrap-action/pull/92</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@sean-riney made their first contribution in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/89">https://github.com/postman-cs/postman-bootstrap-action/pull/89</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-bootstrap-action/compare/v2.9.4...v2.9.5">https://github.com/postman-cs/postman-bootstrap-action/compare/v2.9.4...v2.9.5</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Repo Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/postman-onboarding-repo-sync/</link><pubDate>Fri, 17 Jul 2026 06:48:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/postman-onboarding-repo-sync/</guid><description>Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.1.6.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action exports Postman collections and environments into a repository and automates the setup of CI, mock servers, and monitors. It solves the problem of synchronizing Postman assets with code repositories and provides a seamless integration with workflows. The action supports various configurations such as workspace IDs, collection IDs, and environment details.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-repo-sync-action">https://github.com/postman-cs/postman-repo-sync-action</a></strong> to version <strong>v2.1.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-repo-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action exports Postman collections and environments into a repository and automates the setup of CI, mock servers, and monitors. It solves the problem of synchronizing Postman assets with code repositories and provides a seamless integration with workflows. The action supports various configurations such as workspace IDs, collection IDs, and environment details.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: channel retirement + finalize tagging tests (branch-aware) by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/79">https://github.com/postman-cs/postman-repo-sync-action/pull/79</a></li>
<li>fix: ignore empty input aliases by @sean-riney in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/81">https://github.com/postman-cs/postman-repo-sync-action/pull/81</a></li>
<li>chore(release): v2.1.6 by @sean-riney in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/84">https://github.com/postman-cs/postman-repo-sync-action/pull/84</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@sean-riney made their first contribution in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/81">https://github.com/postman-cs/postman-repo-sync-action/pull/81</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.5...v2.1.6">https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.5...v2.1.6</a></p>
<h2 id="whats-changed-2">What&rsquo;s Changed</h2>
<ul>
<li>feat: channel retirement + finalize tagging tests (branch-aware) by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/79">https://github.com/postman-cs/postman-repo-sync-action/pull/79</a></li>
<li>fix: ignore empty input aliases by @sean-riney in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/81">https://github.com/postman-cs/postman-repo-sync-action/pull/81</a></li>
<li>chore(release): v2.1.6 by @sean-riney in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/84">https://github.com/postman-cs/postman-repo-sync-action/pull/84</a></li>
</ul>
<h2 id="new-contributors-1">New Contributors</h2>
<ul>
<li>@sean-riney made their first contribution in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/81">https://github.com/postman-cs/postman-repo-sync-action/pull/81</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.5...v2.1.6">https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.5...v2.1.6</a></p>
]]></content:encoded></item><item><title>Oversight Lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/oversight-lint/</link><pubDate>Fri, 17 Jul 2026 06:46:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/oversight-lint/</guid><description>Version updated for https://github.com/rachelslurs/oversight-lint-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates linting of Storybook MCP components manifest files. It checks for missing or improperly documented components, surfaces warnings as annotations on pull requests, and exits with appropriate error codes based on rule violations or exceeding warning limits. It requires a built manifest, Node 20.19+, and supports customizable rules through an oversight.config.json file.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rachelslurs/oversight-lint-action">https://github.com/rachelslurs/oversight-lint-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/oversight-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates linting of Storybook MCP components manifest files. It checks for missing or improperly documented components, surfaces warnings as annotations on pull requests, and exits with appropriate error codes based on rule violations or exceeding warning limits. It requires a built manifest, Node 20.19+, and supports customizable rules through an <code>oversight.config.json</code> file.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial release.</p>
<p>Composite GitHub Action that runs <code>oversight-lint</code> over a built Storybook MCP components manifest with <code>--format github</code>, so documentation-coverage findings surface as annotations and can fail the build.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">run</span>: <span style="color:#ae81ff">pnpm build-storybook</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">rachelslurs/oversight-lint-action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">max-warnings</span>: <span style="color:#ae81ff">0</span>
</span></span></code></pre></div><p>Pin <code>@v1</code> for the moving major tag, or <code>@v1.0.0</code> to lock the version.</p>
]]></content:encoded></item><item><title>sbomify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/sbomify/</link><pubDate>Fri, 17 Jul 2026 06:45:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/sbomify/</guid><description>Version updated for https://github.com/sbomify/sbomify-action to version v26.7.0.
This action is used across all versions by 26 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action sbomify-action is designed to automate the creation, enrichment, and management of Software Bill of Materials (SBOMs) in CI/CD pipelines. It supports various ecosystems including Python, Node.js, Rust, Go, Ruby, Dart, C++, and Docker images, and can generate CycloneDX or SPDX SBOM formats. The action can also leverage Chainguard base images for efficient SBOM creation, enhancing the process with additional metadata from package registries.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sbomify/sbomify-action">https://github.com/sbomify/sbomify-action</a></strong> to version <strong>v26.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>26</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sbomify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>sbomify-action</code> is designed to automate the creation, enrichment, and management of Software Bill of Materials (SBOMs) in CI/CD pipelines. It supports various ecosystems including Python, Node.js, Rust, Go, Ruby, Dart, C++, and Docker images, and can generate CycloneDX or SPDX SBOM formats. The action can also leverage Chainguard base images for efficient SBOM creation, enhancing the process with additional metadata from package registries.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Interactive setup wizard</strong>: a new Textual TUI (<code>sbomify-action wizard</code>, bundled in the Docker image) that scans your repo for lockfiles, signs you in to sbomify, registers matching components, and writes a release-ready <code>.github/workflows/sboms.yml</code> — with <code>--dry-run</code> support (<a href="https://github.com/sbomify/sbomify-action/pull/238">#238</a>, <a href="https://github.com/sbomify/sbomify-action/pull/240">#240</a>). Follow-ups add responsive terminal layouts, truecolor in Docker, per-ecosystem lockfile discovery, SHA-pinned action refs, and CalVer-aware tag dispatch (<a href="https://github.com/sbomify/sbomify-action/pull/247">#247</a>–<a href="https://github.com/sbomify/sbomify-action/pull/283">#283</a>).</li>
<li><strong>OIDC trusted publishing</strong>: authenticate uploads to sbomify with GitHub OIDC instead of long-lived tokens, and let the wizard auto-register the trusted publisher during apply (<a href="https://github.com/sbomify/sbomify-action/pull/235">#235</a>, <a href="https://github.com/sbomify/sbomify-action/pull/242">#242</a>).</li>
<li><strong>VEX, CBOM, and HBOM uploads</strong>: new <code>BOM_TYPE</code> setting uploads non-SBOM artifacts verbatim, accepting CycloneDX VEX, OpenVEX, and CSAF documents (<a href="https://github.com/sbomify/sbomify-action/pull/255">#255</a>, <a href="https://github.com/sbomify/sbomify-action/pull/265">#265</a>).</li>
<li><strong>Multi-arch Docker images</strong>: amd64 + arm64 images built natively per architecture, with ghcr.io as the primary registry and Docker Hub as the mirror (<a href="https://github.com/sbomify/sbomify-action/pull/226">#226</a>, <a href="https://github.com/sbomify/sbomify-action/pull/248">#248</a>, <a href="https://github.com/sbomify/sbomify-action/pull/275">#275</a>).</li>
<li><strong>Stricter failure semantics</strong>: post-upload processor errors and partial product-release tagging failures now fail the run instead of passing silently (<a href="https://github.com/sbomify/sbomify-action/pull/261">#261</a>, <a href="https://github.com/sbomify/sbomify-action/pull/272">#272</a>).</li>
<li><strong>Dependency-Track</strong>: expose the missing upload options (<a href="https://github.com/sbomify/sbomify-action/pull/230">#230</a>) — thanks @Erik-Hoffmann for the first-time contribution!</li>
<li><strong>Enrichment &amp; generation fixes</strong>: preserve versionless PURLs during enrichment (<a href="https://github.com/sbomify/sbomify-action/pull/229">#229</a>), drop <code>--required-only</code> for Go in cdxgen (<a href="https://github.com/sbomify/sbomify-action/pull/234">#234</a>), and get-or-create components on duplicate names (<a href="https://github.com/sbomify/sbomify-action/pull/236">#236</a>).</li>
<li><strong>Supply-chain hygiene</strong>: OpenGrep SAST in CI (<a href="https://github.com/sbomify/sbomify-action/pull/246">#246</a>), security patches for <code>idna</code>/<code>urllib3</code>/<code>pip</code> (<a href="https://github.com/sbomify/sbomify-action/pull/241">#241</a>), and bumped bundled SBOM tools (<a href="https://github.com/sbomify/sbomify-action/pull/274">#274</a>).</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Make ghcr.io the primary registry, Docker Hub the mirror by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/226">https://github.com/sbomify/sbomify-action/pull/226</a></li>
<li>Preserve PURLs without versions during enrichment by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/229">https://github.com/sbomify/sbomify-action/pull/229</a></li>
<li>Skip &ndash;required-only for Go in cdxgen (fixes #231) by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/234">https://github.com/sbomify/sbomify-action/pull/234</a></li>
<li>Handle DUPLICATE_NAME on component create (get-or-create) by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/236">https://github.com/sbomify/sbomify-action/pull/236</a></li>
<li>Add OIDC trusted-publishing support by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/235">https://github.com/sbomify/sbomify-action/pull/235</a></li>
<li>fix(deps): patch non-test Dependabot security alerts (idna, urllib3, pip) by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/241">https://github.com/sbomify/sbomify-action/pull/241</a></li>
<li>fix(wizard): component_type 422, existing sbomify.json, edge-case hardening + review fixes by @aurangzaib048 in <a href="https://github.com/sbomify/sbomify-action/pull/240">https://github.com/sbomify/sbomify-action/pull/240</a></li>
<li>chore(deps): bump docker/login-action from 4.1.0 to 4.2.0 by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/237">https://github.com/sbomify/sbomify-action/pull/237</a></li>
<li>feat(wizard): auto-register OIDC trusted publisher during apply by @aurangzaib048 in <a href="https://github.com/sbomify/sbomify-action/pull/242">https://github.com/sbomify/sbomify-action/pull/242</a></li>
<li>chore(deps): bump astral-sh/setup-uv from 8.1.0 to 8.2.0 by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/244">https://github.com/sbomify/sbomify-action/pull/244</a></li>
<li>chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/243">https://github.com/sbomify/sbomify-action/pull/243</a></li>
<li>feat: Textual onboarding wizard + consolidated sbomify API client by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/238">https://github.com/sbomify/sbomify-action/pull/238</a></li>
<li>ci: add OpenGrep SAST workflow by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/246">https://github.com/sbomify/sbomify-action/pull/246</a></li>
<li>docs: lead README with the setup wizard by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/245">https://github.com/sbomify/sbomify-action/pull/245</a></li>
<li>fix: bundle wizard styles.tcss in published package by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/247">https://github.com/sbomify/sbomify-action/pull/247</a></li>
<li>ci: build and push multi-arch (amd64+arm64) Docker images by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/248">https://github.com/sbomify/sbomify-action/pull/248</a></li>
<li>fix: render wizard in truecolor inside Docker by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/249">https://github.com/sbomify/sbomify-action/pull/249</a></li>
<li>fix(wizard): derive repo name from git remote; ship git in runtime image by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/251">https://github.com/sbomify/sbomify-action/pull/251</a></li>
<li>feat: make the onboarding wizard fit any terminal (responsive TUI) by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/253">https://github.com/sbomify/sbomify-action/pull/253</a></li>
<li>Add missing deptrack upload options by @Erik-Hoffmann in <a href="https://github.com/sbomify/sbomify-action/pull/230">https://github.com/sbomify/sbomify-action/pull/230</a></li>
<li>fix: fail the run when a post-upload processor fails by @aurangzaib048 in <a href="https://github.com/sbomify/sbomify-action/pull/261">https://github.com/sbomify/sbomify-action/pull/261</a></li>
<li>feat: add BOM_TYPE to upload VEX/CBOM/HBOM artifacts verbatim by @aurangzaib048 in <a href="https://github.com/sbomify/sbomify-action/pull/255">https://github.com/sbomify/sbomify-action/pull/255</a></li>
<li>chore(deps): bump actions/cache from 5.0.5 to 6.1.0 by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/263">https://github.com/sbomify/sbomify-action/pull/263</a></li>
<li>chore(deps): bump github/codeql-action/upload-sarif from 3.36.2 to 4.36.2 by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/262">https://github.com/sbomify/sbomify-action/pull/262</a></li>
<li>chore(deps): bump actions/setup-python from 6.2.0 to 6.3.0 by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/257">https://github.com/sbomify/sbomify-action/pull/257</a></li>
<li>chore(deps): bump actions/checkout from 6.0.3 to 7.0.0 by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/256">https://github.com/sbomify/sbomify-action/pull/256</a></li>
<li>chore(deps): bump github/codeql-action from 3.36.2 to 4.36.2 by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/254">https://github.com/sbomify/sbomify-action/pull/254</a></li>
<li>feat(wizard): resolve sbomify-action pin at runtime with offline fallback by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/250">https://github.com/sbomify/sbomify-action/pull/250</a></li>
<li>chore(deps): bump docker/setup-buildx-action from 4.1.0 to 4.2.0 by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/270">https://github.com/sbomify/sbomify-action/pull/270</a></li>
<li>chore(deps): bump docker/setup-qemu-action from 4.1.0 to 4.2.0 by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/269">https://github.com/sbomify/sbomify-action/pull/269</a></li>
<li>chore(deps): bump actions/attest-build-provenance from 4.1.0 to 4.1.1 by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/268">https://github.com/sbomify/sbomify-action/pull/268</a></li>
<li>chore(deps): bump github/codeql-action/upload-sarif from 4.36.2 to 4.37.0 by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/267">https://github.com/sbomify/sbomify-action/pull/267</a></li>
<li>chore(deps): bump docker/login-action from 4.2.0 to 4.4.0 by @dependabot[bot] in <a href="https://github.com/sbomify/sbomify-action/pull/266">https://github.com/sbomify/sbomify-action/pull/266</a></li>
<li>fix(wizard): skip AI agent worktree dirs during lockfile discovery by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/271">https://github.com/sbomify/sbomify-action/pull/271</a></li>
<li>fix: make partial release failures fatal by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/272">https://github.com/sbomify/sbomify-action/pull/272</a></li>
<li>Bumps tools by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/274">https://github.com/sbomify/sbomify-action/pull/274</a></li>
<li>ci: build Docker images natively per-arch via matrix by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/275">https://github.com/sbomify/sbomify-action/pull/275</a></li>
<li>chore: bump version to 26.7.0 and upgrade lockfiles by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/276">https://github.com/sbomify/sbomify-action/pull/276</a></li>
<li>fix(wizard): discover one lockfile per ecosystem, not per directory by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/277">https://github.com/sbomify/sbomify-action/pull/277</a></li>
<li>fix(wizard): use full relative path to disambiguate suggested component names by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/278">https://github.com/sbomify/sbomify-action/pull/278</a></li>
<li>fix(wizard): sort product and component pickers alphabetically by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/279">https://github.com/sbomify/sbomify-action/pull/279</a></li>
<li>fix(wizard): pin emitted action ref to the latest GitHub release SHA by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/280">https://github.com/sbomify/sbomify-action/pull/280</a></li>
<li>feat: accept OpenVEX and CSAF VEX documents for BOM_TYPE=vex by @aurangzaib048 in <a href="https://github.com/sbomify/sbomify-action/pull/265">https://github.com/sbomify/sbomify-action/pull/265</a></li>
<li>fix(wizard): default augmentation to the recommended contact-profile option by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/282">https://github.com/sbomify/sbomify-action/pull/282</a></li>
<li>fix: wizard tag dispatch covers bare-numeric versions; sentinel carries real version by @vpetersson in <a href="https://github.com/sbomify/sbomify-action/pull/283">https://github.com/sbomify/sbomify-action/pull/283</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@Erik-Hoffmann made their first contribution in <a href="https://github.com/sbomify/sbomify-action/pull/230">https://github.com/sbomify/sbomify-action/pull/230</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sbomify/sbomify-action/compare/v26.2.0...v26.7.0">https://github.com/sbomify/sbomify-action/compare/v26.2.0...v26.7.0</a></p>
]]></content:encoded></item><item><title>Skill Provenance Validate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/skill-provenance-validate/</link><pubDate>Fri, 17 Jul 2026 06:43:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/skill-provenance-validate/</guid><description>Version updated for https://github.com/snapsynapse/skill-provenance to version v5.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action ensures that agent skills across local folders, registries, and platform uploads maintain their integrity by recording version information and hash-based integrity verification inside the bundle. This helps teams verify version identity, detect staleness, and ensure no accidental drift during transitions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/snapsynapse/skill-provenance">https://github.com/snapsynapse/skill-provenance</a></strong> to version <strong>v5.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skill-provenance-validate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action ensures that agent skills across local folders, registries, and platform uploads maintain their integrity by recording version information and hash-based integrity verification inside the bundle. This helps teams verify version identity, detect staleness, and ensure no accidental drift during transitions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="validated_against-release-bound-attestation-records">validated_against: release-bound attestation records</h2>
<p>MANIFEST.yaml now takes an optional <code>validated_against</code> block. Each entry binds a validation event — harness, model, date, result, method — to the <strong>exact <code>bundle_version</code> it validated</strong>:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">validated_against</span>:
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">bundle_version</span>: <span style="color:#ae81ff">5.1.0</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">harness</span>: <span style="color:#ae81ff">Anthropic Claude Code</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">model</span>: <span style="color:#ae81ff">claude-fable-5</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">date</span>: <span style="color:#e6db74">2026-07-16</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">result</span>: <span style="color:#ae81ff">pass</span>
</span></span></code></pre></div><p>This is a different claim from <code>compatibility.tested_on</code> (design-time compatibility, not bound to a release) and a different concern from <code>hash</code> (integrity). An attestation for 5.0.0 says nothing about 5.1.0, and the tooling treats it that way.</p>
<p><code>validate.sh</code> reports attestation after the hash results — entries matching the current bundle version, or a stale flag when none match — and <strong>never changes its exit code over attestation state</strong>. That is the design rule this release encodes: integrity gates, attestation informs. The same pinned bytes can behave differently as harnesses and models move, so a stale attestation means re-validate, not reject.</p>
<h3 id="also-in-this-release">Also in this release</h3>
<ul>
<li>2 new core evals covering attestation reporting and stale-attestation semantics (35 core / 52 total)</li>
<li>Regression tests asserting attestation state (matching, stale, absent) never changes validate.sh exit codes</li>
<li>SKILL.md manifest schema + rules coverage; README section &ldquo;Attestation: validated_against&rdquo;</li>
</ul>
<p>Full details in <a href="https://github.com/snapsynapse/skill-provenance/blob/main/CHANGELOG.md">CHANGELOG.md</a>.</p>
]]></content:encoded></item><item><title>Tenzai Test</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/tenzai-test/</link><pubDate>Fri, 17 Jul 2026 06:42:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/tenzai-test/</guid><description>Version updated for https://github.com/TenzaiLtd/tenzai-github-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Tenzai Test GitHub Action automates security testing of an existing Tenzai application after a deployment. It triggers a commit-diff test and posts results as a Tenzai Test check run on the tested commit, providing feedback directly within the repository workflow. The action is designed to be fire-and-forget, ensuring that tests are triggered asynchronously and providing real-time status updates.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TenzaiLtd/tenzai-github-action">https://github.com/TenzaiLtd/tenzai-github-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tenzai-test">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Tenzai Test GitHub Action automates security testing of an existing Tenzai application after a deployment. It triggers a commit-diff test and posts results as a <code>Tenzai Test</code> check run on the tested commit, providing feedback directly within the repository workflow. The action is designed to be fire-and-forget, ensuring that tests are triggered asynchronously and providing real-time status updates.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ENG-5087: Publish Tenzai Test GitHub Action by @Dor256 in <a href="https://github.com/TenzaiLtd/tenzai-github-action/pull/1">https://github.com/TenzaiLtd/tenzai-github-action/pull/1</a></li>
<li>Bump the github-actions group with 2 updates by @dependabot[bot] in <a href="https://github.com/TenzaiLtd/tenzai-github-action/pull/2">https://github.com/TenzaiLtd/tenzai-github-action/pull/2</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@Dor256 made their first contribution in <a href="https://github.com/TenzaiLtd/tenzai-github-action/pull/1">https://github.com/TenzaiLtd/tenzai-github-action/pull/1</a></li>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/TenzaiLtd/tenzai-github-action/pull/2">https://github.com/TenzaiLtd/tenzai-github-action/pull/2</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/TenzaiLtd/tenzai-github-action/commits/v1.0.0">https://github.com/TenzaiLtd/tenzai-github-action/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>gw - Go workspaces</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/gw-go-workspaces/</link><pubDate>Fri, 17 Jul 2026 06:41:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/gw-go-workspaces/</guid><description>Version updated for https://github.com/Toyz/gw to version v0.7.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary gw is a Go tool designed to manage multi-module workspaces efficiently, automating common tasks such as bootstraping go.work, linting dependency versions, and running commands across modules. It helps developers maintain complex Go projects more effectively by streamlining the process of managing dependencies and automating repetitive tasks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Toyz/gw">https://github.com/Toyz/gw</a></strong> to version <strong>v0.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gw-go-workspaces">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>gw</code> is a Go tool designed to manage multi-module workspaces efficiently, automating common tasks such as bootstraping <code>go.work</code>, linting dependency versions, and running commands across modules. It helps developers maintain complex Go projects more effectively by streamlining the process of managing dependencies and automating repetitive tasks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Toyz/gw/compare/v0.6.0...v0.7.0">https://github.com/Toyz/gw/compare/v0.6.0...v0.7.0</a></p>
]]></content:encoded></item><item><title>MIU PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/miu-pr-review/</link><pubDate>Fri, 17 Jul 2026 06:40:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/miu-pr-review/</guid><description>Version updated for https://github.com/vanducng/miu-cr to version v0.89.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The miu-cr GitHub Action automates AI-based code review for CLI, CI, and MCP hosts. It provides features like local review of staged changes, integration with GitHub PRs for inline comments, and support for custom project rules via .miu/cr/rules/*.md files. The action also offers CI/Actions integration through reusable workflows and supports evaluation using miucr eval.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vanducng/miu-cr">https://github.com/vanducng/miu-cr</a></strong> to version <strong>v0.89.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/miu-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The miu-cr GitHub Action automates AI-based code review for CLI, CI, and MCP hosts. It provides features like local review of staged changes, integration with GitHub PRs for inline comments, and support for custom project rules via <code>.miu/cr/rules/*.md</code> files. The action also offers CI/Actions integration through reusable workflows and supports evaluation using <code>miucr eval</code>.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="miu-cr-v0890">miu-cr v0.89.0</h2>
<p>AI code review for local changes and GitHub pull requests. Use it as a CLI, CI gate, or GitHub Action with your own LLM key.</p>
<h3 id="install">Install</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>curl -fsSL https://cr.miu.sh/install.sh | sh -s -- v0.89.0
</span></span><span style="display:flex;"><span>brew install vanducng/tap/miucr
</span></span><span style="display:flex;"><span>go install github.com/vanducng/miu-cr/cmd/miucr@v0.89.0
</span></span></code></pre></div><p>GitHub Action:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v6</span>
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">vanducng/miu-cr@v0.89.0</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span></code></pre></div><h3 id="common-commands">Common commands</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>miucr login --provider openai
</span></span><span style="display:flex;"><span>miucr review --staged
</span></span><span style="display:flex;"><span>miucr review --from main --to HEAD --gate high
</span></span><span style="display:flex;"><span>miucr review --pr owner/repo#123 --post
</span></span><span style="display:flex;"><span>miucr upgrade
</span></span></code></pre></div><p>Docs: <a href="https://cr.miu.sh">https://cr.miu.sh</a></p>
]]></content:encoded></item><item><title>Sync Issues and PRs</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/sync-issues-and-prs/</link><pubDate>Fri, 17 Jul 2026 06:39:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/sync-issues-and-prs/</guid><description>Version updated for https://github.com/vig-os/sync-issues-action to version v0.4.0.
This action is used across all versions by 8 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, sync-issues-action, automates the process of syncing all issues and pull requests from a repository into markdown files. It captures all comments and conversations within each issue or PR, groups review threads with diff snippets when available, preserves original bodies without extra headers, and includes metadata such as labels, dates, authors, state, relationships, etc. The action supports various options for customization, including specifying output directories, filtering issues or pull requests, customizing the format command, and using GitHub App authentication. It also provides outputs for tracking sync results and managing state files for caching purposes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vig-os/sync-issues-action">https://github.com/vig-os/sync-issues-action</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sync-issues-and-prs">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>sync-issues-action</code>, automates the process of syncing all issues and pull requests from a repository into markdown files. It captures all comments and conversations within each issue or PR, groups review threads with diff snippets when available, preserves original bodies without extra headers, and includes metadata such as labels, dates, authors, state, relationships, etc. The action supports various options for customization, including specifying output directories, filtering issues or pull requests, customizing the format command, and using GitHub App authentication. It also provides outputs for tracking sync results and managing state files for caching purposes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>No changelog notes found for 0.4.0</p>
]]></content:encoded></item><item><title>Setup ZeroDrop</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/setup-zerodrop/</link><pubDate>Fri, 17 Jul 2026 06:38:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/setup-zerodrop/</guid><description>Version updated for https://github.com/zerodrop-dev/setup-zerodrop to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The setup-zerodrop GitHub Action generates a unique inbox per CI run, allowing email verification and OTP extraction at Cloudflare’s edge. It solves the problem of managing isolated inboxes for parallel test runs and provides an easy way to integrate email verification into workflows using ZeroDrop SDKs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zerodrop-dev/setup-zerodrop">https://github.com/zerodrop-dev/setup-zerodrop</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-zerodrop">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>setup-zerodrop</code> GitHub Action generates a unique inbox per CI run, allowing email verification and OTP extraction at Cloudflare&rsquo;s edge. It solves the problem of managing isolated inboxes for parallel test runs and provides an easy way to integrate email verification into workflows using ZeroDrop SDKs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial release of setup-zerodrop — successor to create-inbox.</p>
<ul>
<li>Generates an isolated ZeroDrop inbox per CI run (no network request)</li>
<li>Outputs: inbox, name · Exports: ZERODROP_INBOX, ZERODROP_INBOX_NAME</li>
<li>New: api-key input for Workspaces, base-url for self-hosted</li>
<li>Zero dependencies — single auditable dist/index.js</li>
<li>Pin by SHA for supply chain security</li>
</ul>
]]></content:encoded></item><item><title>Agent Lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/agent-lint/</link><pubDate>Fri, 17 Jul 2026 06:37:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/17/agent-lint/</guid><description>Version updated for https://github.com/zhupanov/agent-lint to version v2.5.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Agent Lint GitHub Action is a lint tool for validating Claude Code, Cursor, and Codex configurations. It implements a robust suite of 286 lint rules across 20 categories to ensure consistent and high-quality setup files. The action supports both Basic and Plugin modes and can be easily integrated into CI pipelines or used with pre-commit hooks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zhupanov/agent-lint">https://github.com/zhupanov/agent-lint</a></strong> to version <strong>v2.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Agent Lint GitHub Action is a lint tool for validating Claude Code, Cursor, and Codex configurations. It implements a robust suite of 286 lint rules across 20 categories to ensure consistent and high-quality setup files. The action supports both Basic and Plugin modes and can be easily integrated into CI pipelines or used with pre-commit hooks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Fix release major tag update by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/150">https://github.com/zhupanov/agent-lint/pull/150</a></li>
<li>Harden release reruns by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/153">https://github.com/zhupanov/agent-lint/pull/153</a></li>
<li>Classify new lint rules as minor releases by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/154">https://github.com/zhupanov/agent-lint/pull/154</a></li>
<li>Harden release tag promotion by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/156">https://github.com/zhupanov/agent-lint/pull/156</a></li>
<li>Select recovery release run by main commit by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/157">https://github.com/zhupanov/agent-lint/pull/157</a></li>
<li>Use semantic release tags as baseline by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/159">https://github.com/zhupanov/agent-lint/pull/159</a></li>
<li>Release v2.5.0 by @zhupanov in <a href="https://github.com/zhupanov/agent-lint/pull/160">https://github.com/zhupanov/agent-lint/pull/160</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/zhupanov/agent-lint/compare/v2...v2.5.0">https://github.com/zhupanov/agent-lint/compare/v2...v2.5.0</a></p>
]]></content:encoded></item><item><title>BPFCompat eBPF Compatibility Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/bpfcompat-ebpf-compatibility-gate/</link><pubDate>Thu, 16 Jul 2026 22:59:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/bpfcompat-ebpf-compatibility-gate/</guid><description>Version updated for https://github.com/Kernel-Guard/bpfcompat to version v0.3.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary bpfcompat is an open-source compatibility validator that tests eBPF artifacts across real distro kernels. It boots virtual machines, runs the artifact in those environments, and produces JSON/Markdown reports that indicate whether the artifact loads and attaches on the specified kernels. This allows for empirical validation of eBPF compatibility, unlike CO-RE which provides a portability guarantee but not necessarily a load-and-attach guarantee.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Kernel-Guard/bpfcompat">https://github.com/Kernel-Guard/bpfcompat</a></strong> to version <strong>v0.3.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bpfcompat-ebpf-compatibility-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>bpfcompat</code> is an open-source compatibility validator that tests eBPF artifacts across real distro kernels. It boots virtual machines, runs the artifact in those environments, and produces JSON/Markdown reports that indicate whether the artifact loads and attaches on the specified kernels. This allows for empirical validation of eBPF compatibility, unlike CO-RE which provides a portability guarantee but not necessarily a load-and-attach guarantee.</p>
]]></content:encoded></item><item><title>npm-scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/npm-scan/</link><pubDate>Thu, 16 Jul 2026 22:57:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/npm-scan/</guid><description>Version updated for https://github.com/lateos-ai/npm-scan to version v1.5.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Purpose and Functionality: npm-scan is an advanced tool designed to detect a wide range of supply chain attacks, including eBPF kernel rootkits, memory extraction, credential theft, GitHub spoofing, AI-targeted attacks, and more. It complements traditional tools like npm audit and Snyk by offering behavioral detection that can identify hidden threats.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lateos-ai/npm-scan">https://github.com/lateos-ai/npm-scan</a></strong> to version <strong>v1.5.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/npm-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Purpose and Functionality:</strong> npm-scan is an advanced tool designed to detect a wide range of supply chain attacks, including eBPF kernel rootkits, memory extraction, credential theft, GitHub spoofing, AI-targeted attacks, and more. It complements traditional tools like npm audit and Snyk by offering behavioral detection that can identify hidden threats.</p>
<p><strong>Problems Solved or Tasks Automated:</strong> By detecting known vulnerabilities as well as advanced attack vectors, npm-scan helps organizations reduce their risk of data breaches, regulatory fines, downtime, and reputational damage. It provides a comprehensive approach to supply chain security that ensures businesses are protected against emerging threats.</p>
<p><strong>Key Capabilities:</strong> The action is capable of scanning individual packages or the entire node package ecosystem, exporting findings to JSON format for easier analysis, and detecting 23 types of attacks with high confidence rates.</p>
]]></content:encoded></item><item><title>Lingo.Dev AI Localization</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/lingo.dev-ai-localization/</link><pubDate>Thu, 16 Jul 2026 22:56:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/lingo.dev-ai-localization/</guid><description>Version updated for https://github.com/lingodotdev/lingo.dev to version lingo.dev@0.138.1.
This action is used across all versions by 104 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action “Lingo.dev” automates the localization process by connecting to Lingo.dev’s translation platform. It enables continuous localization in GitHub Actions, reducing terminology errors and providing a structured approach to i18n setup, especially for React applications. The action supports various file formats like JSON, YAML, Markdown, CSV, and PO files, and it integrates with Lingo.dev’s API for seamless integration into development workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lingodotdev/lingo.dev">https://github.com/lingodotdev/lingo.dev</a></strong> to version <strong><a href="mailto:lingo.dev@0.138.1">lingo.dev@0.138.1</a></strong>.</p>
<ul>
<li>This action is used across all versions by <strong>104</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lingo-dev-ai-localization">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action &ldquo;Lingo.dev&rdquo; automates the localization process by connecting to Lingo.dev&rsquo;s translation platform. It enables continuous localization in GitHub Actions, reducing terminology errors and providing a structured approach to i18n setup, especially for React applications. The action supports various file formats like JSON, YAML, Markdown, CSV, and PO files, and it integrates with Lingo.dev&rsquo;s API for seamless integration into development workflows.</p>
]]></content:encoded></item><item><title>Install Lua / LuaJIT / OpenResty + LuaRocks</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/install-lua-/-luajit-/-openresty--luarocks/</link><pubDate>Thu, 16 Jul 2026 22:54:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/install-lua-/-luajit-/-openresty--luarocks/</guid><description>Version updated for https://github.com/luau-project/setup-lua to version v2.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action installs Lua (or LuaJIT or OpenResty) and LuaRocks in a single step within the .lua folder, supporting various versions and configurations. It automates the setup process across different operating systems and toolchains, including MSVC on Windows. The action allows for customization of Lua and LuaRocks versions through inputs, providing options to skip LuaRocks installation or specify specific commit hashes for LuaJIT and OpenResty.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/luau-project/setup-lua">https://github.com/luau-project/setup-lua</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-lua-luajit-openresty-luarocks">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action installs Lua (or LuaJIT or OpenResty) and LuaRocks in a single step within the <code>.lua</code> folder, supporting various versions and configurations. It automates the setup process across different operating systems and toolchains, including MSVC on Windows. The action allows for customization of Lua and LuaRocks versions through inputs, providing options to skip LuaRocks installation or specify specific commit hashes for LuaJIT and OpenResty.</p>
]]></content:encoded></item><item><title>CSDA Version</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/csda-version/</link><pubDate>Thu, 16 Jul 2026 22:53:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/csda-version/</guid><description>Version updated for https://github.com/NASA-IMPACT/csda-version to version v0.4.3.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action calculates and updates the CSDA version for the checked-out repository. It automates the process of determining the next version based on predefined rules and is particularly useful when integrating with tools like release-please to handle automated releases. The action ensures that the versioning follows a specific format (vYY.PI.SP-X) and can be customized by setting release-as and config-file in the with block of the Github Action YAML file.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NASA-IMPACT/csda-version">https://github.com/NASA-IMPACT/csda-version</a></strong> to version <strong>v0.4.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/csda-version">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action calculates and updates the CSDA version for the checked-out repository. It automates the process of determining the next version based on predefined rules and is particularly useful when integrating with tools like <code>release-please</code> to handle automated releases. The action ensures that the versioning follows a specific format (<code>vYY.PI.SP-X</code>) and can be customized by setting <code>release-as</code> and <code>config-file</code> in the <code>with</code> block of the Github Action YAML file.</p>
]]></content:encoded></item><item><title>StayAwakeBot Strix</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/stayawakebot-strix/</link><pubDate>Thu, 16 Jul 2026 22:52:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/stayawakebot-strix/</guid><description>Version updated for https://github.com/Ndevu12/strix to version v0.1.4.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Strix, automates the detection of self-propagating worm indicators in checked-out repositories by running a Python package called stayawakebot. It scans the repository and reports on any suspicious or infected targets, failing CI when necessary. The action is configured with various inputs for customization such as specifying a specific version of stayawakebot, including a configuration file, setting failure conditions, and controlling how findings are reported (e.g., through SARIF files, artifacts, or comments).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Ndevu12/strix">https://github.com/Ndevu12/strix</a></strong> to version <strong>v0.1.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/stayawakebot-strix">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <strong>Strix</strong>, automates the detection of self-propagating worm indicators in checked-out repositories by running a Python package called <code>stayawakebot</code>. It scans the repository and reports on any suspicious or infected targets, failing CI when necessary. The action is configured with various inputs for customization such as specifying a specific version of <code>stayawakebot</code>, including a configuration file, setting failure conditions, and controlling how findings are reported (e.g., through SARIF files, artifacts, or comments).</p>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/go-proxy-cache-updater/</link><pubDate>Thu, 16 Jul 2026 22:51:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.26.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically updates a specified proxy cache whenever new releases are tagged in your Go module repository. It supports both standard and submodule version tags and allows customization of the proxy configuration, import path, and Go version. The action ensures that your module is immediately available on platforms like pkg.go.dev, making it simple to integrate into continuous integration workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.26</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically updates a specified proxy cache whenever new releases are tagged in your Go module repository. It supports both standard and submodule version tags and allows customization of the proxy configuration, import path, and Go version. The action ensures that your module is immediately available on platforms like pkg.go.dev, making it simple to integrate into continuous integration workflows.</p>
]]></content:encoded></item><item><title>Open Delivery Spec</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/open-delivery-spec/</link><pubDate>Thu, 16 Jul 2026 22:50:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/open-delivery-spec/</guid><description>Version updated for https://github.com/open-delivery-spec/validate-action to version v0.2.3.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The ODS Validate Action automates the AI code quality gate by attributing AI-generated code using Co-Authored-By trailers, analyzing code quality, scoring technical debt, and enforcing policy through OPA Rego. It runs on every pull request to prevent low-quality AI code from reaching production.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/open-delivery-spec/validate-action">https://github.com/open-delivery-spec/validate-action</a></strong> to version <strong>v0.2.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/open-delivery-spec">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The ODS Validate Action automates the AI code quality gate by attributing AI-generated code using <code>Co-Authored-By</code> trailers, analyzing code quality, scoring technical debt, and enforcing policy through OPA Rego. It runs on every pull request to prevent low-quality AI code from reaching production.</p>
]]></content:encoded></item><item><title>Minisign Release Signer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/minisign-release-signer/</link><pubDate>Thu, 16 Jul 2026 22:49:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/minisign-release-signer/</guid><description>Version updated for https://github.com/pattonwebz/minisign-release-signer to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the signing of release artifacts (like WordPress plugins and themes) with Minisign, a digital signature tool that uses Ed25519 keys. The action creates detached signatures, verifies them against a published public key, and logs each signature in Sigstore Rekor for transparency. It supports multiple files per release and provides replay protection by embedding trusted comments in the signatures. The action is designed to work seamlessly with WordPress workflows but can be used for any distributable artifact.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pattonwebz/minisign-release-signer">https://github.com/pattonwebz/minisign-release-signer</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/minisign-release-signer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the signing of release artifacts (like WordPress plugins and themes) with Minisign, a digital signature tool that uses Ed25519 keys. The action creates detached signatures, verifies them against a published public key, and logs each signature in Sigstore Rekor for transparency. It supports multiple files per release and provides replay protection by embedding trusted comments in the signatures. The action is designed to work seamlessly with WordPress workflows but can be used for any distributable artifact.</p>
]]></content:encoded></item><item><title>MegaLinter Custom Flavor PracticalliZensical</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/megalinter-custom-flavor-practicallizensical/</link><pubDate>Thu, 16 Jul 2026 22:48:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/megalinter-custom-flavor-practicallizensical/</guid><description>Version updated for https://github.com/practicalli/megalinter-custom-flavor-zensical to version Error loading version from page [https://github.com/marketplace/actions/megalinter-custom-flavor-practicallizensical], unable to determine latest release.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This custom MegaLinter aims to reduce the Docker image size by removing unused linters and dependencies. It focuses on providing a lightweight and optimized version of the official MegaLinter images, suitable for use in GitHub Actions workflows and Docker environments. The action automatically keeps up to date with MegaLinter releases through scheduled builds and can be configured to publish to both GitHub Container Registry (ghcr.io) and Docker Hub.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/practicalli/megalinter-custom-flavor-zensical">https://github.com/practicalli/megalinter-custom-flavor-zensical</a></strong> to version <strong>Error loading version from page [https://github.com/marketplace/actions/megalinter-custom-flavor-practicallizensical], unable to determine latest release</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/megalinter-custom-flavor-practicallizensical">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This custom MegaLinter aims to reduce the Docker image size by removing unused linters and dependencies. It focuses on providing a lightweight and optimized version of the official MegaLinter images, suitable for use in GitHub Actions workflows and Docker environments. The action automatically keeps up to date with MegaLinter releases through scheduled builds and can be configured to publish to both GitHub Container Registry (ghcr.io) and Docker Hub.</p>
]]></content:encoded></item><item><title>ramen-ai PR Compliance Interceptor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/ramen-ai-pr-compliance-interceptor/</link><pubDate>Thu, 16 Jul 2026 22:46:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/ramen-ai-pr-compliance-interceptor/</guid><description>Version updated for https://github.com/ramen-ai-dev/ramen-ai-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 22.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action “ramen-ai PR Compliance Interceptor” is designed to block unsafe AI outputs before execution in pull requests. It scans pull request diffs, evaluates added text against the ramen-ai L2 Semantic Firewall, and fails the CI build on a [BLOCKED] verdict, posting a cryptographically-receipted comment on the PR.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ramen-ai-dev/ramen-ai-action">https://github.com/ramen-ai-dev/ramen-ai-action</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>22</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ramen-ai-pr-compliance-interceptor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action &ldquo;ramen-ai PR Compliance Interceptor&rdquo; is designed to block unsafe AI outputs before execution in pull requests. It scans pull request diffs, evaluates added text against the ramen-ai L2 Semantic Firewall, and fails the CI build on a <code>[BLOCKED]</code> verdict, posting a cryptographically-receipted comment on the PR.</p>
]]></content:encoded></item><item><title>Misata Seed Data Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/misata-seed-data-audit/</link><pubDate>Thu, 16 Jul 2026 22:45:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/misata-seed-data-audit/</guid><description>Version updated for https://github.com/rasinmuhammed/misata-audit-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the validation of seed data by running the misata audit tool on a specified directory of CSV files. It checks for various inconsistencies such as orders shipped before they were placed, ages not matching birth dates, cancelled orders with tracking numbers, negative counts, high fraud rates, and cross-table relationships like foreign-key orphans and causality issues. The action fails the CI job if any problems are found, and provides detailed logs indicating which tables, columns, and rows have issues. It supports schema validation to further enhance checks and can be run with zero tolerance for errors.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rasinmuhammed/misata-audit-action">https://github.com/rasinmuhammed/misata-audit-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/misata-seed-data-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the validation of seed data by running the <code>misata audit</code> tool on a specified directory of CSV files. It checks for various inconsistencies such as orders shipped before they were placed, ages not matching birth dates, cancelled orders with tracking numbers, negative counts, high fraud rates, and cross-table relationships like foreign-key orphans and causality issues. The action fails the CI job if any problems are found, and provides detailed logs indicating which tables, columns, and rows have issues. It supports schema validation to further enhance checks and can be run with zero tolerance for errors.</p>
]]></content:encoded></item><item><title>skill-switch audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/skill-switch-audit/</link><pubDate>Thu, 16 Jul 2026 22:44:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/skill-switch-audit/</guid><description>Version updated for https://github.com/rtwsvj/skill-switch to version v0.10.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action scans Claude Code, Cursor, Gemini CLI, Windsurf, Zed, and VSCode skills and configurations to detect potential security issues such as反弹 shell, exfiltration of sensitive files, phishing credential theft, dangerous MCP servers, plaintext remote transmission, hard-coded keys, among others. It provides SARIF output for easy integration into GitHub code scanning, supports project-level policies, and includes automated fixes (--fix).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rtwsvj/skill-switch">https://github.com/rtwsvj/skill-switch</a></strong> to version <strong>v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skill-switch-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action scans Claude Code, Cursor, Gemini CLI, Windsurf, Zed, and VSCode skills and configurations to detect potential security issues such as反弹 shell, exfiltration of sensitive files, phishing credential theft, dangerous MCP servers, plaintext remote transmission, hard-coded keys, among others. It provides SARIF output for easy integration into GitHub code scanning, supports project-level policies, and includes automated fixes (<code>--fix</code>).</p>
]]></content:encoded></item><item><title>pi GitHub Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/pi-github-action/</link><pubDate>Thu, 16 Jul 2026 22:42:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/pi-github-action/</guid><description>Version updated for https://github.com/shaftoe/pi-coding-agent-action to version v2.26.0.
This action is used across all versions by 11 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action integrates the Pi coding agent with various CI/CD platforms like GitHub, Codeberg, and self-hosted Forgejo. It supports a familiar workflow, minimalistic philosophy, and integrates seamlessly into GitHub issue/PR workflows, providing tools for generating reports, sharing sessions, and automating code reviews.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/shaftoe/pi-coding-agent-action">https://github.com/shaftoe/pi-coding-agent-action</a></strong> to version <strong>v2.26.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pi-github-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action integrates the <a href="https://pi.dev">Pi coding agent</a> with various CI/CD platforms like GitHub, Codeberg, and self-hosted Forgejo. It supports a familiar workflow, minimalistic philosophy, and integrates seamlessly into GitHub issue/PR workflows, providing tools for generating reports, sharing sessions, and automating code reviews.</p>
]]></content:encoded></item><item><title>Pipr Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/pipr-review/</link><pubDate>Thu, 16 Jul 2026 22:41:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/pipr-review/</guid><description>Version updated for https://github.com/somus/pipr to version v0.4.1.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Pipr is a code review tool that automates AI-based analysis across various code hosts, providing structured and commentable reviews. It simplifies the setup process by using Code Host Adapters, allowing users to own their review runtime and policy in their repository files.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somus/pipr">https://github.com/somus/pipr</a></strong> to version <strong>v0.4.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pipr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Pipr is a code review tool that automates AI-based analysis across various code hosts, providing structured and commentable reviews. It simplifies the setup process by using Code Host Adapters, allowing users to own their review runtime and policy in their repository files.</p>
]]></content:encoded></item><item><title>spek - OpenSpec Static Site</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/spek-openspec-static-site/</link><pubDate>Thu, 16 Jul 2026 22:40:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/spek-openspec-static-site/</guid><description>Version updated for https://github.com/spekhq/spek to version v1.8.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary spek is a lightweight read-only viewer for OpenSpec content that provides structured browsing with BDD syntax highlighting, task progress tracking, and full-text search. It allows developers to navigate through specs, changes, and tasks in a local directory without server deployment or data leaving their machine. The action automates the process of aggregating git worktrees into one view, enabling seamless access to all in-flight changes across multiple branches and worktrees.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spekhq/spek">https://github.com/spekhq/spek</a></strong> to version <strong>v1.8.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spek-openspec-static-site">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>spek is a lightweight read-only viewer for OpenSpec content that provides structured browsing with BDD syntax highlighting, task progress tracking, and full-text search. It allows developers to navigate through specs, changes, and tasks in a local directory without server deployment or data leaving their machine. The action automates the process of aggregating git worktrees into one view, enabling seamless access to all in-flight changes across multiple branches and worktrees.</strong></p>
]]></content:encoded></item><item><title>Graveyard Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/graveyard-check/</link><pubDate>Thu, 16 Jul 2026 22:39:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/graveyard-check/</guid><description>Version updated for https://github.com/TahaKotwal12/graveyard-check to version v0.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Graveyard Check is a tool that scans dependency files to identify abandoned or at-risk packages, providing verified successor recommendations. It supports various ecosystems and provides flags for filtering and output formats. The tool can be used as a CI gate or shell guard on its own by exiting with an error if a package is at-risk or likely abandoned.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TahaKotwal12/graveyard-check">https://github.com/TahaKotwal12/graveyard-check</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/graveyard-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Graveyard Check is a tool that scans dependency files to identify abandoned or at-risk packages, providing verified successor recommendations. It supports various ecosystems and provides flags for filtering and output formats. The tool can be used as a CI gate or shell guard on its own by exiting with an error if a package is at-risk or likely abandoned.</p>
]]></content:encoded></item><item><title>gw - Go workspaces</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/gw-go-workspaces/</link><pubDate>Thu, 16 Jul 2026 22:38:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/gw-go-workspaces/</guid><description>Version updated for https://github.com/Toyz/gw to version v0.5.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The gw action automates the management of Go workspaces by generating and maintaining the go.work file, lints cross-module dependency versions, and runs commands across every module. It solves problems related to managing multi-module Go projects efficiently and ensures consistent dependency versions across all modules. The action supports various commands such as bootstrapping, syncing go.work, linting, running commands in each module, building, testing, vetting, generating code, tidying dependencies, listing modules, adding/removing modules, printing the dependency graph, diffing working tree against a git ref, and performing health checks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Toyz/gw">https://github.com/Toyz/gw</a></strong> to version <strong>v0.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gw-go-workspaces">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>gw</code> action automates the management of Go workspaces by generating and maintaining the <code>go.work</code> file, lints cross-module dependency versions, and runs commands across every module. It solves problems related to managing multi-module Go projects efficiently and ensures consistent dependency versions across all modules. The action supports various commands such as bootstrapping, syncing <code>go.work</code>, linting, running commands in each module, building, testing, vetting, generating code, tidying dependencies, listing modules, adding/removing modules, printing the dependency graph, diffing working tree against a git ref, and performing health checks.</p>
]]></content:encoded></item><item><title>Publish updated packages</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/publish-updated-packages/</link><pubDate>Thu, 16 Jul 2026 22:37:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/publish-updated-packages/</guid><description>Version updated for https://github.com/TypeFox/gh-publish-npm to version v0.4.0.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the publishing process for npm packages, VS Code extensions, and Open VSX extensions. It ensures that only newer versions are published by comparing them with previously published versions. The action supports token-based authentication for npm and personal access tokens for VS Marketplace and Open VSX. The tool is configured to use OIDC trusted publishing by default unless an explicit npm token is provided for token-based authentication.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TypeFox/gh-publish-npm">https://github.com/TypeFox/gh-publish-npm</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/publish-updated-packages">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the publishing process for npm packages, VS Code extensions, and Open VSX extensions. It ensures that only newer versions are published by comparing them with previously published versions. The action supports token-based authentication for npm and personal access tokens for VS Marketplace and Open VSX. The tool is configured to use OIDC trusted publishing by default unless an explicit npm token is provided for token-based authentication.</p>
]]></content:encoded></item><item><title>MIU PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/miu-pr-review/</link><pubDate>Thu, 16 Jul 2026 22:36:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/miu-pr-review/</guid><description>Version updated for https://github.com/vanducng/miu-cr to version v0.88.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
miu-cr is an AI code review tool for CLI, CI, and MCP hosts that automates the process of reviewing staged changes, gate PRs in CI, or drive the engine from any MCP-capable agent. The action provides deterministic engine functionality using LLMs and outputs a stable JSON envelope on stdout, solving problems related to code review automation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vanducng/miu-cr">https://github.com/vanducng/miu-cr</a></strong> to version <strong>v0.88.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/miu-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>miu-cr is an AI code review tool for CLI, CI, and MCP hosts that automates the process of reviewing staged changes, gate PRs in CI, or drive the engine from any MCP-capable agent. The action provides deterministic engine functionality using LLMs and outputs a stable JSON envelope on stdout, solving problems related to code review automation.</p>
]]></content:encoded></item><item><title>Commit via GitHub API</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/commit-via-github-api/</link><pubDate>Thu, 16 Jul 2026 22:35:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/commit-via-github-api/</guid><description>Version updated for https://github.com/vig-os/commit-action to version v0.3.1.
This action is used across all versions by 6 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of committing changes to a repository using the GitHub API, enabling the creation of signed commits that bypass branch protection rules. It supports both standalone usage and integration as a module, making it versatile for various use cases in CI/CD pipelines. The action is designed to be type-safe and well-tested, with optimized API usage for handling large files efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vig-os/commit-action">https://github.com/vig-os/commit-action</a></strong> to version <strong>v0.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/commit-via-github-api">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of committing changes to a repository using the GitHub API, enabling the creation of signed commits that bypass branch protection rules. It supports both standalone usage and integration as a module, making it versatile for various use cases in CI/CD pipelines. The action is designed to be type-safe and well-tested, with optimized API usage for handling large files efficiently.</p>
]]></content:encoded></item><item><title>Sync Issues and PRs</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/sync-issues-and-prs/</link><pubDate>Thu, 16 Jul 2026 22:34:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/sync-issues-and-prs/</guid><description>Version updated for https://github.com/vig-os/sync-issues-action to version v0.3.0.
This action is used across all versions by 8 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Sync Issues and PRs Action automates the process of syncing all issues and pull requests from a repository into markdown files, preserving their original content, comments, and metadata. It supports syncing closed items, filtering by issue or pull request numbers, and offers options for customizing output formats and handling attachments. The action can be used with various authentication methods and outputs sync statistics and file paths.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vig-os/sync-issues-action">https://github.com/vig-os/sync-issues-action</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sync-issues-and-prs">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Sync Issues and PRs Action automates the process of syncing all issues and pull requests from a repository into markdown files, preserving their original content, comments, and metadata. It supports syncing closed items, filtering by issue or pull request numbers, and offers options for customizing output formats and handling attachments. The action can be used with various authentication methods and outputs sync statistics and file paths.</p>
]]></content:encoded></item><item><title>PlatformIO Dependency Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/platformio-dependency-updater/</link><pubDate>Thu, 16 Jul 2026 22:32:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/platformio-dependency-updater/</guid><description>Version updated for https://github.com/VIPnytt/platformio-dependency-updater to version v1.0.0-b1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks for updates to dependencies in a platformio.ini file and creates pull requests when newer versions are available. It supports multiple dependency sources and provides built-in features like automatic versioning and cooldowns. The action is useful for keeping projects up-to-date with the latest library releases and maintaining clean PR histories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VIPnytt/platformio-dependency-updater">https://github.com/VIPnytt/platformio-dependency-updater</a></strong> to version <strong>v1.0.0-b1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/platformio-dependency-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks for updates to dependencies in a <code>platformio.ini</code> file and creates pull requests when newer versions are available. It supports multiple dependency sources and provides built-in features like automatic versioning and cooldowns. The action is useful for keeping projects up-to-date with the latest library releases and maintaining clean PR histories.</p>
]]></content:encoded></item><item><title>void git identity</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/void-git-identity/</link><pubDate>Thu, 16 Jul 2026 22:32:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/void-git-identity/</guid><description>Version updated for https://github.com/voidmason/git-identity to version v1.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action resolves the Git committer identity (name and email) from a token or a PAT, handling various resolution strategies including lookup based on user information. It supports specifying explicit names and emails directly in the action inputs or using default values if no specific pair is found. The resolved pair can be used to configure Git settings or passed to other actions as needed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/voidmason/git-identity">https://github.com/voidmason/git-identity</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/void-git-identity">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action resolves the Git committer identity (name and email) from a token or a PAT, handling various resolution strategies including lookup based on user information. It supports specifying explicit names and emails directly in the action inputs or using default values if no specific pair is found. The resolved pair can be used to configure Git settings or passed to other actions as needed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Add optional setup mode to apply git config (a97729d)</li>
<li>Add git-identity action to resolve committer from token (4466523)</li>
<li>Initial commit (233ed78)</li>
</ul>
]]></content:encoded></item><item><title>hreflang-forge</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/hreflang-forge/</link><pubDate>Thu, 16 Jul 2026 22:31:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/hreflang-forge/</guid><description>Version updated for https://github.com/wonsukchoi/hreflang-forge to version v1.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
This GitHub Action, hreflang-forge, generates a sitemap with hreflang alternate links for every page in a Next.js project. It scans the project to identify routes and locales, then creates an XML file detailing each page’s URL structure and hreflang tags. The action is zero-dependency and can be run using Node.js directly or through npm packages.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wonsukchoi/hreflang-forge">https://github.com/wonsukchoi/hreflang-forge</a></strong> to version <strong>v1.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hreflang-forge">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>This GitHub Action, <code>hreflang-forge</code>, generates a sitemap with <code>hreflang</code> alternate links for every page in a Next.js project. It scans the project to identify routes and locales, then creates an XML file detailing each page&rsquo;s URL structure and <code>hreflang</code> tags. The action is zero-dependency and can be run using Node.js directly or through npm packages.</p>
]]></content:encoded></item><item><title>Agent Lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/agent-lint/</link><pubDate>Thu, 16 Jul 2026 22:30:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/agent-lint/</guid><description>Version updated for https://github.com/zhupanov/agent-lint to version v2.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Agent Lint is a linter for Claude Code, Cursor, and Codex configuration files. It automates the validation of configuration files across multiple categories and provides two lint modes: Basic mode for validating detected configurations and Plugin mode for running the full rule suite when .claude-plugin/ is present. The tool can be integrated into CI workflows using a GitHub Action or used as a pre-commit hook to ensure configuration integrity before committing changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zhupanov/agent-lint">https://github.com/zhupanov/agent-lint</a></strong> to version <strong>v2.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Agent Lint is a linter for Claude Code, Cursor, and Codex configuration files. It automates the validation of configuration files across multiple categories and provides two lint modes: Basic mode for validating detected configurations and Plugin mode for running the full rule suite when <code>.claude-plugin/</code> is present. The tool can be integrated into CI workflows using a GitHub Action or used as a pre-commit hook to ensure configuration integrity before committing changes.</p>
]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/ai-plugin-scanner/</link><pubDate>Thu, 16 Jul 2026 15:08:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.494.
This action is used across all versions by 19 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the security and quality checks of AI plugin repositories across different platforms (Codex, Claude, Gemini, OpenCode) by generating structured reports, SARIF files, policy results, and submission metadata. It helps identify security vulnerabilities, compliance issues, and trust signals in AI plugins, ensuring they are secure, publishable, and ready for runtime usage.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.494</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>19</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the security and quality checks of AI plugin repositories across different platforms (Codex, Claude, Gemini, OpenCode) by generating structured reports, SARIF files, policy results, and submission metadata. It helps identify security vulnerabilities, compliance issues, and trust signals in AI plugins, ensuring they are secure, publishable, and ready for runtime usage.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/25734ba79b1d1241aa7fe300c33463f31e88f645">https://github.com/hashgraph-online/hol-guard/tree/25734ba79b1d1241aa7fe300c33463f31e88f645</a> with plugin-scanner 2.0.1095.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.493...v1.2.494">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.493...v1.2.494</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/hol-codex-plugin-scanner/</link><pubDate>Thu, 16 Jul 2026 15:07:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.493.
This action is used across all versions by 12 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action automates the security, publishability, runtime readiness, and trust signals of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems. It emits structured reports, SARIF, policy results, and submission metadata while staying aligned with the main scanner release train. The summary provides a concise overview of the action’s main purpose, functionality, and problem-solving capabilities.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.493</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>12</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action automates the security, publishability, runtime readiness, and trust signals of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems. It emits structured reports, SARIF, policy results, and submission metadata while staying aligned with the main scanner release train. The summary provides a concise overview of the action&rsquo;s main purpose, functionality, and problem-solving capabilities.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.493">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.493</a></p>
]]></content:encoded></item><item><title>Supply Chain Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/supply-chain-guard/</link><pubDate>Thu, 16 Jul 2026 15:06:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/supply-chain-guard/</guid><description>Version updated for https://github.com/homeofe/supply-chain-guard to version v5.12.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically scans various package managers and ecosystems to detect potential security threats such as malware, code-level vulnerabilities, and supply chain attacks. It generates CycloneDX SBOMs to provide a comprehensive view of dependencies and verifies SLSA provenance, helping organizations identify and remediate risks in their software supply chains.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/homeofe/supply-chain-guard">https://github.com/homeofe/supply-chain-guard</a></strong> to version <strong>v5.12.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/supply-chain-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically scans various package managers and ecosystems to detect potential security threats such as malware, code-level vulnerabilities, and supply chain attacks. It generates CycloneDX SBOMs to provide a comprehensive view of dependencies and verifies SLSA provenance, helping organizations identify and remediate risks in their software supply chains.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="v5123-2026-07-16">v5.12.3 (2026-07-16)</h3>
<p><strong>Threat-intel: AsyncAPI npm supply-chain compromise (July 2026)</strong></p>
<ul>
<li>Added IOCs for the AsyncAPI npm supply-chain attack (The Hacker News /
BleepingComputer / Socket / StepSecurity, 2026-07-14 to 07-15). Five malicious
versions across four packages in the <code>@asyncapi</code> namespace were published to
npm during a roughly 4-hour window on 2026-07-14 (07:10-11:18 UTC) and
delivered a credential-stealing multi-stage botnet loader. The loader pulls a
second stage from IPFS and supports C2 over HTTP, Nostr relays, IPFS,
BitTorrent DHT, libp2p GossipSub, and an Ethereum smart contract. All five
versions have since been unpublished from npm. Reported jointly by OX Security,
SafeDep, Socket, StepSecurity, Microsoft, Wiz and Aikido.</li>
<li>Version-pinned entries added to <code>KNOWN_BAD_NPM_VERSIONS</code> and <code>BUNDLED_FEED</code>:
<code>@asyncapi/generator@3.3.1</code>, <code>@asyncapi/generator-helpers@1.1.1</code>,
<code>@asyncapi/generator-components@0.7.1</code>, and <code>@asyncapi/specs@6.11.2</code> /
<code>6.11.2-alpha.1</code>. These are legitimate packages, so the bare names are
intentionally NOT blocked - only the listed versions match.</li>
<li>Added the specific IPFS second-stage CID as a dead-drop resolver. The exact
malicious CID path is matched, never the <code>ipfs[.]io</code> gateway host, so
legitimate IPFS usage is not flagged.</li>
<li>New &ldquo;AsyncAPI npm compromise (July 2026)&rdquo; campaign test block.</li>
<li>Source excerpts came from the arena.elvatis.com feed; the exact package
versions were confirmed against two independent primary reports before being
added.</li>
</ul>
]]></content:encoded></item><item><title>JFrog Boost</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/jfrog-boost/</link><pubDate>Thu, 16 Jul 2026 15:04:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/jfrog-boost/</guid><description>Version updated for https://github.com/jfrog/boost to version v0.9.10.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 2 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Boost is a tool designed to help developers and agents manage and save tokens in their output by trimming noise while preserving critical information about task execution. It enhances terminal logs with structured context, reducing verbosity without compromising performance or agent effectiveness.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jfrog/boost">https://github.com/jfrog/boost</a></strong> to version <strong>v0.9.10</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>2</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jfrog-boost">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Boost is a tool designed to help developers and agents manage and save tokens in their output by trimming noise while preserving critical information about task execution. It enhances terminal logs with structured context, reducing verbosity without compromising performance or agent effectiveness.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Release v0.7.23 by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/41">https://github.com/jfrog/boost/pull/41</a></li>
<li>Release v0.7.25 by @menachemm-byte in <a href="https://github.com/jfrog/boost/pull/44">https://github.com/jfrog/boost/pull/44</a></li>
<li>docs(readme): simplify mascot, focus on token savings, add report commands by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/47">https://github.com/jfrog/boost/pull/47</a></li>
<li>docs(readme): update release badge to v0.8.6 and stars to 258 by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/48">https://github.com/jfrog/boost/pull/48</a></li>
<li>docs(readme): add how-to-use walkthrough GIF above Quick start by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/52">https://github.com/jfrog/boost/pull/52</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@menachemm-byte made their first contribution in <a href="https://github.com/jfrog/boost/pull/44">https://github.com/jfrog/boost/pull/44</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jfrog/boost/compare/v0.7.23...v0.9.10">https://github.com/jfrog/boost/compare/v0.7.23...v0.9.10</a></p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/neurolink-ai/</link><pubDate>Thu, 16 Jul 2026 15:03:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v9.88.10.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is an AI integration platform that provides a unified API for accessing 30+ AI providers and models. It allows developers to switch between different providers with a single parameter change and leverages built-in tools and MCP servers. NeuroLink also offers enterprise features like Redis memory and multi-provider failover, and intelligent routing to optimize costs automatically.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v9.88.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>NeuroLink is an AI integration platform that provides a unified API for accessing 30+ AI providers and models. It allows developers to switch between different providers with a single parameter change and leverages built-in tools and MCP servers. NeuroLink also offers enterprise features like Redis memory and multi-provider failover, and intelligent routing to optimize costs automatically.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="98810-2026-07-16"><a href="https://github.com/juspay/neurolink/compare/v9.88.9...v9.88.10">9.88.10</a> (2026-07-16)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(message-builder):</strong>  image input download + data-URI safety (<a href="https://github.com/juspay/neurolink/commit/746eab54cce86a47ceec3049e46e2f51c4ef8547">746eab5</a>), closes <a href="https://github.com/juspay/neurolink/issues/334">#334</a> <a href="https://github.com/juspay/neurolink/issues/270">#270</a> <a href="https://github.com/juspay/neurolink/issues/348">#348</a></li>
</ul>
]]></content:encoded></item><item><title>MathArts Sync Labels</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/matharts-sync-labels/</link><pubDate>Thu, 16 Jul 2026 15:02:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/matharts-sync-labels/</guid><description>Version updated for https://github.com/matharts/sync-labels-action to version v1.5.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary MathArts Sync Labels 是一个 GitHub Actions 动作，用于同步组织内多个仓库的标签。它使用一份标签清单和一份所有权策略，确保只有管理员声明为保留或管理的标签能够被更新、删除或重命名。Action 默认预览变更并只操作策略允许的操作，可以离线校验配置。
What’s Changed 仓库范围与离线校验 新增可选的 repositories.exclude 策略；未配置时保持原有仓库选择行为。 仓库范围按固定顺序应用：全部仓库或 repositories.include，然后是 repositories.exclude，最后是可选的 repository input。 在访问 GitHub 前拒绝重叠、重复、空或无效的仓库选择。 新增 validate_only Action input，无需 GitHub 凭据或网络访问即可校验标签和仓库策略文件。 新增 pnpm validate:config，复用 Action 使用的 GovernanceConfig 规则。 保持 v1.4 inputs、outputs、默认 dry-run 行为、删除安全、重试行为、部分失败计数和 Unicode 处理不变。 明确 changed 在 dry-run 模式报告计划变更，在写入模式报告已完成的变更。 通过全组织排除 dry-run、无凭据离线校验、非法策略一致性及现有 workflow 兼容性验证候选版本。 将稳定错误分类、失败仓库输出、可归档计划文件、并发、缓存和批处理推迟到后续版本。 建议审核发布提交并固定其完整 SHA，而不是可移动版本标签。 验证：pnpm check、Node.js 24 CI、可复现 dist/index.js bundle 比对、Actionlint、CodeQL、全组织排除 dry-run、发布演练、发布后测试及发布后组织预览均通过。</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/matharts/sync-labels-action">https://github.com/matharts/sync-labels-action</a></strong> to version <strong>v1.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/matharts-sync-labels">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>MathArts Sync Labels 是一个 GitHub Actions 动作，用于同步组织内多个仓库的标签。它使用一份标签清单和一份所有权策略，确保只有管理员声明为保留或管理的标签能够被更新、删除或重命名。Action 默认预览变更并只操作策略允许的操作，可以离线校验配置。</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="仓库范围与离线校验">仓库范围与离线校验</h2>
<ul>
<li>新增可选的 <code>repositories.exclude</code> 策略；未配置时保持原有仓库选择行为。</li>
<li>仓库范围按固定顺序应用：全部仓库或 <code>repositories.include</code>，然后是 <code>repositories.exclude</code>，最后是可选的 <code>repository</code> input。</li>
<li>在访问 GitHub 前拒绝重叠、重复、空或无效的仓库选择。</li>
<li>新增 <code>validate_only</code> Action input，无需 GitHub 凭据或网络访问即可校验标签和仓库策略文件。</li>
<li>新增 <code>pnpm validate:config</code>，复用 Action 使用的 <code>GovernanceConfig</code> 规则。</li>
<li>保持 v1.4 inputs、outputs、默认 dry-run 行为、删除安全、重试行为、部分失败计数和 Unicode 处理不变。</li>
<li>明确 <code>changed</code> 在 dry-run 模式报告计划变更，在写入模式报告已完成的变更。</li>
<li>通过全组织排除 dry-run、无凭据离线校验、非法策略一致性及现有 workflow 兼容性验证候选版本。</li>
<li>将稳定错误分类、失败仓库输出、可归档计划文件、并发、缓存和批处理推迟到后续版本。</li>
<li>建议审核发布提交并固定其完整 SHA，而不是可移动版本标签。</li>
</ul>
<p>验证：<code>pnpm check</code>、Node.js 24 CI、可复现 <code>dist/index.js</code> bundle 比对、Actionlint、CodeQL、<a href="https://github.com/matharts/sync-labels-action/actions/runs/29458270313">全组织排除 dry-run</a>、<a href="https://github.com/matharts/sync-labels-action/issues/32#issuecomment-4986231343">发布演练</a>、<a href="https://github.com/matharts/sync-labels-action/actions/runs/29458816128">发布后测试</a>及<a href="https://github.com/matharts/sync-labels-action/actions/runs/29458817745">发布后组织预览</a>均通过。</p>
]]></content:encoded></item><item><title>agent-bom Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/agent-bom-scan/</link><pubDate>Thu, 16 Jul 2026 15:00:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/agent-bom-scan/</guid><description>Version updated for https://github.com/msaad00/agent-bom to version v0.96.3.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the process of scanning software assets to identify vulnerabilities, generating a Unified Graph for context and visibility, and serving findings in real-time. It streamlines security operations by providing a unified interface for both internal and external stakeholders to access security information. The action supports various tools and platforms, making it versatile for organizations looking to enhance their cybersecurity posture and streamline incident response processes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/msaad00/agent-bom">https://github.com/msaad00/agent-bom</a></strong> to version <strong>v0.96.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-bom-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action automates the process of scanning software assets to identify vulnerabilities, generating a Unified Graph for context and visibility, and serving findings in real-time. It streamlines security operations by providing a unified interface for both internal and external stakeholders to access security information. The action supports various tools and platforms, making it versatile for organizations looking to enhance their cybersecurity posture and streamline incident response processes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(repo): README self-host + accuracy, Pages concurrency fix, contributor identity cleanup by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4043">https://github.com/msaad00/agent-bom/pull/4043</a></li>
<li>feat(graph): readable-at-scale unified graph — auto-layout, clustering, no pagination by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4045">https://github.com/msaad00/agent-bom/pull/4045</a></li>
<li>feat(ia): consolidate Connections/Cloud/Data-sources into one hub by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4047">https://github.com/msaad00/agent-bom/pull/4047</a></li>
<li>feat(inventory): unified Asset Inventory section by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4046">https://github.com/msaad00/agent-bom/pull/4046</a></li>
<li>test(e2e): update connections screenshot spec for the consolidated hub by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4048">https://github.com/msaad00/agent-bom/pull/4048</a></li>
<li>fix(audit): Codex-flagged correctness bugs — skills FP, traversal OOM, nested-worktree recursion, &ndash;no-ui, startup auth log by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4050">https://github.com/msaad00/agent-bom/pull/4050</a></li>
<li>feat(scale): bounded retention + default ~90d time-window filters by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4052">https://github.com/msaad00/agent-bom/pull/4052</a></li>
<li>perf(findings): index-backed unfiltered effective-reach sort + trust materialized score by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4054">https://github.com/msaad00/agent-bom/pull/4054</a></li>
<li>chore(release): 0.96.3 by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/4056">https://github.com/msaad00/agent-bom/pull/4056</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/msaad00/agent-bom/compare/v0.96.2...v0.96.3">https://github.com/msaad00/agent-bom/compare/v0.96.2...v0.96.3</a></p>
]]></content:encoded></item><item><title>AI PR Review (GitHub Models)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/ai-pr-review-github-models/</link><pubDate>Thu, 16 Jul 2026 14:59:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/ai-pr-review-github-models/</guid><description>Version updated for https://github.com/muhammedshibilm/ai-pr-review-action to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The AI PR Review Action is a GitHub Action that uses pre-trained models to review pull requests in your repository. It provides feedback on areas like bugs, security, and readability, with the ability to focus reviews on specific aspects of the code. The action automates the process by running multiple specialized reviews in parallel, allowing for a comprehensive assessment of the PR’s quality.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/muhammedshibilm/ai-pr-review-action">https://github.com/muhammedshibilm/ai-pr-review-action</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-pr-review-github-models">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The AI PR Review Action is a GitHub Action that uses pre-trained models to review pull requests in your repository. It provides feedback on areas like bugs, security, and readability, with the ability to focus reviews on specific aspects of the code. The action automates the process by running multiple specialized reviews in parallel, allowing for a comprehensive assessment of the PR&rsquo;s quality.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new">What&rsquo;s new</h2>
<ul>
<li><strong>Prioritized feedback</strong> — reviews are now grouped into 🚨 Must Fix, ⚠️ Should Fix, 💡 Suggestions, and ✅ Good, instead of one flat list.</li>
<li><strong>Configurable focus areas</strong> — target the review via the new <code>focus_areas</code> input (bugs, security, edge-cases, readability, performance, tests).</li>
<li><strong>Configurable ignore patterns</strong> — exclude extra paths via <code>extra_ignore_patterns</code>, on top of built-in defaults (lock files, generated code, binaries).</li>
<li><strong>Multi-reviewer workflows</strong> — run the action in parallel jobs with different <code>focus_areas</code> values to simulate specialised reviewers (security, performance, readability, etc). See README for an example workflow.</li>
</ul>
<h2 id="upgrading">Upgrading</h2>
<p>No breaking changes from v1.1.0 — all new inputs are optional with sensible defaults.</p>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/go-proxy-cache-updater/</link><pubDate>Thu, 16 Jul 2026 14:57:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.25.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically updates a Go proxy cache when new module releases are tagged according to semantic versioning conventions (vX.Y.Z and submodule/path/vX.Y.Z). It supports customizing the proxy configuration, import path, and Go version. The action uses actions/setup-go for setting up the Go environment and caches dependencies for faster builds.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.25</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically updates a Go proxy cache when new module releases are tagged according to semantic versioning conventions (<code>vX.Y.Z</code> and <code>submodule/path/vX.Y.Z</code>). It supports customizing the proxy configuration, import path, and Go version. The action uses actions/setup-go for setting up the Go environment and caches dependencies for faster builds.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1125-2026-07-16"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.24...v1.1.25">1.1.25</a> (2026-07-16)</h2>
]]></content:encoded></item><item><title>AI Harness Doctor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/ai-harness-doctor/</link><pubDate>Thu, 16 Jul 2026 14:56:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/ai-harness-doctor/</guid><description>Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v1.10.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Harness Doctor is a tool that automates the consolidation of scattered agent configurations into one canonical AGENTS.md file in a repository, helping to eliminate drift and maintain consistency across different tools. It also provides functionality to apply changes, guard against further drift, and ensure repositories do not rewrite or delete through symlinks. The action can be run with a single command to scan a repository and generate a full checkup report.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NieZhuZhu/ai-harness-doctor">https://github.com/NieZhuZhu/ai-harness-doctor</a></strong> to version <strong>v1.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-harness-doctor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AI Harness Doctor is a tool that automates the consolidation of scattered agent configurations into one canonical <code>AGENTS.md</code> file in a repository, helping to eliminate drift and maintain consistency across different tools. It also provides functionality to apply changes, guard against further drift, and ensure repositories do not rewrite or delete through symlinks. The action can be run with a single command to scan a repository and generate a full checkup report.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(sarif): stable fingerprints and per-command category (Plan 042) by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/207">https://github.com/NieZhuZhu/ai-harness-doctor/pull/207</a></li>
<li>docs(plans): mark Plan 042 done by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/209">https://github.com/NieZhuZhu/ai-harness-doctor/pull/209</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NieZhuZhu/ai-harness-doctor/compare/v1.9.2...v1.10.0">https://github.com/NieZhuZhu/ai-harness-doctor/compare/v1.9.2...v1.10.0</a></p>
]]></content:encoded></item><item><title>OSuite Governed Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/osuite-governed-action/</link><pubDate>Thu, 16 Jul 2026 14:55:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/osuite-governed-action/</guid><description>Version updated for https://github.com/OndCo/osuite-governed-action to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the governance of GitHub Actions by creating an OSuite action envelope that includes runtime context and applies policies before the workflow continues. It allows teams to track actions in OSuite, manage approvals, and ensure compliance with governance rules. The action emits outputs for decision, replay link, and proof URL, enhancing transparency and accountability in CI/CD workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/OndCo/osuite-governed-action">https://github.com/OndCo/osuite-governed-action</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/osuite-governed-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the governance of GitHub Actions by creating an OSuite action envelope that includes runtime context and applies policies before the workflow continues. It allows teams to track actions in OSuite, manage approvals, and ensure compliance with governance rules. The action emits outputs for decision, replay link, and proof URL, enhancing transparency and accountability in CI/CD workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial public release of OSuite Governed Action.</p>
<p>This release adds a GitHub Actions gate for teams that want high-impact workflow steps to pass through OSuite before execution.</p>
<p>Included in v0.1.0:</p>
<ul>
<li>Create OSuite governed action records from GitHub Actions workflows.</li>
<li>Send repository, ref, commit, workflow, actor, run id, target, reversibility, and declared goal to OSuite.</li>
<li>Support enforce mode and observe mode.</li>
<li>Wait for OSuite approval when a workflow requires human review.</li>
<li>Fail safely when OSuite blocks an action.</li>
<li>Emit decision, action id, risk score, action hash, replay URL, and proof bundle URL.</li>
<li>Add dry-run mode for safe CI validation.</li>
<li>Include examples for production deployment gates and pull request review workflows.</li>
</ul>
<p>Recommended use cases:</p>
<ul>
<li>Production deployments</li>
<li>Release workflows</li>
<li>Infrastructure changes</li>
<li>Database migrations</li>
<li>AI-assisted engineering workflows</li>
<li>High-risk CI/CD automation requiring approval, replay, or evidence</li>
</ul>
]]></content:encoded></item><item><title>Polygraph MCP gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/polygraph-mcp-gate/</link><pubDate>Thu, 16 Jul 2026 14:54:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/polygraph-mcp-gate/</guid><description>Version updated for https://github.com/polygraphso/litmus to version litmus-v0.34.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the evaluation of MCP servers to provide a reproducible grade A-F, ensuring compliance and consistency across different environments. It allows users to quickly check, list, or request grades for servers, verify attestation proofs, and run litmus tests directly from an agent server. The action supports various inputs including npm packages, pypi packages, GitHub repository clones, MCP endpoints, and local entry files, and ensures that the target’s code is executed within Docker sandboxing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/polygraphso/litmus">https://github.com/polygraphso/litmus</a></strong> to version <strong>litmus-v0.34.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/polygraph-mcp-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the evaluation of MCP servers to provide a reproducible grade A-F, ensuring compliance and consistency across different environments. It allows users to quickly check, list, or request grades for servers, verify attestation proofs, and run litmus tests directly from an agent server. The action supports various inputs including npm packages, pypi packages, GitHub repository clones, MCP endpoints, and local entry files, and ensures that the target&rsquo;s code is executed within Docker sandboxing.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>request_grade now surfaces polygraph.so&rsquo;s $1 grading fee: recording a request is free, grading starts on payment (web checkout in $POLYGRAPH, or $1 USDC on Base via x402 for agents), and the grade publishes within 48h of payment. The fee buys the run, never the grade. Additive API fields — the tool keeps working against older deployments. (#118, #119)</p>
]]></content:encoded></item><item><title>MegaLinter Custom Flavor Zensical</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/megalinter-custom-flavor-zensical/</link><pubDate>Thu, 16 Jul 2026 14:53:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/megalinter-custom-flavor-zensical/</guid><description>Version updated for https://github.com/practicalli-johnny/megalinter-custom-flavor-zensical to version Error loading version from page [https://github.com/marketplace/actions/megalinter-custom-flavor-zensical], unable to determine latest release.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action customizes the official MegaLinter Docker image to include only specific linters and optimize it for a smaller size. It solves the problem of having an optimized, lightweight MegaLinter environment by embedding only essential linters like MARKDOWN_MARKDOWN_TABLE_FORMATTER, markdown_rumdl, repository_betterleaks, spell_lychee, and yaml_v8r.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/practicalli-johnny/megalinter-custom-flavor-zensical">https://github.com/practicalli-johnny/megalinter-custom-flavor-zensical</a></strong> to version <strong>Error loading version from page [https://github.com/marketplace/actions/megalinter-custom-flavor-zensical], unable to determine latest release</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/megalinter-custom-flavor-zensical">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action customizes the official MegaLinter Docker image to include only specific linters and optimize it for a smaller size. It solves the problem of having an optimized, lightweight MegaLinter environment by embedding only essential linters like MARKDOWN_MARKDOWN_TABLE_FORMATTER, markdown_rumdl, repository_betterleaks, spell_lychee, and yaml_v8r.</p>
]]></content:encoded></item><item><title>RabbitMQ Publish</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/rabbitmq-publish/</link><pubDate>Thu, 16 Jul 2026 14:50:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/rabbitmq-publish/</guid><description>Version updated for https://github.com/rikkaneko/rabbitmq-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the publishing of UTF-8 payloads to a RabbitMQ or AMQP exchange or queue. It supports various authentication methods, including username/password and mTLS certificate-based authentication, as well as header support for custom routing keys. The action ensures that the connection is validated before publication and provides options for consumer acknowledgment with timeout settings.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rikkaneko/rabbitmq-action">https://github.com/rikkaneko/rabbitmq-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rabbitmq-publish">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the publishing of UTF-8 payloads to a RabbitMQ or AMQP exchange or queue. It supports various authentication methods, including username/password and mTLS certificate-based authentication, as well as header support for custom routing keys. The action ensures that the connection is validated before publication and provides options for consumer acknowledgment with timeout settings.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Inital release</p>
]]></content:encoded></item><item><title>Droid LLM Hunter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/droid-llm-hunter/</link><pubDate>Thu, 16 Jul 2026 14:50:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/droid-llm-hunter/</guid><description>Version updated for https://github.com/roomkangali/droid-llm-hunter to version 1.1.9.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Droid LLM Hunter is an automated security analysis tool designed to detect vulnerabilities in Android applications with high precision. It combines traditional static analysis (SAST) with the contextual understanding of Large Language Models (LLMs) to provide intelligent, risk-filtered findings and active Red Team Assistant capabilities through auto-exploit generation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/roomkangali/droid-llm-hunter">https://github.com/roomkangali/droid-llm-hunter</a></strong> to version <strong>1.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/droid-llm-hunter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Droid LLM Hunter is an automated security analysis tool designed to detect vulnerabilities in Android applications with high precision. It combines traditional static analysis (SAST) with the contextual understanding of Large Language Models (LLMs) to provide intelligent, risk-filtered findings and active Red Team Assistant capabilities through auto-exploit generation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Updates the project to v1.1.9, focusing on improving scan UX/robustness (LLM JSON parsing) and restoring cross-reference context injection (call graph) to work reliably in JADX/hybrid modes, alongside accompanying documentation/version text updates.</p>
<p>Changes:</p>
<ul>
<li>Make LLM JSON extraction string-aware (ignores braces inside JSON string values) and adjust parsing flow.</li>
<li>Rework call-graph dependency handling to operate on normalized class names and support JADX/hybrid path mapping.</li>
</ul>
<img width="1254" height="992" alt="Screenshot from 2026-07-16 11-39-34" src="https://github.com/user-attachments/assets/584c266e-fcfe-4929-b5b5-ef961d50a11f" />
]]></content:encoded></item><item><title>RW AI Reviewer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/rw-ai-reviewer/</link><pubDate>Thu, 16 Jul 2026 14:49:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/rw-ai-reviewer/</guid><description>Version updated for https://github.com/rw-core/rw-ai-reviewer to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The AI code review action automates the process of performing AI-based reviews on pull requests by gathering PR context, diff, and customizable instructions. It sends the combined data to a GitHub Models inference API and posts the result as a sticky comment on the PR, along with job summaries and outputs. The action supports extending or replacing built-in review instructions with custom markdown files.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rw-core/rw-ai-reviewer">https://github.com/rw-core/rw-ai-reviewer</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rw-ai-reviewer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The AI code review action automates the process of performing AI-based reviews on pull requests by gathering PR context, diff, and customizable instructions. It sends the combined data to a GitHub Models inference API and posts the result as a sticky comment on the PR, along with job summaries and outputs. The action supports extending or replacing built-in review instructions with custom markdown files.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Rolling release; tracks the latest v1.x. Pin to v1.0.1 for immutability.</p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/bernstein-multi-agent-orchestration/</link><pubDate>Thu, 16 Jul 2026 14:47:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.5.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bernstein automates multi-agent deterministic scheduling of CLIs such as Claude Code, Codex, and Gemini CLI in parallel Git worktrees. It uses an HMAC-signed audit chain to track each step of the process and provides signed agent cards for secure delegation. The lineage feature records every adapter file write, ensuring artifact provenance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Bernstein automates multi-agent deterministic scheduling of CLIs such as Claude Code, Codex, and Gemini CLI in parallel Git worktrees. It uses an HMAC-signed audit chain to track each step of the process and provides signed agent cards for secure delegation. The lineage feature records every adapter file write, ensuring artifact provenance.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v350">v3.5.0</h1>
<p>Released 2026-07-16.</p>
<p>A feature release that hardens the two guarantees the orchestrator is built on: audit identity that survives protocol change, and replay that notices when a provider rewrites what the model saw. Plus a security dependency bump and a round of CI reliability work.</p>
<h2 id="mcp-stateless-chain-anchored-call-identity-2506">MCP: stateless, chain-anchored call identity (#2506)</h2>
<p>The MCP client, remote transport, and gateway no longer depend on protocol sessions. Every call carries content-derived trace and span ids in <code>_meta</code>, input-required retries resume from an echoed request state on any server instance, and each served or proxied call is recorded as an <code>mcp.stateless_call</code> entry bound to the audit-chain head. In practice:</p>
<ul>
<li>A tool-call sequence completes correctly even when consecutive requests land on different transport instances with no shared memory.</li>
<li><code>bernstein audit verify</code> reconstructs the full MCP call ordering of a run from chain entries alone, and tampering with any single entry fails verification at exactly that entry.</li>
<li>Legacy clients that still send a session header keep working through a compatibility shim with an explicit removal window.</li>
</ul>
<p>This also sweeps deprecated protocol surfaces (Roots, Sampling, Logging advertisement) behind the same shim, ahead of the upcoming MCP specification revision.</p>
<h2 id="replay-provider-side-context-mutations-are-now-recorded-2507">Replay: provider-side context mutations are now recorded (#2507)</h2>
<p>Byte-identical replay assumed context-as-sent equals context-as-consumed. Providers can now mutate context server side (context compaction and similar opaque state), so the journal records every such mutation as a content-addressed chain entry:</p>
<ul>
<li>Deterministic runs request suppression and fail loudly if a mutation arrives anyway.</li>
<li>Replay flags an unrecorded mutation as divergence at the exact step, instead of drifting silently.</li>
<li>Two replays of a run with recorded mutations produce byte-identical journal heads.</li>
</ul>
<h2 id="security">Security</h2>
<ul>
<li>pillow raised to 12.3.0, clearing eight published advisories (PYSEC-2026-2253 through 2257, 3451 through 3453). (#2498)</li>
<li>Code-scanning findings addressed: unique salt derivation, cookie security flags, workflow hardening. (#2495)</li>
<li>SonarQube SARIF export scoped to security-relevant findings so the Security tab stays signal-only. (#2501)</li>
</ul>
<h2 id="ci-reliability">CI reliability</h2>
<ul>
<li>The workflow topology report now self-heals on main after workflow-editing merges, removing a recurring transient red. (#2531)</li>
<li>The weekly CI digest counts real failures only (cancelled, superseded runs excluded) and keeps a single rolling issue. (#2496)</li>
<li>Observability snapshots collect from all backends again, and metric regressions now page instead of rotting in a file. (#2502)</li>
<li>The aider adapter conformance probe no longer misreads a broken help probe as full flag drift. (#2497)</li>
<li>CodeQL analyses on main are no longer cancelled mid-run. (#2477)</li>
</ul>
<h2 id="community">Community</h2>
<ul>
<li>The web UI overview docs now match the shipped seven-route surface. Thanks @Om-Rohilla. (#2505)</li>
<li>The web UI tracking issue (#1262) carries a prioritized contributor roadmap with good first picks.</li>
</ul>
<h2 id="housekeeping">Housekeeping</h2>
<p>Dependency digest updates via Renovate, coverage-report retention extended to 14 days, GlitchTip regression cases imported into the eval corpus, adapter last-green table refreshed from canary receipts.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sipyourdrink-ltd/bernstein/compare/v3.4.4...v3.5.0">https://github.com/sipyourdrink-ltd/bernstein/compare/v3.4.4...v3.5.0</a></p>
]]></content:encoded></item><item><title>spek - OpenSpec Static Site</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/spek-openspec-static-site/</link><pubDate>Thu, 16 Jul 2026 14:46:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/spek-openspec-static-site/</guid><description>Version updated for https://github.com/spekhq/spek to version v1.8.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Spek is a lightweight read-only viewer that transforms local OpenSpec directories into an interactive, structured interface. It provides features like dashboard overview, spec browsing, change management, Git worktree aggregation, timeline visualization, BDD syntax highlighting, task progress tracking, and full-text search. The tool is available in various forms including web apps, VS Code extensions, and IntelliJ plugins, all designed for read-only access to OpenSpec content without server deployment or authentication.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spekhq/spek">https://github.com/spekhq/spek</a></strong> to version <strong>v1.8.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spek-openspec-static-site">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Spek</strong> is a lightweight read-only viewer that transforms local OpenSpec directories into an interactive, structured interface. It provides features like dashboard overview, spec browsing, change management, Git worktree aggregation, timeline visualization, BDD syntax highlighting, task progress tracking, and full-text search. The tool is available in various forms including web apps, VS Code extensions, and IntelliJ plugins, all designed for read-only access to OpenSpec content without server deployment or authentication.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>
<p><strong>Changes shared across git worktrees no longer show up multiple times (Web and VS Code).</strong> When you work in several worktrees of one repo, each inherits a copy of every open change; spek was listing every copy, cluttering the Changes list and the dependency Graph, and inflating each spec&rsquo;s fan-in count in the graph. It now shows one entry per change — the copy from the worktree actually editing it — decided from git history (which worktree has advanced the change past the main worktree) rather than file timestamps as the primary signal; timestamps now only break a tie between copies that have <em>both</em> genuinely advanced. Because a fresh worktree rewrites every file&rsquo;s timestamp on checkout, the old timestamp-first guess could pick an idle, never-touched copy and make an in-progress change look reset to zero; that no longer happens. Thanks to <a href="https://github.com/david-lutz">@david-lutz</a> (David Lutz) for contributing this.</p>
<p><strong>Note:</strong> the IntelliJ plugin has its own copy of the scanning logic and is not fixed by this release — changes still appear once per worktree there.</p>
</li>
</ul>
<p>Also in this release: <a href="https://www.npmjs.com/package/@spekjs/core/v/1.1.2"><code>@spekjs/core@1.1.2</code></a> ships the same fix to API consumers.</p>
]]></content:encoded></item><item><title>runward gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/runward-gate/</link><pubDate>Thu, 16 Jul 2026 14:45:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/runward-gate/</guid><description>Version updated for https://github.com/stranxik/runward to version v0.18.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Runward is a delivery framework designed to structure agentic systems from idea to production. It automates the gating process, ensuring that agents are built and run correctly before deployment, covering six key phases of development: frame, spec kit or open spec, brownfield characterization, floor first (testing), evolution on evidence, governance from day zero, and handover. Runward helps prevent architecture failures by addressing core assumptions of classical distributed engineering and providing a structured approach to the delivery of agentic systems.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stranxik/runward">https://github.com/stranxik/runward</a></strong> to version <strong>v0.18.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/runward-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Runward is a delivery framework designed to structure agentic systems from idea to production. It automates the gating process, ensuring that agents are built and run correctly before deployment, covering six key phases of development: frame, spec kit or open spec, brownfield characterization, floor first (testing), evolution on evidence, governance from day zero, and handover. Runward helps prevent architecture failures by addressing core assumptions of classical distributed engineering and providing a structured approach to the delivery of agentic systems.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>A five-agent adversarial audit before public marketplace submission (security, compliance, code coherence, packagings, architecture). The verdict was sound — self-gate honestly green, no cited-not-applied, architecture faithful to its own doctrine — with two real security holes to close and some polish. All fixed.</p>
<ul>
<li><strong>Seal traversal closed (security).</strong> The seal <em>writer</em> confined paths (v0.17), the <em>verifier</em> did not — a forged <code>evidence-lock.json</code> with a <code>../</code> or absolute key made <code>check --strict</code> read/hash a file outside the project (arbitrary-file-read oracle + DoS). The verifier now contains lock keys like the writer.</li>
<li><strong>Command injection closed in the GitHub Action (CWE-78).</strong> Inputs are passed through the environment (not interpolated into <code>run:</code>) and <code>version</code> is allowlisted — a malicious input can&rsquo;t inject shell.</li>
<li><strong>ReDoS screen bypass closed.</strong> A nested quantifier hidden in a character class (<code>([^()]+)+</code>) slipped past the screen and hung V8. Character classes are normalized first; <code>([^()]+)+</code> and <code>([a-z]+)*</code> are now caught, real signatures stay safe.</li>
<li><strong><code>runward rules</code> no longer mislabels the gated hand-over rules</strong> (one CRITICAL) as advisory — the gated phases derive from <code>GATED_DELIVERABLES</code> now.</li>
<li><strong>Packaging polish before submission</strong>: 4 manifests bumped off 0.17.0; the Codex <code>marketplace.json</code> rewritten to the documented schema; the Cursor tier corrected to advisory <code>stop</code>; the <code>npx --yes</code> supply-chain posture documented with how to pin.</li>
<li><strong>Guards</strong>: unit tests for the seal-traversal rejection, the ReDoS screen, and a packaging version/hook check that would have caught the version drift. ADR count harmonized to 28.</li>
</ul>
<p>Full detail: <a href="https://github.com/stranxik/runward/blob/main/CHANGELOG.md">CHANGELOG</a></p>
]]></content:encoded></item><item><title>Pi Review Agent</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/pi-review-agent/</link><pubDate>Thu, 16 Jul 2026 14:44:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/pi-review-agent/</guid><description>Version updated for https://github.com/sun-praise/pi-review-agent to version v1.5.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Multi-persona PR review agent using Pi and Litellm AI to automate inline reviews, cache management, and team collaboration on GitHub or Gitea platforms.
What’s Changed Highlights Two-layer verifier suppresses hallucinated findings — rule-based line/file checks plus LLM re-confirmation. Demoted items appear in a collapsible section. Regex grep tool — the walkGrep matcher now accepts regex patterns by default. Cross-model fallback — configure a comma-separated fallback model list (PI_REVIEW_FALLBACK_MODELS) so the agent retries on another model when the primary fails. What’s Changed Added Two-layer verifier to suppress hallucinated findings (#21) Regex support in grep tool Cross-model fallback support (#29) Fixed parseDiffPath handles file paths containing spaces (#25) filterDiff truncates at section boundaries and excludes build artifacts by default (#28) walkGrep glob matching normalizes path separators for Windows compatibility Full Changelog: https://github.com/sun-praise/pi-review-agent/compare/v1.4.0...v1.5.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sun-praise/pi-review-agent">https://github.com/sun-praise/pi-review-agent</a></strong> to version <strong>v1.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pi-review-agent">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Multi-persona PR review agent using Pi and Litellm AI to automate inline reviews, cache management, and team collaboration on GitHub or Gitea platforms.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Two-layer verifier</strong> suppresses hallucinated findings — rule-based line/file checks plus LLM re-confirmation. Demoted items appear in a collapsible section.</li>
<li><strong>Regex grep tool</strong> — the <code>walkGrep</code> matcher now accepts regex patterns by default.</li>
<li><strong>Cross-model fallback</strong> — configure a comma-separated fallback model list (<code>PI_REVIEW_FALLBACK_MODELS</code>) so the agent retries on another model when the primary fails.</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>Two-layer verifier to suppress hallucinated findings (#21)</li>
<li>Regex support in grep tool</li>
<li>Cross-model fallback support (#29)</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><code>parseDiffPath</code> handles file paths containing spaces (#25)</li>
<li><code>filterDiff</code> truncates at section boundaries and excludes build artifacts by default (#28)</li>
<li><code>walkGrep</code> glob matching normalizes path separators for Windows compatibility</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sun-praise/pi-review-agent/compare/v1.4.0...v1.5.0">https://github.com/sun-praise/pi-review-agent/compare/v1.4.0...v1.5.0</a></p>
]]></content:encoded></item><item><title>setup-hcloud</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/setup-hcloud/</link><pubDate>Thu, 16 Jul 2026 14:43:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/setup-hcloud/</guid><description>Version updated for https://github.com/vbem/setup-hcloud to version v1.0.6.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up Huawei Cloud KooCLI (Huawei CLI) on your runner, supporting Linux, macOS, and Windows. It supports downloading the tool from internal mirrors if needed, and can automatically check its version and accept the privacy statement during installation. The action provides outputs for the download URL, binary path, and version detected after setup.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vbem/setup-hcloud">https://github.com/vbem/setup-hcloud</a></strong> to version <strong>v1.0.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-hcloud">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up Huawei Cloud KooCLI (Huawei CLI) on your runner, supporting Linux, macOS, and Windows. It supports downloading the tool from internal mirrors if needed, and can automatically check its version and accept the privacy statement during installation. The action provides outputs for the download URL, binary path, and version detected after setup.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vbem/setup-hcloud/compare/v1.0.5...v1.0.6">https://github.com/vbem/setup-hcloud/compare/v1.0.5...v1.0.6</a></p>
]]></content:encoded></item><item><title>warmup.rocks — CDN Cache Warmer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/warmup.rocks-cdn-cache-warmer/</link><pubDate>Thu, 16 Jul 2026 14:42:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/warmup.rocks-cdn-cache-warmer/</guid><description>Version updated for https://github.com/warmup-rocks/warm-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The warmup.rocks CDN Cache Warmer Action automatically triggers a cache warm run on the warmup.rocks service right after a deployment in your GitHub repository. It helps ensure that your CDN cache is hot and ready to serve content to visitors before they arrive, improving performance and user experience. The action uses an encrypted secret for the deploy hook URL and can skip runs if it detects a warm pass in progress or within the cooldown period.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/warmup-rocks/warm-action">https://github.com/warmup-rocks/warm-action</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/warmup-rocks-cdn-cache-warmer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The warmup.rocks CDN Cache Warmer Action automatically triggers a cache warm run on the warmup.rocks service right after a deployment in your GitHub repository. It helps ensure that your CDN cache is hot and ready to serve content to visitors before they arrive, improving performance and user experience. The action uses an encrypted secret for the deploy hook URL and can skip runs if it detects a warm pass in progress or within the cooldown period.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Marketplace-ready: shortened action description (&lt;125 chars). No functional changes.</p>
]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/cowork-harness/</link><pubDate>Thu, 16 Jul 2026 14:41:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, cowork-harness, provides a scriptable, CI-friendly test harness to reproduce the observable runtime contract of Claude Cowork. It allows users to test their skills across many scenarios headless and in CI environments without relying on the locked Desktop app. The action supports different fidelity tiers, including replay mode for free demos, linting functionality with Python3, and live testing modes that require a running agent, token, and runtime environment. The summary highlights its main purpose, how it solves the need to test skills in various contexts, and the key capabilities it offers for developers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, cowork-harness, provides a scriptable, CI-friendly test harness to reproduce the observable runtime contract of Claude Cowork. It allows users to test their skills across many scenarios headless and in CI environments without relying on the locked Desktop app. The action supports different fidelity tiers, including replay mode for free demos, linting functionality with Python3, and live testing modes that require a running agent, token, and runtime environment. The summary highlights its main purpose, how it solves the need to test skills in various contexts, and the key capabilities it offers for developers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Minor: <code>analyze-skill</code> gains interactive-artifact write-back detection (static + an optional <code>--runtime</code>
headless-DOM confirmer), <code>lint</code> gains a container-only-key tier check, and the <code>doctor</code> JSON envelope is
frozen as a covered SPEC §12 surface. All additive.</p>
<h3 id="added">Added</h3>
<ul>
<li><strong><code>analyze-skill</code> now detects interactive-artifact write-backs lost under Cowork.</strong> Alongside the
existing <code>/sessions</code> path scan, it statically analyzes <code>.html/.htm/.js/.mjs/.ts/.jsx/.tsx/.py</code> sources
under the target for a relative <code>fetch</code>/XHR/<code>sendBeacon</code>/<code>&lt;form method=post&gt;</code> write-back that silently
fails under Cowork (the artifact is served from Cowork&rsquo;s own origin, so a relative write-back resolves
non-ok and a page that doesn&rsquo;t check <code>resp.ok</code> shows a false &ldquo;Saved&rdquo;). Findings: <code>artifact-write-back-lost</code>
(error — gates under <code>--strict</code>), <code>artifact-write-back-suspect</code> (advisory), and a separate top-level
<code>analysisFailures</code> <strong>could-not-verify</strong> channel (a candidate that couldn&rsquo;t be parsed/analyzed) that
always exits <code>3</code>, <code>--strict</code>-independent. A guard that isn&rsquo;t statically provable-truthy is <code>suspect</code>,
never silently clean; the blanket <code>analyze-skill: ignore</code> marker does not silence artifact rules.
Each <code>SkillFinding</code> now carries a <code>severity</code> (<code>error|advisory</code>); <code>--strict</code> gates on any error finding.</li>
<li><strong><code>analyze-skill --runtime</code></strong> — an optional headless-DOM confirmation that drives a materialized <code>.html</code>
artifact in jsdom (stubbed network + synthetic user actions, run twice) to <em>observe</em> whether a relative
write-back fires and is lost. Enrichment only (never changes the exit code); trusted-source scope. <code>jsdom</code>
is an optional, dynamically-imported dependency — absent it reports &ldquo;run <code>npm i jsdom</code> to enable&rdquo;.</li>
<li><strong><code>schema/doctor.json</code></strong> — the <code>doctor --output-format json</code> envelope is now a covered SPEC §12 surface
(<code>oneOf</code> the completed-probe shape and the shared error envelope for every category). <code>doctor</code>&rsquo;s normal
JSON output is standardized through the shared envelope frame.</li>
<li><strong><code>lint</code> flags container-only assertion keys off-container</strong> — <code>no_scratchpad_leak</code>/<code>present_files_called</code>
on <code>fidelity: protocol|microvm|hostloop</code> is an ERROR, on <code>fidelity: cowork</code> a WARN, clean on <code>container</code>.</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>release: 1.1.0 — analyze-skill artifact write-back detection, lint tier check, doctor SPEC §12 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/50">https://github.com/yaniv-golan/cowork-harness/pull/50</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.1.0">https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.1.0</a></p>
]]></content:encoded></item><item><title>Kover Report Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/kover-report-action/</link><pubDate>Thu, 16 Jul 2026 14:39:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/kover-report-action/</guid><description>Version updated for https://github.com/yshrsmz/kover-report-action to version v3.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of generating and reporting code coverage from Kover XML reports in Kotlin/Android projects. It supports multi-module support with flexible discovery methods (command-based or glob pattern) and configurable thresholds for different module types and names. The action also provides options to include coverage history and trends in PR comments, making it useful for tracking code coverage improvements over time.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yshrsmz/kover-report-action">https://github.com/yshrsmz/kover-report-action</a></strong> to version <strong>v3.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kover-report-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of generating and reporting code coverage from Kover XML reports in Kotlin/Android projects. It supports multi-module support with flexible discovery methods (command-based or glob pattern) and configurable thresholds for different module types and names. The action also provides options to include coverage history and trends in PR comments, making it useful for tracking code coverage improvements over time.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>v3.0.0: PR #138 - chore(deps): update actions/checkout action to v7</p>
]]></content:encoded></item><item><title>AI Harness Doctor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/ai-harness-doctor/</link><pubDate>Thu, 16 Jul 2026 06:40:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/ai-harness-doctor/</guid><description>Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v1.9.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Harness Doctor is a GitHub Action that automates the consolidation of scattered agent configurations into a single canonical file (AGENTS.md) to prevent drift in repository settings such as tools, paths, and package managers. It helps manage agent configurations by providing a full checkup including inventory, conflict evidence, security audit, missing infrastructure gaps, and tech-stack snapshot. The action avoids mutating files or directories that are linked through symlinks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NieZhuZhu/ai-harness-doctor">https://github.com/NieZhuZhu/ai-harness-doctor</a></strong> to version <strong>v1.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-harness-doctor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AI Harness Doctor is a GitHub Action that automates the consolidation of scattered agent configurations into a single canonical file (<code>AGENTS.md</code>) to prevent drift in repository settings such as tools, paths, and package managers. It helps manage agent configurations by providing a full checkup including inventory, conflict evidence, security audit, missing infrastructure gaps, and tech-stack snapshot. The action avoids mutating files or directories that are linked through symlinks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs(plans): define post-v1.8.1 premium upgrades by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/183">https://github.com/NieZhuZhu/ai-harness-doctor/pull/183</a></li>
<li>fix(eval): derive health from validated results by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/184">https://github.com/NieZhuZhu/ai-harness-doctor/pull/184</a></li>
<li>test(action): cover command and version success paths by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/185">https://github.com/NieZhuZhu/ai-harness-doctor/pull/185</a></li>
<li>feat(scan): model structured rule applicability by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/186">https://github.com/NieZhuZhu/ai-harness-doctor/pull/186</a></li>
<li>docs(agents): record post-v1.8.1 maintenance invariants by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/187">https://github.com/NieZhuZhu/ai-harness-doctor/pull/187</a></li>
<li>chore(release): v1.9.0 by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/188">https://github.com/NieZhuZhu/ai-harness-doctor/pull/188</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NieZhuZhu/ai-harness-doctor/compare/v1.8.1...v1.9.0">https://github.com/NieZhuZhu/ai-harness-doctor/compare/v1.8.1...v1.9.0</a></p>
]]></content:encoded></item><item><title>XAI Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/xai-review/</link><pubDate>Thu, 16 Jul 2026 06:38:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/xai-review/</guid><description>Version updated for https://github.com/Nikita-Filonov/ai-review to version v0.71.0.
This action is used across all versions by 8 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Review is a code review tool that leverages AI to automate code reviews, improving efficiency and reducing noise in pull requests. It supports multiple LLM providers, integrates with popular version control systems, allows customizable prompts, and includes agent mode for deeper context exploration. The tool runs automatically within CI/CD pipelines, posting inline comments, summary reviews, and AI-generated replies directly into merge requests.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Nikita-Filonov/ai-review">https://github.com/Nikita-Filonov/ai-review</a></strong> to version <strong>v0.71.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/xai-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>AI Review</strong> is a code review tool that leverages AI to automate code reviews, improving efficiency and reducing noise in pull requests. It supports multiple LLM providers, integrates with popular version control systems, allows customizable prompts, and includes agent mode for deeper context exploration. The tool runs automatically within CI/CD pipelines, posting inline comments, summary reviews, and AI-generated replies directly into merge requests.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>claude (52a2012)</li>
<li>fixes (82d9947)</li>
<li>Merge pull request #111 from dansan/feature/gitlab-batched-inline-comments (28f8a63)</li>
<li>docs: document the GitLab-only batch_comments setting (fdb169c)</li>
<li>feat(review): finalize the review pipeline via ReviewService context manager (676aaba)</li>
<li>feat(gitlab): batch review comments as draft notes behind vcs.batch_comments (87aa23d)</li>
<li>feat(gitlab): add Draft Notes API support to the GitLab HTTP client (790afba)</li>
<li>azure openai (978e700)</li>
<li>Merge pull request #99 from crow-ua/add-support-for-gpt-5-max-complete-tokens (e28ac59)</li>
<li>renamed files (61d7b2b)</li>
</ul>
]]></content:encoded></item><item><title>Run AER Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/run-aer-tests/</link><pubDate>Thu, 16 Jul 2026 06:37:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/run-aer-tests/</guid><description>Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.16.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action runs Apex unit tests locally using the aer tool, allowing developers to execute and debug Apex code without needing an org. It supports various features like local SObject management, trigger execution, governor limits enforcement, and testing with coverage reports. The action is particularly useful for CI/CD pipelines where developers can quickly validate their code changes before deploying.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/octoberswimmer/aer-dist">https://github.com/octoberswimmer/aer-dist</a></strong> to version <strong>v1.2.16</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-aer-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action runs Apex unit tests locally using the <code>aer</code> tool, allowing developers to execute and debug Apex code without needing an org. It supports various features like local SObject management, trigger execution, governor limits enforcement, and testing with coverage reports. The action is particularly useful for CI/CD pipelines where developers can quickly validate their code changes before deploying.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Version v1.2.16</p>
<ul>
<li>
<p>Resolve Field Access On Variable Named Like A Type</p>
</li>
<li>
<p>Return Boolean From System.FlexQueue Move Methods</p>
</li>
<li>
<p>Support Full Java Regex Classes In String.replaceAll and replaceFirst</p>
</li>
<li>
<p>Purge Soft-deleted Restrict-lookup Children When Parent Is Deleted</p>
</li>
<li>
<p>Resolve Return Type Of System-qualified Builtin Static Methods</p>
</li>
<li>
<p>Flatten Multi-variable Declarations In Property Accessor Bodies</p>
</li>
<li>
<p>Compare String Operands Case-insensitively In Relational Operators</p>
</li>
<li>
<p>Fix Custom Object Share Record DML</p>
</li>
<li>
<p>Escape Backslashes In String.escapeSingleQuotes</p>
</li>
</ul>
]]></content:encoded></item><item><title>Initialize GitHub Job</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/initialize-github-job/</link><pubDate>Thu, 16 Jul 2026 06:36:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/initialize-github-job/</guid><description>Version updated for https://github.com/PandasWhoCode/initialize-github-job to version v1.3.0.
This action is used across all versions by 17 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Initialize GitHub Job composite action automates the setup steps for various programming languages and tools, including security hardening, repository checkout options, multi-language support, build tool setups, and dependency caching. It helps streamline the process of starting a job in GitHub Actions by consolidating common setup tasks. The action supports Node.js, Java, Python, Go, Rust, and Swift, providing flexible configurations for each language and build tool.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/PandasWhoCode/initialize-github-job">https://github.com/PandasWhoCode/initialize-github-job</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>17</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/initialize-github-job">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Initialize GitHub Job composite action automates the setup steps for various programming languages and tools, including security hardening, repository checkout options, multi-language support, build tool setups, and dependency caching. It helps streamline the process of starting a job in GitHub Actions by consolidating common setup tasks. The action supports Node.js, Java, Python, Go, Rust, and Swift, providing flexible configurations for each language and build tool.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): Bump dtolnay/rust-toolchain from 67ef31d5b988238dd797d409d6f9574278e20537 to fa04a1451ff1842e2626ccb99004d0195b455a88 by @dependabot[bot] in <a href="https://github.com/PandasWhoCode/initialize-github-job/pull/85">https://github.com/PandasWhoCode/initialize-github-job/pull/85</a></li>
<li>feat: add setup-deterministic-zip with pinned, checksum-verified install by @nathanklick in <a href="https://github.com/PandasWhoCode/initialize-github-job/pull/92">https://github.com/PandasWhoCode/initialize-github-job/pull/92</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/PandasWhoCode/initialize-github-job/compare/v1.2.2...v1.3.0">https://github.com/PandasWhoCode/initialize-github-job/compare/v1.2.2...v1.3.0</a></p>
]]></content:encoded></item><item><title>Prowler Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/prowler-security-scan/</link><pubDate>Thu, 16 Jul 2026 06:35:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/prowler-security-scan/</guid><description>Version updated for https://github.com/prowler-cloud/prowler to version 5.34.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Prowler automates security and compliance tasks by providing a comprehensive suite of cloud security checks and integrations. It helps organizations identify potential risks, implement automated remediations, and maintain compliance with regulatory standards across various cloud environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/prowler-cloud/prowler">https://github.com/prowler-cloud/prowler</a></strong> to version <strong>5.34.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/prowler-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Prowler</strong> automates security and compliance tasks by providing a comprehensive suite of cloud security checks and integrations. It helps organizations identify potential risks, implement automated remediations, and maintain compliance with regulatory standards across various cloud environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="-new-features-to-highlight-in-this-version">✨ New features to highlight in this version</h1>
<p>Enjoy them all now for free at <a href="https://cloud.prowler.com">https://cloud.prowler.com</a></p>
<h2 id="-new-product-names">🏷️ New product names</h2>
<p>The Prowler family has grown, and the names now say what each product is. Same products, clearer names:</p>
<p><strong>Prowler products:</strong></p>
<ul>
<li><strong>Prowler Cloud</strong> — the managed cloud security platform operated by the Prowler team.</li>
<li><strong>Prowler Private Cloud</strong> (formerly <em>Prowler Enterprise</em>) — the self-hosted deployment of Prowler Cloud in your own environment.</li>
<li><strong>Prowler Hub</strong> — the free public library of versioned checks, cloud service artifacts, and compliance frameworks.</li>
<li><strong>Prowler Lighthouse AI</strong> — The Agentic Cloud Defender in Prowler Cloud and Prowler Private Cloud.</li>
<li><strong>Prowler MCP</strong> — the MCP server that connects AI assistants and agents to Prowler, including the IDE plugins.</li>
</ul>
<p><strong>Open source projects:</strong></p>
<ul>
<li><strong>Prowler CLI</strong> — the command-line scanner for all supported providers.</li>
<li><strong>Prowler Local Server</strong> (formerly <em>Prowler App</em>) — the self-hosted web application and API to run scans, visualize findings, and manage providers.</li>
<li><strong>Prowler Local Dashboard</strong> — the web dashboard for visualizing Prowler CLI scan results, distributed with the CLI.</li>
<li><strong>Prowler SDK</strong> — the Python library behind Prowler CLI and Prowler Local Server.</li>
</ul>
<p>See the full family in the <a href="https://docs.prowler.com/getting-started/products">Prowler products documentation</a>.</p>
<h2 id="-cross-provider-compliance">🧭 Cross-Provider Compliance</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Private Cloud</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>One framework, every cloud, a single answer. The new <strong>Cross-provider</strong> tab in Compliance takes the most recent completed scan of every compatible provider and rolls them up into a single compliance posture per framework, with a per-provider breakdown and a combined executive PDF report. Requirement status follows strict precedence (FAIL &gt; PASS &gt; MANUAL), so one failing provider is enough to flag a requirement across your whole estate.</p>
<img width="2116" height="1008" alt="Screenshot 2026-07-15 at 17 18 25" src="https://github.com/user-attachments/assets/c2fbe4a9-5b23-41e2-a1a8-fd75fbbb081c" />
<p>Three universal frameworks support it today:</p>
<ul>
<li><strong>CIS Controls 8.1</strong> — AWS, Azure, Google Cloud, Microsoft 365, Kubernetes, GitHub, Google Workspace, Okta, Oracle Cloud, Alibaba Cloud, Cloudflare, MongoDB Atlas, OpenStack, and Vercel.</li>
<li><strong>CSA CCM 4.0</strong> — AWS, Azure, Google Cloud, Alibaba Cloud, and Oracle Cloud.</li>
<li><strong>DORA 2022/2554</strong> — AWS, Azure, Google Cloud, Alibaba Cloud, and Cloudflare.</li>
</ul>
<p>Filter by provider type, account, or provider group, drill into each framework&rsquo;s requirements, and export the combined PDF.</p>
<img width="2113" height="1014" alt="Screenshot 2026-07-15 at 17 18 32" src="https://github.com/user-attachments/assets/ccf0d474-2c54-43bc-81a4-d651df294889" />
<p>Read more in our <a href="https://docs.prowler.com/user-guide/compliance/tutorials/cross-provider-compliance">Cross-Provider Compliance documentation</a>.</p>
<h2 id="-new-provider--e2e-networks">🏢 New Provider — E2E Networks</h2>
<p>Prowler now scans <a href="https://www.e2enetworks.com/"><strong>E2E Networks</strong></a>, with <strong>27 checks</strong> spanning compute nodes, networking, security groups, load balancers, block and file storage, and managed databases. Thanks to @deepak7093 for their 1st provider in Prowler!</p>
<p>Available in the Prowler CLI:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>export E2E_NETWORKS_API_KEY<span style="color:#f92672">=</span><span style="color:#e6db74">&#34;your-api-key&#34;</span>
</span></span><span style="display:flex;"><span>export E2E_NETWORKS_AUTH_TOKEN<span style="color:#f92672">=</span><span style="color:#e6db74">&#34;your-auth-token&#34;</span>
</span></span><span style="display:flex;"><span>export E2E_NETWORKS_PROJECT_ID<span style="color:#f92672">=</span><span style="color:#e6db74">&#34;your-project-id&#34;</span>
</span></span><span style="display:flex;"><span>prowler e2enetworks
</span></span></code></pre></div><p>Read more in our <a href="https://docs.prowler.com/user-guide/providers/e2enetworks/getting-started-e2enetworks">E2E Networks documentation</a>.</p>
<p>Explore all E2E Networks checks at <a href="https://hub.prowler.com/check?provider=e2enetworks">Prowler Hub</a>.</p>
<h2 id="-security">🔐 Security</h2>
<p>User role relationship updates in the API are now limited to the active tenant, preserving the role assignments the same user holds in other tenants.</p>
<h2 id="-checks">🔍 Checks</h2>
<h3 id="aws">AWS</h3>
<ul>
<li><code>ec2_ami_account_block_public_access</code> — verifies AMI block public access is enabled at the account level in each Region, so AMIs cannot be shared publicly. Thanks to @goutham-hari!</li>
<li><code>datapipeline_pipeline_no_secrets_in_definition</code> — scans Data Pipeline object fields, parameter objects, and parameter values for hardcoded secrets with Kingfisher. Thanks to @YinkaMetrics!</li>
<li><code>elbv2_listener_pqc_tls_enabled</code> — verifies ELBv2 HTTPS/TLS listeners use post-quantum TLS security policies with TLS 1.2 or higher, helping reduce harvest-now-decrypt-later exposure.</li>
<li><code>amplify_app_no_secrets_in_environment</code> — scans Amplify app and branch environment variables and build settings (buildSpec) for hardcoded secrets with Kingfisher. Thanks to @Deep070203!</li>
</ul>
<p>Read more in our <a href="https://docs.prowler.com/user-guide/providers/aws/getting-started-aws">AWS documentation</a>.</p>
<p>Explore all AWS checks at <a href="https://hub.prowler.com/check?provider=aws">Prowler Hub</a>.</p>
<h3 id="azure">Azure</h3>
<ul>
<li><code>app_function_ensure_http_is_redirected_to_https</code> — verifies that Function Apps enforce HTTPS-only traffic. Thanks to @amandalal007!</li>
</ul>
<p>Read more in our <a href="https://docs.prowler.com/user-guide/providers/azure/getting-started-azure">Azure documentation</a>.</p>
<p>Explore all Azure checks at <a href="https://hub.prowler.com/check?provider=azure">Prowler Hub</a>.</p>
<h3 id="kubernetes">Kubernetes</h3>
<ul>
<li><code>core_minimize_hostpath_volume_mounts</code> — detects Pods that use <code>hostPath</code> volumes. Thanks to @0xTaoZ!</li>
<li><code>core_readonly_root_filesystem_enabled</code> — verifies that every container in each Pod explicitly sets <code>readOnlyRootFilesystem: true</code> in its security context. Thanks to @Weedle02!</li>
</ul>
<p>Read more in our <a href="https://docs.prowler.com/user-guide/providers/kubernetes/getting-started-k8s">Kubernetes documentation</a>.</p>
<p>Explore all Kubernetes checks at <a href="https://hub.prowler.com/check?provider=kubernetes">Prowler Hub</a>.</p>
<h3 id="stackit">STACKIT</h3>
<ul>
<li><code>iaas_server_public_ip_attached</code> — flags IaaS servers that have a public IP address directly attached to a network interface. Thanks to @johannes-engler-mw!</li>
</ul>
<p>Read more in our <a href="https://docs.prowler.com/user-guide/providers/stackit/getting-started-stackit">STACKIT documentation</a>.</p>
<p>Explore all STACKIT checks at <a href="https://hub.prowler.com/check?provider=stackit">Prowler Hub</a>.</p>
<h2 id="-external-contributors">🙌 External Contributors</h2>
<p>Thank you to our community contributors for this release!</p>
<ul>
<li>@deepak7093 — New E2E Networks provider: 27 checks across compute nodes, networking, security groups, load balancers, block/file storage, and managed databases <a href="https://github.com/prowler-cloud/prowler/pull/11654">(#11654)</a></li>
<li>@goutham-hari — AWS <code>ec2_ami_account_block_public_access</code> check <a href="https://github.com/prowler-cloud/prowler/pull/11828">(#11828)</a></li>
<li>@YinkaMetrics — AWS <code>datapipeline_pipeline_no_secrets_in_definition</code> check <a href="https://github.com/prowler-cloud/prowler/pull/11821">(#11821)</a></li>
<li>@amandalal007 — Azure <code>app_function_ensure_http_is_redirected_to_https</code> check <a href="https://github.com/prowler-cloud/prowler/pull/11929">(#11929)</a></li>
<li>@0xTaoZ — Kubernetes <code>core_minimize_hostpath_volume_mounts</code> check <a href="https://github.com/prowler-cloud/prowler/pull/11837">(#11837)</a></li>
<li>@Weedle02 — Kubernetes <code>core_readonly_root_filesystem_enabled</code> check <a href="https://github.com/prowler-cloud/prowler/pull/11835">(#11835)</a></li>
<li>@johannes-engler-mw — STACKIT <code>iaas_server_public_ip_attached</code> check <a href="https://github.com/prowler-cloud/prowler/pull/11549">(#11549)</a></li>
<li>@janderik — Trailing newlines added to compliance, region, and fixture data files for POSIX compliance <a href="https://github.com/prowler-cloud/prowler/pull/11765">(#11765)</a></li>
<li>@Deep070203 — AWS <code>amplify_app_no_secrets_in_environment</code> check <a href="https://github.com/prowler-cloud/prowler/pull/11825">(#11825)</a></li>
</ul>
<hr>
<h2 id="ui">UI</h2>
<h3 id="-added">🚀 Added</h3>
<ul>
<li>Dynamically registered providers are now listed, filtered, and rendered across the UI, using a generic icon and humanized label when no bespoke assets exist, a &ldquo;Custom&rdquo; badge, and read-only handling for non-configurable providers <a href="https://github.com/prowler-cloud/prowler/pull/11869">(#11869)</a></li>
<li>Prowler Local Server branding and contextual Prowler Cloud upgrade prompts across navigation, scans, providers, compliance, findings, alerts, and Lighthouse AI <a href="https://github.com/prowler-cloud/prowler/pull/11982">(#11982)</a></li>
</ul>
<h3 id="-changed">🔄 Changed</h3>
<ul>
<li>UI components migrated from HeroUI to shared shadcn primitives <a href="https://github.com/prowler-cloud/prowler/pull/11532">(#11532)</a></li>
<li>UI integration enable flags renamed to past tense — <code>UI_SENTRY_ENABLE</code> → <code>UI_SENTRY_ENABLED</code>, <code>UI_GOOGLE_TAG_MANAGER_ENABLE</code> → <code>UI_GOOGLE_TAG_MANAGER_ENABLED</code>, <code>UI_POSTHOG_ENABLE</code> → <code>UI_POSTHOG_ENABLED</code>; deployments that set the former names must update them <a href="https://github.com/prowler-cloud/prowler/pull/11917">(#11917)</a></li>
</ul>
<h3 id="-fixed">🐞 Fixed</h3>
<ul>
<li>Metronome billing failing to start when PostHog was enabled, caused by a stale reference to the renamed UI_POSTHOG_ENABLED flag <a href="https://github.com/prowler-cloud/prowler/pull/11938">(#11938)</a></li>
<li>Lighthouse AI overview entry now starts a new remediation conversation, and returning to Overview restores app navigation mode <a href="https://github.com/prowler-cloud/prowler/pull/11955">(#11955)</a></li>
</ul>
<h2 id="api">API</h2>
<h3 id="-fixed-1">🐞 Fixed</h3>
<ul>
<li><code>rls_transaction</code> now falls back directly to the primary DB for connection-level mid-query read replica failures via <code>execute_wrapper</code>, reducing non-streaming read crashes during replica recovery <a href="https://github.com/prowler-cloud/prowler/pull/10379">(#10379)</a></li>
<li>RBAC permission gates now combine permissions from every role assigned to a user in the active tenant <a href="https://github.com/prowler-cloud/prowler/pull/11979">(#11979)</a></li>
<li><code>attack-paths-cleanup-stale-scans</code> now retries worker pings and checks recent scan activity before failing scans and removing temporary databases <a href="https://github.com/prowler-cloud/prowler/pull/11986">(#11986)</a></li>
</ul>
<h3 id="-security-1">🔐 Security</h3>
<ul>
<li>User role relationship updates are limited to the active tenant to preserve role assignments in other tenants <a href="https://github.com/prowler-cloud/prowler/pull/11903">(#11903)</a></li>
<li>Container image removes the unused Debian <code>libxml2</code> runtime package and scopes the <code>CVE-2026-13221</code> Trivy exception to unaffected Perl 5.36 packages <a href="https://github.com/prowler-cloud/prowler/pull/11991">(#11991)</a></li>
</ul>
<h2 id="sdk">SDK</h2>
<h3 id="-added-1">🚀 Added</h3>
<ul>
<li><code>elbv2_listener_pqc_tls_enabled</code> check for AWS provider, verifying that ELBv2 listeners use post-quantum TLS policies <a href="https://github.com/prowler-cloud/prowler/pull/11254">(#11254)</a></li>
<li><code>iaas_server_public_ip_attached</code> check for STACKIT provider, flagging IaaS servers that have a public IP address directly attached to a network interface <a href="https://github.com/prowler-cloud/prowler/pull/11549">(#11549)</a></li>
<li>Changelog fragment workflow for SDK, API, UI, and MCP Server releases, including PR attribution, fragment validation, release compilation, and preserved section ordering <a href="https://github.com/prowler-cloud/prowler/pull/11572">(#11572)</a></li>
<li>E2E Networks provider with 27 checks across compute nodes, networking, security groups, load balancers, block/file storage, and managed databases <a href="https://github.com/prowler-cloud/prowler/pull/11654">(#11654)</a></li>
<li><code>datapipeline_pipeline_no_secrets_in_definition</code> check for AWS provider, scanning Data Pipeline object fields, parameter objects, and parameter values for hardcoded secrets with Kingfisher <a href="https://github.com/prowler-cloud/prowler/pull/11821">(#11821)</a></li>
<li><code>amplify_app_no_secrets_in_environment</code> check for AWS provider, scanning Amplify app and branch environment variables and build settings for hardcoded secrets <a href="https://github.com/prowler-cloud/prowler/pull/11825">(#11825)</a></li>
<li><code>ec2_ami_account_block_public_access</code> check for AWS provider, verifying AMI block public access is enabled at the account level in each Region so AMIs cannot be shared publicly <a href="https://github.com/prowler-cloud/prowler/pull/11828">(#11828)</a></li>
<li><code>core_readonly_root_filesystem_enabled</code> check for Kubernetes provider, verifying that every container in each Pod explicitly sets <code>readOnlyRootFilesystem: true</code> in its security context <a href="https://github.com/prowler-cloud/prowler/pull/11835">(#11835)</a></li>
<li><code>core_minimize_hostpath_volume_mounts</code> check for Kubernetes provider, detecting Pods that use <code>hostPath</code> volumes <a href="https://github.com/prowler-cloud/prowler/pull/11837">(#11837)</a></li>
<li><code>app_function_ensure_http_is_redirected_to_https</code> check for Azure provider, verifying that Function Apps enforce HTTPS-only traffic <a href="https://github.com/prowler-cloud/prowler/pull/11929">(#11929)</a></li>
</ul>
<h3 id="-changed-1">🔄 Changed</h3>
<ul>
<li>Missing trailing newlines to compliance, region, and fixture data files for POSIX compliance <a href="https://github.com/prowler-cloud/prowler/pull/11765">(#11765)</a></li>
<li>Oracle Cloud API key authentication now uses an internal bootstrap region when no explicit scan region filter is provided <a href="https://github.com/prowler-cloud/prowler/pull/11853">(#11853)</a></li>
<li>Redesign the local dashboard sidebar and informational pages <a href="https://github.com/prowler-cloud/prowler/pull/11972">(#11972)</a></li>
</ul>
]]></content:encoded></item><item><title>Jira Xport</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/jira-xport/</link><pubDate>Thu, 16 Jul 2026 06:34:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/jira-xport/</guid><description>Version updated for https://github.com/PunteriaCero/Jira-Xport to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Jira-xport GitHub Action exports all tickets from a specified Jira filter to a CSV file. It handles the 3-level hierarchy of Epics → Issues → Sub-tasks and automatically converts time-tracking fields to hours. The tool supports exporting with subtasks and restricting them by labels, and outputs are kept for one day before deletion. Users can run the action through GitHub Actions workflows or locally using Docker.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/PunteriaCero/Jira-Xport">https://github.com/PunteriaCero/Jira-Xport</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jira-xport">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Jira-xport GitHub Action exports all tickets from a specified Jira filter to a CSV file. It handles the 3-level hierarchy of Epics → Issues → Sub-tasks and automatically converts time-tracking fields to hours. The tool supports exporting with subtasks and restricting them by labels, and outputs are kept for one day before deletion. Users can run the action through GitHub Actions workflows or locally using Docker.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/PunteriaCero/Jira-Xport/commits/v1">https://github.com/PunteriaCero/Jira-Xport/commits/v1</a></p>
]]></content:encoded></item><item><title>PR Explainer AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/pr-explainer-ai/</link><pubDate>Thu, 16 Jul 2026 06:33:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/pr-explainer-ai/</guid><description>Version updated for https://github.com/rafaeltorresng/pr-explainer-action to version v1.0.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary PR Explainer AI is a GitHub Action that automates the process of creating interactive HTML artifacts for pull requests. It turns diffs into clear learning experiences by providing context, technical intuition, visual diagrams, code walkthroughs, and quizzes. The action helps teams align on changes and provides durable, visual understanding that can be revisited later.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rafaeltorresng/pr-explainer-action">https://github.com/rafaeltorresng/pr-explainer-action</a></strong> to version <strong>v1.0.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pr-explainer-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>PR Explainer AI is a GitHub Action that automates the process of creating interactive HTML artifacts for pull requests. It turns diffs into clear learning experiences by providing context, technical intuition, visual diagrams, code walkthroughs, and quizzes. The action helps teams align on changes and provides durable, visual understanding that can be revisited later.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new">What&rsquo;s new</h2>
<ul>
<li><strong>README preview</strong>: artifact sidebar screenshot at <code>public/artifact-preview.png</code></li>
<li><strong>Docs accuracy</strong>: clarifies that the HTML inlines layout assets but loads Tailwind CSS and fonts from CDNs</li>
</ul>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">rafaeltorresng/pr-explainer-action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">openrouter_api_key</span>: <span style="color:#ae81ff">${{ secrets.OPENROUTER_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">language</span>: <span style="color:#ae81ff">en</span>
</span></span></code></pre></div><p><code>@v1</code> tracks this release.</p>
]]></content:encoded></item><item><title>raviqqe/muffy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/raviqqe/muffy/</link><pubDate>Thu, 16 Jul 2026 06:32:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/raviqqe/muffy/</guid><description>Version updated for https://github.com/raviqqe/muffy to version v0.3.13.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the validation of static websites using Muffet, a tool for checking website content for issues like broken links and accessibility problems. It provides a straightforward way to ensure that a website is functional and accessible before deployment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/raviqqe/muffy">https://github.com/raviqqe/muffy</a></strong> to version <strong>v0.3.13</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/raviqqe-muffy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the validation of static websites using Muffet, a tool for checking website content for issues like broken links and accessibility problems. It provides a straightforward way to ensure that a website is functional and accessible before deployment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>90a725e99b5b6acb40075ea88dc2075e6433a19c Bump version (#1070)</li>
<li>3c52a1bff5d15f60e4c49baea503b0e6695907fe Action cache (#1069)</li>
<li>4cfec2107c14e6b0fad5fd3dfe6bd6d87e10d43e Bump rust-toolchain from 1.96.1 to 1.97.0 (#1068)</li>
<li>9a715e0cf4b3dae19a8f088bc67c91aedba58b90 Bump syn from 2.0.118 to 2.0.119 (#1065)</li>
<li>651439cf6898378ff0076092864d39187e6817a6 Bump @biomejs/biome from 2.5.3 to 2.5.4 in /doc (#1067)</li>
<li>db972e1cae373767d6cf60d576fb9a2d5a15eead Cache Muffy cache (#1064)</li>
<li>71d6991bb90da70dedf1106bc6fa145533aa9577 Bump scc from 3.8.4 to 3.8.5 (#1061)</li>
<li>e302a5120096916320880fb828b1ba66064f37ee Bump toml from 1.1.2+spec-1.1.0 to 1.1.3+spec-1.1.0 (#1059)</li>
<li>7a8d1b5eb8ef58346366dc14f0106fc0786dbc9b Bump astro from 7.0.8 to 7.0.9 in /doc in the astro group across 1 directory (#1060)</li>
<li>aa24ab7d2771b5b1789e30d0e9bcd6df8b1a64b0 Bump actions/setup-node from 6.4.0 to 7.0.0 in /.github/actions/setup (#1062)</li>
<li>5997ba912837d209d91abe38901e072826ff5833 Fix rate limited sites (#1063)</li>
<li>034b4ebb131ba78b54f01f74e339cecd11b96531 Bump astro from 7.0.7 to 7.0.8 in /doc in the astro group (#1058)</li>
<li>c438eb87140bf6053b93b2f812bb5cabb445c9a3 Bump @types/node from 26.1.0 to 26.1.1 in /doc (#1051)</li>
<li>dc2859252a43a1dbec6682af60d5a5c6090a066c Bump @biomejs/biome from 2.5.2 to 2.5.3 in /doc (#1052)</li>
<li>05321e2f436d182ac955584679206427a88c58eb Bump homebrew/actions/setup-homebrew from 50b8c2ab4a835c38897ed2c56c293b07167c0b59 to 18fcb8e3e06b4247c676c506750dc95ea7226479 (#1057)</li>
<li>c4df0b1e9b1369365fe90312824f225742cce4ab Bump astro from 7.0.6 to 7.0.7 in /doc in the astro group across 1 directory (#1050)</li>
<li>6cc3a7b0836e0319dc8f4d4fd4fe67fa493fc2e8 Bump rust from 1.96.1-alpine to 1.97.0-alpine (#1054)</li>
<li>315de4e4121001ab710ce718b077286c430dd973 Bump lycheeverse/lychee-action from 2.8.0 to 2.9.0 (#1055)</li>
<li>84d4e975ebe0820740fdadffc75e7cc13ec2212f Bump regex from 1.12.4 to 1.13.0 (#1053)</li>
<li>cab7a154d0b031923ea95eb2b0a593065ecd26f2 Bump scc from 3.8.3 to 3.8.4 (#1049)</li>
<li>f9d7c431e378766e57e10bc1e4b110bdffa130e0 Bump fjall from 3.1.5 to 3.1.6 (#1048)</li>
<li>8706a8263bfd2d46c1cb5c8cb5fde6ad2ae32fa3 Bump @astrojs/starlight from 0.41.2 to 0.41.3 in /doc in the astro group across 1 directory (#1046)</li>
<li>fb8f426b8c87a724cb5bc1103f2b21d55bd97e09 Bump docker/login-action from 4.3.0 to 4.4.0 (#1047)</li>
<li>2c5ef983253726b1498494f71afe3c6e5c25558d Bump docker/login-action from 4.2.0 to 4.3.0 (#1042)</li>
<li>368fece882536f49196ba2198be493468a4b06c8 Bump docker/setup-buildx-action from 4.1.0 to 4.2.0 (#1043)</li>
<li>9e775cd2a808b2e3241d64c7e16ff60581f9b414 Bump docker/metadata-action from 6.1.0 to 6.2.0 (#1044)</li>
<li>156065695bb7c13c5feca63d99e4f56dda4318eb Bump astro from 7.0.5 to 7.0.6 in /doc in the astro group (#1041)</li>
<li>85acbca5d93880a5a08fc30db3d132c1d34985a5 Bump sharp from 0.35.2 to 0.35.3 in /doc (#1033)</li>
<li>66f681534bd96a83c9f3b382783caa5db2f574c6 Bump docker/build-push-action from 7.2.0 to 7.3.0 (#1039)</li>
<li>7f2a740a5e7f4ceefebb63e90daa1010d08a5d20 Bump rust from 1.96.0-alpine to 1.96.1-alpine (#1037)</li>
<li>bd8ed599b1dfcaff625c5d8f2ef11d14e1804376 Bump the astro group across 1 directory with 2 updates (#1035)</li>
<li>64a1ca3a181cbef64dd9b0429b34531ab28b77e7 Increase timeout (#1040)</li>
<li>c1a3f4b0d53876146e5d706e944b548090a14e32 Bump @types/node from 26.0.1 to 26.1.0 in /doc (#1036)</li>
<li>30801c44044e129d3597615d4a26bc4b6d98762c Bump docker/setup-qemu-action from 4.1.0 to 4.2.0 (#1038)</li>
<li>5b9d8ccdb4e8edfb531948407bc4c2f3b8fa8327 Bump @biomejs/biome from 2.5.1 to 2.5.2 in /doc (#1034)</li>
<li>ad3533938632ba466a397a8463b5a123a74cc5e6 Bump the astro group across 1 directory with 2 updates (#1028)</li>
<li>3be068e3d6ae902b72658f130c37a1d2163fe48c Bump es-toolkit from 1.48.1 to 1.49.0 in /doc (#1029)</li>
<li>00e0a9ff8998d9c2020700060935ac77d133f5b8 Bump @types/node from 26.0.0 to 26.0.1 in /doc (#1031)</li>
<li>3ce591d926089b135bab4063756d8fedabf2d944 Bump @biomejs/biome from 2.4.16 to 2.5.1 in /doc (#1030)</li>
<li>f36fef8317b268d37dbc967a121ccacdf856f8e4 Bump env_logger from 0.11.10 to 0.11.11 (#1027)</li>
<li>6eb3cc90119b94c11cd514e7f0044cc91d0c334f Bump log from 0.4.32 to 0.4.33 (#1021)</li>
<li>a9690090de6664bf7c085411b1e539d2a757b007 Ignore 404 on web test (#1025)</li>
<li>55b67e18ba5d8cc8eab30ec09c4f674c71d697d4 Bump quote from 1.0.45 to 1.0.46 (#1024)</li>
<li>d146c48670ea72ec42cb9c5097adf16421e4b7bf Bump @raviqqe/biome-config from 2.0.26 to 2.0.27 in /doc (#1020)</li>
<li>baff18af1df86c6c4b545300df2344e48e05a90f Bump sharp from 0.35.0 to 0.35.2 in /doc (#1018)</li>
<li>b3af2903fffe58add2d1cdeeecda0a040e5a80ff Bump es-toolkit from 1.47.1 to 1.48.1 in /doc (#1022)</li>
<li>8a4870430dfbc4e23f8c0a0f57867e9ddfb9cad5 Bump astro from 6.4.7 to 7.0.0 in /doc in the astro group across 1 directory (#1014)</li>
<li>632039c7ab7a8c8bbbdbc92e5ae84d2de288d663 Bump scc from 3.8.1 to 3.8.3 (#1017)</li>
<li>35fa38e3e4247ea5a25734fbf747269257b2bd73 Bump @types/node from 25.9.2 to 26.0.0 in /doc (#1019)</li>
<li>e96b8a0a04c6e2182dde6f9fddf9b0c3a2dfa833 Bump es-toolkit from 1.47.0 to 1.47.1 in /doc (#1006)</li>
<li>dada259575a30c8ea546386508fe0dca9f805a1b Bump scc from 3.7.3 to 3.8.1 (#1015)</li>
<li>38dc7c79b95d0494c3d30910829eaa3a63dff365 Bump actions/checkout from 6.0.3 to 7.0.0 (#1016)</li>
<li>b0173d767551471c457f83e8e422dd32aca77ea4 Bump rust-lang/crates-io-auth-action from 1.0.4 to 1.0.5 (#1013)</li>
<li>960341d40e2643d46ee21f9c7e45254f7739c004 Bump itertools from 0.14.0 to 0.15.0 (#1012)</li>
<li>8630918eae8669dfc719e78e607c8f618401ad8c Bump rust from <code>2ea3db1</code> to <code>f87aa87</code> (#1010)</li>
<li>d37a07760751496d6506fc20d46ea84498aedf61 Bump syn from 2.0.117 to 2.0.118 (#1011)</li>
<li>bd635332fdc8944d59e9b657638a45cda42130e9 Bump astro from 6.4.6 to 6.4.7 in /doc in the astro group (#1007)</li>
<li>75003d07761b916eb3f53778722dde53b1367845 Bump pnpm/action-setup from 6.0.8 to 6.0.9 in /.github/actions/setup (#1009)</li>
<li>1da9397da27ee8e1424abe5b90afca90efc85d5c Bump insta from 1.47.2 to 1.48.0 (#1002)</li>
<li>5cf4d23dd143d5c47e717241d89556454049c6e6 Bump rust from <code>66f48b1</code> to <code>2ea3db1</code> (#1001)</li>
<li>3e05c17660ecc401ad30fe66cb9b5be2be4a5df8 Bump astro from 6.4.5 to 6.4.6 in /doc in the astro group across 1 directory (#998)</li>
<li>a36b0d8d6c74281e404ef70cffc7b1ffc10396b6 Bump scc from 3.7.2 to 3.7.3 (#999)</li>
<li>c9f62d8256be22e23890c685fd8a8d703abd153b Bump sharp from 0.34.5 to 0.35.0 in /doc (#1000)</li>
<li>e333ce9506405b358172caa9a916b87feba1b505 Bump fjall from 3.1.4 to 3.1.5 (#996)</li>
<li>e6cd1b2acb66c5284ffe7f3d0a6ceafdbcf7039a Bump the astro group in /doc with 2 updates (#994)</li>
<li>c29efaadeac688447804bb9c56c920f0eb42e4d5 Bump http from 1.4.1 to 1.4.2 (#993)</li>
<li>0e7313384a4aa37847b6f2135f8ba019645bc369 Bump regex from 1.12.3 to 1.12.4 (#997)</li>
<li>90df65764ae1bf77afe06b80248259ca5433f34c Bump scc from 3.7.1 to 3.7.2 (#995)</li>
<li>6bac44996fe2ea5dfb9f88c9635245572affc211 Bump @types/node from 25.9.1 to 25.9.2 in /doc (#990)</li>
<li>e67ec9e1f0e64e1c3590981da977b62678a40b2e Fix command test (#992)</li>
<li>ffb8ba20a55b08d0f72159209357d2bdf7ba41e9 Bump the astro group across 1 directory with 2 updates (#985)</li>
<li>c56ae7b546758ce884fdfa1817620b1da90896d6 Bump log from 0.4.31 to 0.4.32 (#988)</li>
<li>8187706cde785a83dee9c3e33b457a5912316e73 Fix integration test (#989)</li>
<li>62737f1403572d6cbc984eea9aa7c813677707dc Bump tabled from 0.20.0 to 0.21.0 (#984)</li>
<li>f735ff30fc6ed99ea170ec6de4c1ca121e391b44 Bump log from 0.4.30 to 0.4.31 (#983)</li>
<li>917a752383e7eb38d59fdc41b033140b30227f54 Bump actions/checkout from 6.0.2 to 6.0.3 (#986)</li>
<li>ed5ea44d481cf99cc913412daaa02b558c034865 Fix doc test (#987)</li>
<li>716fe2fd285b452f2e5fe4504e7d7be5e90b0536 Bump rust from 1.95.0-alpine to 1.96.0-alpine (#981)</li>
<li>68cd41b42f31b7b2bb201065df17f8aa00c919e0 Bump astro from 6.3.8 to 6.4.2 in /doc in the astro group (#980)</li>
<li>8dd77a6112784ab2f13fbae422c770d95718a32e Bump docker/setup-qemu-action from 4.0.0 to 4.1.0 (#979)</li>
<li>0dba43a545ee5b1719e92bb4897fcaca63487763 Bump @biomejs/biome from 2.4.15 to 2.4.16 in /doc (#978)</li>
<li>4584eb392a71c348ad21161f29bab96f6d4b12d9 Bump the astro group in /doc with 2 updates (#977)</li>
<li>ab0012d03e95adc4207ce9a02e9c79932677c453 Bump es-toolkit from 1.46.1 to 1.47.0 in /doc (#975)</li>
<li>a3f36a9b031215f98519d123764ea65996161648 Bump log from 0.4.29 to 0.4.30 (#974)</li>
<li>e1b1badff910ca5549f2cf2a47b9d1f132153773 Bump http from 1.4.0 to 1.4.1 (#976)</li>
<li>ae77bd3ceccf95c67278109caa238fcec5a70b50 Bump docker/login-action from 4.1.0 to 4.2.0 (#972)</li>
<li>809acf48cfc63d76673f1a43e8f8b7e3b3b0cef7 Bump docker/setup-buildx-action from 4.0.0 to 4.1.0 (#973)</li>
<li>f35cd2a5ab3859dc4401ade854ed5e910e788574 Bump docker/metadata-action from 6.0.0 to 6.1.0 (#971)</li>
<li>513013da61cfc793ff2f1787589e81f55ab48ff8 Bump docker/build-push-action from 7.1.0 to 7.2.0 (#969)</li>
<li>220e7093f1db0965c0d511dc5f30435fb0d17045 Bump astro from 6.3.6 to 6.3.7 (via audit fix) in /doc in the astro group (#967)</li>
<li>f9d27cbae6adf6cfdfb58c5530c83e3229115884 Bump serde_json from 1.0.149 to 1.0.150 (#966)</li>
<li>11709f3764a4481186e9f1072ea95920ce28b36b Bump astro from 6.3.5 to 6.3.6 (via audit fix) in /doc in the astro group (#965)</li>
<li>8469c7327b48769587fe962f2d4164f574fc9d5f Bump @types/node from 25.9.0 to 25.9.1 in /doc (#964)</li>
<li>cd129d4c4f668623679a0ff87502afe6ab43fe49 Bump astro from 6.3.3 to 6.3.5 (via audit fix) in /doc in the astro group across 1 directory (#959)</li>
<li>86528617626628a3fbe32cdcac5ff296cdc3dd80 Bump @types/node from 25.8.0 to 25.9.0 in /doc (#960)</li>
<li>797f55114092cd703f3f0aeb0332279e528c5d09 Bump codecov/codecov-action from 6.0.0 to 6.0.1 (#962)</li>
<li>61397d5ce5bdbb2f9cc3afa4ac5e9378bea4e207 Disable Englia (#963)</li>
<li>516c65fbf3fea972c9d676b8851b96e9ae8d09ed Bump astro from 6.3.2 to 6.3.3 (via audit fix) in /doc in the astro group across 1 directory (#954)</li>
<li>30bd345672cdd3c435d643715ec2eb4a8c5671a4 Fix linting (#957)</li>
<li>f361a776b05ea32ef37ce61fe7e616944d43234d Bump @types/node from 25.7.0 to 25.8.0 in /doc (#955)</li>
<li>f1ec7e840f2f1a9bb9e2039fb61d3019d3232acb Bump astro from 6.3.1 to 6.3.2 in /doc in the astro group (#952)</li>
<li>f658a47d44073ed8424fbec25db21fa16fc8aa3d Bump pnpm/action-setup from 6.0.7 to 6.0.8 in /.github/actions/setup (#951)</li>
<li>6d6fe8de03e46862985726c5c71fc6bb25bf0293 Bump scc from 3.7.0 to 3.7.1 (#949)</li>
<li>f455696e2eac67d0e513bc5dd5ec1cf26948c863 Bump @types/node from 25.6.2 to 25.7.0 in /doc (#946)</li>
<li>035a5f104f4853ed9ef7b29dff5ea4ca7eeb9a24 Bump pnpm/action-setup from 6.0.5 to 6.0.7 in /.github/actions/setup (#948)</li>
<li>cc21f45897d6c1e4e10489e003fce86a230c67a3 Bump @biomejs/biome from 2.4.14 to 2.4.15 in /doc (#945)</li>
<li>82cb5a082c9bc5c725922dd31a862d65c427e1b1 Bump tokio from 1.52.2 to 1.52.3 (#942)</li>
<li>09a6cc1494cab8a76a8dbdcc729d3b5ae145636d Bump @astrojs/starlight from 0.39.1 to 0.39.2 in /doc in the astro group (#943)</li>
<li>bb4a25de07206524fdee3ff9d96641d855c00665 Bump @types/node from 25.6.0 to 25.6.2 in /doc (#940)</li>
<li>af56e6b9db018987cab032007f445806892a0f49 Bump the astro group in /doc with 2 updates (#939)</li>
<li>f9a280ac040d8457e26f693a9940b2b5b94bcb57 Bump @astrojs/starlight from 0.38.4 to 0.38.5 in /doc in the astro group (#936)</li>
<li>8760c5b330708aa4d7271d3f7f1a3f62bb34fa45 Bump the html5ever group across 1 directory with 2 updates (#935)</li>
<li>cdb2899c080d7671115eb549527f943252956f9e Bump typescript from 5.9.3 to 6.0.3 in /doc (#937)</li>
<li>f3fed968f5c3ffe0882221829fa627844245c2e2 Bump pnpm/action-setup from 6.0.4 to 6.0.5 in /.github/actions/setup (#934)</li>
<li>440529e19c6d21c51360b8cf9aeef9e1066989f4 Bump tokio from 1.52.1 to 1.52.2 (#932)</li>
<li>41a5b30c3ce83f98823c0944a416962ae2a89a16 Bump astro from 6.2.1 to 6.2.2 in /doc in the astro group (#931)</li>
<li>a28f1c33d2040e68c4fe569fbdf379bdfd3cfe33 Bump @biomejs/biome from 2.4.13 to 2.4.14 in /doc (#927)</li>
<li>908d1c254b21d536a627f57096a5593d6b105078 Fix default config (#929)</li>
<li>c9e7b3cf0df2712ff91ee9bf0fe38968e87f4ff4 Bump pnpm/action-setup from 6.0.3 to 6.0.4 in /.github/actions/setup (#926)</li>
<li>e6118e03b6c7b5d223a216616d83c69a78585a09 Bump astro from 6.1.10 to 6.2.1 in /doc in the astro group (#925)</li>
<li>ba7995db1e3d47b1f77c539440fa00e656d4eac3 Bump es-toolkit from 1.46.0 to 1.46.1 in /doc (#924)</li>
<li>cfb1dde72ba68ef24fe8626b70f0cfaeb1ba4bfd Bump astro from 6.1.9 to 6.1.10 in /doc in the astro group (#923)</li>
<li>7aa02d5f1bd2ee01a3bdef793a7944cd278f6497 Pin base Docker image (#921)</li>
</ul>
]]></content:encoded></item><item><title>setup-tq</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/setup-tq/</link><pubDate>Thu, 16 Jul 2026 06:32:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/setup-tq/</guid><description>Version updated for https://github.com/remarkablemark/setup-tq to version v1.0.13.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action sets up the tq tool, a TOML query language interpreter, in your GitHub Actions workflow. It allows you to automate tasks such as extracting specific information from TOML files, making it useful for projects that use TOML configuration files.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remarkablemark/setup-tq">https://github.com/remarkablemark/setup-tq</a></strong> to version <strong>v1.0.13</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-tq">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action sets up the <code>tq</code> tool, a TOML query language interpreter, in your GitHub Actions workflow. It allows you to automate tasks such as extracting specific information from TOML files, making it useful for projects that use TOML configuration files.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1013-2026-07-15"><a href="https://github.com/remarkablemark/setup-tq/compare/v1.0.12...v1.0.13">1.0.13</a> (2026-07-15)</h2>
<h3 id="build-system">Build System</h3>
<ul>
<li><strong>deps:</strong> bump cargo-bins/cargo-binstall from 1.20.1 to 1.21.0 (<a href="https://github.com/remarkablemark/setup-tq/issues/32">#32</a>) (<a href="https://github.com/remarkablemark/setup-tq/commit/cc5502d226ca368b70ce718420fd8654eb08a3b9">cc5502d</a>)</li>
</ul>
]]></content:encoded></item><item><title>SBOMForge</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/sbomforge/</link><pubDate>Thu, 16 Jul 2026 06:31:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/sbomforge/</guid><description>Version updated for https://github.com/Richonn/SBOMForge to version v1.4.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SBOMForge is a GitHub Action that automates the creation, signing, and attaching of Software Bill of Materials (SBOM) for projects using Syft and Cosign. It helps ensure compliance with security requirements like SLSA by providing a zero-config solution to generate and attach SBOMs to GitHub releases.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Richonn/SBOMForge">https://github.com/Richonn/SBOMForge</a></strong> to version <strong>v1.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sbomforge">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SBOMForge is a GitHub Action that automates the creation, signing, and attaching of Software Bill of Materials (SBOM) for projects using Syft and Cosign. It helps ensure compliance with security requirements like SLSA by providing a zero-config solution to generate and attach SBOMs to GitHub releases.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Released:</strong> 2026-07-15</p>
<hr>
<h2 id="new-feature">New feature</h2>
<p>SBOMForge can now generate a signed SLSA provenance attestation alongside each SBOM. Enable it with the new <code>attest</code> input:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Richonn/SBOMForge@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">github-token</span>: <span style="color:#ae81ff">${{ secrets.GITHUB_TOKEN }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">attest</span>: <span style="color:#e6db74">&#34;true&#34;</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">id-token</span>: <span style="color:#ae81ff">write  </span> <span style="color:#75715e"># required for cosign keyless signing</span>
</span></span></code></pre></div><p>For each SBOM produced, SBOMForge generates a <code>.provenance</code> file — an <a href="https://in-toto.io">in-toto</a> statement with a <a href="https://slsa.dev/provenance/v0.2">SLSA 0.2</a> predicate — signed with Cosign keyless and uploaded to the release as a separate asset.</p>
<p>The provenance records:</p>
<ul>
<li>The SHA256 digest of the SBOM it attests</li>
<li>The source commit (<code>GITHUB_SHA</code>), ref, and workflow entrypoint</li>
<li>The build invocation ID (link to the Actions run)</li>
<li>Builder identity (<code>https://github.com/Richonn/SBOMForge</code>)</li>
</ul>
<p>This makes each SBOM verifiably tied to a specific build: anyone can confirm that a given SBOM was produced by SBOMForge, from a known commit, in a specific Actions run.</p>
<p>Verify the provenance signature locally:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>cosign verify-blob <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  --bundle<span style="color:#f92672">=</span>sbom.spdx-json.json.provenance.bundle <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  sbom.spdx-json.json.provenance
</span></span></code></pre></div><p>The feature is <strong>opt-in</strong> (<code>attest: &quot;false&quot;</code> by default) to avoid requiring <code>id-token: write</code> on existing workflows.</p>
<hr>
<h2 id="changes">Changes</h2>
<ul>
<li><code>feat(provenance)</code> — new <code>internal/provenance</code> package: generate SLSA 0.2 in-toto statement, compute SBOM SHA256 digest, sign with <code>cosign sign-blob</code></li>
<li><code>feat(release)</code> — add <code>UploadFile()</code> to upload provenance as a release asset</li>
<li><code>feat(config)</code> — add <code>Attest bool</code>, parse <code>INPUT_ATTEST</code></li>
<li><code>feat(main)</code> — call <code>provenance.Generate()</code> + <code>client.UploadFile()</code> per SBOM when <code>attest</code> is enabled</li>
<li><code>feat(action)</code> — add <code>attest</code> input to <code>action.yml</code></li>
<li><code>test(provenance)</code> — 6 tests: file creation, valid JSON, subject digest, cosign failure, sha256 helper</li>
<li><code>docs</code> — add SLSA provenance section to README, update inputs table, check roadmap item</li>
</ul>
]]></content:encoded></item><item><title>Flint AI Inventory Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/flint-ai-inventory-scan/</link><pubDate>Thu, 16 Jul 2026 06:30:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/flint-ai-inventory-scan/</guid><description>Version updated for https://github.com/sandbox-quantum/flintai-codescan-action to version v5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates static analysis of code for detecting AI assets using Flint AI. It provides an inventory of AI assets found in your repository, enriches it with additional information, and sends the results to your Flint AI instance. The action supports various LLM models and requires API keys for authentication.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sandbox-quantum/flintai-codescan-action">https://github.com/sandbox-quantum/flintai-codescan-action</a></strong> to version <strong>v5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/flint-ai-inventory-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates static analysis of code for detecting AI assets using Flint AI. It provides an inventory of AI assets found in your repository, enriches it with additional information, and sends the results to your Flint AI instance. The action supports various LLM models and requires API keys for authentication.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Merge pull request #2 from sandbox-quantum/test-rename (67af605)</li>
<li>test(flint): change variable names (ce6a13a)</li>
<li>Merge pull request #1 from sandbox-quantum/switch-to-flint (0c54ae3)</li>
<li>fix(naming): based on review comments (b663b4f)</li>
<li>chore(action): add LLM specific keys (cd30361)</li>
<li>chore(names): flint -&gt; flintai (b8fbd26)</li>
<li>switch to FlintAI (502563d)</li>
<li>Change sensor download path (a9372c1)</li>
<li>Change description (f430fd5)</li>
<li>Changed README (a83e39e)</li>
</ul>
]]></content:encoded></item><item><title>memi design CI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/memi-design-ci/</link><pubDate>Thu, 16 Jul 2026 06:29:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/memi-design-ci/</guid><description>Version updated for https://github.com/sarveshsea/memi to version v2.5.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
memi is an AI-driven design quality assurance tool that automates the auditing of real product interfaces, remembers design systems, and prevents UI regressions before merge. It works with Grok Build, Codex, Claude Code, Cursor, Hermes, OpenCode, OpenClaw, and other MCP clients. The tool provides skills for audit, remember design system context, enforce design CI gates, and more, making it a valuable tool for developers to ensure code quality and prevent regressions in UI development.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sarveshsea/memi">https://github.com/sarveshsea/memi</a></strong> to version <strong>v2.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/memi-design-ci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>memi is an AI-driven design quality assurance tool that automates the auditing of real product interfaces, remembers design systems, and prevents UI regressions before merge. It works with Grok Build, Codex, Claude Code, Cursor, Hermes, OpenCode, OpenClaw, and other MCP clients. The tool provides skills for audit, remember design system context, enforce design CI gates, and more, making it a valuable tool for developers to ensure code quality and prevent regressions in UI development.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Memi v2.5.0 makes interface understanding operational for AI coding agents.\n\nHighlights:\n- compact, agent-ready design briefs and MCP responses\n- deterministic UX, interface craft, token, and app-quality audits\n- spec-first Atomic Design component and page scaffolding with dry-run JSON\n- updated Codex plugin, Claude/Cursor/Grok agent kits, MCP manifest, and GitHub Action\n- synchronized public proof pages for Codex, MCP, skills, design CI, and the v1-to-v2.5 Product Hunt update\n\nInstall: <code>npm i -g @memi-design/cli@2.5.0</code>\n\nVerify: <code>memi --version</code></p>
]]></content:encoded></item><item><title>SEO.ai trigger pusher event</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/seo.ai-trigger-pusher-event/</link><pubDate>Thu, 16 Jul 2026 06:28:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/seo.ai-trigger-pusher-event/</guid><description>Version updated for https://github.com/seo-ai/pusher-trigger to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action triggers an event on a Pusher channel, providing a simple and reusable way to send custom events with JSON payloads. It automates the process of integrating Pusher notifications into CI/CD pipelines or other automation workflows without requiring manual setup or configuration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/seo-ai/pusher-trigger">https://github.com/seo-ai/pusher-trigger</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/seo-ai-trigger-pusher-event">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action triggers an event on a Pusher channel, providing a simple and reusable way to send custom events with JSON payloads. It automates the process of integrating Pusher notifications into CI/CD pipelines or other automation workflows without requiring manual setup or configuration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Run the action on the Node 24 runtime instead of the deprecated Node 20 (GitHub removes Node 20 from Actions runners on 2026-09-16). The bundled dist/index.js is unchanged and already verified running on Node 24 in a production SEO.ai deploy. (#1)</p>
]]></content:encoded></item><item><title>The Slack GitHub Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/the-slack-github-action/</link><pubDate>Thu, 16 Jul 2026 06:28:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/the-slack-github-action/</guid><description>Version updated for https://github.com/slackapi/slack-github-action to version v4.0.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 26,858 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Slack GitHub Action automates sending data to Slack and running commands, providing features for using webhooks, API methods, incoming webhooks, and Slack CLI commands with service tokens. It simplifies integration between GitHub workflows and Slack, enabling seamless communication and automation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/slackapi/slack-github-action">https://github.com/slackapi/slack-github-action</a></strong> to version <strong>v4.0.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>26,858</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/the-slack-github-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Slack GitHub Action automates sending data to Slack and running commands, providing features for using webhooks, API methods, incoming webhooks, and Slack CLI commands with service tokens. It simplifies integration between GitHub workflows and Slack, enabling seamless communication and automation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="major-changes">Major Changes</h3>
<ul>
<li>
<p>b1974f0: build: parse yaml with more strict multiline indentation rules</p>
<p>Internal dependencies of <a href="https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md#500---2026-06-20"><code>js-yaml@v5</code></a> make YAML parsing more strict and compliant with the YAML specification. Indentation is now required for values that span multiple lines against the base value.</p>
<p>See the YAML <a href="https://yaml.org/spec/1.2.2/#63-line-prefixes">line prefixes</a> spec for the expected indentation rule:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-diff" data-lang="diff"><span style="display:flex;"><span>  channel: &#34;C0123&#34;
</span></span><span style="display:flex;"><span>  text: &#34;first line
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">- second line&#34;
</span></span></span><span style="display:flex;"><span><span style="color:#a6e22e">+   second line&#34;
</span></span></span></code></pre></div></li>
</ul>
<h3 id="patch-changes">Patch Changes</h3>
<ul>
<li>654bb72: chore: provide global fetch proxied configurations with updates to web api and webhook packages</li>
</ul>
]]></content:encoded></item><item><title>Console CensorChecker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/console-censorchecker/</link><pubDate>Thu, 16 Jul 2026 06:27:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/console-censorchecker/</guid><description>Version updated for https://github.com/SpaceTimee/Console-CensorChecker to version 1.1.4.51.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Console CensorChecker, is a PowerShell script that uses Tcping to perform batch pinging and checks the availability of monitoring services. It helps identify if there are network censorship issues by measuring ping latency to specified targets. The action supports various installation methods through PowerShell modules or GitHub Actions integration, making it useful for developers and network administrators who need to check service connectivity without bypassing review devices.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SpaceTimee/Console-CensorChecker">https://github.com/SpaceTimee/Console-CensorChecker</a></strong> to version <strong>1.1.4.51</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/console-censorchecker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, Console CensorChecker, is a PowerShell script that uses Tcping to perform batch pinging and checks the availability of monitoring services. It helps identify if there are network censorship issues by measuring ping latency to specified targets. The action supports various installation methods through PowerShell modules or GitHub Actions integration, making it useful for developers and network administrators who need to check service connectivity without bypassing review devices.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ol>
<li>移除 模块打包时的多余文件</li>
</ol>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/ssg-static-site-generator/</link><pubDate>Thu, 16 Jul 2026 06:27:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.7.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is a static site generator written in Go. It converts Markdown files with YAML frontmatter into a complete website, including features like sitemap, search index, and responsive images. It supports various deployment options such as Cloudflare Pages, GitHub Pages, and Netlify. The action automates the process of building websites from markdown content efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is a static site generator written in Go. It converts Markdown files with YAML frontmatter into a complete website, including features like sitemap, search index, and responsive images. It supports various deployment options such as Cloudflare Pages, GitHub Pages, and Netlify. The action automates the process of building websites from markdown content efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>release(1.8.7): WordPress-migration fixes (#26, #27) + audit round — 15 unfinished-feature tickets by @spagu in <a href="https://github.com/spagu/ssg/pull/30">https://github.com/spagu/ssg/pull/30</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.5...v1.8.7">https://github.com/spagu/ssg/compare/v1.8.5...v1.8.7</a></p>
]]></content:encoded></item><item><title>aidemo Demo Video</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/aidemo-demo-video/</link><pubDate>Thu, 16 Jul 2026 06:25:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/aidemo-demo-video/</guid><description>Version updated for https://github.com/tandryukha/aidemo to version v0.9.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action is designed to generate polished demo videos from code interactions using an AI coding agent. It automatically renders deterministically and updates with each change in the product, eliminating the need for re-recording and API keys. The action automates tasks such as recording a 45-second demo of a checkout flow and generating MP4s with voiceover, captions, and auto-zoom features.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tandryukha/aidemo">https://github.com/tandryukha/aidemo</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aidemo-demo-video">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action is designed to generate polished demo videos from code interactions using an AI coding agent. It automatically renders deterministically and updates with each change in the product, eliminating the need for re-recording and API keys. The action automates tasks such as recording a 45-second demo of a checkout flow and generating MP4s with voiceover, captions, and auto-zoom features.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/tandryukha/aidemo/compare/v0.8.0...v0.9.0">https://github.com/tandryukha/aidemo/compare/v0.8.0...v0.9.0</a></p>
]]></content:encoded></item><item><title>Bumpkin Release Planner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/bumpkin-release-planner/</link><pubDate>Thu, 16 Jul 2026 06:24:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/bumpkin-release-planner/</guid><description>Version updated for https://github.com/trybumpkin/bumpkin to version v2.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Bumpkin automates the creation of reviewed release candidates by analyzing merged pull requests, proposing version bumps and generating public changelogs. It helps teams with inconsistent commit conventions manage releases efficiently and ensures that releases are thoroughly reviewed before publication. The action is suitable for teams publishing GitHub Releases from merged PRs, especially those dealing with mixed-merge workflows or repositories with varying commit discipline.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/trybumpkin/bumpkin">https://github.com/trybumpkin/bumpkin</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bumpkin-release-planner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Bumpkin automates the creation of reviewed release candidates by analyzing merged pull requests, proposing version bumps and generating public changelogs. It helps teams with inconsistent commit conventions manage releases efficiently and ensures that releases are thoroughly reviewed before publication. The action is suitable for teams publishing GitHub Releases from merged PRs, especially those dealing with mixed-merge workflows or repositories with varying commit discipline.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="breaking-changes">Breaking Changes</h2>
<ul>
<li><a href="https://github.com/trybumpkin/bumpkin/pull/85">PR #85</a> by @anasalsharif: Split analysis and diff boundaries</li>
<li><a href="https://github.com/trybumpkin/bumpkin/pull/88">PR #88</a> by @anasalsharif: Separate orchestration boundaries</li>
<li><a href="https://github.com/trybumpkin/bumpkin/pull/89">PR #89</a> by @anasalsharif: Split GitHub integration boundaries</li>
<li><a href="https://github.com/trybumpkin/bumpkin/pull/90">PR #90</a> by @anasalsharif: Split evaluation and corpus tooling</li>
</ul>
<h2 id="fixes">Fixes</h2>
<ul>
<li><a href="https://github.com/trybumpkin/bumpkin/pull/91">PR #91</a> by @anasalsharif: Standardize model runtime environment</li>
</ul>
<h2 id="needs-review">Needs Review</h2>
<ul>
<li><a href="https://github.com/trybumpkin/bumpkin/pull/86">PR #86</a> by @anasalsharif: Split model provider request paths (PR recommendation did not produce a normalized release label)</li>
<li><a href="https://github.com/trybumpkin/bumpkin/pull/87">PR #87</a> by @anasalsharif: Separate policy evaluation modules (PR recommendation did not produce a normalized release label)</li>
</ul>
<h2 id="contributors">Contributors</h2>
<p>@anasalsharif</p>
]]></content:encoded></item><item><title>SR - Semantic Release</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/sr-semantic-release/</link><pubDate>Thu, 16 Jul 2026 06:23:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/sr-semantic-release/</guid><description>Version updated for https://github.com/urmzd/sr to version v8.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action sr automates the release engineering process using semantic versioning from conventional commits. It helps users manage releases by providing a CLI tool that can plan, prepare, and release projects efficiently. Key capabilities include:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/urmzd/sr">https://github.com/urmzd/sr</a></strong> to version <strong>v8.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sr-semantic-release">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>sr</code> automates the release engineering process using semantic versioning from conventional commits. It helps users manage releases by providing a CLI tool that can plan, prepare, and release projects efficiently. Key capabilities include:</p>
<ul>
<li>Using Terraform-shaped verbs like <code>plan</code>, <code>prepare</code>, and <code>release</code></li>
<li>Supports multiple publishers such as Cargo, npm, Docker, PyPI, and Go</li>
<li>Works with workspace-aware tools like cargo, npm, pnpm, yarn, and uv monorepos</li>
<li>Allows setting release channels for trunk-based promotion</li>
<li>Ships as a portable Agent Skill for various AI tools</li>
<li>Includes single static binaries with no runtime dependencies</li>
</ul>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="810-2026-07-15">8.1.0 (2026-07-15)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>release</strong>: lock releases to a base ref commit (#29) (<a href="https://github.com/urmzd/sr/commit/aab933bdd90096e656b498093b9bd7eac2f8bc01">aab933b</a>)</li>
</ul>
<h3 id="misc">Misc</h3>
<ul>
<li>bump GitHub Actions to Node 24 majors and switch app token to client-id (<a href="https://github.com/urmzd/sr/commit/8edb124aaf638025d8bfa0d189b28977c616b5ef">8edb124</a>)</li>
</ul>
<p><a href="https://github.com/urmzd/sr/compare/v8.0.9...v8.1.0">Full Changelog</a></p>
]]></content:encoded></item><item><title>Setup Vamposer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/setup-vamposer/</link><pubDate>Thu, 16 Jul 2026 06:22:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/setup-vamposer/</guid><description>Version updated for https://github.com/ValaFoundation/vamposer to version v0.7.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary vamposer is a tool that automates the dependency management of Vala projects using Meson. It resolves package dependencies, installs system dependencies where possible, and generates necessary files to integrate with Meson subprojects. The action is designed to streamline the development process by handling dependency resolution and integration tasks automatically.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ValaFoundation/vamposer">https://github.com/ValaFoundation/vamposer</a></strong> to version <strong>v0.7.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-vamposer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>vamposer</code> is a tool that automates the dependency management of Vala projects using Meson. It resolves package dependencies, installs system dependencies where possible, and generates necessary files to integrate with Meson subprojects. The action is designed to streamline the development process by handling dependency resolution and integration tasks automatically.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changes">Changes</h2>
<p>From v0.7.1 to v0.7.2:</p>
<ul>
<li>[Update] meson version to 0.7.2 (387d9fd) by @JanGalek</li>
<li>[Update] README with link to coverage and license (b7b34e8) by @JanGalek</li>
<li>[Update] improve logging (3d92d6d) by @JanGalek</li>
<li>[Update] supported versions in SECURITY.md (e07e881) by @JanGalek</li>
<li>[Update] Revise supported versions in SECURITY.md (30e67ff) by @JanGalek</li>
<li>[Add] tests to coverage (1572686) by @JanGalek</li>
<li>[Add] tests to coverage (c55937f) by @JanGalek</li>
<li>[Add] tests to coverage (4e96d11) by @JanGalek</li>
<li>[Add] codecov.io (a043c32) by @JanGalek</li>
<li>[Add] Prepare copr publish workflow (0adb9ec) by @JanGalek</li>
<li>[Add] Prepare aur publish workflow (40bbab4) by @JanGalek</li>
<li>[Update] alias list (d5e69a1) by @JanGalek</li>
<li>[Update] README add contents (c23b19e) by @JanGalek</li>
<li>[Add] github action icon and color (6a19ad4) by @JanGalek</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ValaFoundation/vamposer/compare/v0.7.1...v0.7.2">https://github.com/ValaFoundation/vamposer/compare/v0.7.1...v0.7.2</a></p>
]]></content:encoded></item><item><title>Commit via GitHub API</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/commit-via-github-api/</link><pubDate>Thu, 16 Jul 2026 06:20:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/commit-via-github-api/</guid><description>Version updated for https://github.com/vig-os/commit-action to version v0.3.0.
This action is used across all versions by 6 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action automates the process of committing changes to a repository using the GitHub API, creating signed commits that bypass branch protection rules. It supports modular design and provides type safety with TypeScript. The action can be used as a standalone GitHub Action or imported as a module for integration into larger workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vig-os/commit-action">https://github.com/vig-os/commit-action</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/commit-via-github-api">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action automates the process of committing changes to a repository using the GitHub API, creating signed commits that bypass branch protection rules. It supports modular design and provides type safety with TypeScript. The action can be used as a standalone GitHub Action or imported as a module for integration into larger workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>No changelog notes found for 0.3.0</p>
]]></content:encoded></item><item><title>UCP Conformance (spck)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/ucp-conformance-spck/</link><pubDate>Thu, 16 Jul 2026 06:19:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/ucp-conformance-spck/</guid><description>Version updated for https://github.com/vishkaty/spck-conformance-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action adds a behavioral UCP conformance gate to your CI pipeline. It runs the spck-conformance suite against your UCP merchant server, checking for MUST deviations and ensuring compliance. The action supports both server and agent-side modes, allowing you to verify shopping agent functionality. It outputs JUnit reports with spec citations for any deviations found during testing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vishkaty/spck-conformance-action">https://github.com/vishkaty/spck-conformance-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ucp-conformance-spck">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action adds a behavioral UCP conformance gate to your CI pipeline. It runs the spck-conformance suite against your UCP merchant server, checking for MUST deviations and ensuring compliance. The action supports both server and agent-side modes, allowing you to verify shopping agent functionality. It outputs JUnit reports with spec citations for any deviations found during testing.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release.</p>
<ul>
<li><strong>Server mode</strong>: runs the <a href="https://pypi.org/project/spck-conformance/">spck-conformance</a> suite against a UCP merchant server; fails the build on MUST deviations; writes a JUnit report — every entry is named with its check id from the spec-derived register, and deviations include the full spec citation. Versions 2026-01-11 / 2026-01-23 / 2026-04-08 auto-detected.</li>
<li><strong>Agent-lane mode</strong>: self-contained agent-side conformance harness (reference agent vs adversarial sandbox), no server needed.</li>
<li>Input validation (exactly one mode), pinned-version support, configurable JUnit path.</li>
</ul>
<p>The action&rsquo;s own CI proves the gate both ways on every change and weekly: agent lane passes, a non-UCP server fails the build, and a full run against the UCP reference sample merchant must produce a JUnit report consistent with the verdict.</p>
<p>Unofficial; not affiliated with the UCP project.</p>
]]></content:encoded></item><item><title>Prune Old GitHub Actions Runs</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/prune-old-github-actions-runs/</link><pubDate>Thu, 16 Jul 2026 06:18:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/prune-old-github-actions-runs/</guid><description>Version updated for https://github.com/yanovian/delete-old-actions to version v1.0.12.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action delete-old-actions is designed to remove old GitHub Actions runs from repositories. It solves the problem of keeping repository clean by automatically deleting runs that are older than a specified number of days or keeping a certain number of the most recent runs. The action can be configured to run as part of a schedule and supports dry-run mode for testing purposes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yanovian/delete-old-actions">https://github.com/yanovian/delete-old-actions</a></strong> to version <strong>v1.0.12</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/prune-old-github-actions-runs">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>delete-old-actions</code> is designed to remove old GitHub Actions runs from repositories. It solves the problem of keeping repository clean by automatically deleting runs that are older than a specified number of days or keeping a certain number of the most recent runs. The action can be configured to run as part of a schedule and supports dry-run mode for testing purposes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Sec/undici bump version before breaking by @prazian in <a href="https://github.com/yanovian/delete-old-actions/pull/1">https://github.com/yanovian/delete-old-actions/pull/1</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@prazian made their first contribution in <a href="https://github.com/yanovian/delete-old-actions/pull/1">https://github.com/yanovian/delete-old-actions/pull/1</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yanovian/delete-old-actions/compare/v1.0.11...v1.0.12">https://github.com/yanovian/delete-old-actions/compare/v1.0.11...v1.0.12</a></p>
]]></content:encoded></item><item><title>Open License Auditor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/open-license-auditor/</link><pubDate>Thu, 16 Jul 2026 06:17:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/open-license-auditor/</guid><description>Version updated for https://github.com/yanovian/open-license-auditor to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Open License Auditor GitHub Action scans all dependencies in a repository to identify risky open source licenses and posts comments on pull requests. It supports various package managers including npm, Yarn, pnpm, pip, Poetry, and more, and flags problematic licenses as critical or warning. The action automatically detects licenses and provides detailed information about each dependency, helping teams manage their software dependencies effectively.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yanovian/open-license-auditor">https://github.com/yanovian/open-license-auditor</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/open-license-auditor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Open License Auditor GitHub Action scans all dependencies in a repository to identify risky open source licenses and posts comments on pull requests. It supports various package managers including npm, Yarn, pnpm, pip, Poetry, and more, and flags problematic licenses as critical or warning. The action automatically detects licenses and provides detailed information about each dependency, helping teams manage their software dependencies effectively.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yanovian/open-license-auditor/compare/v1.0.0...v1.0.1">https://github.com/yanovian/open-license-auditor/compare/v1.0.0...v1.0.1</a></p>
]]></content:encoded></item><item><title>judgegate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/judgegate/</link><pubDate>Thu, 16 Jul 2026 06:16:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/judgegate/</guid><description>Version updated for https://github.com/yashchimata/judgegate to version v0.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary judgegate is a CI trust gate for LLM judges that measures their reliability against human labels using Cohen’s kappa and bootstrap confidence intervals. It helps teams avoid relying solely on AI judgments by verifying their accuracy and identifying noisy or unreliable judges. The action verifies a judge, asks the label budget question, stops labeling early, and validates any labels file before running.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yashchimata/judgegate">https://github.com/yashchimata/judgegate</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/judgegate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>judgegate is a CI trust gate for LLM judges that measures their reliability against human labels using Cohen&rsquo;s kappa and bootstrap confidence intervals. It helps teams avoid relying solely on AI judgments by verifying their accuracy and identifying noisy or unreliable judges. The action verifies a judge, asks the label budget question, stops labeling early, and validates any labels file before running.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release.</p>
<p>You gate releases on an LLM judge&rsquo;s scores. judgegate checks the judge. It measures agreement against your human labels with Cohen&rsquo;s kappa and bootstrap confidence intervals, probes for position, verbosity, stability, and format bias, and returns a verdict CI can enforce: TRUSTED (0), UNTRUSTED (1), or INCONCLUSIVE (2) with the label count that would decide it.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><code>judgegate verify</code>: the trust gate, with interval-disciplined decisions for both agreement and probes</li>
<li><code>judgegate power</code>: the label budget calculator, validated against the real bootstrap decision procedure</li>
<li><code>judgegate sequential</code>: always-valid early stopping for the labeling effort itself</li>
<li><code>judgegate probe</code> and <code>judgegate validate</code> for the battery and pre-flight checks</li>
<li>Fully offline in CI when labels files carry precomputed judge verdicts: no network, no API key</li>
<li>Works with any OpenAI-compatible endpoint, with retries, bounded concurrency, and a SQLite response cache</li>
<li>Composite GitHub Action with sticky PR comments</li>
</ul>
<h2 id="live-demo">Live demo</h2>
<p>Two open pull requests on this repository show the gate working on real data: <a href="https://github.com/yashchimata/judgegate/pull/1">a judge upgrade it certifies</a> and <a href="https://github.com/yashchimata/judgegate/pull/2">a cheaper judge it refuses to trust</a>.</p>
<h2 id="install">Install</h2>
<pre tabindex="0"><code>pip install judgegate
</code></pre><p>Pairs with <a href="https://github.com/yashchimata/statgate">statgate</a>: first prove the judge deserves the job, then gate changes on what it reports.</p>
]]></content:encoded></item><item><title>zizmor-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/zizmor-action/</link><pubDate>Thu, 16 Jul 2026 06:15:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/16/zizmor-action/</guid><description>Version updated for https://github.com/zizmorcore/zizmor-action to version v0.6.0.
This action is used across all versions by 6,734 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the execution of zizmor, a security analysis tool, within GitHub Actions workflows. It helps organizations integrate comprehensive security assessments into their CI/CD pipelines to identify and remediate vulnerabilities quickly. The action supports both public and private repositories and provides options for advanced security features, such as collecting and reporting findings via GitHub’s Advanced Security integration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zizmorcore/zizmor-action">https://github.com/zizmorcore/zizmor-action</a></strong> to version <strong>v0.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6,734</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zizmor-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the execution of <code>zizmor</code>, a security analysis tool, within GitHub Actions workflows. It helps organizations integrate comprehensive security assessments into their CI/CD pipelines to identify and remediate vulnerabilities quickly. The action supports both public and private repositories and provides options for advanced security features, such as collecting and reporting findings via GitHub&rsquo;s Advanced Security integration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>zizmor 1.27.0 is now the default version used by the action.</p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Fold Docker image pull output into a collapsed Actions log group by @woodruffw with @Copilot in <a href="https://github.com/zizmorcore/zizmor-action/pull/132">https://github.com/zizmorcore/zizmor-action/pull/132</a></li>
<li>Readme: document missing inputs by @staabm in <a href="https://github.com/zizmorcore/zizmor-action/pull/130">https://github.com/zizmorcore/zizmor-action/pull/130</a></li>
<li>ci: block version sync workflow on forks by @shaanmajid in <a href="https://github.com/zizmorcore/zizmor-action/pull/129">https://github.com/zizmorcore/zizmor-action/pull/129</a></li>
<li>Sync zizmor versions by @github-actions[bot] in <a href="https://github.com/zizmorcore/zizmor-action/pull/137">https://github.com/zizmorcore/zizmor-action/pull/137</a></li>
<li>Add <code>collect</code> input by @woodruffw in <a href="https://github.com/zizmorcore/zizmor-action/pull/139">https://github.com/zizmorcore/zizmor-action/pull/139</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@woodruffw with @Copilot made their first contribution in <a href="https://github.com/zizmorcore/zizmor-action/pull/132">https://github.com/zizmorcore/zizmor-action/pull/132</a></li>
<li>@staabm made their first contribution in <a href="https://github.com/zizmorcore/zizmor-action/pull/130">https://github.com/zizmorcore/zizmor-action/pull/130</a></li>
<li>@shaanmajid made their first contribution in <a href="https://github.com/zizmorcore/zizmor-action/pull/129">https://github.com/zizmorcore/zizmor-action/pull/129</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/zizmorcore/zizmor-action/compare/v0.5.7...v0.6.0">https://github.com/zizmorcore/zizmor-action/compare/v0.5.7...v0.6.0</a></p>
]]></content:encoded></item><item><title>Magento 2 build deploy v.05</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/magento-2-build-deploy-v.05/</link><pubDate>Wed, 15 Jul 2026 15:11:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/magento-2-build-deploy-v.05/</guid><description>Version updated for https://github.com/brohon/magento-actions to version v.58.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates various tasks for Magento and PWA-Studio CI/CD, including unit tests, static code analysis, build processes, and zero-downtime deployments. It supports different versions of Magento and uses Docker containers to manage services like MySQL and Elasticsearch. The action is designed to be integrated into a repository’s workflows, allowing users to easily set up and run automated builds and checks on their Magento projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/brohon/magento-actions">https://github.com/brohon/magento-actions</a></strong> to version <strong>v.58</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/magento-2-build-deploy-v-05">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates various tasks for Magento and PWA-Studio CI/CD, including unit tests, static code analysis, build processes, and zero-downtime deployments. It supports different versions of Magento and uses Docker containers to manage services like MySQL and Elasticsearch. The action is designed to be integrated into a repository&rsquo;s workflows, allowing users to easily set up and run automated builds and checks on their Magento projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update Dockerfile (6844b71)</li>
<li>Update Dockerfile (1eabfea)</li>
<li>updated php version (3ea4847)</li>
<li>Updated docker file for new composer version and PHP 8.3 only (cdd8b02)</li>
<li>Updated bullseye (9da9114)</li>
<li>Updated bullseye (86c6023)</li>
<li>Updated buster to bookworm (a074562)</li>
<li>Update Dockerfile (84ab213)</li>
<li>Updated the composer hash (5752ab8)</li>
<li>Added php 8.2 (d9842d4)</li>
</ul>
]]></content:encoded></item><item><title>AI Diff Reviewer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/ai-diff-reviewer/</link><pubDate>Wed, 15 Jul 2026 15:10:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/ai-diff-reviewer/</guid><description>Version updated for https://github.com/DailybotHQ/ai-diff-reviewer to version v1.6.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the AI-driven code review process for your Git diffs, providing inline comments and severity-based merge gating. It runs on every pull request and supports both CI and local coding-agent skills with shared configuration files for seamless integration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/DailybotHQ/ai-diff-reviewer">https://github.com/DailybotHQ/ai-diff-reviewer</a></strong> to version <strong>v1.6.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-diff-reviewer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the AI-driven code review process for your Git diffs, providing inline comments and severity-based merge gating. It runs on every pull request and supports both CI and local coding-agent skills with shared configuration files for seamless integration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>chore(release): sync skill artifacts for v1.6.2 [skip release] (59a0a3d)</li>
<li>fix(ci): pass -y to skills add in auto-release Step 3.5 (#36) (6f74984)</li>
<li>chore(release): dogfood vendored ai-diff-reviewer to v1.6.1 [skip release] (#35) (f533261)</li>
</ul>
<p><strong>Full changelog:</strong> <a href="https://github.com/DailybotHQ/ai-diff-reviewer/compare/v1.6.1...v1.6.2"><code>v1.6.1...v1.6.2</code></a></p>
]]></content:encoded></item><item><title>MUADDIB Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/muaddib-scanner/</link><pubDate>Wed, 15 Jul 2026 15:09:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/muaddib-scanner/</guid><description>Version updated for https://github.com/DNSZLSK/muad-dib to version v2.11.170.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary MUAD’DIB is a free supply-chain scanner for npm and PyPI that detects known malicious packages, install-time RCE, credential-then-exfiltration flows, obfuscated payloads, binary droppers, and other suspicious behavioral patterns. It combines parallel scanning, deobfuscation, inter-module analysis, compound scoring, and a sandbox environment to provide comprehensive detection capabilities without telemetry.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/DNSZLSK/muad-dib">https://github.com/DNSZLSK/muad-dib</a></strong> to version <strong>v2.11.170</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/muad-dib-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>MUAD&rsquo;DIB is a free supply-chain scanner for npm and PyPI that detects known malicious packages, install-time RCE, credential-then-exfiltration flows, obfuscated payloads, binary droppers, and other suspicious behavioral patterns. It combines parallel scanning, deobfuscation, inter-module analysis, compound scoring, and a sandbox environment to provide comprehensive detection capabilities without telemetry.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Track R malice floor extended for stealth-exec + obfuscation compound. asyncapi/specs recovered from score 4 to 20. DFPR=0, GT identical.</p>
]]></content:encoded></item><item><title>DoesQA Trigger</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/doesqa-trigger/</link><pubDate>Wed, 15 Jul 2026 15:08:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/doesqa-trigger/</guid><description>Version updated for https://github.com/Does-QA/action to version v1.1.39.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action triggers a test run in DoesQA and waits for it to complete. It automates CI/CD testing by providing input parameters for key data such as API keys, account IDs, and tags, and outputs the final status and report URL of the test run. The action also supports creating Check Runs with automatic or custom labels for better integration with GitHub’s workflow system.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Does-QA/action">https://github.com/Does-QA/action</a></strong> to version <strong>v1.1.39</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/doesqa-trigger">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action triggers a test run in DoesQA and waits for it to complete. It automates CI/CD testing by providing input parameters for key data such as API keys, account IDs, and tags, and outputs the final status and report URL of the test run. The action also supports creating Check Runs with automatic or custom labels for better integration with GitHub&rsquo;s workflow system.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Security patch: fixed 1 → 1 vulnerabilities via <code>npm audit fix</code>.</p>
]]></content:encoded></item><item><title>npm-pkg-lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/npm-pkg-lint/</link><pubDate>Wed, 15 Jul 2026 15:07:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/npm-pkg-lint/</guid><description>Version updated for https://github.com/ext/npm-pkg-lint to version v5.1.12.
This action is used across all versions by 37 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, npm-pkg-lint, is an opinionated linter designed to validate NPM packages. It checks for syntactic correctness and adheres to strict guidelines, ensuring that the tarball and package.json metadata are technically valid according to specification. The action helps ensure that package metadata is clear, concise, and accurate, which is crucial for maintaining the integrity of NPM packages.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ext/npm-pkg-lint">https://github.com/ext/npm-pkg-lint</a></strong> to version <strong>v5.1.12</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>37</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/npm-pkg-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>npm-pkg-lint</code>, is an opinionated linter designed to validate NPM packages. It checks for syntactic correctness and adheres to strict guidelines, ensuring that the tarball and <code>package.json</code> metadata are technically valid according to specification. The action helps ensure that package metadata is clear, concise, and accurate, which is crucial for maintaining the integrity of NPM packages.</p>
<p>The tool is particularly useful in environments like GitHub Actions where continuous integration can automatically verify package quality before publishing or distribution. It provides a flexible interface through command-line options and supports reading from standard input, making it easy to integrate into workflows that require quick inspection of package metadata.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="5112-2026-07-15">5.1.12 (2026-07-15)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> update dependency tar to v7.5.20 (<a href="https://github.com/ext/npm-pkg-lint/commit/8afbd366a017a4781d831f22c521875903781837">8afbd36</a>)</li>
</ul>
]]></content:encoded></item><item><title>Github Action Podcast Generator workflow-1</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/github-action-podcast-generator-workflow-1/</link><pubDate>Wed, 15 Jul 2026 15:06:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/github-action-podcast-generator-workflow-1/</guid><description>Version updated for https://github.com/hackerone07-cmd/podcast-generater-github-actions to version v1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates podcasts by converting YouTube videos into MP3 files using FFmpeg. It automates the process of downloading audio from YouTube, converting it to MP3 format, and storing the result in a specified directory. This action helps streamline content creation for podcast producers by eliminating manual steps and saving time.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hackerone07-cmd/podcast-generater-github-actions">https://github.com/hackerone07-cmd/podcast-generater-github-actions</a></strong> to version <strong>v1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-action-podcast-generator-workflow-1">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates podcasts by converting YouTube videos into MP3 files using FFmpeg. It automates the process of downloading audio from YouTube, converting it to MP3 format, and storing the result in a specified directory. This action helps streamline content creation for podcast producers by eliminating manual steps and saving time.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hackerone07-cmd/podcast-generater-github-actions/commits/v1.0">https://github.com/hackerone07-cmd/podcast-generater-github-actions/commits/v1.0</a></p>
]]></content:encoded></item><item><title>GitHub Wiki Organiser</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/github-wiki-organiser/</link><pubDate>Wed, 15 Jul 2026 15:06:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/github-wiki-organiser/</guid><description>Version updated for https://github.com/hayat01sh1da/github-wiki-organiser-action to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action organises a GitHub wiki by regenerating the Home.md and _Sidebar.md files based on the Owner/Category declared at the beginning of each page, grouping them accordingly (English and Japanese labels built in). It also allows exporting reports or generating LLM exports of pages with unknown owner or category. The action is powered by the spreen-wiki PyPI package and requires a token to check out and push changes to the wiki repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hayat01sh1da/github-wiki-organiser-action">https://github.com/hayat01sh1da/github-wiki-organiser-action</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-wiki-organiser">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action organises a GitHub wiki by regenerating the <code>Home.md</code> and <code>_Sidebar.md</code> files based on the Owner/Category declared at the beginning of each page, grouping them accordingly (English and Japanese labels built in). It also allows exporting reports or generating LLM exports of pages with unknown owner or category. The action is powered by the <code>spreen-wiki</code> PyPI package and requires a token to check out and push changes to the wiki repository.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release of the <strong>GitHub Wiki Organiser</strong> composite action: <code>uses: hayat01sh1da/github-wiki-organiser-action@v0.1.0</code> — powered by the <a href="https://pypi.org/project/spreen-wiki/">spreen-wiki</a> PyPI package.</p>
<h2 id="1-added">1. Added</h2>
<ul>
<li>Composite action that checks out the caller&rsquo;s wiki (<code>wiki-repository</code>, defaulting to the calling repository&rsquo;s own wiki), installs the pinned <code>spreen-wiki==0.1.0</code> PyPI package, and runs the <code>spreen</code> CLI (<code>update</code> / <code>count-report</code> / <code>llm-export</code> selected via <code>command</code>).</li>
<li>Inputs mirroring the CLI flags (<code>group-by</code>, <code>language</code>, <code>home-overflow</code>, <code>template-dir</code>, <code>output</code>) plus action-side controls (<code>token</code>, <code>push</code>, <code>commit-message</code>, <code>slack-webhook-url</code>).</li>
<li>Commit-and-push of wiki changes as <code>github-actions[bot]</code> when the run produced a diff, exposed via the <code>changed</code> output; optional Slack Incoming Webhook notification on pushed changes.</li>
<li><code>Action - CI</code> workflow dry-running <code>update</code> and <code>count-report</code> against the <a href="https://github.com/hayat01sh1da/spreen-wiki/wiki">spreen-wiki wiki</a> on every change to <code>action.yml</code>.</li>
</ul>
<h2 id="2-full-changelog">2. Full Changelog</h2>
<p><a href="https://github.com/hayat01sh1da/github-wiki-organiser-action/commits/v0.1.0">https://github.com/hayat01sh1da/github-wiki-organiser-action/commits/v0.1.0</a></p>
]]></content:encoded></item><item><title>jk-neospec</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/jk-neospec/</link><pubDate>Wed, 15 Jul 2026 15:05:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/jk-neospec/</guid><description>Version updated for https://github.com/jedi-knights/neospec to version v0.2.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary neospec is a self-contained test runner and coverage tool for Neovim plugins and distributions. It manages its own Neovim binary, isolates tests in a clean environment, instruments Lua coverage using debug.sethook, and generates reports in various formats that are compatible with CI pipelines. This allows developers to test their plugins effectively without requiring system installations or complex shell scripts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jedi-knights/neospec">https://github.com/jedi-knights/neospec</a></strong> to version <strong>v0.2.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jk-neospec">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>neospec is a self-contained test runner and coverage tool for Neovim plugins and distributions. It manages its own Neovim binary, isolates tests in a clean environment, instruments Lua coverage using <code>debug.sethook</code>, and generates reports in various formats that are compatible with CI pipelines. This allows developers to test their plugins effectively without requiring system installations or complex shell scripts.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/neurolink-ai/</link><pubDate>Wed, 15 Jul 2026 15:03:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v9.87.2.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary NeuroLink is a universal AI integration platform that unifies 24+ AI providers and 100+ models under one consistent API. It provides production-ready solutions for integrating AI into any application, with features such as switchable providers, built-in tools, enterprise-grade features like Redis memory and multi-provider failover, and intelligent routing optimizations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v9.87.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>NeuroLink is a universal AI integration platform that unifies 24+ AI providers and 100+ models under one consistent API. It provides production-ready solutions for integrating AI into any application, with features such as switchable providers, built-in tools, enterprise-grade features like Redis memory and multi-provider failover, and intelligent routing optimizations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="9872-2026-07-15"><a href="https://github.com/juspay/neurolink/compare/v9.87.1...v9.87.2">9.87.2</a> (2026-07-15)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(utils):</strong>  pin SSRF downloads to the full validated address set (IPv4 first) (<a href="https://github.com/juspay/neurolink/commit/bfc4c14252b62f23e8f11785ffb88924c6375413">bfc4c14</a>)</li>
</ul>
]]></content:encoded></item><item><title>jira-cve-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/jira-cve-action/</link><pubDate>Wed, 15 Jul 2026 15:03:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/jira-cve-action/</guid><description>Version updated for https://github.com/levigo/jira-cve-action to version v1.23.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Jira-CVE-Action is an action that takes a JSON output from the Trivy Action and creates Jira issues for all identified CVEs under a predefined parent issue. If the parent issue is on a sprint board, it automates adding sub-tickets to the sprint. The action also allows sharing issues across multiple GitHub projects within the same Jira project by tagging them with specific project versions. It automatically moves issues between states (waiting or ready) based on whether a fix version is included in the scan results.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/levigo/jira-cve-action">https://github.com/levigo/jira-cve-action</a></strong> to version <strong>v1.23</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jira-cve-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Jira-CVE-Action is an action that takes a JSON output from the Trivy Action and creates Jira issues for all identified CVEs under a predefined parent issue. If the parent issue is on a sprint board, it automates adding sub-tickets to the sprint. The action also allows sharing issues across multiple GitHub projects within the same Jira project by tagging them with specific project versions. It automatically moves issues between states (waiting or ready) based on whether a fix version is included in the scan results.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Merge pull request #16 from levigo/fix/NF-2994-link-to-cve-database-in-generated-cve-tickets-doesnt-work-404-error (81c9666)</li>
<li>fix(NF-2994): update URL resolution to return multiple references for CVE tickets (e3d857b)</li>
<li>Merge pull request #14 from levigo/fix/NF-2994-link-to-cve-database-in-generated-cve-tickets-doesnt-work-404-error (ada9e08)</li>
<li>fix(NF-2994): update URL resolution to return multiple references for CVE tickets (1cb2f2d)</li>
<li>fix(NF-2994): update URL resolution to return multiple references for CVE tickets (1e8feb2)</li>
<li>Merge pull request #13 from levigo/feature/esm (6130050)</li>
<li>fix(INF-346): json syntax error (2b9e63b)</li>
<li>Merge pull request #12 from levigo/feature/esm (a3852cf)</li>
<li>fix: fix ESM build (1417660)</li>
<li>Merge pull request #11 from levigo/feature/esm (5a567b9)</li>
</ul>
]]></content:encoded></item><item><title>Repository Languages and CodeQL Support Map</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/repository-languages-and-codeql-support-map/</link><pubDate>Wed, 15 Jul 2026 15:02:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/repository-languages-and-codeql-support-map/</guid><description>Version updated for https://github.com/lfventura/list-repository-languages to version v4.0.0.
This action is used across all versions by 7 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, list-repository-languages, automates the detection of repository languages and maps them to the CodeQL matrix. It supports two detection methods: linguist-js (default) and using the GitHub API. The action helps in accurately identifying the programming languages in a repository by either analyzing the local checkout or querying GitHub’s API, depending on user preference. This is particularly useful for integrating language-based analysis into CI/CD pipelines with CodeQL.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lfventura/list-repository-languages">https://github.com/lfventura/list-repository-languages</a></strong> to version <strong>v4.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/repository-languages-and-codeql-support-map">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>list-repository-languages</code>, automates the detection of repository languages and maps them to the CodeQL matrix. It supports two detection methods: linguist-js (default) and using the GitHub API. The action helps in accurately identifying the programming languages in a repository by either analyzing the local checkout or querying GitHub&rsquo;s API, depending on user preference. This is particularly useful for integrating language-based analysis into CI/CD pipelines with CodeQL.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: local linguist detection method and undetected-language pruning (v4) by @lfventura in <a href="https://github.com/lfventura/list-repository-languages/pull/9">https://github.com/lfventura/list-repository-languages/pull/9</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/lfventura/list-repository-languages/compare/v3.3.0...v4.0.0">https://github.com/lfventura/list-repository-languages/compare/v3.3.0...v4.0.0</a></p>
]]></content:encoded></item><item><title>crabd</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/crabd/</link><pubDate>Wed, 15 Jul 2026 15:01:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/crabd/</guid><description>Version updated for https://github.com/louisescher/crabd to version v0.5.2.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, crab’d, is a versatile coding assistant that automates the implementation of whole issues and reviews pull requests using various AI models (Anthropic, OpenAI, OpenRouter, or local Ollama). It supports any model on both GitHub and Forgejo platforms, offering a customizable workflow for developers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/louisescher/crabd">https://github.com/louisescher/crabd</a></strong> to version <strong>v0.5.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/crab-d">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, crab&rsquo;d, is a versatile coding assistant that automates the implementation of whole issues and reviews pull requests using various AI models (Anthropic, OpenAI, OpenRouter, or local Ollama). It supports any model on both GitHub and Forgejo platforms, offering a customizable workflow for developers.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: Fallback for missing npm auth by @louisescher in <a href="https://github.com/louisescher/crabd/pull/27">https://github.com/louisescher/crabd/pull/27</a></li>
<li>chore: version packages by @github-actions[bot] in <a href="https://github.com/louisescher/crabd/pull/28">https://github.com/louisescher/crabd/pull/28</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/louisescher/crabd/compare/v0...v0.5.2">https://github.com/louisescher/crabd/compare/v0...v0.5.2</a></p>
]]></content:encoded></item><item><title>JulesOps</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/julesops/</link><pubDate>Wed, 15 Jul 2026 15:01:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/julesops/</guid><description>Version updated for https://github.com/mkshp-dev/julesops to version v0.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary JulesOps is a GitHub Action that automates the process of running Google Jules tasks using pull requests, comments, and labels. It helps prevent duplicate runs, retries failed operations, synchronizes PR states, recovers from failures, and works with any repository. The action uses GitHub Actions for local workflow management and a state machine driven by GitHub labels to handle task execution and status updates.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mkshp-dev/julesops">https://github.com/mkshp-dev/julesops</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/julesops">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>JulesOps is a GitHub Action that automates the process of running Google Jules tasks using pull requests, comments, and labels. It helps prevent duplicate runs, retries failed operations, synchronizes PR states, recovers from failures, and works with any repository. The action uses GitHub Actions for local workflow management and a state machine driven by GitHub labels to handle task execution and status updates.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This release introduces the rewritten <code>README.md</code> and Marketplace listing documentation to optimize for developer adoption, onboarding, and trust.</p>
<p><strong>Highlights:</strong></p>
<ul>
<li>A redesigned, value-focused <strong>Hero Section</strong> showing the configuration above the fold.</li>
<li>Streamlined <strong>Quick Start</strong> steps to get JulesOps running in under 2 minutes.</li>
<li>A <strong>Security and Trust</strong> audit summary clarifying permissions, secrets, and data egress.</li>
<li>Streamlined <strong>Marketplace descriptions</strong> targeted at repository contributors.</li>
<li>Automated validation of the kit using <code>./scripts/validate-kit.ps1</code> successfully passed.</li>
</ul>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/totem-shield/</link><pubDate>Wed, 15 Jul 2026 15:00:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.97.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Totem is a file-based tool designed to enhance collaboration in AI-driven development. It uses plain markdown lessons stored in the repository, which are compiled into lint rules that enforce project rules and context. This approach avoids architectural mistakes by keeping documentation and lessons alongside the code, ensuring consistency across sessions. Totem provides a deterministic zero-LLM linter for linting and an offline queryable knowledge index derived from these lessons, enhancing both the efficiency of development cycles and the integrity of architectural decisions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.97.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Totem is a file-based tool designed to enhance collaboration in AI-driven development. It uses plain markdown lessons stored in the repository, which are compiled into lint rules that enforce project rules and context. This approach avoids architectural mistakes by keeping documentation and lessons alongside the code, ensuring consistency across sessions. Totem provides a deterministic zero-LLM linter for linting and an offline queryable knowledge index derived from these lessons, enhancing both the efficiency of development cycles and the integrity of architectural decisions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>Review Buddy AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/review-buddy-ai/</link><pubDate>Wed, 15 Jul 2026 14:59:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/review-buddy-ai/</guid><description>Version updated for https://github.com/nexoral/ReviewBuddy to version v6.28.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Review Buddy is an AI-powered GitHub Action that automates code reviews, focusing on quality, metadata updates, best practices suggestions, and interactive feedback. It helps improve the efficiency of code reviews by providing intelligent comments, recommendations, and summaries.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nexoral/ReviewBuddy">https://github.com/nexoral/ReviewBuddy</a></strong> to version <strong>v6.28</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/review-buddy-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Review Buddy is an AI-powered GitHub Action that automates code reviews, focusing on quality, metadata updates, best practices suggestions, and interactive feedback. It helps improve the efficiency of code reviews by providing intelligent comments, recommendations, and summaries.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v628">v6.28</h2>
<p>This release was automatically created based on the VERSION file update.</p>
<h3 id="changes">Changes</h3>
<p>See the merged PR: #56</p>
<p><strong>Previous Version:</strong> v6.27
<strong>New Version:</strong> v6.28</p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs: update README with v6.28 features + add adaptive_api_token support by @AnkanSaha in <a href="https://github.com/nexoral/ReviewBuddy/pull/56">https://github.com/nexoral/ReviewBuddy/pull/56</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nexoral/ReviewBuddy/compare/v6.27...v6.28">https://github.com/nexoral/ReviewBuddy/compare/v6.27...v6.28</a></p>
]]></content:encoded></item><item><title>AI Harness Doctor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/ai-harness-doctor/</link><pubDate>Wed, 15 Jul 2026 14:58:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/ai-harness-doctor/</guid><description>Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v1.3.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Harness Doctor is a tool designed to help manage agent configurations across different repositories. It consolidates scattered agent config files into one canonical AGENTS.md, providing visibility into drift, conflict evidence, security audits, missing infrastructure gaps, and tech-stack snapshots. The action ensures that the repo does not forget about stale instructions by using write-capable stubs, drift-fixing commands, and guards.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NieZhuZhu/ai-harness-doctor">https://github.com/NieZhuZhu/ai-harness-doctor</a></strong> to version <strong>v1.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-harness-doctor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AI Harness Doctor is a tool designed to help manage agent configurations across different repositories. It consolidates scattered agent config files into one canonical <code>AGENTS.md</code>, providing visibility into drift, conflict evidence, security audits, missing infrastructure gaps, and tech-stack snapshots. The action ensures that the repo does not forget about stale instructions by using write-capable stubs, drift-fixing commands, and guards.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(tests): detach tempdir finalizer to stop spurious ResourceWarning by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/131">https://github.com/NieZhuZhu/ai-harness-doctor/pull/131</a></li>
<li>docs(plans): add post-v1.3 improvement audits by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/133">https://github.com/NieZhuZhu/ai-harness-doctor/pull/133</a></li>
<li>fix(installer): protect manifest ownership state by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/134">https://github.com/NieZhuZhu/ai-harness-doctor/pull/134</a></li>
<li>fix(sarif): include all active scan findings by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/135">https://github.com/NieZhuZhu/ai-harness-doctor/pull/135</a></li>
<li>fix(mcp): expose tool failure semantics by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/136">https://github.com/NieZhuZhu/ai-harness-doctor/pull/136</a></li>
<li>chore(release): v1.3.1 by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/137">https://github.com/NieZhuZhu/ai-harness-doctor/pull/137</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NieZhuZhu/ai-harness-doctor/compare/v1.3.0...v1.3.1">https://github.com/NieZhuZhu/ai-harness-doctor/compare/v1.3.0...v1.3.1</a></p>
]]></content:encoded></item><item><title>Turbo Repo Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/turbo-repo-sync/</link><pubDate>Wed, 15 Jul 2026 14:57:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/turbo-repo-sync/</guid><description>Version updated for https://github.com/nullptr-t-oss/turbo-repo-sync to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: Turbo Repo Sync is a GitHub Action that optimizes Android-style manifest-based project synchronization by using concurrent downloads with aria2c. It provides flexibility in specifying local or remote manifest.xml locations, supports project overrides, handles Git LFS, and works with multiple forge types. The action can be integrated into workflows to quickly set up source trees for building or testing purposes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nullptr-t-oss/turbo-repo-sync">https://github.com/nullptr-t-oss/turbo-repo-sync</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/turbo-repo-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong>
Turbo Repo Sync is a GitHub Action that optimizes Android-style manifest-based project synchronization by using concurrent downloads with <code>aria2c</code>. It provides flexibility in specifying local or remote <code>manifest.xml</code> locations, supports project overrides, handles Git LFS, and works with multiple forge types. The action can be integrated into workflows to quickly set up source trees for building or testing purposes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nullptr-t-oss/turbo-repo-sync/commits/v1.0.0">https://github.com/nullptr-t-oss/turbo-repo-sync/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>Obviously Concept Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/obviously-concept-scanner/</link><pubDate>Wed, 15 Jul 2026 14:56:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/obviously-concept-scanner/</guid><description>Version updated for https://github.com/Obviously-Not/concept-scanner to version v1.0.5.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Concept Scanner is an open-source tool that automates the process of identifying and analyzing technical concepts in codebases using local or remote language models. It helps identify distinctive engineering mechanisms, scores them on various quality axes, and saves the results locally. The action supports both Ollama and OpenAI-compatible providers for running the analysis.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Obviously-Not/concept-scanner">https://github.com/Obviously-Not/concept-scanner</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/obviously-concept-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Concept Scanner is an open-source tool that automates the process of identifying and analyzing technical concepts in codebases using local or remote language models. It helps identify distinctive engineering mechanisms, scores them on various quality axes, and saves the results locally. The action supports both Ollama and OpenAI-compatible providers for running the analysis.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>fe8d1a0481d9c4f8fa58642cbc4b1bf519d5565e ci: bump workflow actions off Node 20 to Node 24 (clears obs 49 deprecation)</li>
<li>a28b5462be340adca7cf9815fb056985008bcd8b docs(providers): document F2 host-matched key selection + F1 multi-model secondary requirement</li>
</ul>
]]></content:encoded></item><item><title>Runtime Contract Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/runtime-contract-check/</link><pubDate>Wed, 15 Jul 2026 14:55:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/runtime-contract-check/</guid><description>Version updated for https://github.com/piotr-adamski/runtime-contract to version v0.1.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action for runtime-contract checks whether environment variables used by a specific application component are actually supplied to that component in the correct build or runtime phase. It automates the process of static analysis and ensures that configuration contracts are adhered to, without executing code or accessing secret values. The action provides outputs for exit codes, result files, and CLI version verification.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/piotr-adamski/runtime-contract">https://github.com/piotr-adamski/runtime-contract</a></strong> to version <strong>v0.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/runtime-contract-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action for <code>runtime-contract</code> checks whether environment variables used by a specific application component are actually supplied to that component in the correct build or runtime phase. It automates the process of static analysis and ensures that configuration contracts are adhered to, without executing code or accessing secret values. The action provides outputs for exit codes, result files, and CLI version verification.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="runtime-contract-v012">runtime-contract v0.1.2</h1>
<p>This patch makes the root composite GitHub Action safe for five-minute adoption from a clean
consumer repository while preserving the product CLI as the only analyzer and argument parser.</p>
<h2 id="changes">Changes</h2>
<ul>
<li>Add the root composite Action, injection-safe process adapter, public inputs and outputs,
three-platform compatibility CI, consumer E2E, SARIF guidance, and Marketplace checklist.</li>
<li>Exclude <code>.github</code> from default discovery so <code>runtime-contract check .</code> does not interpret the
consumer&rsquo;s workflow YAML as Kubernetes. An explicit configuration <code>include</code> can still opt in.</li>
<li>Publish the package from an exact current <code>main</code> SHA through PyPI Trusted Publishing before
creating immutable Action tags. No PyPI token is used.</li>
</ul>
<h2 id="release-gates">Release gates</h2>
<ul>
<li>Merge through the rebase-only protected branch.</li>
<li>Require all pull-request checks and exact-main workflows to pass.</li>
<li>Publish <code>runtime-contract==0.1.2</code> from the verified exact-main SHA.</li>
<li>Create the signed immutable <code>v0.1.2</code> tag only after the PyPI version exists.</li>
<li>Promote <code>v0</code> only after public immutable-tag adoption succeeds.</li>
</ul>
<p>The existing <code>v0.1.1</code> Action tag remains immutable and is not promoted because public adoption
found the <code>.github</code> discovery conflict. It does not identify a PyPI package release.</p>
]]></content:encoded></item><item><title>Star History CI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/star-history-ci/</link><pubDate>Wed, 15 Jul 2026 14:54:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/star-history-ci/</guid><description>Version updated for https://github.com/ranxi2001/star-history-ci to version v2.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Star History CI GitHub Action automates the process of keeping star history charts alive in READMEs by rendering, renaming, and publishing SVG files to a stable output branch. It solves the problem of maintaining up-to-date star chart visualizations without manually updating images in the default repository branch. The action runs from source within the repository and does not rely on third-party services for rendering or publishing, ensuring security and control over the data.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ranxi2001/star-history-ci">https://github.com/ranxi2001/star-history-ci</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/star-history-ci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Star History CI GitHub Action automates the process of keeping star history charts alive in READMEs by rendering, renaming, and publishing SVG files to a stable output branch. It solves the problem of maintaining up-to-date star chart visualizations without manually updating images in the default repository branch. The action runs from source within the repository and does not rely on third-party services for rendering or publishing, ensuring security and control over the data.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="breaking-change">Breaking change</h2>
<p>Version 2 requires a PAT owned by an admin or collaborator of every repository being charted. Store it as <code>STAR_HISTORY_TOKEN</code> and pass it through the <code>token</code> input.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Vendors the Star History renderer and locked dependencies into this repository.</li>
<li>Replaces third-party render and publishing Actions with local scripts.</li>
<li>Handles both 403 and restricted empty stargazer responses safely.</li>
<li>Adds offline renderer, access-control, filename, and publishing tests.</li>
</ul>
<h2 id="upgrade">Upgrade</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">ranxi2001/star-history-ci@v2</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">repos</span>: <span style="color:#ae81ff">${{ github.repository }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">token</span>: <span style="color:#ae81ff">${{ secrets.STAR_HISTORY_TOKEN }}</span>
</span></span></code></pre></div><p>See <a href="https://github.com/ranxi2001/star-history-ci/blob/v2.0.0/CHANGELOG.md">CHANGELOG.md</a> for details.</p>
]]></content:encoded></item><item><title>SFDT for Salesforce</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/sfdt-for-salesforce/</link><pubDate>Wed, 15 Jul 2026 14:53:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/sfdt-for-salesforce/</guid><description>Version updated for https://github.com/scoobydrew83/sfdt to version v0.18.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the deployment, testing, and release management of Salesforce changes using the @sfdt/cli tool from the SFDT suite. It provides interactive workflows with preflight validation and tagging, automated release manifest generation, parallel Apex test execution, code and test quality analysis, a pre-release checklist, rollback support, smoke tests, org metadata drift detection, multi-package project support, smart package.xml generation, AI deployment error log interpretation, AI-generated PR descriptions, AI-powered code review, and more. The action supports CI/CD pipelines for GitHub, GitLab, Azure, and Bitbucket and can be integrated with other tools like Slack, MS Teams, Google Chat, email, webhook, and Grafana Loki.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/scoobydrew83/sfdt">https://github.com/scoobydrew83/sfdt</a></strong> to version <strong>v0.18.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sfdt-for-salesforce">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the deployment, testing, and release management of Salesforce changes using the <code>@sfdt/cli</code> tool from the SFDT suite. It provides interactive workflows with preflight validation and tagging, automated release manifest generation, parallel Apex test execution, code and test quality analysis, a pre-release checklist, rollback support, smoke tests, org metadata drift detection, multi-package project support, smart package.xml generation, AI deployment error log interpretation, AI-generated PR descriptions, AI-powered code review, and more. The action supports CI/CD pipelines for GitHub, GitLab, Azure, and Bitbucket and can be integrated with other tools like Slack, MS Teams, Google Chat, email, webhook, and Grafana Loki.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: release extension v0.7.0 by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/210">https://github.com/scoobydrew83/sfdt/pull/210</a></li>
<li>chore: release vscode v0.5.0 by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/211">https://github.com/scoobydrew83/sfdt/pull/211</a></li>
<li>chore: release v0.18.1 by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/213">https://github.com/scoobydrew83/sfdt/pull/213</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/scoobydrew83/sfdt/compare/v0.18.0...v0.18.1">https://github.com/scoobydrew83/sfdt/compare/v0.18.0...v0.18.1</a></p>
]]></content:encoded></item><item><title>Console CensorChecker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/console-censorchecker/</link><pubDate>Wed, 15 Jul 2026 14:52:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/console-censorchecker/</guid><description>Version updated for https://github.com/SpaceTimee/Console-CensorChecker to version 1.1.4.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Console-CensorChecker, is a PowerShell-based Tcping batch probe and review detection script designed to check the availability of monitoring services and detect network censorship. It supports multiple platforms and can be installed via PowerShell Module or invoked as a command in PowerShell scripts or within a workflow using GitHub Actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SpaceTimee/Console-CensorChecker">https://github.com/SpaceTimee/Console-CensorChecker</a></strong> to version <strong>1.1.4.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/console-censorchecker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, Console-CensorChecker, is a PowerShell-based Tcping batch probe and review detection script designed to check the availability of monitoring services and detect network censorship. It supports multiple platforms and can be installed via PowerShell Module or invoked as a command in PowerShell scripts or within a workflow using GitHub Actions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ol>
<li>添加 App 静态字段 root，点源时赋值为模块目录</li>
<li>修改 Target.txt / Provider.js 路径为基于 [App]::root</li>
<li>修改 Start-Process 参数为数组形式传入</li>
<li>移除 ConvertFrom-Json 上多余的 -ErrorAction Stop</li>
<li>修改进程等待为 Wait-Process</li>
<li>修改部分入口脚本编码风格</li>
<li>移除 Copy-Item 的 -Destination 参数名</li>
</ol>
]]></content:encoded></item><item><title>gw - Go workspaces</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/gw-go-workspaces/</link><pubDate>Wed, 15 Jul 2026 14:51:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/gw-go-workspaces/</guid><description>Version updated for https://github.com/Toyz/gw to version v0.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The gw action automates the management of Go workspaces, including generating and maintaining go.work, linting cross-module dependencies, running commands across modules, and checking the release contract. It helps in managing multi-module projects efficiently by handling module discovery, version consistency, dependency alignment, and CI readiness.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Toyz/gw">https://github.com/Toyz/gw</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gw-go-workspaces">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>gw</code> action automates the management of Go workspaces, including generating and maintaining <code>go.work</code>, linting cross-module dependencies, running commands across modules, and checking the release contract. It helps in managing multi-module projects efficiently by handling module discovery, version consistency, dependency alignment, and CI readiness.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Toyz/gw/compare/v0...v0.2.0">https://github.com/Toyz/gw/compare/v0...v0.2.0</a></p>
]]></content:encoded></item><item><title>Feishu Notification</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/feishu-notification/</link><pubDate>Wed, 15 Jul 2026 14:50:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/feishu-notification/</guid><description>Version updated for https://github.com/Waybox-AI/feishu-notification to version v1.0.20.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Feishu Notification is a GitHub Action that sends interactive card notifications to [Feishu (Lark)] channels when pull request events occur. It automates the process of notifying team members about new issues, merge requests, and commits. The action supports different colors for different types of events and handles PRs merged into main, with others being skipped silently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Waybox-AI/feishu-notification">https://github.com/Waybox-AI/feishu-notification</a></strong> to version <strong>v1.0.20</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/feishu-notification">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Feishu Notification is a GitHub Action that sends interactive card notifications to [Feishu (Lark)] channels when pull request events occur. It automates the process of notifying team members about new issues, merge requests, and commits. The action supports different colors for different types of events and handles PRs merged into <code>main</code>, with others being skipped silently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Waybox-AI/feishu-notification/compare/v1.0.19...v1.0.20">https://github.com/Waybox-AI/feishu-notification/compare/v1.0.19...v1.0.20</a></p>
]]></content:encoded></item><item><title>wcagc accessibility check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/wcagc-accessibility-check/</link><pubDate>Wed, 15 Jul 2026 14:48:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/wcagc-accessibility-check/</guid><description>Version updated for https://github.com/WCAG-Compliance/wcagc-ci to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses the wcagc service to automate accessibility checks on URLs, comparing them with a saved baseline and reporting findings for integration into the review workflow. It covers part of WCAG and EN 301 549, but does not modify a site. The action emits URL-level workflow annotations and provides a summary of coverage limitations and results.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/WCAG-Compliance/wcagc-ci">https://github.com/WCAG-Compliance/wcagc-ci</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wcagc-accessibility-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses the wcagc service to automate accessibility checks on URLs, comparing them with a saved baseline and reporting findings for integration into the review workflow. It covers part of WCAG and EN 301 549, but does not modify a site. The action emits URL-level workflow annotations and provides a summary of coverage limitations and results.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First production release of the wcagc accessibility check for GitHub Actions and GitLab CI.</p>
<p>Highlights:</p>
<ul>
<li>URL-level accessibility checks with baseline comparison</li>
<li>Configurable failure policies: new-critical, any-critical, serious-or-worse, and none</li>
<li>GitHub annotations, step summary, severity outputs, and report link</li>
<li>GitLab CI CLI and ready-to-copy pipeline template</li>
<li>Honest WCAG and EN 301 549 automation-coverage disclaimer</li>
<li>Node.js 24 runtime with zero production dependencies</li>
</ul>
<p>Use the stable major tag:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">WCAG-Compliance/wcagc-ci@v1</span>
</span></span></code></pre></div><p>Or pin the immutable exact release:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">WCAG-Compliance/wcagc-ci@v1.0.0</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/cowork-harness/</link><pubDate>Wed, 15 Jul 2026 14:47:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.0.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary cowork-harness is a technical tool designed to test Claude Cowork skills through scripting and CI pipelines. It reproduces the observable runtime contract closely enough to allow testing skills across various scenarios without using the locked Desktop application, thereby simulating sealed filesystems, default-deny egress, and MCP-only cross-boundary limitations. This helps in identifying issues related to behavior and restrictions before deploying a skill in production environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>cowork-harness is a technical tool designed to test Claude Cowork skills through scripting and CI pipelines. It reproduces the observable runtime contract closely enough to allow testing skills across various scenarios without using the locked Desktop application, thereby simulating sealed filesystems, default-deny egress, and MCP-only cross-boundary limitations. This helps in identifying issues related to behavior and restrictions before deploying a skill in production environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Patch: routine pushes to <code>main</code> no longer red CI on a repo without <code>ANTHROPIC_API_KEY</code> — the live
scenario suite is best-effort now — plus a CodeQL cleanup in the release tooling. Internal tooling +
CI only; no runtime or API change.</p>
<h3 id="changed">Changed</h3>
<ul>
<li><code>scripts/release-preflight.ts</code>: <code>changelogHasVersionSection</code> now finds the CHANGELOG heading with a
literal line-prefix match instead of a regex assembled from the version string. Behavior is
unchanged — the version is already <code>isValidSemver</code>-gated to <code>X.Y.Z</code> before this runs — and it drops
a redundant, only-partially-escaped regex flagged by CodeQL (<code>js/incomplete-sanitization</code>). Internal
release tooling only; no runtime or API change.</li>
<li><strong>CI: the live scenario suite (<code>scenarios</code> job) is now best-effort, not a publish gate.</strong> When
<code>ANTHROPIC_API_KEY</code> is absent it soft-skips green on every event — pushes to <code>main</code> included —
instead of hard-failing the run, so routine pushes to <code>main</code> (dependency bumps, docs, small fixes)
no longer turn CI red on a repo without the secret set. A loud <code>⚠️ NOT live-validated</code> marker still
flags any run that skipped live inference. The <code>SKIP_LIVE_SCENARIOS</code> admin-override variable is
removed (nothing hard-fails, so there is nothing to override). Trade-off: <code>release.yml</code> still gates
publish on <code>ci.yml</code> being green for the tagged commit, but a green <code>ci.yml</code> no longer proves the
scenarios were validated against a real model — set the <code>ANTHROPIC_API_KEY</code> repo secret to actually
run the live suite in CI. No runtime or API change.</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps-dev): bump the npm-minor-patch group across 1 directory with 4 updates by @dependabot[bot] in <a href="https://github.com/yaniv-golan/cowork-harness/pull/44">https://github.com/yaniv-golan/cowork-harness/pull/44</a></li>
<li>chore(deps): bump the actions group across 1 directory with 3 updates by @dependabot[bot] in <a href="https://github.com/yaniv-golan/cowork-harness/pull/47">https://github.com/yaniv-golan/cowork-harness/pull/47</a></li>
<li>release: 1.0.5 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/48">https://github.com/yaniv-golan/cowork-harness/pull/48</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.0.5">https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.0.5</a></p>
]]></content:encoded></item><item><title>tofu-garnish</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/tofu-garnish/</link><pubDate>Wed, 15 Jul 2026 07:03:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/tofu-garnish/</guid><description>Version updated for https://github.com/lowlydba/tofu-garnish to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The tofu-garnish GitHub Action automates the process of publishing OpenTofu/Terraform outputs into a simple, readable static page on a repository’s GitHub Pages, enhancing visibility and accessibility for engineers in finding resource ARNs without running tofu output or manually navigating through state. It supports structure-aware HTML rendering, discrete multi-workspace publishing, sensitive outputs masking, and plug-and-play integration with dflook/terraform-github-actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lowlydba/tofu-garnish">https://github.com/lowlydba/tofu-garnish</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tofu-garnish">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The tofu-garnish GitHub Action automates the process of publishing OpenTofu/Terraform outputs into a simple, readable static page on a repository&rsquo;s GitHub Pages, enhancing visibility and accessibility for engineers in finding resource ARNs without running <code>tofu output</code> or manually navigating through state. It supports structure-aware HTML rendering, discrete multi-workspace publishing, sensitive outputs masking, and plug-and-play integration with dflook/terraform-github-actions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add source repo link-back and toggleable footer link by @lowlydba in <a href="https://github.com/lowlydba/tofu-garnish/pull/5">https://github.com/lowlydba/tofu-garnish/pull/5</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/lowlydba/tofu-garnish/compare/v1.0.1...v1.1.0">https://github.com/lowlydba/tofu-garnish/compare/v1.0.1...v1.1.0</a></p>
]]></content:encoded></item><item><title>ansede-static</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/ansede-static/</link><pubDate>Wed, 15 Jul 2026 07:01:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/ansede-static/</guid><description>Version updated for https://github.com/mattybellx/Ansede to version v6.4.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Ansede is an open-source static application security testing (SAST) tool that focuses on detecting authorization flaws, including the CWE-639 IDOR vulnerability. It provides 100% recall of known CVEs and a low level of noise in production code compared to existing tools like Semgrep, CodeQL, and Bandit. Ansede offers full offline functionality and supports multiple programming languages.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mattybellx/Ansede">https://github.com/mattybellx/Ansede</a></strong> to version <strong>v6.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ansede-static">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Ansede is an open-source static application security testing (SAST) tool that focuses on detecting authorization flaws, including the CWE-639 IDOR vulnerability. It provides 100% recall of known CVEs and a low level of noise in production code compared to existing tools like Semgrep, CodeQL, and Bandit. Ansede offers full offline functionality and supports multiple programming languages.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="630--2026-07-13">[6.3.0] — 2026-07-13</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>CWE-639 IDOR Detection</strong> — World-first among open-source SAST tools. Detects
Insecure Direct Object Reference patterns across Express/DAO (JS), Django ORM
(Python), Flask-SQLAlchemy (Python), and Spring Boot JPA (Java). Identifies route
parameters used in database queries without session/ownership verification.</li>
<li><strong>Variable propagation in fallback detectors</strong> — All three language analyzers
(JS, Python, Java) now trace taint through variable assignments, enabling detection
of patterns like <code>const x = req.query.file</code> → <code>fs.readFile(x)</code>.</li>
<li><strong>Struts2/Spring parameter binding detection</strong> — Java fallback now recognizes
implicit taint sources from framework parameter binding (setters, <code>@RequestParam</code>,
<code>@PathVariable</code>) in addition to explicit <code>getParameter()</code> calls.</li>
<li><strong>Django ORM <code>.raw()</code> propagation</strong> — Multi-hop taint tracing through string
concatenation assignments: <code>name = request.GET.get('q')</code> → <code>sql = &quot;SELECT...&quot; + name</code>
→ <code>Model.objects.raw(sql)</code>.</li>
</ul>
<h3 id="improved">Improved</h3>
<ul>
<li><strong>Known-vulnerability detection: 88.6% → 91.4%</strong> across 4 test applications
(NodeGoat, goof, pygoat, dvja) covering 35 CWE instances.</li>
<li><strong>Production noise: 0.04 findings/kLOC</strong> — Verified across 16 real production
repositories (366,638 LOC). Scanner correctly identifies well-written production
code as clean.</li>
<li><strong>Python fallback cap</strong> — Increased from 20 to 25 with injection CWE prioritization
to prevent CWE-89/CWE-78 truncation.</li>
<li><strong>Java <code>Runtime.exec()</code> pattern</strong> — Now matches <code>runtime.exec(command)</code> where
<code>command</code> is a variable, not just chained <code>.exec(var + &quot;...&quot;)</code>.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>Confidence pipeline bug</strong> — <code>pattern-rust</code> analysis kind now recognized as
structural evidence, preventing false demotion of legitimate findings.</li>
<li><strong>Paren-location bug</strong> — <code>_arg_contains_taint</code> now correctly locates the opening
parenthesis in regex-matched sink patterns across all three language fallbacks.</li>
<li><strong>SQLAlchemy parameterized query FP</strong> — <code>.execute(text(...), {'key': var})</code> now
correctly identified as safe (parameterized).</li>
<li><strong>CWE-22 method-call FP</strong> — <code>f.read()</code>, <code>obj.write()</code> patterns no longer flagged
as path traversal.</li>
<li><strong>Python CWE-22 secure_filename guard</strong> — Files using <code>werkzeug.utils.secure_filename</code>
are now correctly excluded from path traversal detection.</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li>1,215 tests passing (96.4%)</li>
<li>CVE recall: 100% (164/164 across 5 languages)</li>
<li>16-repo production benchmark: 0.04 findings/kLOC average</li>
</ul>
]]></content:encoded></item><item><title>TestivAI Visual Report</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/testivai-visual-report/</link><pubDate>Wed, 15 Jul 2026 07:00:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/testivai-visual-report/</guid><description>Version updated for https://github.com/mcbuddy/testivai-oss to version @testivai/witness-webdriverio@0.2.2.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action enables local-first visual regression testing for modern web applications using TestivAI SDKs. It provides a fully self-contained solution with no account or API key, using Playwright and WebdriverIO adapters to capture, diff, and report changes in UI elements without network interaction. Users can approve baselines directly from PR comments via the /testivai approve command.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mcbuddy/testivai-oss">https://github.com/mcbuddy/testivai-oss</a></strong> to version <strong>@testivai/witness-webdriverio@0.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/testivai-visual-report">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action enables local-first visual regression testing for modern web applications using TestivAI SDKs. It provides a fully self-contained solution with no account or API key, using Playwright and WebdriverIO adapters to capture, diff, and report changes in UI elements without network interaction. Users can approve baselines directly from PR comments via the <code>/testivai approve</code> command.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="patch-changes">Patch Changes</h3>
<ul>
<li>Updated dependencies [7cb179f]
<ul>
<li>@testivai/witness@1.3.1</li>
</ul>
</li>
</ul>
]]></content:encoded></item><item><title>Mozilla SOPS Installer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/mozilla-sops-installer/</link><pubDate>Wed, 15 Jul 2026 06:59:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/mozilla-sops-installer/</guid><description>Version updated for https://github.com/mdgreenwald/mozilla-sops-action to version v2.1.1.
This action is used across all versions by 241 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action installs a specific version of the SOPS binary on the runner, automating tasks such as securing sensitive information in configuration files. It provides a caching mechanism to speed up future runs and supports various platforms through native binaries. The action also includes features like handling latest versions and pinning for security.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mdgreenwald/mozilla-sops-action">https://github.com/mdgreenwald/mozilla-sops-action</a></strong> to version <strong>v2.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>241</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mozilla-sops-installer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action installs a specific version of the SOPS binary on the runner, automating tasks such as securing sensitive information in configuration files. It provides a caching mechanism to speed up future runs and supports various platforms through native binaries. The action also includes features like handling <code>latest</code> versions and pinning for security.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><code>downloadSops()</code> no longer calls <code>fs.chmodSync</code> unconditionally on a cache hit. Tool caches on filesystems that reject chmod (e.g. an SMB/CIFS share mounted on a self-hosted runner) previously failed the run with <code>EPERM: operation not permitted</code>, even though the cached binary already carried the executable bit from its original download. The chmod is now skipped whenever the cached binary is already executable. (<a href="https://github.com/mdgreenwald/mozilla-sops-action/issues/250">#250</a>, <a href="https://github.com/mdgreenwald/mozilla-sops-action/pull/252">#252</a>)</li>
</ul>
<h3 id="internal">Internal</h3>
<ul>
<li>Dependency bumps: <code>@types/node</code> to <code>^26.1.1</code>, <code>@vercel/ncc</code> to <code>^0.44.1</code>, <code>prettier</code> to <code>^3.9.5</code>. (<a href="https://github.com/mdgreenwald/mozilla-sops-action/pull/246">#246</a>, <a href="https://github.com/mdgreenwald/mozilla-sops-action/pull/252">#252</a>)</li>
</ul>
]]></content:encoded></item><item><title>invAIriant audit gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/invairiant-audit-gate/</link><pubDate>Wed, 15 Jul 2026 06:58:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/invairiant-audit-gate/</guid><description>Version updated for https://github.com/mindicator/invAIriant to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: invAIriant is a CI/CD tool designed to audit codebases for architectural invariants, providing evidence-based architecture audits. It helps gate merges based on real findings and prevents architectural drift by ensuring every candidate survives adversarial evidence checks before becoming a finding. The tool supports a set of review lenses that discover and verify issues before severity gates, making it useful for maintaining robust architectures during AI-assisted development.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mindicator/invAIriant">https://github.com/mindicator/invAIriant</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/invairiant-audit-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong> invAIriant is a CI/CD tool designed to audit codebases for architectural invariants, providing evidence-based architecture audits. It helps gate merges based on real findings and prevents architectural drift by ensuring every candidate survives adversarial evidence checks before becoming a finding. The tool supports a set of review lenses that discover and verify issues before severity gates, making it useful for maintaining robust architectures during AI-assisted development.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v030--evidence-provenance--integrity">v0.3.0 — evidence provenance &amp; integrity</h2>
<p>Ships the issue #2 provenance workstream: mechanical, judgment-free integrity checks that raise the trust floor without the CLI ever deciding whether a finding is real.</p>
<p><strong>Provenance &amp; integrity</strong></p>
<ul>
<li>Bind <strong>report ↔ bundle ↔ commit</strong> — <code>collect</code> emits <code>commit_sha</code> / <code>scope_hash</code> / <code>bundle_hash</code>; the report carries them; <code>invairiant verify-provenance</code> (and the GitHub Action) check them.</li>
<li><code>validate-report --check-citations</code> — every <code>file_lines</code> citation must point at a real file whose line range exists.</li>
<li><code>verification</code> records <code>model</code> / <code>run</code> beside <code>verified_by</code> / <code>method</code>.</li>
<li>Staged enforcement so existing reports don&rsquo;t break: <code>validate-report --strict</code>, <code>verify-provenance --require-exact-bundle</code>, and the Action&rsquo;s <code>require-provenance</code>.</li>
</ul>
<p><strong>Also in this release</strong></p>
<ul>
<li>The CLI is now the <code>invairiant/</code> package (split for readability; <code>python3 cli/invairiant.py</code> and <code>python -m invairiant</code> both work).</li>
<li>Typed scope models — <code>ScopeKind</code> enum + frozen <code>ResolvedScope</code>.</li>
<li><code>ci-gate</code> self-validates the report before gating; every <code>except</code> narrowed.</li>
</ul>
<p><strong>Honest limit:</strong> the CLI proves provenance and citation-existence, not that the agent <em>reasoned</em> correctly — and can&rsquo;t stop a determined hand-edit without signing the report at synthesis.</p>
<p>Full detail in <a href="https://github.com/mindicator/invAIriant/blob/main/CHANGELOG.md#030--2026-07-14">CHANGELOG</a>.</p>
<pre tabindex="0"><code>pip install -U invairiant
</code></pre>]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/totem-shield/</link><pubDate>Wed, 15 Jul 2026 06:57:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.96.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Totem GitHub Action automates linting, helping developers enforce architectural guidelines and maintain code quality by reading and writing to a file-based substrate of plain markdown lessons. It provides a deterministic, offline lint engine that runs in under 2 seconds, reducing friction and improving collaboration among AI coding agents.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.96.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Totem GitHub Action automates linting, helping developers enforce architectural guidelines and maintain code quality by reading and writing to a file-based substrate of plain markdown lessons. It provides a deterministic, offline lint engine that runs in under 2 seconds, reducing friction and improving collaboration among AI coding agents.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>AI Harness Doctor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/ai-harness-doctor/</link><pubDate>Wed, 15 Jul 2026 06:56:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/ai-harness-doctor/</guid><description>Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v1.0.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Harness Doctor is a tool that helps automate the process of consolidating scattered agent configurations into one canonical file (AGENTS.md). It ensures that all references to old or outdated tools are replaced with pointers to existing files, preventing future drift and confusion. The action also provides safeguards to prevent accidental modifications or deletions through symbolic links.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NieZhuZhu/ai-harness-doctor">https://github.com/NieZhuZhu/ai-harness-doctor</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-harness-doctor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AI Harness Doctor is a tool that helps automate the process of consolidating scattered agent configurations into one canonical file (<code>AGENTS.md</code>). It ensures that all references to old or outdated tools are replaced with pointers to existing files, preventing future drift and confusion. The action also provides safeguards to prevent accidental modifications or deletions through symbolic links.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs(plans): add three deep improvement audits by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/105">https://github.com/NieZhuZhu/ai-harness-doctor/pull/105</a></li>
<li>fix(scan): keep file reads inside repo by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/106">https://github.com/NieZhuZhu/ai-harness-doctor/pull/106</a></li>
<li>fix(review): fall back when inline comments fail by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/107">https://github.com/NieZhuZhu/ai-harness-doctor/pull/107</a></li>
<li>fix(release): isolate prerelease channels by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/108">https://github.com/NieZhuZhu/ai-harness-doctor/pull/108</a></li>
<li>fix(scan): contain all repository-derived facts by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/109">https://github.com/NieZhuZhu/ai-harness-doctor/pull/109</a></li>
<li>chore(release): v1.0.1 by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/110">https://github.com/NieZhuZhu/ai-harness-doctor/pull/110</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NieZhuZhu/ai-harness-doctor/compare/v1.0.0...v1.0.1">https://github.com/NieZhuZhu/ai-harness-doctor/compare/v1.0.0...v1.0.1</a></p>
]]></content:encoded></item><item><title>XAI Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/xai-review/</link><pubDate>Wed, 15 Jul 2026 06:55:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/xai-review/</guid><description>Version updated for https://github.com/Nikita-Filonov/ai-review to version v0.70.0.
This action is used across all versions by 8 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Review is an AI-powered code review tool that automates the review process, using LLMs to identify potential improvements in code quality and consistency. It integrates seamlessly with popular version control systems like GitLab, GitHub, and Bitbucket, allowing teams to focus on code development rather than managing reviews manually. With customizable prompts and agent mode, it can explore the repository for deeper insights before generating detailed reviews, making the process faster and more efficient.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Nikita-Filonov/ai-review">https://github.com/Nikita-Filonov/ai-review</a></strong> to version <strong>v0.70.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/xai-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>AI Review</strong> is an AI-powered code review tool that automates the review process, using LLMs to identify potential improvements in code quality and consistency. It integrates seamlessly with popular version control systems like GitLab, GitHub, and Bitbucket, allowing teams to focus on code development rather than managing reviews manually. With customizable prompts and agent mode, it can explore the repository for deeper insights before generating detailed reviews, making the process faster and more efficient.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fixes (82d9947)</li>
<li>Merge pull request #111 from dansan/feature/gitlab-batched-inline-comments (28f8a63)</li>
<li>docs: document the GitLab-only batch_comments setting (fdb169c)</li>
<li>feat(review): finalize the review pipeline via ReviewService context manager (676aaba)</li>
<li>feat(gitlab): batch review comments as draft notes behind vcs.batch_comments (87aa23d)</li>
<li>feat(gitlab): add Draft Notes API support to the GitLab HTTP client (790afba)</li>
<li>azure openai (978e700)</li>
<li>Merge pull request #99 from crow-ua/add-support-for-gpt-5-max-complete-tokens (e28ac59)</li>
<li>renamed files (61d7b2b)</li>
<li>bitbucket server (1bbc1d8)</li>
</ul>
]]></content:encoded></item><item><title>Run AER Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/run-aer-tests/</link><pubDate>Wed, 15 Jul 2026 06:54:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/run-aer-tests/</guid><description>Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.15.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the execution of Apex unit tests locally, providing developers with a way to run and debug their Apex code without needing an org. It supports various Salesforce functionalities such as SObjects, database operations, triggers, validation rules, flows, and testing framework features like @IsTest.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/octoberswimmer/aer-dist">https://github.com/octoberswimmer/aer-dist</a></strong> to version <strong>v1.2.15</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-aer-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the execution of Apex unit tests locally, providing developers with a way to run and debug their Apex code without needing an org. It supports various Salesforce functionalities such as SObjects, database operations, triggers, validation rules, flows, and testing framework features like <code>@IsTest</code>.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Version v1.2.15</p>
<ul>
<li>
<p>Switch Object-Keyed Maps To Identity Lookup After Enumeration</p>
</li>
<li>
<p>Add License Key And Website Links To CLI Help And Errors</p>
</li>
<li>
<p>Strip Relationship Records From Trigger Context Records</p>
</li>
<li>
<p>Require Exact List Element Types And SObject Collections At Compile Time</p>
</li>
<li>
<p>Clear Package Execution Context When Resetting Pooled VMs</p>
</li>
<li>
<p>Support Method Definitions In Anonymous Apex</p>
</li>
<li>
<p>Reject Invalid Assignments And Bare Namespaced Builtin References</p>
</li>
<li>
<p>Apply Flex Queue Rules To Database.executeBatch And Add FlexQueueItem Rows</p>
</li>
<li>
<p>Include Null Fields In AggregateResult getPopulatedFieldsAsMap</p>
</li>
<li>
<p>Default Text Name Fields To The 15-Character Id</p>
</li>
<li>
<p>Enforce Restrict Delete Constraints On Lookup Relationships</p>
</li>
<li>
<p>Support Custom Iterable Arguments In String.join</p>
</li>
<li>
<p>Fix QueryLocator Iterable Dispatch Semantics</p>
</li>
<li>
<p>Fix Trigger Map Nullness And Collection Conversion Rules</p>
</li>
<li>
<p>Route Built-In Describe Type Properties Through Their Getter Methods</p>
</li>
<li>
<p>Evaluate Builtin Arguments Before Opening Their Trace Span</p>
</li>
<li>
<p>Apply The Simulated CPU Time Limit Only When Governor Limits Are Enforced</p>
</li>
<li>
<p>Embed Full Cause Stack And Namespace-Qualify Trigger Frames</p>
</li>
<li>
<p>Support Java regex \p{&hellip;} property classes in Pattern/Matcher</p>
</li>
<li>
<p>Make List Membership Type-strict For Numeric Values</p>
</li>
<li>
<p>Support Java regex whitespace, dot, octal, class-op and (?U) constructs</p>
</li>
<li>
<p>Populate EntityDefinition Rows For Associated Entities And Fix Share Ids</p>
</li>
<li>
<p>Accept Numeric-element List Arguments For User Method Calls</p>
</li>
<li>
<p>Resolve Parent Relationships In Workflow Formulas</p>
</li>
</ul>
]]></content:encoded></item><item><title>PatchRail CI Triage</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/patchrail-ci-triage/</link><pubDate>Wed, 15 Jul 2026 06:53:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/patchrail-ci-triage/</guid><description>Version updated for https://github.com/patchrail/ci-triage-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The PatchRail CI Triage Action classifies a failed CI log locally using the patchrail CLI, providing a remediation guide as a job annotation and step summary. It handles logs correctly by redirecting stderr to the output file and supports both local files and raw log text inputs, while also allowing for redaction of sensitive information. The action is designed to be read-only and does not interact with external services or open pull requests.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/patchrail/ci-triage-action">https://github.com/patchrail/ci-triage-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/patchrail-ci-triage">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The PatchRail CI Triage Action classifies a failed CI log locally using the <code>patchrail</code> CLI, providing a remediation guide as a job annotation and step summary. It handles logs correctly by redirecting stderr to the output file and supports both local files and raw log text inputs, while also allowing for redaction of sensitive information. The action is designed to be read-only and does not interact with external services or open pull requests.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Classify a failed CI log <strong>locally</strong> on the runner and surface the matching PatchRail <code>/fix</code> guide as a job annotation and step summary. Read-only by design: it never opens a pull request, posts a comment, or sends your logs anywhere.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">name</span>: <span style="color:#ae81ff">Build</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">shell</span>: <span style="color:#ae81ff">bash</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">run</span>: <span style="color:#ae81ff">make build 2&gt;&amp;1 | tee build.log</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">name</span>: <span style="color:#ae81ff">PatchRail CI triage</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">if</span>: <span style="color:#ae81ff">failure()</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">patchrail/ci-triage-action@v1.1.0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">log-path</span>: <span style="color:#ae81ff">build.log</span>
</span></span></code></pre></div><h2 id="what-this-release-fixes">What this release fixes</h2>
<ul>
<li><strong>An <code>unknown</code> verdict now names the line the runner flagged.</strong> When no rule matches, the action still hands back the line the runner itself reported for the failing step, so you land on the error instead of on &ldquo;no signal found&rdquo;.</li>
<li><strong>A success line announced through the error channel is no longer reported as the place to start.</strong> Runners that print <code>✅ task started.</code> on the error stream used to be offered as the cause of the failure. (Ships via the <code>patchrail</code> 0.6.1 classifier.)</li>
<li><strong>The action refuses a result schema it cannot read</strong> instead of annotating a wrong answer, and it bounds the <code>patchrail</code> version it installs.</li>
<li><strong>The README capture snippet no longer hides failed builds.</strong> The documented step now runs under <code>shell: bash</code> (<code>-o pipefail</code>), so <code>make build | tee build.log</code> cannot exit <code>0</code> on a broken build and sail through CI.</li>
</ul>
<h2 id="pinning">Pinning</h2>
<p><code>v1.1.0</code> is immutable — pin it if you want a fixed version. <code>v1</code> is a moving major tag kept on the latest tested commit; both currently point at the same code.</p>
]]></content:encoded></item><item><title>Postman API Onboarding</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/postman-api-onboarding/</link><pubDate>Wed, 15 Jul 2026 06:51:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/postman-api-onboarding/</guid><description>Version updated for https://github.com/postman-cs/postman-api-onboarding-action to version v2.0.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the setup and onboarding process of a new API repository by leveraging Postman’s suite to bootstrap a workspace, upload an OpenAPI specification, generate collections for smoke testing and contract enforcement, and integrate with CI/CD workflows. The action handles environment creation, mock server configuration, and runs automated tests using JUnit output, ensuring that the repository is fully equipped with standards-grounded testing mechanisms.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-api-onboarding-action">https://github.com/postman-cs/postman-api-onboarding-action</a></strong> to version <strong>v2.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-api-onboarding">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the setup and onboarding process of a new API repository by leveraging Postman&rsquo;s suite to bootstrap a workspace, upload an OpenAPI specification, generate collections for smoke testing and contract enforcement, and integrate with CI/CD workflows. The action handles environment creation, mock server configuration, and runs automated tests using JUnit output, ensuring that the repository is fully equipped with standards-grounded testing mechanisms.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>perf(ci): complete deterministic fast-loop gates by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/67">https://github.com/postman-cs/postman-api-onboarding-action/pull/67</a></li>
<li>chore: advance sibling pins to hardening-wave releases by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/68">https://github.com/postman-cs/postman-api-onboarding-action/pull/68</a></li>
<li>chore(release): v2.0.5 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/69">https://github.com/postman-cs/postman-api-onboarding-action/pull/69</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-api-onboarding-action/compare/v2...v2.0.5">https://github.com/postman-cs/postman-api-onboarding-action/compare/v2...v2.0.5</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Workspace Bootstrap</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/postman-onboarding-workspace-bootstrap/</link><pubDate>Wed, 15 Jul 2026 06:50:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/postman-onboarding-workspace-bootstrap/</guid><description>Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.9.4.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman Onboarding: Workspace Bootstrap GitHub Action automates the creation of a Postman workspace from an OpenAPI specification, generating baseline, smoke, and contract collections with executable contract tests. This action helps developers automate the setup process for testing APIs in their projects by providing comprehensive test coverage and enforcing standards through various protocols.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-bootstrap-action">https://github.com/postman-cs/postman-bootstrap-action</a></strong> to version <strong>v2.9.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-workspace-bootstrap">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman Onboarding: Workspace Bootstrap GitHub Action automates the creation of a Postman workspace from an OpenAPI specification, generating baseline, smoke, and contract collections with executable contract tests. This action helps developers automate the setup process for testing APIs in their projects by providing comprehensive test coverage and enforcing standards through various protocols.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: harden gateway + adapter transport and PATCH reconciliation by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/85">https://github.com/postman-cs/postman-bootstrap-action/pull/85</a></li>
<li>chore(release): v2.9.4 by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/86">https://github.com/postman-cs/postman-bootstrap-action/pull/86</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.9.4">https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.9.4</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Repo Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/postman-onboarding-repo-sync/</link><pubDate>Wed, 15 Jul 2026 06:49:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/postman-onboarding-repo-sync/</guid><description>Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.1.5.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action exports Postman collections and environments into a repository and automates CI, mock servers, and monitors around them. It solves the problem of managing API testing tools in repositories by providing seamless integration with Postman’s API and GitHub Actions workflow files. The action also supports generating CI workflows for easy deployment and monitoring setup.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-repo-sync-action">https://github.com/postman-cs/postman-repo-sync-action</a></strong> to version <strong>v2.1.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-repo-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action exports Postman collections and environments into a repository and automates CI, mock servers, and monitors around them. It solves the problem of managing API testing tools in repositories by providing seamless integration with Postman&rsquo;s API and GitHub Actions workflow files. The action also supports generating CI workflows for easy deployment and monitoring setup.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: warn when empty system-env-map hides Catalog services (v2.1.5) by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/78">https://github.com/postman-cs/postman-repo-sync-action/pull/78</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.4...v2.1.5">https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.4...v2.1.5</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Smoke Flow</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/postman-onboarding-smoke-flow/</link><pubDate>Wed, 15 Jul 2026 06:48:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/postman-onboarding-smoke-flow/</guid><description>Version updated for https://github.com/postman-cs/postman-smoke-flow-action to version v2.1.4.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, Postman Onboarding: Smoke Flow, reshapes a generated Postman Smoke collection to match a curated flow.yaml and optionally injects runtime auth for OAuth2 and API keys. It is part of the Postman API Onboarding suite and requires credentials such as postman-access-token, which is minted by postman-resolve-service-token-action. The action runs entirely through the Postman gateway under the token and can handle both US and EU data residency settings for consistent region calls.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-smoke-flow-action">https://github.com/postman-cs/postman-smoke-flow-action</a></strong> to version <strong>v2.1.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-smoke-flow">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, Postman Onboarding: Smoke Flow, reshapes a generated Postman Smoke collection to match a curated <code>flow.yaml</code> and optionally injects runtime auth for OAuth2 and API keys. It is part of the Postman API Onboarding suite and requires credentials such as <code>postman-access-token</code>, which is minted by <code>postman-resolve-service-token-action</code>. The action runs entirely through the Postman gateway under the token and can handle both US and EU data residency settings for consistent region calls.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: safe item-PATCH reconciliation and strict uid parsing by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/43">https://github.com/postman-cs/postman-smoke-flow-action/pull/43</a></li>
<li>chore(release): v2.1.4 by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/44">https://github.com/postman-cs/postman-smoke-flow-action/pull/44</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-smoke-flow-action/compare/v2...v2.1.4">https://github.com/postman-cs/postman-smoke-flow-action/compare/v2...v2.1.4</a></p>
]]></content:encoded></item><item><title>Remyx Outrider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/remyx-outrider/</link><pubDate>Wed, 15 Jul 2026 06:46:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/remyx-outrider/</guid><description>Version updated for https://github.com/remyxai/outrider to version v1.7.28.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Outrider is a GitHub Action that automates the validation and comparison of new methods against an organization’s codebase. It provides draft PRs with a self-review, handles preflight checks and issues, supports branch-only mode for exploring multiple candidates without committing to any one, and allows quickstart installation via CLI tools. The action uses Anthropic Opus or z.ai GLM-5.2 as model backends, with configurable costs based on the backend used.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remyxai/outrider">https://github.com/remyxai/outrider</a></strong> to version <strong>v1.7.28</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/remyx-outrider">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Outrider is a GitHub Action that automates the validation and comparison of new methods against an organization&rsquo;s codebase. It provides draft PRs with a self-review, handles preflight checks and issues, supports branch-only mode for exploring multiple candidates without committing to any one, and allows quickstart installation via CLI tools. The action uses Anthropic Opus or z.ai GLM-5.2 as model backends, with configurable costs based on the backend used.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="new">New</h2>
<p><strong>Two-tier drafter/refiner setup</strong> (<a href="https://github.com/remyxai/outrider/pull/91">PR #91</a>) — a companion pair of workflow templates alongside the existing <code>outrider.yml</code>:</p>
<ul>
<li><strong><code>outrider-daily.yml</code></strong> — drafter role: high-frequency, <code>publish=branch</code>, Anthropic Claude Haiku 4.5 default. Distinctive defaults: <code>maintain-state=true</code>, <code>staged-synthesis=false</code>. Accumulates <code>.remyx/repo_intel.yaml</code> across dispatches; produces branches that the refiner selects from weekly.</li>
<li><strong><code>outrider-weekly-refine.yml</code></strong> — refiner orchestrator: weekly cron + <code>workflow_dispatch</code>. Three steps in one job: pick candidate from past 7 days of drafter output → generate targeted gap analysis via Claude Sonnet 4.6 → dispatch <code>outrider.yml</code> with <code>pin-arxiv</code> + <code>start-from-ref</code> + <code>lead-content=&lt;inline markdown&gt;</code> + <code>staged-synthesis=true</code> + Opus 4.8. The refinement&rsquo;s chain (fidelity → convention → test) runs inline. Terminal artifact: a ready-for-review draft PR.</li>
</ul>
<p>Design rationale in <code>docs/customization.md</code> §5:</p>
<ul>
<li>Higher commit-to-PR rate on borderline cases — drafter branches anchor extension point, test scaffolding, and diff shape before Opus&rsquo;s preflight decision.</li>
<li>Cheap exploration of the arxiv frontier — daily dispatches sample from an ever-growing candidate pool; spec generation alone saturates on any given paper × repo pair while the arxiv corpus keeps growing.</li>
<li>Compounding intel accumulation — failed drafts still add negative-space signal to preflight.</li>
</ul>
<p>Single-vendor default: one <code>ANTHROPIC_API_KEY</code> secret covers both tiers. <code>z.ai</code> GLM path documented as an opt-in override in <code>docs/backends.md</code>.</p>
<h2 id="fixed">Fixed</h2>
<p><strong>Refiner picker enumeration</strong> (<a href="https://github.com/remyxai/outrider/pull/92">PR #92</a>) — the auto-pick step now enumerates only branches present in <code>.remyx/repo_intel.yaml</code>&rsquo;s <code>confirmed_by</code> list (the drafter&rsquo;s own landing record) instead of filtering the full branch list on name patterns. Prior behavior let inherited upstream branches on forks (<code>dependabot/*</code>, <code>feat/*</code>, <code>chore/*</code>) slip through and often win the most-recent pick, then fail at the arxiv-resolution gate. Now: only drafter-authored branches are candidates, by construction.</p>
<p>First-time-setup forks with no drafter landings yet emit a clear no-op warning (<code>No drafter-known branches in .remyx/repo_intel.yaml — nothing to promote yet</code>) rather than the misleading &ldquo;no candidate branches in past N days&rdquo; message.</p>
<h2 id="compatibility">Compatibility</h2>
<p>Backwards-compatible. Existing single-file <code>outrider.yml</code> installs continue to work unchanged. The <code>remyxai/outrider@v1</code> action tag now points to v1.7.28; workflows already referencing <code>@v1</code> pick up both changes on next dispatch.</p>
<h2 id="remyxai-cli-companion"><code>remyxai-cli</code> companion</h2>
<p>An opt-in <code>--two-tier</code> flag for <code>remyxai outrider setup-local</code> is proposed in <a href="https://github.com/remyxai/remyxai-cli/pull/47">remyxai/remyxai-cli#47</a>, which fetches these templates from <code>remyxai/outrider@v1</code> at install time.</p>
]]></content:encoded></item><item><title>Foreman Agent Review Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/foreman-agent-review-gate/</link><pubDate>Wed, 15 Jul 2026 06:44:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/foreman-agent-review-gate/</guid><description>Version updated for https://github.com/rohitkumarmanne-442/Foreman to version v1.0.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Foreman is a local code review tool that helps ensure AI-generated changes are verified. It automatically checks each claim made by AI agents against the actual code they produced, ensuring that claims are supported with verification commands.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rohitkumarmanne-442/Foreman">https://github.com/rohitkumarmanne-442/Foreman</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/foreman-agent-review-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Foreman is a local code review tool that helps ensure AI-generated changes are verified. It automatically checks each claim made by AI agents against the actual code they produced, ensuring that claims are supported with verification commands.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Foreman is the review inbox for your AI workforce</strong>, every AI-agent coding session becomes a risk-ranked review card, backed by cryptographically signed receipts that prove what tools your agents actually ran. 100% local, zero external LLM calls.</p>
<p>This release puts Foreman&rsquo;s CI gate on the <strong>GitHub Marketplace</strong> and sharpens the docs so you can wire it in at a glance. Same v1.0.0 engine underneath — <strong>36/36 tests green</strong>.</p>
<h3 id="-now-on-the-github-marketplace">🏪 Now on the GitHub Marketplace</h3>
<p>Block PRs with unreviewed risky agent sessions in a few lines:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#75715e"># .github/workflows/foreman.yml</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">Foreman</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">on</span>: [<span style="color:#ae81ff">pull_request]</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">gate</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">rohitkumarmanne-442/Foreman@v1</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">level</span>: <span style="color:#ae81ff">high  </span> <span style="color:#75715e"># block on unreviewed high/critical sessions</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/rumdl-action/</link><pubDate>Wed, 15 Jul 2026 06:43:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.34.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary: rumdl is a high-performance, Rust-based Markdown linter and formatter that offers speed, extensive lint rules, automatic formatting with --fix, zero dependencies, and multiple installation options. It supports various Markdown flavors and provides detailed error reporting, making it suitable for projects requiring consistent and best-practice markdown files.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.34</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong>
rumdl is a high-performance, Rust-based Markdown linter and formatter that offers speed, extensive lint rules, automatic formatting with <code>--fix</code>, zero dependencies, and multiple installation options. It supports various Markdown flavors and provides detailed error reporting, making it suitable for projects requiring consistent and best-practice markdown files.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>code-block-tools</strong>: restore shuck as a built-in shell linter (<a href="https://github.com/rvben/rumdl/commit/da66447ae2bea9186c436039111bd161f3e95ba2">da66447</a>)</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li><strong>reflow</strong>: probe inline math at the cursor instead of rescanning the suffix (<a href="https://github.com/rvben/rumdl/commit/1e6ea3b5fada915dd2bde693af058a51afec501a">1e6ea3b</a>)</li>
<li><strong>reflow</strong>: merge emphasis and code span extraction into a single cmark pass (<a href="https://github.com/rvben/rumdl/commit/8e035377b4971f04701cb4b0fefbbebf84844ddd">8e03537</a>)</li>
<li><strong>reflow</strong>: optimize MyST inline role parsing using pre-extracted code spans (<a href="https://github.com/rvben/rumdl/commit/e966899cd377e41e54941949ae0f9c50afb89874">e966899</a>)</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.34/rumdl-v0.2.34-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.34-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.34/rumdl-v0.2.34-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.34/rumdl-v0.2.34-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.34-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.34/rumdl-v0.2.34-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.34/rumdl-v0.2.34-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.34-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.34/rumdl-v0.2.34-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.34/rumdl-v0.2.34-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.34-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.34/rumdl-v0.2.34-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.34/rumdl-v0.2.34-x86_64-apple-darwin.tar.gz">rumdl-v0.2.34-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.34/rumdl-v0.2.34-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.34/rumdl-v0.2.34-aarch64-apple-darwin.tar.gz">rumdl-v0.2.34-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.34/rumdl-v0.2.34-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.34/rumdl-v0.2.34-x86_64-pc-windows-msvc.zip">rumdl-v0.2.34-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.34/rumdl-v0.2.34-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>SFDT for Salesforce</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/sfdt-for-salesforce/</link><pubDate>Wed, 15 Jul 2026 06:42:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/sfdt-for-salesforce/</guid><description>Version updated for https://github.com/scoobydrew83/sfdt to version vscode-v0.5.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates various aspects of Salesforce development, including deploying changes, testing, and monitoring. It supports multi-package projects and provides AI-driven features for error interpretation, PR descriptions, and more. The action simplifies CI/CD processes by offering pre-built templates for common platforms and integrates with multiple notification channels.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/scoobydrew83/sfdt">https://github.com/scoobydrew83/sfdt</a></strong> to version <strong>vscode-v0.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sfdt-for-salesforce">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates various aspects of Salesforce development, including deploying changes, testing, and monitoring. It supports multi-package projects and provides AI-driven features for error interpretation, PR descriptions, and more. The action simplifies CI/CD processes by offering pre-built templates for common platforms and integrates with multiple notification channels.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published to the VS Code Marketplace as sfdt.sfdt-devtools.</p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: release vscode v0.5.0 by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/211">https://github.com/scoobydrew83/sfdt/pull/211</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/scoobydrew83/sfdt/compare/ext-v0.7.0...vscode-v0.5.0">https://github.com/scoobydrew83/sfdt/compare/ext-v0.7.0...vscode-v0.5.0</a></p>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/ssg-static-site-generator/</link><pubDate>Wed, 15 Jul 2026 06:41:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website. It solves the problem of automating the process of generating static websites from content written in Markdown and YAML. The key capabilities include Markdown-to-HTML conversion, built-in themes, template engines (such as Pongo2, Mustache, and Handlebars), and support for deployment to various platforms like GitHub Pages, Netlify, Vercel, and FTP/SFTP.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website. It solves the problem of automating the process of generating static websites from content written in Markdown and YAML. The key capabilities include Markdown-to-HTML conversion, built-in themes, template engines (such as Pongo2, Mustache, and Handlebars), and support for deployment to various platforms like GitHub Pages, Netlify, Vercel, and FTP/SFTP.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs: add comprehensive documentation for templates, configuration, c… by @spagu in <a href="https://github.com/spagu/ssg/pull/24">https://github.com/spagu/ssg/pull/24</a></li>
<li>feat(1.8.4): full i18n, dynamic taxonomies, unified external sources, server access control by @spagu in <a href="https://github.com/spagu/ssg/pull/25">https://github.com/spagu/ssg/pull/25</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.3...v1.8.4">https://github.com/spagu/ssg/compare/v1.8.3...v1.8.4</a></p>
]]></content:encoded></item><item><title>nix init</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/nix-init/</link><pubDate>Wed, 15 Jul 2026 06:40:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/nix-init/</guid><description>Version updated for https://github.com/spotdemo4/nix-init to version v1.58.0.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action automates the initialization of Nix-based repositories by performing several key tasks such as creating a GitHub app token, checking out the repository, setting up Git user information, configuring an optimal Nix environment, installing Nix, and setting Nix configuration from a flake. It also supports caching with Niks3 and loading development shell environments via nicknovitski/nix-develop. The action is designed to run efficiently and works across various runners including self-hosted, Gitea, and Forgejo.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spotdemo4/nix-init">https://github.com/spotdemo4/nix-init</a></strong> to version <strong>v1.58.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nix-init">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action automates the initialization of Nix-based repositories by performing several key tasks such as creating a GitHub app token, checking out the repository, setting up Git user information, configuring an optimal Nix environment, installing Nix, and setting Nix configuration from a flake. It also supports caching with Niks3 and loading development shell environments via <code>nicknovitski/nix-develop</code>. The action is designed to run efficiently and works across various runners including self-hosted, Gitea, and Forgejo.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update dependency NixOS/nix to v2.35.1 (#162) (e59cc89fa80536534c8e6239b65d39ac8c85b0b5)</li>
<li>bump: v1.57.0 -&gt; v1.58.0 (48b6d3dd393260451050b0e6b78bc51fc483d500)</li>
<li>chore(deps): lock file maintenance nix inputs (#161) (6c3518ba1878fdc5166fae8f02a56b7ea87de490)</li>
<li>chore(deps): update github actions to v1.57.0 (#160) (7e51eb91b1026fa110cc8c9ce2dbbb5c8744361c)</li>
</ul>
]]></content:encoded></item><item><title>gw - Go workspaces</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/gw-go-workspaces/</link><pubDate>Wed, 15 Jul 2026 06:37:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/gw-go-workspaces/</guid><description>Version updated for https://github.com/Toyz/gw to version v0.1.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary gw automates the management of Go workspaces by generating and maintaining go.work, lints cross-module dependency versions, and runs commands across every module. It solves the problem of managing multiple Go modules in a workspace, providing tools like init, sync, and lint to bootstrap, update, and validate the workspace configuration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Toyz/gw">https://github.com/Toyz/gw</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gw-go-workspaces">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>gw</code> automates the management of Go workspaces by generating and maintaining <code>go.work</code>, lints cross-module dependency versions, and runs commands across every module. It solves the problem of managing multiple Go modules in a workspace, providing tools like <code>init</code>, <code>sync</code>, and <code>lint</code> to bootstrap, update, and validate the workspace configuration.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Patch release: renames the GitHub Action (<code>action.yml</code> <code>name</code>) to <strong>&ldquo;gw - Go workspaces&rdquo;</strong> so it can be published to the GitHub Marketplace — the Marketplace requires a globally-unique action name and plain <code>gw</code> collided.</p>
<p><strong>Metadata only — no change to the <code>gw</code> binary or the <code>gwext</code> SDK.</strong> Everything in <a href="https://github.com/toyz/gw/releases/tag/v0.1.0">v0.1.0</a> applies.</p>
<h2 id="install">Install</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>go install github.com/toyz/gw@v0.1.1
</span></span></code></pre></div><h2 id="use-in-ci">Use in CI</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/setup-go@v5</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>: { <span style="color:#f92672">go-version</span>: <span style="color:#ae81ff">stable }</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">toyz/gw@v0.1.1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">command</span>: <span style="color:#ae81ff">doctor --strict</span>
</span></span></code></pre></div><p>Full docs: <strong><a href="https://toyz.github.io/gw/">https://toyz.github.io/gw/</a></strong></p>
]]></content:encoded></item><item><title>New Behavioral Health Practices Weekly</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/new-behavioral-health-practices-weekly/</link><pubDate>Wed, 15 Jul 2026 06:36:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/new-behavioral-health-practices-weekly/</guid><description>Version updated for https://github.com/unitedideas/behavioral-health-practice-leads-action to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action downloads the latest Behavioral Health NPI leads from the CMS weekly file. It provides a free preview of 15 current records as clean JSON and can run a full edition in the buyer’s Apify account, charging $9 plus platform usage or refusing to run without both a token and an explicit total-charge cap.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/unitedideas/behavioral-health-practice-leads-action">https://github.com/unitedideas/behavioral-health-practice-leads-action</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/new-behavioral-health-practices-weekly">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action downloads the latest Behavioral Health NPI leads from the CMS weekly file. It provides a free preview of 15 current records as clean JSON and can run a full edition in the buyer&rsquo;s Apify account, charging $9 plus platform usage or refusing to run without both a token and an explicit total-charge cap.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Free previews now produce a source-linked GitHub workflow summary with the delivered count, CMS weekly period, state filter, data limitations, and the explicit $9 full-edition handoff. Full-edition summaries confirm fulfillment without another purchase prompt. State filters now reject non-code input, and repository CI uses current GitHub action runtimes.</p>
]]></content:encoded></item><item><title>PlatformIO Dependency Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/platformio-dependency-updater/</link><pubDate>Wed, 15 Jul 2026 06:35:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/platformio-dependency-updater/</guid><description>Version updated for https://github.com/VIPnytt/platformio-dependency-updater to version v1.0.0-a2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks for dependency updates in a project’s platformio.ini, identifies newer versions, and creates pull requests if available. It supports various dependency sources and provides features like pre-release versions and label application. However, it requires dependencies to be pinned to specific versions and does not support version ranges. The action is designed to manage multiple dependency PRs and handle inactive repositories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VIPnytt/platformio-dependency-updater">https://github.com/VIPnytt/platformio-dependency-updater</a></strong> to version <strong>v1.0.0-a2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/platformio-dependency-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks for dependency updates in a project&rsquo;s <code>platformio.ini</code>, identifies newer versions, and creates pull requests if available. It supports various dependency sources and provides features like pre-release versions and label application. However, it requires dependencies to be pinned to specific versions and does not support version ranges. The action is designed to manage multiple dependency PRs and handle inactive repositories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>Fix module init, rename and update version by @JanPetterMG in <a href="https://github.com/VIPnytt/platformio-dependency-updater/pull/1">https://github.com/VIPnytt/platformio-dependency-updater/pull/1</a></li>
<li>Refactor project into a package by @JanPetterMG in <a href="https://github.com/VIPnytt/platformio-dependency-updater/pull/3">https://github.com/VIPnytt/platformio-dependency-updater/pull/3</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/VIPnytt/platformio-dependency-updater/compare/v1.0.0-a1...v1.0.0-a2">https://github.com/VIPnytt/platformio-dependency-updater/compare/v1.0.0-a1...v1.0.0-a2</a></p>
]]></content:encoded></item><item><title>Zephyr Preview Environments</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/zephyr-preview-environments/</link><pubDate>Wed, 15 Jul 2026 06:35:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/15/zephyr-preview-environments/</guid><description>Version updated for https://github.com/ZephyrCloudIO/zephyr-preview-environment-action to version v0.2.0.
This action is used across all versions by 6 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action automates the creation, update, and cleanup of Zephyr preview environments for pull requests in a GitHub repository. It ensures that every PR gets a live preview deployment with a URL posted as a comment, aiding in code review processes by providing real-time feedback on changes. The action supports both personal and server tokens for authentication, allowing users to choose the most suitable method based on their project’s security requirements.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zephyr-preview-environments">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action automates the creation, update, and cleanup of Zephyr preview environments for pull requests in a GitHub repository. It ensures that every PR gets a live preview deployment with a URL posted as a comment, aiding in code review processes by providing real-time feedback on changes. The action supports both personal and server tokens for authentication, allowing users to choose the most suitable method based on their project&rsquo;s security requirements.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: Configure Renovate by @renovate[bot] in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/7">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/7</a></li>
<li>chore(deps): update dependency ultracite to v6.3.10 by @renovate[bot] in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/16">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/16</a></li>
<li>chore: renovate config by @Nsttt in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/26">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/26</a></li>
<li>chore(deps): update actions/checkout action to v6 by @renovate[bot] in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/28">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/28</a></li>
<li>fix(deps): update all non-major dependencies by @renovate[bot] in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/27">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/27</a></li>
<li>fix(chore): &lsquo;vite&rsquo;: &lsquo;&gt;=7.0.8&rsquo; by @SvetlanaMuravlova in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/39">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/39</a></li>
<li>fix: override qs to &gt;=6.14.1 to resolve CVE-2025-15284 by @arthurfiorette in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/44">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/44</a></li>
<li>fix: update zephyr-agent by @ryok90 in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/45">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/45</a></li>
<li>fix: catch all errors from action by @ryok90 in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/51">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/51</a></li>
<li>fix(chore): vanta by @SvetlanaMuravlova in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/52">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/52</a></li>
<li>Fix PR action fallback and Husky formatter execution by @ryok90 in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/54">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/54</a></li>
<li>fix: remediate package vulnerabilities by @arthurfiorette in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/56">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/56</a></li>
<li>chore(deps): remediate security vulnerabilities by @arthurfiorette in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/59">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/59</a></li>
<li>chore(deps): remediate security vulnerabilities by @Nsttt in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/60">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/60</a></li>
<li>chore: add pnpm workspace security policy by @arthurfiorette in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/64">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/64</a></li>
<li>Sveta/feat vulnerabilities by @SvetlanaMuravlova in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/66">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/66</a></li>
<li>chore(deps): update dependency axios to v1.15.0 [security] by @renovate[bot] in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/65">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/65</a></li>
<li>chore(deps): pin dependencies by @renovate[bot] in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/62">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/62</a></li>
<li>fix(deps): update dependency @actions/github to v9 by @renovate[bot] in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/50">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/50</a></li>
<li>chore(deps): pin dependencies by @renovate[bot] in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/61">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/61</a></li>
<li>chore(deps): update eslint monorepo to v10 (major) by @renovate[bot] in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/49">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/49</a></li>
<li>fix(deps): update dependency @actions/core to v3 by @renovate[bot] in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/47">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/47</a></li>
<li>chore(deps): update node.js to v24 by @renovate[bot] in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/46">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/46</a></li>
<li>chore(deps): update dependency globals to v17 by @renovate[bot] in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/42">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/42</a></li>
<li>chore(deps): update dependency @vitejs/plugin-react-swc to v4 by @renovate[bot] in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/41">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/41</a></li>
<li>chore(deps): update dependency eslint-plugin-react-hooks to v7 by @renovate[bot] in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/34">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/34</a></li>
<li>fix: make preview environment comments collapsible by @ryok90 in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/69">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/69</a></li>
<li>fix(preview-comment): merge multi-app preview rows by @Nsttt in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/72">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/72</a></li>
<li>fix: bump axios to 1.15.1 to resolve prototype pollution alerts by @SvetlanaMuravlova in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/80">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/80</a></li>
<li>fix: bump axios to 1.15.2 to resolve CVE-2026-42264 by @arthurfiorette in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/81">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/81</a></li>
<li>chore(deps): update dependency axios to v1.16.0 [security] by @renovate[bot] in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/73">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/73</a></li>
<li>chore(deps): update dependency vite to v8.0.16 [security] by @renovate[bot] in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/83">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/83</a></li>
<li>fix(deps): remediate follow-redirects advisory (Vanta) by @ryok90 in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/86">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/86</a></li>
<li>chore: bump version for release by @ryok90 in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/88">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/88</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@renovate[bot] made their first contribution in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/7">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/7</a></li>
<li>@SvetlanaMuravlova made their first contribution in <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/39">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/pull/39</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/compare/v0.1.1...v0.2.0">https://github.com/ZephyrCloudIO/zephyr-preview-environment-action/compare/v0.1.1...v0.2.0</a></p>
]]></content:encoded></item><item><title>Prowler Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/prowler-security-scan/</link><pubDate>Tue, 14 Jul 2026 22:48:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/prowler-security-scan/</guid><description>Version updated for https://github.com/prowler-cloud/prowler to version 5.33.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Prowler is an open-source tool designed to automate security and compliance checks in any cloud environment. It offers a wide range of security checks, remediation guidance, and compliance frameworks to help organizations stay secure and compliant with various regulations and standards.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/prowler-cloud/prowler">https://github.com/prowler-cloud/prowler</a></strong> to version <strong>5.33.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/prowler-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Prowler is an open-source tool designed to automate security and compliance checks in any cloud environment. It offers a wide range of security checks, remediation guidance, and compliance frameworks to help organizations stay secure and compliant with various regulations and standards.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="api">API</h2>
<h3 id="-fixed">🐞 Fixed</h3>
<ul>
<li>Attack Paths graph mutations now retry transient Neptune concurrency and deadline failures, while Neo4j mutations use managed transaction retries <a href="https://github.com/prowler-cloud/prowler/pull/11968">(#11968)</a></li>
<li>Attack Paths scans now use bounded child node identifiers for normalized list values in Neo4j and Neptune, preventing Neo4j RANGE index key size failures <a href="https://github.com/prowler-cloud/prowler/pull/11969">(#11969)</a></li>
<li><code>scan-summary</code> aggregation now upserts summaries in deterministic conflict-key order, preventing PostgreSQL deadlocks during concurrent reaggregation <a href="https://github.com/prowler-cloud/prowler/pull/11971">(#11971)</a></li>
</ul>
<h2 id="sdk">SDK</h2>
<h3 id="-fixed-1">🐞 Fixed</h3>
<ul>
<li>EC2 AMI loading now targets Amazon-owned AMIs used by audited instances, reducing AWS API calls during EC2 scans <a href="https://github.com/prowler-cloud/prowler/pull/11958">(#11958)</a></li>
<li><code>ec2_instance_account_imdsv2_enabled</code> findings now use regional resource ARNs, preventing findings from different AWS Regions from collapsing into one resource <a href="https://github.com/prowler-cloud/prowler/pull/11966">(#11966)</a></li>
</ul>
]]></content:encoded></item><item><title>esc-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/esc-action/</link><pubDate>Tue, 14 Jul 2026 22:47:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/esc-action/</guid><description>Version updated for https://github.com/pulumi/esc-action to version v3.1.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 199 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Pulumi ESC action automates the process of securely managing and injecting secrets into GitHub Actions workflows using Pulumi’s Environment, Secrets, and Configuration service. It simplifies the management of sensitive information by providing a seamless integration with popular secret stores and CI/CD platforms, ensuring that secrets are only accessible to the necessary actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pulumi/esc-action">https://github.com/pulumi/esc-action</a></strong> to version <strong>v3.1.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>199</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/esc-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Pulumi ESC action automates the process of securely managing and injecting secrets into GitHub Actions workflows using Pulumi&rsquo;s Environment, Secrets, and Configuration service. It simplifies the management of sensitive information by providing a seamless integration with popular secret stores and CI/CD platforms, ensuring that secrets are only accessible to the necessary actions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s changed</h2>
<p>A backward-compatible release — no changes required to existing workflows. <code>@v3</code> picks these up automatically.</p>
<h3 id="fixes">Fixes</h3>
<ul>
<li><strong>Newline-separated inputs now work</strong> (#52). <code>export-environment-variables</code> and the deprecated <code>keys</code> inputs accept entries separated by commas, newlines, or both — so YAML block scalars (<code>|</code>, one entry per line) work as expected instead of silently failing to export.</li>
<li><strong>Use the <code>pulumi env</code> subcommand instead of the <code>pulumi esc</code> alias</strong> (#48).</li>
<li><strong>Fix the tool-cache extraction directory</strong> (#49).</li>
</ul>
<h3 id="maintenance">Maintenance</h3>
<ul>
<li>Mark <code>dist/</code> as generated for GitHub linguist (#51).</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pulumi/esc-action/compare/v3.0.0...v3.1.0">https://github.com/pulumi/esc-action/compare/v3.0.0...v3.1.0</a></p>
]]></content:encoded></item><item><title>action-semver</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/action-semver/</link><pubDate>Tue, 14 Jul 2026 22:44:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/action-semver/</guid><description>Version updated for https://github.com/quike/action-semantic-release to version v3.15.0.
This action is used across all versions by 5 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action-semantic-release GitHub action automates the process of releasing projects using semantic versioning with semantic-release. It simplifies the release workflow by handling versioning, generating changelogs, and publishing releases to various platforms. This action is particularly useful for open-source projects where continuous integration (CI) and deployment (CD) are automated, ensuring that all team members follow semantic versioning practices.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/quike/action-semantic-release">https://github.com/quike/action-semantic-release</a></strong> to version <strong>v3.15.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/action-semver">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>action-semantic-release</code> GitHub action automates the process of releasing projects using semantic versioning with semantic-release. It simplifies the release workflow by handling versioning, generating changelogs, and publishing releases to various platforms. This action is particularly useful for open-source projects where continuous integration (CI) and deployment (CD) are automated, ensuring that all team members follow semantic versioning practices.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="3150-2026-07-14"><a href="https://github.com/quike/action-semantic-release/compare/v3.14.0...v3.15.0">3.15.0</a> (2026-07-14)</h1>
]]></content:encoded></item><item><title>ZeroPatch CI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/zeropatch-ci/</link><pubDate>Tue, 14 Jul 2026 22:44:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/zeropatch-ci/</guid><description>Version updated for https://github.com/rdx644/ZeroPatch-CI to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates evidence-first security assessments for GitHub Actions workflows by analyzing five high-confidence controls, identifying potential vulnerabilities, and generating a draft remediation artifact. It restricts transformations to approved SHA pins and least-privilege permissions, ensuring secure workflow execution. The action also provides an API that rejects unsupported or ambiguous findings, requiring manual review. The tool runs as a standalone application or Docker container, with options for running locally or in a production environment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rdx644/ZeroPatch-CI">https://github.com/rdx644/ZeroPatch-CI</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zeropatch-ci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates evidence-first security assessments for GitHub Actions workflows by analyzing five high-confidence controls, identifying potential vulnerabilities, and generating a draft remediation artifact. It restricts transformations to approved SHA pins and least-privilege permissions, ensuring secure workflow execution. The action also provides an API that rejects unsupported or ambiguous findings, requiring manual review. The tool runs as a standalone application or Docker container, with options for running locally or in a production environment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Exclude optional self-check workflow from action release (1661e95)</li>
<li>Add reusable GitHub Action (3a53579)</li>
<li>Merge remote-tracking branch &lsquo;origin/main&rsquo; (c389673)</li>
<li>Finalize ZeroPatch CI hardening and deployment (cc83d0f)</li>
<li>Initial commit (3956637)</li>
</ul>
]]></content:encoded></item><item><title>Claude BugBot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/claude-bugbot/</link><pubDate>Tue, 14 Jul 2026 22:43:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/claude-bugbot/</guid><description>Version updated for https://github.com/rekpero/claude-bugbot-github-action to version v1.0.12.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates automated PR bug analysis using Claude Code CLI, providing inline review comments on exact lines where issues are detected. It runs directly on top of Claude Code and is free to use with any Claude Pro or Max subscription without paying for a Cursor subscription. The action focuses only on real bugs and handles large diffs gracefully by truncating at 200KB.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rekpero/claude-bugbot-github-action">https://github.com/rekpero/claude-bugbot-github-action</a></strong> to version <strong>v1.0.12</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/claude-bugbot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates automated PR bug analysis using Claude Code CLI, providing inline review comments on exact lines where issues are detected. It runs directly on top of Claude Code and is free to use with any Claude Pro or Max subscription without paying for a Cursor subscription. The action focuses only on real bugs and handles large diffs gracefully by truncating at 200KB.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="fixed">Fixed</h2>
<ul>
<li><strong>Analysis failed when Claude narrated its findings as prose instead of JSON</strong> — Running as an agent with codebase access, Claude would frequently finish the review correctly (even identifying a real bug) but return a natural-language write-up rather than the required JSON object. <code>parseResponse</code> found no JSON to extract and threw <code>Could not extract JSON from Claude's response</code>; the retry loop then re-ran the <em>identical</em> tool-using prompt, which deterministically produced prose again, so all 3 attempts failed the same way and the completed review was discarded. Two-part fix: (1) a <code>JSON_ONLY_SYSTEM_PROMPT</code> is now appended via <code>--append-system-prompt</code> on the analysis call — a system-prompt contract is followed far more reliably than the same instruction buried at the end of a long agentic user turn; (2) when parsing still fails, a new <code>reformatToJson</code> helper makes a cheap single-turn call (<code>--max-turns 1</code>, fast <code>REFORMAT_MODEL</code>, no tool use) that repackages the prose write-up into the required schema, recovering the review instead of throwing it away. Only if that recovery also fails does the loop fall back to re-running the full analysis. Verified end-to-end against the exact prose from a failing production run — the rate-limiter regression it had described in prose was recovered as well-formed JSON.</li>
</ul>
<h2 id="changed">Changed</h2>
<ul>
<li><strong>Single source of truth for the response schema</strong> — The JSON schema block is now emitted by a shared <code>jsonSchema(hasOpenThreads)</code> helper used by both <code>buildPrompt</code> and <code>reformatToJson</code>, so the recovery pass always targets the identical shape the analysis was asked for.</li>
<li><strong><code>analyze.mjs</code> is importable for testing</strong> — <code>main()</code> now runs only when the file is executed directly (<code>node analyze.mjs</code>), guarded by an <code>import.meta.url</code> check, and the core functions are exported. Production invocation is unchanged.</li>
</ul>
]]></content:encoded></item><item><title>Remyx Outrider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/remyx-outrider/</link><pubDate>Tue, 14 Jul 2026 22:42:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/remyx-outrider/</guid><description>Version updated for https://github.com/remyxai/outrider to version v1.7.24.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the validation and comparison of new methods against an organization’s codebase by integrating them into real call sites, providing a self-review process and handling issues when preflight, validators, or self-review routes the paper to discussion. It supports various model backends like Anthropic Opus and z.ai GLM-5.2 for different scenarios, including exploration and branch-mode exploration. The action is designed to streamline the workflow by running coding agents in ephemeral runners and handling multiple candidates per week efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remyxai/outrider">https://github.com/remyxai/outrider</a></strong> to version <strong>v1.7.24</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/remyx-outrider">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the validation and comparison of new methods against an organization&rsquo;s codebase by integrating them into real call sites, providing a self-review process and handling issues when preflight, validators, or self-review routes the paper to discussion. It supports various model backends like Anthropic Opus and z.ai GLM-5.2 for different scenarios, including exploration and branch-mode exploration. The action is designed to streamline the workflow by running coding agents in ephemeral runners and handling multiple candidates per week efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changes">Changes</h2>
<p><strong>Path guardrails: permissive-by-default.</strong> Every landed diff already runs through human review + coordination-issue-first policy + <code>check_integration</code> + <code>stub_density</code> + <code>diff_risk_score</code> — path-pattern allowlisting duplicated those checks and generated false negatives across every fork we touched (task YAML in lm-evaluation-harness, adapter JSON in peft&rsquo;s method_comparison, <code>.gitignore</code> in training-pipeline branches, <code>uv.lock</code> during dep-add).</p>
<ul>
<li><code>DEFAULT_ALLOWLIST_GLOBS</code> = <code>[&quot;**/*&quot;]</code> — everything matches.</li>
<li><code>ALWAYS_BLOCKED</code> reduced to <code>.github/workflows/**</code> only. This is the one class where agent edits could silently expand a run&rsquo;s own future agency (permissions, interest-id, concurrency, secrets). Every other former block is now surfaced to human review in the standard PR diff.</li>
<li><code>guardrails-allowlist</code> input: <strong>deprecated no-op</strong>. Reads through for backwards compat, logs a deprecation warning when non-empty. Removal planned in v2.</li>
<li><code>guardrails-blocklist</code> input: <strong>new</strong>, empty default. Extends <code>ALWAYS_BLOCKED</code> for teams that want defense-in-depth (<code>secrets/**</code>, <code>*.lock</code>, <code>Dockerfile*</code>, etc.). Matches take precedence over the permissive allowlist.</li>
</ul>
<p><strong>Higher <code>claude-timeout</code> default.</strong> Raised from 900s → 1500s. GLM sessions with staged-synthesis routinely reach 15-20 min; users triggering runs without prior tuning were hitting the old 15-min ceiling. Opus refinement sits comfortably under 25 min at the new default.</p>
<h2 id="migration">Migration</h2>
<ul>
<li>Existing customer workflows keep working — <code>guardrails-allowlist</code> inputs are ignored with a warning.</li>
<li>Teams that want the old strict behavior set <code>guardrails-blocklist</code> to whatever files their policy protects. E.g. to restore the pre-v1.7.24 defaults: <code>guardrails-blocklist: 'Dockerfile*,*Dockerfile.*,*.dockerfile,*.sh,*requirements*.txt,setup.py,setup.cfg,pyproject.toml,MANIFEST.in,*.lock'</code>.</li>
</ul>
<h2 id="tests">Tests</h2>
<p>1033 tests pass, 1 skipped. <code>test_path_matching.py</code> rewritten around permissive-allowlist + workflow-only-blocklist semantics; <code>test_integration_gates.py</code> updated.</p>
]]></content:encoded></item><item><title>codemetrics complexity gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/codemetrics-complexity-gate/</link><pubDate>Tue, 14 Jul 2026 22:41:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/codemetrics-complexity-gate/</guid><description>Version updated for https://github.com/richardwooding/codemetrics to version v0.12.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action checks pull requests to ensure they do not introduce functions with high cyclomatic or cognitive complexity, using code metrics for multiple programming languages. It automates the computation of these metrics and integrates into GitHub workflows to gate out complex changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/richardwooding/codemetrics">https://github.com/richardwooding/codemetrics</a></strong> to version <strong>v0.12.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/codemetrics-complexity-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action checks pull requests to ensure they do not introduce functions with high cyclomatic or cognitive complexity, using code metrics for multiple programming languages. It automates the computation of these metrics and integrates into GitHub workflows to gate out complex changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<h3 id="others">Others</h3>
<ul>
<li>3da655b0b5e1b7de198a318afe2ba1c65b319cbf: chore(deps): Bump github.com/odvcencio/gotreesitter (#25) (@dependabot[bot])</li>
<li>29038939bd7fb8b0a76769a1766c4e428b5e7027: chore(site): sync gloam assets to f5ac1871af22055721843d5ba24b1c894978871a (#26) (@github-actions[bot])</li>
</ul>
]]></content:encoded></item><item><title>file-search-on review gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/file-search-on-review-gate/</link><pubDate>Tue, 14 Jul 2026 22:39:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/file-search-on-review-gate/</guid><description>Version updated for https://github.com/richardwooding/file-search-on to version v0.119.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The file-search-on action automates file searches based on metadata and content types using CEL expressions. It helps find files that match specific criteria, such as PDFs with more than 10 pages or images taken in a certain area. The tool supports 74 formats across 13 content type families and is designed to be used in both Claude Code and the command line.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/richardwooding/file-search-on">https://github.com/richardwooding/file-search-on</a></strong> to version <strong>v0.119.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/file-search-on-review-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>file-search-on</code> action automates file searches based on metadata and content types using CEL expressions. It helps find files that match specific criteria, such as PDFs with more than 10 pages or images taken in a certain area. The tool supports 74 formats across 13 content type families and is designed to be used in both Claude Code and the command line.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<h3 id="others">Others</h3>
<ul>
<li>bccf7ed71443d5fe0670569b0e3f23ef9ed04369 chore(deps): Bump actions/checkout from 4 to 7 (#560)</li>
<li>8cba2f3aca69457536a2a36baeb0e786cf69ecab chore(deps): Bump github.com/richardwooding/go-coupling (#561)</li>
<li>5d2897c8c0a352593316c269d1d9fad6e48001b1 chore(site): sync gloam assets to f5ac1871af22055721843d5ba24b1c894978871a (#562)</li>
</ul>
]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/rumdl-action/</link><pubDate>Tue, 14 Jul 2026 22:38:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.33.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary
rumdl is a high-performance Markdown linter and formatter written in Rust, designed to speed up linting tasks with its Rust-based implementation. It includes 76 lint rules covering common Markdown issues and offers automatic formatting with the --fix flag for files and stdin/stdout. The tool supports multiple Markdown flavors, is zero-dependency, highly configurable, and has a modern CLI interface with detailed error reporting.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.33</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary</strong></p>
<p>rumdl is a high-performance Markdown linter and formatter written in Rust, designed to speed up linting tasks with its Rust-based implementation. It includes 76 lint rules covering common Markdown issues and offers automatic formatting with the <code>--fix</code> flag for files and stdin/stdout. The tool supports multiple Markdown flavors, is zero-dependency, highly configurable, and has a modern CLI interface with detailed error reporting.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>md044</strong>: stop flagging proper names inside bare URLs (<a href="https://github.com/rvben/rumdl/commit/5e9b51a9936b9e009a332914951b1b89d91c4655">5e9b51a</a>)</li>
<li><strong>md040</strong>: recognize file-extension fence labels as known languages (<a href="https://github.com/rvben/rumdl/commit/686ba20b9bfa573cf6fdd66193a0736f3f50cbd0">686ba20</a>)</li>
<li><strong>cli</strong>: replace unhelpful panic message with an actionable one (#717) (<a href="https://github.com/rvben/rumdl/commit/37ac880b9804322dee3523e200592b3e4d82d524">37ac880</a>)</li>
<li><strong>reflow</strong>: re-search cached inline-math after a dollar sign (<a href="https://github.com/rvben/rumdl/commit/a30a4f97cd0328e60347e402b3332e2bf896741e">a30a4f9</a>)</li>
<li><strong>reflow</strong>: support multiple backticks and optimize code span parsing (<a href="https://github.com/rvben/rumdl/commit/81944c5addd6579b729f438c8768cedd55a2816d">81944c5</a>)</li>
<li><strong>md013</strong>: stop reflow from starting lines with block markers (<a href="https://github.com/rvben/rumdl/commit/eebd18b751bfe880e5a16fab8544e07070f08de2">eebd18b</a>)</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li><strong>reflow</strong>: implement cached match lookups to prevent quadratic suffix scanning (<a href="https://github.com/rvben/rumdl/commit/1cc8d2bc6ea3b37848ab4253cb1059bc7e77b69e">1cc8d2b</a>)</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.33/rumdl-v0.2.33-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.33-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.33/rumdl-v0.2.33-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.33/rumdl-v0.2.33-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.33-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.33/rumdl-v0.2.33-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.33/rumdl-v0.2.33-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.33-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.33/rumdl-v0.2.33-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.33/rumdl-v0.2.33-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.33-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.33/rumdl-v0.2.33-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.33/rumdl-v0.2.33-x86_64-apple-darwin.tar.gz">rumdl-v0.2.33-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.33/rumdl-v0.2.33-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.33/rumdl-v0.2.33-aarch64-apple-darwin.tar.gz">rumdl-v0.2.33-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.33/rumdl-v0.2.33-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.33/rumdl-v0.2.33-x86_64-pc-windows-msvc.zip">rumdl-v0.2.33-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.33/rumdl-v0.2.33-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>SchemaCrawler (Local) Action for GitHub Actions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/schemacrawler-local-action-for-github-actions/</link><pubDate>Tue, 14 Jul 2026 22:37:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/schemacrawler-local-action-for-github-actions/</guid><description>Version updated for https://github.com/schemacrawler/SchemaCrawler-Local-Action to version v17.12.1.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the generation of a database schema report using SchemaCrawler, a tool for discovering and documenting databases. It installs SchemaCrawler locally on the runner and allows users to specify database connection details such as URL, user, password, and driver class. The report can be generated as a CSV file or in XML format, providing insights into the database structure.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/schemacrawler/SchemaCrawler-Local-Action">https://github.com/schemacrawler/SchemaCrawler-Local-Action</a></strong> to version <strong>v17.12.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/schemacrawler-local-action-for-github-actions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the generation of a database schema report using SchemaCrawler, a tool for discovering and documenting databases. It installs SchemaCrawler locally on the runner and allows users to specify database connection details such as URL, user, password, and driver class. The report can be generated as a CSV file or in XML format, providing insights into the database structure.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>SchemaCrawler (Local) Action v17.12.1 release at last commit 2b2e44f1008e1c588b5383ba7df14d23dcdee520
See the change history at <a href="https://www.schemacrawler.com/changes-report.html">https://www.schemacrawler.com/changes-report.html</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump actions/checkout from 6 to 7 by @dependabot[bot] in <a href="https://github.com/schemacrawler/SchemaCrawler-Local-Action/pull/3">https://github.com/schemacrawler/SchemaCrawler-Local-Action/pull/3</a></li>
<li>v17.12.1 by @sualeh in <a href="https://github.com/schemacrawler/SchemaCrawler-Local-Action/pull/4">https://github.com/schemacrawler/SchemaCrawler-Local-Action/pull/4</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/schemacrawler/SchemaCrawler-Local-Action/pull/3">https://github.com/schemacrawler/SchemaCrawler-Local-Action/pull/3</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/schemacrawler/SchemaCrawler-Local-Action/compare/v17.11.4...v17.12.1">https://github.com/schemacrawler/SchemaCrawler-Local-Action/compare/v17.11.4...v17.12.1</a></p>
]]></content:encoded></item><item><title>SFDT for Salesforce</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/sfdt-for-salesforce/</link><pubDate>Tue, 14 Jul 2026 22:37:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/sfdt-for-salesforce/</guid><description>Version updated for https://github.com/scoobydrew83/sfdt to version v0.18.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The SFDT GitHub Action automates Salesforce deployment and testing processes, including interactive workflows, automated release manifest generation, parallel Apex test execution, code and test quality analysis, pre-release validation checklist, deployment rollback, post-deploy smoke testing, org metadata drift detection, multi-package project support, smart package.xml generator, AI deployment error log interpreter, AI-generated PR descriptions and Slack messages, AI-powered code review, test failure analysis, changelog generation, release notes, org metadata comparison, local web dashboard, smart delta deployments, native org health &amp;amp; operations suite, CI/CD pipeline templates, multi-channel notifications, plugin architecture, and compatibility with any Salesforce DX project.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/scoobydrew83/sfdt">https://github.com/scoobydrew83/sfdt</a></strong> to version <strong>v0.18.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sfdt-for-salesforce">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The SFDT GitHub Action automates Salesforce deployment and testing processes, including interactive workflows, automated release manifest generation, parallel Apex test execution, code and test quality analysis, pre-release validation checklist, deployment rollback, post-deploy smoke testing, org metadata drift detection, multi-package project support, smart package.xml generator, AI deployment error log interpreter, AI-generated PR descriptions and Slack messages, AI-powered code review, test failure analysis, changelog generation, release notes, org metadata comparison, local web dashboard, smart delta deployments, native org health &amp; operations suite, CI/CD pipeline templates, multi-channel notifications, plugin architecture, and compatibility with any Salesforce DX project.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Sprint 1: gap fixes, deploy manifest detection, Salesforce release research plan by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/171">https://github.com/scoobydrew83/sfdt/pull/171</a></li>
<li>Sprint 2: VS Code uplift — native results, diagnostics, smart-deploy preview, onboarding by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/172">https://github.com/scoobydrew83/sfdt/pull/172</a></li>
<li>Sprint 3: API v67 readiness, new org checks, annotation-aware tests, GUI run actions, VS Code coverage by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/174">https://github.com/scoobydrew83/sfdt/pull/174</a></li>
<li>4.7 tail: warn on cross-org Salesforce release mismatch in compare/retrofit by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/175">https://github.com/scoobydrew83/sfdt/pull/175</a></li>
<li>docs: reconcile ROADMAP/plan status + verified RunRelevantTests-still-Beta note by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/176">https://github.com/scoobydrew83/sfdt/pull/176</a></li>
<li>Sprint 4: unified logic tests, Code Analyzer v5, MCP read-only tools + CI cleanup by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/177">https://github.com/scoobydrew83/sfdt/pull/177</a></li>
<li>Agentforce metadata + agent-test gate + npx-skills pack export by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/181">https://github.com/scoobydrew83/sfdt/pull/181</a></li>
<li>chore(deps): bump the production-dependencies group with 3 updates by @dependabot[bot] in <a href="https://github.com/scoobydrew83/sfdt/pull/178">https://github.com/scoobydrew83/sfdt/pull/178</a></li>
<li>chore(deps): bump the development-dependencies group across 1 directory with 7 updates by @dependabot[bot] in <a href="https://github.com/scoobydrew83/sfdt/pull/179">https://github.com/scoobydrew83/sfdt/pull/179</a></li>
<li>Chrome extension: Flow Scanner + Dependency Explorer cross-link + org release badge by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/183">https://github.com/scoobydrew83/sfdt/pull/183</a></li>
<li>Native-host read-only kinds + Dependency Explorer on real pages by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/184">https://github.com/scoobydrew83/sfdt/pull/184</a></li>
<li>Cross-surface expansion: VS Code depth, CLI test/history, MCP mutating tools, GUI pages, extension fix by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/185">https://github.com/scoobydrew83/sfdt/pull/185</a></li>
<li>perf(docs): concurrent Apex file reads in doc generation by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/182">https://github.com/scoobydrew83/sfdt/pull/182</a></li>
<li>chore(deps): bump @types/node from 22.20.0 to 25.9.4 by @dependabot[bot] in <a href="https://github.com/scoobydrew83/sfdt/pull/180">https://github.com/scoobydrew83/sfdt/pull/180</a></li>
<li>chore: relicense from MIT to Apache-2.0 by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/189">https://github.com/scoobydrew83/sfdt/pull/189</a></li>
<li>feat: notify on smart deploys, SARIF quality output, and an LWC test runner by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/191">https://github.com/scoobydrew83/sfdt/pull/191</a></li>
<li>Audit and refresh the bundled agent skills by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/192">https://github.com/scoobydrew83/sfdt/pull/192</a></li>
<li>Promote develop → main for v0.17.0 by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/194">https://github.com/scoobydrew83/sfdt/pull/194</a></li>
<li>Truth corrections: license strings, stale counts, dead claims by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/195">https://github.com/scoobydrew83/sfdt/pull/195</a></li>
<li>Hardening: Action shell-eval, host logDir, &ndash;wait validation, analyzer v4 policy by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/200">https://github.com/scoobydrew83/sfdt/pull/200</a></li>
<li>Fix cleanup-pr-beta failing on every PR close (unexported env vars) by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/201">https://github.com/scoobydrew83/sfdt/pull/201</a></li>
<li>fix(action): shorten Marketplace description to under 125 chars by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/199">https://github.com/scoobydrew83/sfdt/pull/199</a></li>
<li>Surface catalog framework: generated inventories + drift/consistency CI by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/202">https://github.com/scoobydrew83/sfdt/pull/202</a></li>
<li>Docs rewrite: ARCHITECTURE, ROADMAP, RELEASING + README de-inventory by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/204">https://github.com/scoobydrew83/sfdt/pull/204</a></li>
<li>API-version audit: sfdt versions command + extended audit check + Chrome feature by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/205">https://github.com/scoobydrew83/sfdt/pull/205</a></li>
<li>Registry-grounded AI upgrade advisor: sfdt versions &ndash;advise (phase 2) by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/206">https://github.com/scoobydrew83/sfdt/pull/206</a></li>
<li>Audit + expand the API-version registry (v64–v67 in depth, all claims source-verified) by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/207">https://github.com/scoobydrew83/sfdt/pull/207</a></li>
<li>Pre-release: fix VS Code surface parity + expand registry (v60–v63) by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/208">https://github.com/scoobydrew83/sfdt/pull/208</a></li>
<li>chore: release v0.18.0 by @scoobydrew83 in <a href="https://github.com/scoobydrew83/sfdt/pull/209">https://github.com/scoobydrew83/sfdt/pull/209</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/scoobydrew83/sfdt/compare/v0.17.0...v0.18.0">https://github.com/scoobydrew83/sfdt/compare/v0.17.0...v0.18.0</a></p>
]]></content:encoded></item><item><title>Shieldly — AI-Powered Security Analysis</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/shieldly-ai-powered-security-analysis/</link><pubDate>Tue, 14 Jul 2026 22:35:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/shieldly-ai-powered-security-analysis/</guid><description>Version updated for https://github.com/shieldly-io/action to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action uses AI-powered security analysis to identify and report potential security vulnerabilities in AWS infrastructure defined by CloudFormation templates or CDK stacks. It checks IAM policies, posts findings as a PR comment, and fails the build if issues meet a severity threshold set by the user. The action requires an API key for authentication and is suitable for use in CI environments to ensure secure deployment practices.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/shieldly-io/action">https://github.com/shieldly-io/action</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/shieldly-ai-powered-security-analysis">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action uses AI-powered security analysis to identify and report potential security vulnerabilities in AWS infrastructure defined by CloudFormation templates or CDK stacks. It checks IAM policies, posts findings as a PR comment, and fails the build if issues meet a severity threshold set by the user. The action requires an API key for authentication and is suitable for use in CI environments to ensure secure deployment practices.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>See <a href="https://github.com/shieldly-io/shieldly">https://github.com/shieldly-io/shieldly</a> for full changelog.</p>
]]></content:encoded></item><item><title>Console CensorChecker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/console-censorchecker/</link><pubDate>Tue, 14 Jul 2026 22:34:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/console-censorchecker/</guid><description>Version updated for https://github.com/SpaceTimee/Console-CensorChecker to version 1.1.4.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Console-CensorChecker GitHub Action automates the process of checking for network censorship by performing TCP ping tests on specified domains or IP addresses and provides a simple interface for developers to integrate this functionality into their workflows. It helps identify if a domain or service is blocked by content filters or other security measures, ensuring that applications can operate smoothly in environments with restricted access.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SpaceTimee/Console-CensorChecker">https://github.com/SpaceTimee/Console-CensorChecker</a></strong> to version <strong>1.1.4.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/console-censorchecker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Console-CensorChecker GitHub Action automates the process of checking for network censorship by performing TCP ping tests on specified domains or IP addresses and provides a simple interface for developers to integrate this functionality into their workflows. It helps identify if a domain or service is blocked by content filters or other security measures, ensuring that applications can operate smoothly in environments with restricted access.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ol>
<li>添加页面就绪等待中的按需注入</li>
</ol>
]]></content:encoded></item><item><title>Graveyard Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/graveyard-check/</link><pubDate>Tue, 14 Jul 2026 22:32:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/graveyard-check/</guid><description>Version updated for https://github.com/TahaKotwal12/graveyard-check to version v0.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Graveyard Check automates the discovery and recommendation of maintainers for abandoned dependencies, helping users identify packages that are effectively dead. It provides a comprehensive scan of project dependencies across various ecosystems (npm, PyPI) to determine which ones may require migration, offering verified community successors as recommendations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TahaKotwal12/graveyard-check">https://github.com/TahaKotwal12/graveyard-check</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/graveyard-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Graveyard Check automates the discovery and recommendation of maintainers for abandoned dependencies, helping users identify packages that are effectively dead. It provides a comprehensive scan of project dependencies across various ecosystems (npm, PyPI) to determine which ones may require migration, offering verified community successors as recommendations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Add GitHub contribution templates and issue bootstrap script. (de88857)</li>
<li>Refactor command display in App component: update CLI commands to use &rsquo;npm i graveyard-check&rsquo; and reorganize layout for better user experience. Modify section titles for clarity. (0125547)</li>
<li>Update package.json files: change repository URL format in root package.json and add dependencies and devDependencies in website package.json for improved project structure and functionality. (d5e67a2)</li>
<li>Rename project from &lsquo;Lifeboat&rsquo; to &lsquo;Graveyard Check&rsquo;, updating all relevant files and references. Modify action.yml, README, and documentation to reflect the new name and functionality. Add website structure for marketing and documentation. Update CLI commands and error messages accordingly. (deebb75)</li>
<li>Add project structure with essential files including .gitignore, README, configuration files, and GitHub Actions for CI. Implement core functionality for dependency scanning and successor recommendations. (ffa9b31)</li>
<li>first commit (e7c3bcf)</li>
</ul>
]]></content:encoded></item><item><title>Set up Rocq</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/set-up-rocq/</link><pubDate>Tue, 14 Jul 2026 22:31:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/set-up-rocq/</guid><description>Version updated for https://github.com/tchajed/setup-rocq to version v1.8.0.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the installation of Rocq using OPAM with caching capabilities to speed up future installations, especially for developers who frequently work on projects that depend on Rocq. It supports specifying a specific version or the latest stable release of Rocq, as well as additional OPAM repositories and customizing which OPAM files are used to generate a cache key.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tchajed/setup-rocq">https://github.com/tchajed/setup-rocq</a></strong> to version <strong>v1.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/set-up-rocq">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the installation of Rocq using OPAM with caching capabilities to speed up future installations, especially for developers who frequently work on projects that depend on Rocq. It supports specifying a specific version or the latest stable release of Rocq, as well as additional OPAM repositories and customizing which OPAM files are used to generate a cache key.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s changed</h2>
<ul>
<li>Fixed installation of Rocq ≥ 9.2: specific <code>rocq-version</code> values now install via <code>rocq-core.&lt;version&gt;</code> with an unconstrained <code>rocq-stdlib</code>, instead of the <code>coq</code> compat metapackage, which stopped being published at 9.1.1 (#70). Versions starting with <code>8.</code> continue to use <code>coq.&lt;version&gt;</code>.</li>
<li><code>rocq-version: latest</code> now resolves to the actual latest release (currently 9.2.0) via <code>rocq-core</code> + <code>rocq-stdlib</code>, rather than the stale <code>coq</code> metapackage (#70).</li>
<li><code>pin-depends</code> handling now recognizes <code>rocq-core</code>, <code>rocq-runtime</code>, and <code>rocq-stdlib</code> pins: they get the same install-override treatment as <code>coq</code> pins and are included in the cache key (#70).</li>
</ul>
<p>The major version tag <code>v1</code> has been updated to point at this release.</p>
]]></content:encoded></item><item><title>cargo-oxidate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/cargo-oxidate/</link><pubDate>Tue, 14 Jul 2026 22:30:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/cargo-oxidate/</guid><description>Version updated for https://github.com/timweri/cargo-oxidate to version v0.1.8.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks Cargo.lock for packages that are either too new (potentially introducing vulnerabilities) or too old (stale). It automates the process of identifying and flagging these packages based on specified age thresholds. The action also provides options to exempt certain packages, handle missing publish dates, and include caching features for improved performance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/timweri/cargo-oxidate">https://github.com/timweri/cargo-oxidate</a></strong> to version <strong>v0.1.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cargo-oxidate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks <code>Cargo.lock</code> for packages that are either too new (potentially introducing vulnerabilities) or too old (stale). It automates the process of identifying and flagging these packages based on specified age thresholds. The action also provides options to exempt certain packages, handle missing publish dates, and include caching features for improved performance.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump v0.1.8 by @timweri in <a href="https://github.com/timweri/cargo-oxidate/pull/7">https://github.com/timweri/cargo-oxidate/pull/7</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/timweri/cargo-oxidate/compare/v0.1.7...v0.1.8">https://github.com/timweri/cargo-oxidate/compare/v0.1.7...v0.1.8</a></p>
]]></content:encoded></item><item><title>Build Beet project</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/build-beet-project/</link><pubDate>Tue, 14 Jul 2026 22:30:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/build-beet-project/</guid><description>Version updated for https://github.com/Trioplane/action-build-beet-project to version v5-beta3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the build process for a Beet project, generating data packs, resource packs, and unknown files. It outputs these as JSON arrays and the built directory. The action can be used to streamline the release of Beetle projects by creating ZIP archives of the generated content and uploading them to GitHub releases.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Trioplane/action-build-beet-project">https://github.com/Trioplane/action-build-beet-project</a></strong> to version <strong>v5-beta3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/build-beet-project">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the build process for a Beet project, generating data packs, resource packs, and unknown files. It outputs these as JSON arrays and the built directory. The action can be used to streamline the release of Beetle projects by creating ZIP archives of the generated content and uploading them to GitHub releases.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>oh come on (4a7cf21)</li>
<li>gawd damn rahh (8718566)</li>
<li>come on please tell me this works (97f1935)</li>
<li>aeaea (38bfa81)</li>
<li>forgor to rollup (38c6129)</li>
<li>dont zip (027fef8)</li>
<li>Respect beet dir more (e5e5165)</li>
<li>more examples (eae927c)</li>
<li>cleanup (de356d1)</li>
<li>fix outputs (359645b)</li>
</ul>
]]></content:encoded></item><item><title>Symfony Security Auditor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/symfony-security-auditor/</link><pubDate>Tue, 14 Jul 2026 22:29:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/symfony-security-auditor/</guid><description>Version updated for https://github.com/vinceAmstoutz/symfony-security-auditor to version 1.15.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Symfony Security Auditor is an AI-powered multi-agent security auditor for Symfony applications that targets application-level logic flaws missed by traditional SAST tools. It uses an adversarial Attacker agent to find vulnerabilities and a skeptical Reviewer agent to cull false positives, emitting validated reports in various formats. The standalone CLI or Symfony bundle can be used to audit projects with minimal footprint.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vinceAmstoutz/symfony-security-auditor">https://github.com/vinceAmstoutz/symfony-security-auditor</a></strong> to version <strong>1.15.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/symfony-security-auditor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Symfony Security Auditor is an AI-powered multi-agent security auditor for Symfony applications that targets application-level logic flaws missed by traditional SAST tools. It uses an adversarial Attacker agent to find vulnerabilities and a skeptical Reviewer agent to cull false positives, emitting validated reports in various formats. The standalone CLI or Symfony bundle can be used to audit projects with minimal footprint.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(command): add mcp:serve MCP server exposing the auditor as a tool by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/162">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/162</a></li>
<li>fix(standalone): resolve the provider bridge for the binary&rsquo;s bundled PHP by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/164">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/164</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/compare/1.14.0...1.15.0">https://github.com/vinceAmstoutz/symfony-security-auditor/compare/1.14.0...1.15.0</a></p>
]]></content:encoded></item><item><title>PlatformIO Dependency Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/platformio-dependency-updater/</link><pubDate>Tue, 14 Jul 2026 22:28:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/platformio-dependency-updater/</guid><description>Version updated for https://github.com/VIPnytt/platformio-dependency-updater to version v1.0.0-a1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The PlatformIO Dependency Updater is a GitHub Action that checks for updates to dependencies listed in the platformio.ini file of a project. It automates the process of creating pull requests when newer versions are available, resolving issues such as unresolved dependencies and providing links to release notes and changelogs. The action supports multiple dependency sources and keeps track of open dependency pull requests to avoid duplicates and ensure updates remain current.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VIPnytt/platformio-dependency-updater">https://github.com/VIPnytt/platformio-dependency-updater</a></strong> to version <strong>v1.0.0-a1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/platformio-dependency-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The PlatformIO Dependency Updater is a GitHub Action that checks for updates to dependencies listed in the <code>platformio.ini</code> file of a project. It automates the process of creating pull requests when newer versions are available, resolving issues such as unresolved dependencies and providing links to release notes and changelogs. The action supports multiple dependency sources and keeps track of open dependency pull requests to avoid duplicates and ensure updates remain current.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial release.</p>
]]></content:encoded></item><item><title>install spaces</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/install-spaces/</link><pubDate>Tue, 14 Jul 2026 22:27:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/install-spaces/</guid><description>Version updated for https://github.com/work-spaces/install-spaces to version v0.19.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the installation of Spaces, a cloud-based platform for developers. It simplifies the setup process by handling dependencies and configurations automatically, ensuring that new environments or projects are ready for development with minimal manual intervention.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/work-spaces/install-spaces">https://github.com/work-spaces/install-spaces</a></strong> to version <strong>v0.19.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-spaces">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the installation of Spaces, a cloud-based platform for developers. It simplifies the setup process by handling dependencies and configurations automatically, ensuring that new environments or projects are ready for development with minimal manual intervention.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump version to v0.19.0 by @tyler-gilbert in <a href="https://github.com/work-spaces/install-spaces/pull/36">https://github.com/work-spaces/install-spaces/pull/36</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/work-spaces/install-spaces/compare/v0.18.0...v0.19.0">https://github.com/work-spaces/install-spaces/compare/v0.18.0...v0.19.0</a></p>
]]></content:encoded></item><item><title>spaces checkout run</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/spaces-checkout-run/</link><pubDate>Tue, 14 Jul 2026 22:27:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/spaces-checkout-run/</guid><description>Version updated for https://github.com/work-spaces/spaces-checkout-run to version v0.19.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action for executing a spaces checkout/spaces run sequence using the spaces CLI automates the process of checking out and running a workspace on GitHub Actions. It solves the problem of integrating workspace deployment into CI/CD pipelines, providing users with a simple way to automate the setup and execution of workspaces using the spaces CLI. The action is particularly useful for developers who need to build, test, or deploy workspaces in their CI/CD processes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/work-spaces/spaces-checkout-run">https://github.com/work-spaces/spaces-checkout-run</a></strong> to version <strong>v0.19.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spaces-checkout-run">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action for executing a <code>spaces checkout</code>/<code>spaces run</code> sequence using the <a href="https://github.com/work-spaces/spaces">spaces</a> CLI automates the process of checking out and running a workspace on GitHub Actions. It solves the problem of integrating workspace deployment into CI/CD pipelines, providing users with a simple way to automate the setup and execution of workspaces using the <code>spaces</code> CLI. The action is particularly useful for developers who need to build, test, or deploy workspaces in their CI/CD processes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump version to v0.19.0 by @tyler-gilbert in <a href="https://github.com/work-spaces/spaces-checkout-run/pull/30">https://github.com/work-spaces/spaces-checkout-run/pull/30</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/work-spaces/spaces-checkout-run/compare/v0.18.0...v0.19.0">https://github.com/work-spaces/spaces-checkout-run/compare/v0.18.0...v0.19.0</a></p>
]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/cowork-harness/</link><pubDate>Tue, 14 Jul 2026 22:27:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.0.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action creates a headless test harness for Claude Cowork skills. It allows developers to reproduce the observable runtime contract of the platform closely enough for automated testing across various scenarios and CI jobs without needing a locked Desktop app. The action supports different fidelity tiers, including a free demo (replay), linting with python3, live tiers requiring Claude Desktop, token, Docker, or Lima, and provides debugging tools to understand session outputs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action creates a headless test harness for Claude Cowork skills. It allows developers to reproduce the observable runtime contract of the platform closely enough for automated testing across various scenarios and CI jobs without needing a locked Desktop app. The action supports different fidelity tiers, including a free demo (<code>replay</code>), linting with <code>python3</code>, live tiers requiring Claude Desktop, token, Docker, or Lima, and provides debugging tools to understand session outputs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Patch: parity sync to Claude Desktop <code>1.20186.9</code>. No runtime/API change.</p>
<h3 id="changed">Changed</h3>
<ul>
<li>Synced the platform baseline to Claude Desktop <code>1.20186.9</code>
(<code>baselines/desktop-1.20186.9.json</code>, now what <code>baseline: latest</code> resolves to). A routine
per-release parity refresh: the app version, the native agent staging path, and the asar
fingerprint moved; the Cowork system prompt, egress allowlist, gate states, and agent (VM)
version are unchanged from <code>1.20186.1</code>. README and the companion skill&rsquo;s baseline pointer were
updated to match.</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>release: 1.0.3 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/45">https://github.com/yaniv-golan/cowork-harness/pull/45</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.0.3">https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.0.3</a></p>
]]></content:encoded></item><item><title>Delete Old GitHub Actions Runs</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/delete-old-github-actions-runs/</link><pubDate>Tue, 14 Jul 2026 22:25:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/delete-old-github-actions-runs/</guid><description>Version updated for https://github.com/yanovation/delete-old-actions to version v1.0.7.
This action is used across all versions by 39 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action deletes old GitHub Actions runs to keep repositories clean. It automates the process of removing unnecessary runs, helping maintain a tidy repository history. Users can set parameters like the number of days ago and how many latest runs should be kept. The action also provides a dry-run option to preview what will be deleted before executing the deletion.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yanovation/delete-old-actions">https://github.com/yanovation/delete-old-actions</a></strong> to version <strong>v1.0.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>39</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/delete-old-github-actions-runs">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action deletes old GitHub Actions runs to keep repositories clean. It automates the process of removing unnecessary runs, helping maintain a tidy repository history. Users can set parameters like the number of days ago and how many latest runs should be kept. The action also provides a dry-run option to preview what will be deleted before executing the deletion.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This release shows the deprecated warning to users and instructs them how to upgrade</p>
]]></content:encoded></item><item><title>Prune Old GitHub Actions Runs</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/prune-old-github-actions-runs/</link><pubDate>Tue, 14 Jul 2026 22:24:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/prune-old-github-actions-runs/</guid><description>Version updated for https://github.com/yanovian/delete-old-actions to version v1.0.11.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This action deletes old GitHub Actions runs in your repository to keep it clean. It helps automate tasks like managing large run logs and reducing costs associated with long-running actions. The action can be configured to delete runs based on age or retain a certain number of the most recent runs, making it useful for maintaining a clean and efficient workflow.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yanovian/delete-old-actions">https://github.com/yanovian/delete-old-actions</a></strong> to version <strong>v1.0.11</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/prune-old-github-actions-runs">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This action deletes old GitHub Actions runs in your repository to keep it clean. It helps automate tasks like managing large run logs and reducing costs associated with long-running actions. The action can be configured to delete runs based on age or retain a certain number of the most recent runs, making it useful for maintaining a clean and efficient workflow.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yanovian/delete-old-actions/compare/v1.0.10...v1.0.11">https://github.com/yanovian/delete-old-actions/compare/v1.0.10...v1.0.11</a></p>
]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/ai-plugin-scanner/</link><pubDate>Tue, 14 Jul 2026 15:21:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.468.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The action scans AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems to evaluate security, publishability, runtime readiness, and trust signals. It emits structured reports, SARIF, policy results, and submission metadata while aligning with the main scanner release train. The action is available as a Marketplace-ready GitHub Action for Hashgraph Online’s AI plugin scanning capabilities.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.468</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>18</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The action scans AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems to evaluate security, publishability, runtime readiness, and trust signals. It emits structured reports, SARIF, policy results, and submission metadata while aligning with the main scanner release train. The action is available as a Marketplace-ready GitHub Action for Hashgraph Online&rsquo;s AI plugin scanning capabilities.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/b75aec781146f83c8a54075f83a147c2aafa818f">https://github.com/hashgraph-online/hol-guard/tree/b75aec781146f83c8a54075f83a147c2aafa818f</a> with plugin-scanner 2.0.1069.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.467...v1.2.468">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.467...v1.2.468</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/hol-codex-plugin-scanner/</link><pubDate>Tue, 14 Jul 2026 15:20:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.468.
This action is used across all versions by 12 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The HOL AI Plugin Scanner GitHub Action automates the scanning of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems. It aims to ensure security, publishability, runtime readiness, and trust signals by emitting structured reports, SARIF files, policy results, and submission metadata. The action is compatible with existing workflows and provides advanced distribution paths for enterprise runners.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.468</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>12</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The HOL AI Plugin Scanner GitHub Action automates the scanning of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems. It aims to ensure security, publishability, runtime readiness, and trust signals by emitting structured reports, SARIF files, policy results, and submission metadata. The action is compatible with existing workflows and provides advanced distribution paths for enterprise runners.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.468">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.468</a></p>
]]></content:encoded></item><item><title>Holon Solve</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/holon-solve/</link><pubDate>Tue, 14 Jul 2026 15:19:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/holon-solve/</guid><description>Version updated for https://github.com/holon-run/holon to version v0.29.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Holon is a local workbench that provides agents with a continuous working context, organizing tasks and waits explicitly as “Work,” preserving state and context. It supports event-driven wait and wake mechanisms and allows clear separation of operator input, external events, tool results, and execution traces. Holon runs in the real working environment for local repositories, shell, worktrees, and development toolchains.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/holon-run/holon">https://github.com/holon-run/holon</a></strong> to version <strong>v0.29.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/holon-solve">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Holon is a local workbench that provides agents with a continuous working context, organizing tasks and waits explicitly as &ldquo;Work,&rdquo; preserving state and context. It supports event-driven wait and wake mechanisms and allows clear separation of operator input, external events, tool results, and execution traces. Holon runs in the real working environment for local repositories, shell, worktrees, and development toolchains.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="runtime-line">Runtime line</h2>
<p>Holon v0.29.0 is part of the Rust runtime line. The Rust runtime is now the main <code>holon</code> binary.</p>
<p>This release introduces a model route resolution system that resolves model capabilities through provider endpoints, calibrates catalogs across 30+ providers, adds an isolated xAI XSearch tool with OAuth device login, distinguishes Volcengine provider tiers, and improves Web GUI event timeline rendering, settings UI, and skill management. It also fixes Codex credential profile prioritization, prompt budget for continuations, workspace file download authentication, provider continuation lineage, and checkpoint operator delivery gaps.</p>
<p>Supported binary assets for this release are Linux amd64, macOS amd64, and macOS arm64.</p>
<h2 id="changes">Changes</h2>
<ul>
<li>Introduce model route resolution and route-aware model catalog capabilities through provider endpoints, then canonicalize catalog routes across all built-in providers (<a href="https://github.com/holon-run/holon/pull/2133">#2133</a>, <a href="https://github.com/holon-run/holon/pull/2134">#2134</a>, <a href="https://github.com/holon-run/holon/pull/2135">#2135</a>, <a href="https://github.com/holon-run/holon/pull/2196">#2196</a>, <a href="https://github.com/holon-run/holon/pull/2198">#2198</a>, <a href="https://github.com/holon-run/holon/pull/2233">#2233</a>).</li>
<li>Calibrate and unify model catalogs across 30+ providers including OpenAI, Codex, Anthropic, xAI, Gemini, DeepSeek, MiniMax, Moonshot, Mistral, DashScope, Volcengine, Tencent TokenHub, Venice, Hugging Face, and more (<a href="https://github.com/holon-run/holon/pull/2199">#2199</a>–<a href="https://github.com/holon-run/holon/pull/2228">#2228</a>).</li>
<li>Add an isolated xAI XSearch tool with OAuth device login and credential handling (<a href="https://github.com/holon-run/holon/pull/2183">#2183</a>, <a href="https://github.com/holon-run/holon/pull/2154">#2154</a>, <a href="https://github.com/holon-run/holon/pull/2155">#2155</a>, <a href="https://github.com/holon-run/holon/pull/2185">#2185</a>, <a href="https://github.com/holon-run/holon/pull/2186">#2186</a>).</li>
<li>Distinguish Volcengine provider tiers (standard, agent-plan, coding-plan) and switch the plan tier to OpenAI Responses transport (<a href="https://github.com/holon-run/holon/pull/2136">#2136</a>, <a href="https://github.com/holon-run/holon/pull/2137">#2137</a>, <a href="https://github.com/holon-run/holon/pull/2138">#2138</a>).</li>
<li>Improve Web GUI event timeline rendering, tool execution details, workspace detail renderers, settings UI, OAuth auth mode, fallback model chip, and image generation settings (<a href="https://github.com/holon-run/holon/pull/2144">#2144</a>, <a href="https://github.com/holon-run/holon/pull/2147">#2147</a>, <a href="https://github.com/holon-run/holon/pull/2148">#2148</a>, <a href="https://github.com/holon-run/holon/pull/2160">#2160</a>, <a href="https://github.com/holon-run/holon/pull/2161">#2161</a>, <a href="https://github.com/holon-run/holon/pull/2164">#2164</a>, <a href="https://github.com/holon-run/holon/pull/2156">#2156</a>, <a href="https://github.com/holon-run/holon/pull/2169">#2169</a>, <a href="https://github.com/holon-run/holon/pull/2170">#2170</a>).</li>
<li>Run skill catalog updates as jobs with hardened feedback and Web GUI skill management UI (<a href="https://github.com/holon-run/holon/pull/2181">#2181</a>, <a href="https://github.com/holon-run/holon/pull/2182">#2182</a>).</li>
<li>Fix Codex credential profile prioritization, use full prompt budget for continuations, authenticate workspace file downloads, and preserve provider continuation lineage (<a href="https://github.com/holon-run/holon/pull/2236">#2236</a>, <a href="https://github.com/holon-run/holon/pull/2235">#2235</a>, <a href="https://github.com/holon-run/holon/pull/2231">#2231</a>, <a href="https://github.com/holon-run/holon/pull/2168">#2168</a>).</li>
</ul>
<h2 id="install">Install</h2>
<p>Homebrew:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>brew tap holon-run/tap
</span></span><span style="display:flex;"><span>brew install holon
</span></span></code></pre></div><p>Direct binary:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -L <span style="color:#e6db74">&#34;https://github.com/holon-run/holon/releases/download/v0.29.0/holon-linux-amd64.tar.gz&#34;</span> | tar -xz
</span></span><span style="display:flex;"><span>chmod +x holon
</span></span><span style="display:flex;"><span>./holon --help
</span></span></code></pre></div><p>Replace <code>holon-linux-amd64.tar.gz</code> with <code>holon-darwin-amd64.tar.gz</code> or <code>holon-darwin-arm64.tar.gz</code> on macOS.</p>
]]></content:encoded></item><item><title>Self Merge Sentinel</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/self-merge-sentinel/</link><pubDate>Tue, 14 Jul 2026 15:18:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/self-merge-sentinel/</guid><description>Version updated for https://github.com/inakam/claude-code-actions-self-merge-sentinel to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automatically determines whether to approve or require human review for PRs based on a set of rules defined in a YAML file. It uses Claude AI to analyze the changes and make decisions, updating PR comments and labels accordingly. The action supports bot actors and integrates with Anthropic and Cloud provider credentials, allowing for customizable settings like model configurations and API URLs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/inakam/claude-code-actions-self-merge-sentinel">https://github.com/inakam/claude-code-actions-self-merge-sentinel</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/self-merge-sentinel">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automatically determines whether to approve or require human review for PRs based on a set of rules defined in a YAML file. It uses Claude AI to analyze the changes and make decisions, updating PR comments and labels accordingly. The action supports bot actors and integrates with Anthropic and Cloud provider credentials, allowing for customizable settings like model configurations and API URLs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at bf90a170f2bcd9265baa53ef0760974c4e427634 -->
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: Botによるセルフマージ判定を許可 by @inakam in <a href="https://github.com/inakam/claude-code-actions-self-merge-sentinel/pull/9">https://github.com/inakam/claude-code-actions-self-merge-sentinel/pull/9</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/inakam/claude-code-actions-self-merge-sentinel/compare/v1.0.2...v1.0.3">https://github.com/inakam/claude-code-actions-self-merge-sentinel/compare/v1.0.2...v1.0.3</a></p>
]]></content:encoded></item><item><title>jk-publish-test-results</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/jk-publish-test-results/</link><pubDate>Tue, 14 Jul 2026 15:17:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/jk-publish-test-results/</guid><description>Version updated for https://github.com/jedi-knights/publish-test-results to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, publish-test-results, automates the process of publishing multi-format test results as a drilldownable per-test check-run in GitHub. It supports ten different input dialects and provides clickable annotations on the diff for every test, making it easier to trace failures directly to source lines. The action is designed for Go, Python, and other languages, and it leverages Go’s fast start time for efficient execution.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jedi-knights/publish-test-results">https://github.com/jedi-knights/publish-test-results</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jk-publish-test-results">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, <code>publish-test-results</code>, automates the process of publishing multi-format test results as a drilldownable per-test check-run in GitHub. It supports ten different input dialects and provides clickable annotations on the diff for every test, making it easier to trace failures directly to source lines. The action is designed for Go, Python, and other languages, and it leverages Go&rsquo;s fast start time for efficient execution.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
]]></content:encoded></item><item><title>JFrog Boost</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/jfrog-boost/</link><pubDate>Tue, 14 Jul 2026 15:15:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/jfrog-boost/</guid><description>Version updated for https://github.com/jfrog/boost to version v0.9.4.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 2 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Boost is a smart token savings tool that reduces the noise in agent output by trimming what’s safe to drop while preserving essential context. It trims only non-sensitive information from noisy logs, allowing agents to focus on important details like errors, timings, and cache hits.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jfrog/boost">https://github.com/jfrog/boost</a></strong> to version <strong>v0.9.4</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>2</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jfrog-boost">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Boost is a smart token savings tool that reduces the noise in agent output by trimming what&rsquo;s safe to drop while preserving essential context. It trims only non-sensitive information from noisy logs, allowing agents to focus on important details like errors, timings, and cache hits.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="windows-self-update">Windows self-update</h2>
<p><code>boost update</code> now works on native Windows, so Windows users can stay current without reinstalling manually.</p>
<h3 id="features">Features</h3>
<ul>
<li>Added <strong>Windows support for <code>boost update</code></strong>, including safe in-place binary replacement when another Boost process is running.</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jfrog/boost/compare/v0.9.3...v0.9.4">https://github.com/jfrog/boost/compare/v0.9.3...v0.9.4</a></p>
]]></content:encoded></item><item><title>Pipelock Agent Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/pipelock-agent-security-scan/</link><pubDate>Tue, 14 Jul 2026 15:14:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/pipelock-agent-security-scan/</guid><description>Version updated for https://github.com/luckyPipewrench/pipelock to version v3.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Pipelock is an AI-powered firewall designed to monitor and control secret exfiltration, prompt injection, and SSRF within mediated networks. It inspects content using various protocols (HTTP, WebSocket, CONNECT, MCP, A2A) and generates mediator-signed action receipts that can be verified outside the agent runtime. This ensures a content-aware decision is made without relying on blind trust in agent behavior.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/luckyPipewrench/pipelock">https://github.com/luckyPipewrench/pipelock</a></strong> to version <strong>v3.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pipelock-agent-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Pipelock is an AI-powered firewall designed to monitor and control secret exfiltration, prompt injection, and SSRF within mediated networks. It inspects content using various protocols (HTTP, WebSocket, CONNECT, MCP, A2A) and generates mediator-signed action receipts that can be verified outside the agent runtime. This ensures a content-aware decision is made without relying on blind trust in agent behavior.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<h3 id="-features">🚀 Features</h3>
<ul>
<li>5564402468dab4f3b493c1c271462352368d835a feat(cli): explain hook blocks via explain &ndash;command/&ndash;tool/&ndash;file (#877)</li>
<li>5a04b7c250e380047189cf71a97fcf05c99b5a63 feat(conductor): add &ndash;dry-run to publish/kill/rollback and a replay CLI (#989)</li>
<li>6440a4502fcf239cb06062ff4c526fe716ff3fa5 feat(conductor): dry-run and decision-replay for signed policy, kill, and rollback actions (#950)</li>
<li>ad6cb93788e1fee73f46f2e8efcd57e2965b47c3 feat(conductor): fleet runtime/apply-state drift guardrail with fail-closed publish preflight (#910)</li>
<li>693b51d9951fa79f5b16e910626898e2f3abd33f feat(conductor): sign follower applied-state into audit batches for verifiable fleet overview (#948)</li>
<li>480371343fb2302f16bd148cd2925444a46e6947 feat(contain): add verified run launcher (#846)</li>
<li>a59d78c59aa4f4165918e9edb960cb57b5637af6 feat(dashboard): add RBAC permission seam (#967)</li>
<li>3add482f41ff2bbb5afa8dd6e634491afd5de43e feat(dashboard): add durable state operability (#971)</li>
<li>fa96926bcc85341ccb4b570bac8836f275528a2a feat(dashboard): add trust and keys audit view (#970)</li>
<li>757263d05238e92814d282d91536d485997b7e81 feat(dashboard): cross-agent evidence explorer, decision investigator, and free viewer (#946)</li>
<li>61d18c4d1b5d51da0f9940a126129cf7dc8a7b9c feat(dashboard): exemption lifecycle store and coverage certificates (#947)</li>
<li>a42d3f3700feb05828067b52e2370056ebc8ce60 feat(dashboard): land on Overview at root; restyle the free evidence console (#995)</li>
<li>86c43a677901f2f2bfd3df7e6f0df879bf52ccd1 feat(dashboard): live per-agent forward-budget data via runtime snapshot (#968)</li>
<li>68eb7c90f74ed8963aff6eaa8e3162522ed9a122 feat(dashboard): mTLS client-certificate authentication (#973)</li>
<li>20bc05625d73ff85c6413616342f38d787517ef4 feat(dashboard): operator console revamp with a free evidence view, tier gating, and honest states (#991)</li>
<li>af2ba15ba77147c49a88463965985fcae915ba06 feat(dashboard): pipelock dashboard serve command for the Evidence view (#888)</li>
<li>f2de27c847e24aecb71d33379f1a2c6c62653803 feat(dashboard): read-only Evidence view for Pro/Enterprise (#885)</li>
<li>ad7d5443ab21764a283182ed538e32af317a6848 feat(dashboard): read-only Signed Action Workbench and Incident Cockpit (#960)</li>
<li>0d4f6d1db6b359ffefc6b16251dd560554e74b13 feat(dashboard): read-only exemptions inventory with inert-exemption detection (#923)</li>
<li>e07c26a20eb330a24639b010858a707b9162b951 feat(dashboard): read-only fleet overview of signed follower state (#951)</li>
<li>3f06e6d82d7dca24396f9a2192e19a0fc275203d feat(dashboard): read-only per-agent budget panel (#966)</li>
<li>5d76d52d93e12d5d124c64b35a9eceda84a07d5c feat(deferred): cascade-depth limit + pending-ancestor linkage for held MCP actions (#887)</li>
<li>8474b3101cae688a048897c61d75a2e4cb95c864 feat(enterprise): add compliance console (#969)</li>
<li>212c4171a20897ed8b2427b6b42e36c7d86d2e72 feat(examples): add tool-poisoning-honeypot MCP manifest-poisoning demo (#997)</li>
<li>426069fc6f208a632554b81728136747ad422322 feat(mcp): record durable receipts before egress for all forwardable verdicts (#937)</li>
<li>596b9b58f05f40437236d25fdd5f41b52b0a96aa feat(mcp): tool-policy type/range/length/value arg validators (#881)</li>
<li>c11639c077e56efa4255e4493c596d112e729bfa feat(playground): WASM browser verifier + load-test harness (#837)</li>
<li>b01a2ce3341c5e3423acd07f844381a371a50a38 feat(playground): broker hardening for public exposure (#838)</li>
<li>55319465c3ee5281bf28bcc56222035617f848a0 feat(playground): harden broker for public internet exposure (#831)</li>
<li>df958342c4cd21fef1ba0b38029c788516fac713 feat(playground): require real live model, add per-session verify kits, fix model 400 (#834)</li>
<li>2b402feaa6f1f1ffd2e3a078fab3ff633a48c07a feat(proxy): surface the exempt_domains full-trust blind spot (#936)</li>
<li>2a284eb21c2d3b9a94f9cd03d189be86057a2341 feat(receipt): additive exact-bytes receipt verification foundation (#915)</li>
<li>d85d4e28b28056ca286e77d84b4edb7b48fe8110 feat(receipt): cross-language verifier parity for rotated chains (#935)</li>
<li>23bce3f4bb826fd766bdc10b4b714545114d5e30 feat(receipt): strict unknown-field rejection and two-mode chain contract (#963)</li>
<li>c012f8970fa52427f480529ac8aa993d6364802b feat(replaycapture): add three Make It Leak episode scenarios (#896)</li>
<li>870e5a0b5804e26ca81ee110dc10ebe5a2dae612 feat(rules): verify official bundles on source builds (#955)</li>
<li>2134bf7644390c54c7d50b2d831a47454ff2532d feat(scanner): central block-remediation table, wired into explain and audit (#875)</li>
<li>42e1d2bc9fa350ae21f5ea5a27d4251b9b2fa3fe feat(scanner): operator-configurable endpoint/parameter query-entropy exemption (#916)</li>
<li>57379581e3361970554aac0f183556e9cd8817bd feat(verifier): wasm raw receipt-chain verification with parity harness (#952)</li>
<li>f24301337d3e0bd913271d7708133967a65f0b5e feat: add CEF SIEM export format and action-aware export filtering (#920)</li>
<li>745459f9eb970083bc1204ad1edbe8f176cdbf45 feat: add MCP taint trust by server name (#865)</li>
<li>1954ff641ea723da68f46f2deba184da1473336a feat: add Rekor anchor submission backend (#861)</li>
<li>446ed5216902e4050bd2d4226a507e243b026630 feat: add durable SIEM event forwarding (#972)</li>
<li>d11094bd71e568ff3ee937b458f791261ce9bd68 feat: add explain-event, quickstart, and status operator commands (#921)</li>
<li>a6a806f861eff9eed289cb9568d7c556835234ce feat: add local receipt anchor bundles (#858)</li>
<li>730d3567e8f9fb4f39798f015581e542c1c277ae feat: add preset listing, richer startup summary, and unset-knob surfacing (#922)</li>
<li>016bce1264afafc13efc54b3a7db5731ac5163fa feat: durable intent before egress on CONNECT-intercept inner requests (#925)</li>
<li>72834c0465bb778620f0cae248301dc8de2db47b feat: durable receipt-evidence lifecycle and honest completeness verifier (#924)</li>
<li>7dfbcf24ab58b869766d919c0b038f0046760bb2 feat: make all seven config presets selectable via &ndash;preset (#874)</li>
<li>e030fe5b3ced8e0d3c9141cd2be7faef4a5d7508 feat: operator surface to list, approve, and deny held (deferred) MCP actions (#905)</li>
<li>a794ae85f65ad4585d08dcc869b1d1bc7f60d01b feat: verify Rekor anchor inclusion proofs (#866)</li>
<li>ace33742d4afc8a96824fac2b35ebf3d9aa985e3 feat: verify the bound-genesis session-control wire format in every language (#926)</li>
</ul>
<h3 id="-bug-fixes">🐛 Bug Fixes</h3>
<ul>
<li>527f4b3d8a417e0fb368673b581615930defefd1 fix(anchor): make the Rekor hashedrekord hash algorithm configurable (#987)</li>
<li>771613d65ad8aa04c7da20e36c3ece93571c1123 fix(anchor): versioned per-session state index and hostile-filesystem fail-closed loading (#979)</li>
<li>18ca6f8209d4403a07d0891e3f172f62bace35fb fix(audit): emit operational visibility events (#843)</li>
<li>cbda57f5bfc0c395e2ed3afc19dc92b34ff31695 fix(baseline): cross-process integrity lock and fail-closed profile integrity (#914)</li>
<li>a1dd7adce39a3d4071e783c3444992ec41656dfb fix(baseline): enforce behavioral baseline on A2A methods (#894)</li>
<li>441f443882ec7ff4dfe451b98cabf2c8d75cff6a fix(baseline): fail closed on persisted profile tamper via signed integrity manifest (#897)</li>
<li>bdd5b936b09145996486ad836cf3187187fbf57c fix(baseline): fail closed on unreadable or corrupt persisted profile under enforcement (#892)</li>
<li>b1e569caa381c328de135697eec53e3ff3d12a96 fix(baseline): fingerprint integrity diagnostics (#943)</li>
<li>41e5c57051866d43c5d87cb4e7d5a927cfe3f95f fix(baseline): restore Windows regular-file reads without following symlinks (#980)</li>
<li>519f44c4034b1c0cd78b2960d50ae59d3136004d fix(baseline): sanitize control characters in agent-identifier log fields (#940)</li>
<li>312a99510176fae14538fcbeea2f4d577e6cf410 fix(conductor): additively merge published detection content onto follower baseline (#999)</li>
<li>c95791ceb5ce64b25043796b155977e00a4212df fix(conductor): make bootstrapped policy bundles publishable with a loaded-config policy hash (#986)</li>
<li>1d883915413dcf54c5b11116216599f52874238e fix(conductor): reject empty-scope audit queries and enforce config-consumption gate (#904)</li>
<li>9f814f56d489cea2adf7d433b393737e6d24dae4 fix(conductor): survive upgrade with an existing bundle and add signed-decision replay modes (#993)</li>
<li>26cda650a7e66cd88ad85e40feeb118bab1d553c fix(coverage-cert): re-validate certificate body on verify and bind signer key (#1000)</li>
<li>dddf7625059d51138a1746ffcb3f0f86a9728a93 fix(coveragecert): reject over-claiming certificates by construction (#1001)</li>
<li>d1e1a3767526a53d3451ae5fabdf2a328ebeb829 fix(dashboard): accept mutual TLS as a sole authenticator (#982)</li>
<li>b87e659f37fe921646f5e850807253a856eb81f2 fix(dashboard): harden auth boundary, store loading, and evidence read bounds (#978)</li>
<li>9484ba8f3b81820b1ee6e5dc78f39edfcaa32572 fix(dashboard,siemforward): default-proxy coverage certs, forwarder metadata floor, brand favicon (#1002)</li>
<li>c331bf3c3986b358e552ef7b012a3b83f9d201f8 fix(deferred): never derive cascade linkage across session-less holds (#889)</li>
<li>58ab15b2a6db37ef0ee1bef7eccdb4262273053d fix(deferred): record depth-limit denials in the audit journal (#913)</li>
<li>b6a29854648d5899372f245826b209ec692477fc fix(dlp): anchor dotted-token patterns case-sensitively to stop prose false positives (#836)</li>
<li>7a332275598d4f54a015f150b9bfca52c2c0d931 fix(emit): queue syslog delivery asynchronously (#845)</li>
<li>df4e973ea94808085238751414ed5716047886a9 fix(evidence): fail closed when a coverage certificate signer is not in the pinned trusted-signer set (#984)</li>
<li>38891a2968f400e17e78fc8082f890968cbfc6e5 fix(evidence): re-tier point-in-time containment grade to kernel_observed (#938)</li>
<li>6d0b1bed9f26d2fffe81c9f6ec41f4a1ecc63f5e fix(mcp): audit completeness, full-object drift, fail-closed hardening (#895)</li>
<li>5cc240d3811ab9168af39ed4994a3752cfe2f9dd fix(mcp): enforce denial-of-wallet and chain detection on A2A methods (#900)</li>
<li>b060d9d12bdf2454bb3680b033f1af4c3a809d6c fix(mcp): enforce session-binding, taint, and contract gates on A2A methods (#909)</li>
<li>0f82ed6a9cc4c88819a14d15375da7aed2f1670b fix(mcp): fail closed without envelope leak on empty action id under require-receipts; harden A2A method match + drift doc (#903)</li>
<li>1ef37c280c512874b750b1d727d9b4ecd35377d7 fix(mcp): harden input envelope handling (#840)</li>
<li>cee8b07f762878d8b3f0ebb832b10ba9cd8b278b fix(mcp): namespace reserved-prefix tool names in enforcement identity (#934)</li>
<li>04438c312249c7260c675fb9cef9788f3c4630ca fix(mcp): reject null envelope params (#841)</li>
<li>edea4fee584bf256f3d72522bf233c9c12767d79 fix(mcp): scan generic SSE across event boundaries (#844)</li>
<li>eac23aa1b5df87bd6b2da692cdbd2ef5c3d0e01b fix(playground): orphan-VM reaper blinded by Fly summary mode (#883)</li>
<li>952ce867eaae94f75b16b2099757d084d4fd54c1 fix(playground): serve broker UI assets world-readable so the verifier wasm loads (#839)</li>
<li>6df4016b1ac23edba068b7ee25645638051affd6 fix(proxy): apply response suppressions inside scan cascade (#848)</li>
<li>bd955774996f5c5a94cf42f741688172ff976786 fix(proxy): fail closed on undecodable multipart transfer encoding (#884)</li>
<li>aae3f1effdc89540c1541061622a456c5a01b8ba fix(proxy): improve receipt failure visibility (#842)</li>
<li>0790b4f771b7550177fe6bac1903ad392821d339 fix(proxy): scan over-cap size-exempt responses with bounded memory (#899)</li>
<li>9f25513051ab3038650f10d283e7c498d01680e8 fix(receipt): bind receipt policy_hash to the request config snapshot (#961)</li>
<li>8d401dc2d3228bab61f5321e30590defe51d8ead fix(reload): fail closed when a bundle-resolution error would drop live detection rules (#988)</li>
<li>65d069c636cb64500c487485f63bcd813642f36a fix(reverse): label unscanned media passthrough honestly, never clean (#962)</li>
<li>40d37928797216df282e050efd968f86d123f1da fix(scanner): close core response-floor bypass (suppression masking + decoded normalization) (#893)</li>
<li>982eda13d4dd01c9dba16813e1c97b193e20322a fix(scanner): cut credential-path directive false positives with intent and path-tier anchoring (#911)</li>
<li>bba7779ec1a2d6178f24458b96e192995ec8c3ff fix(scanner): normalize encoded DLP candidates (#847)</li>
<li>b542aa169c6c474178cdbf362a29767359f45eb8 fix(scanner): reassemble invisible-split keywords across config and decoded scan passes (#882)</li>
<li>c07629da274c48e56e4dc1bc3021a4b5753e5c55 fix(scanner): robust documentation-example-credential exemption (#878)</li>
<li>825205c48d12b422d5388a93de29b5880772a97d fix(scanner): sharpen credential-exfil response-injection patterns (#981)</li>
<li>3f1de21f0eb674f2ef65e44d395a1bd876349f9d fix(scanner): tighten markdown-link credential-exfil pattern to cut benign-docs false positives (#902)</li>
<li>aca78f83c25947b934885cd9758fc83ed9dc3917 fix: add reverse response size exemption parity (#869)</li>
<li>a0b685a5ecc2cdcb5f06374ed3a1c05c5df001e4 fix: attest full MCP tool definitions (#853)</li>
<li>16fd0a27042de252831e9d0277d87cb3c12abc2a fix: block split DLP in A2A task updates (#851)</li>
<li>9ad71caee1cf34699397f4508b6c08a0034c81aa fix: enforce required receipts in reverse proxy (#857)</li>
<li>e3e530ea56b7393b098e5cbc6ee19bb3fb6220a4 fix: eval mint matches net_amount (tax-invariant) + playground bundle signed receipts (#832)</li>
<li>a8bbbbc0dee988c930e886789f6eeba8d92f385b fix: harden containment nft drift proof (#868)</li>
<li>55246cd0601263371c2e6a379245094d7780e3ce fix: keep blocked tool drift out of baseline (#852)</li>
<li>44fdb46d996ef95b9e26464e726ef9a4ec8e71cf fix: reject duplicate MCP and A2A JSON keys (#855)</li>
<li>1cdcb784f9f2a80d839640c8bf1bf81ecc9f9ce5 fix: reject duplicate playground artifact keys (#856)</li>
<li>75994e462a1c8f53b7e7bda5bb594d2c3c206187 fix: reject required-mode reload downgrades (#860)</li>
<li>d3dd85e4b98870d0c8b7a49eb035d87f1b59cb87 fix: scan MCP resource HTTP URIs (#854)</li>
<li>4ef465534bf3a8e383be4e4a872e76018419d818 fix: verify containment nft rules against current uids (#859)</li>
</ul>
<h3 id="-dependencies">📦 Dependencies</h3>
<ul>
<li>294b3c9b63e242b682dc6953e5a60b5f0e1e4488 chore(deps): update actions/cache action to v6 (#956)</li>
<li>969acecac69e03d8f72a7464ea92a817e97f69c4 chore(deps): update actions/checkout action to v7 (#957)</li>
<li>ae33f9d5faf5e0d913594b97bcaccedb307f3f0d chore(deps): update dependency cryptography to v49 (#958)</li>
<li>1e0f42f44329cebb19e556f5703533ee4b160811 chore(deps): update luckypipewrench/pipelock action to v3 (#959)</li>
</ul>
<h3 id="other-changes">Other Changes</h3>
<ul>
<li>d99a9f27951f3c4b9e19829a7ec91bf288e96f51 Add Cursor integration example with verify script (#927)</li>
<li>bfec7d6584ea2c09579393ef32641f650778149c Add WebSocket proxy example with verify script (#932)</li>
<li>fae303fb06108b62399fe75f69a21ce771c6ed20 Add canary tokens example with verify script (#933)</li>
<li>bb4a516b702dd2e5fa19b4cc092ac4eb15419fb0 Add docker-compose proxy example with verify script (#945)</li>
<li>d93034d79ee2da433c6b37051d506df6a37bf6b9 Baseline learning quality: learn only executed tool calls; per-request listener samples (#880)</li>
<li>8c7f7637b5ccc75c0fe2f281b2b2d8b7d60df258 Baseline/taint review follow-ups: startup cleanup + reload downgrade guard (#879)</li>
<li>dcfa01d39cc6a405b4705bb56b48ae289993ec96 Behavioral-baseline runtime enforcement + fail-safe taint default (#876)</li>
<li>0f9e4dc2a5ec3fa1ea414e3747a297bc99366f29 Bound cumulative SSE event reads (#850)</li>
<li>6dfcfbdec78a72d2f26e7d4411d036af906f6c67 Embed validated config paths in installers (#873)</li>
<li>5bea182ebac07574cddd0d855b11371801a44e7d Evidence-health metrics, self-audit loop, and honest scorecard (#931)</li>
<li>3e30904baa7470a075d53e317cc032d9254d4ccb Fail closed on default MCP binary integrity (#849)</li>
<li>7c125e379dc99688efffaeed01b8ab5619af3555 Fail closed on unverifiable git diffs and harden rules config loading (#872)</li>
<li>d167187025b457a9977d624af6a3b2522eb61701 Fix image data URL DLP false positives without weakening embedded-secret detection (#870)</li>
<li>77803d3550cbe6fd2e4316847e85b8776a4fcbf1 Fix taint ask handling for MCP stdio and local gateways (#965)</li>
<li>f92bca161503402949c0cbf54c5119404d23d053 Harden dashboard raw evidence access (#890)</li>
<li>c8ecffa6f5a06aa37fe34ea02da3fb003f49f7a5 Harden evidence rendering, hard-limits table, and containment grade (#930)</li>
<li>3f5fe5168637b280f01901a9b550e5fa504eb3e6 Harden scanner coverage: SSRF surfaces, encoded secrets, FP precision (#891)</li>
<li>ebbef10ea53c0deab23cfc8d374340b8b8ac6507 Make crash reporting opt-in with a minimizing sanitizer (#917)</li>
<li>fd0b94bf13ce0156bc840e0351ce3c97a2ce3949 Tighten inbound DLP enforcement for OCR AWS ID false positives (#906)</li>
<li>50b8045182af69cbb164619e5969d9c899e201af Use vendor-neutral examples and align config docs to defaults (#918)</li>
<li>f80c59f39fa8cd1219b3be7af50d11014ecf9899 Validate signed session_control claims in every verifier (#929)</li>
<li>6b0167491cf59fb70701eb70697d727941dbaa3f chore(release): group and filter changelog, add branded release footer (#944)</li>
<li>e8a396d244af27b1367e116fa22fc61246884ab3 ci(release): raise race-test timeout to 30m on monolithic release test steps (#1003)</li>
<li>f3edb93c3f7dba654be86d849b7b0e6297ddb9b7 docs(dashboard): document OIDC identity-provider audience setup (#985)</li>
<li>f1b5630fefe4bf31d4570057d38475fb123725ff harden(conductor): honest fleet provenance and fail-closed rollback ordering (#977)</li>
<li>f13eab87b6bbfe10cd6894f7cccf180e31235e87 harden(evidence): dev-build rules, checkpoint signing, rekor egress, idempotent bundle merge (#983)</li>
<li>6a8ac5ed2c4dd8c0c8f0d480c05920274f31c7a3 harden(evidence): make posture proofs and session_open durable (#941)</li>
<li>29340c8db18c0d18c5d9b379fc20bb6e24e161ea harden(evidence): strict CSP + no-store on the free evidence-serve console (#998)</li>
<li>c2a88df2cb3a466b0c695d342744f7f78e1cced3 harden(evidence,anchor): bound evidence receipt reads and fix Rekor hashedrekord artifact signatures (#992)</li>
<li>f1c242a0acba37c456356a5c08fee7eba54ae1ca harden(mcp): A2A redaction parity and session-binding inventory (#976)</li>
<li>7a68cb1590e687742404ed75db2e15790ea16a59 harden(receipt): durable session-close and defense-in-depth posture-capsule verification (#949)</li>
<li>d6e5242af5fb2998f0ab20e85f65afffefa8feff harden(receipt): fail-closed audit-completeness for defer, receipts, and baseline reads (#975)</li>
<li>af90fb6efcbf4b61ebf46cfe2e90d84815c84cb2 harden(receipt): fail-closed receipt-emission completeness across MCP, proxy, and reverse (#942)</li>
<li>671890476b56d3a62afe296c9098b4bbd08c8d66 refactor: centralize DLP patterns into one generated source of truth (#919)</li>
<li>f6e3eeefef897e07b6ab65b9bb9cfa057ea9c2d8 test(liveproof): live-proof harness through the shipped binary (#898)</li>
</ul>
<hr>
<p>📚 Docs: <a href="https://pipelab.org">https://pipelab.org</a>  •  💬 Community: <a href="https://discord.gg/badNfhGKTc">https://discord.gg/badNfhGKTc</a></p>
<p>Pipelock is an open-source agent firewall. Come poke holes in it.</p>
]]></content:encoded></item><item><title>TestivAI Visual Report</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/testivai-visual-report/</link><pubDate>Tue, 14 Jul 2026 15:13:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/testivai-visual-report/</guid><description>Version updated for https://github.com/mcbuddy/testivai-oss to version @testivai/witness@1.3.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates local-first visual regression testing for web applications using TestivAI SDKs. It provides a self-contained HTML report with DOM-aware noise hints to identify real changes and render noise, allowing developers to focus on meaningful UI improvements without false positives. The action supports Playwright and WebdriverIO frameworks, making it cross-platform and language-agnostic.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mcbuddy/testivai-oss">https://github.com/mcbuddy/testivai-oss</a></strong> to version <strong>@testivai/witness@1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/testivai-visual-report">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates local-first visual regression testing for web applications using TestivAI SDKs. It provides a self-contained HTML report with DOM-aware noise hints to identify real changes and render noise, allowing developers to focus on meaningful UI improvements without false positives. The action supports Playwright and WebdriverIO frameworks, making it cross-platform and language-agnostic.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="minor-changes">Minor Changes</h3>
<ul>
<li>767385e: Added <code>--dry-run</code> flag to <code>testivai approve</code> that prints what would be approved without modifying files. Also changed <code>testivai approve --undo</code> (without a name) to automatically undo the last approval by finding the most recent <code>.previous/</code> backup — no longer requires an explicit snapshot name.</li>
<li>0158619: New <code>testivai report</code> command — the language-agnostic half of the adapter contract. Any Playwright binding (Python, Java, .NET, …) can capture by writing <code>.testivai/temp/&lt;name&gt;/screenshot.png</code> (+ <code>dom.html</code>) with its native APIs, then run <code>testivai report</code> for diffing, tolerances, the noise hint, the HTML report, and CI exit codes (<code>--fail-on-diff</code>, <code>--open</code>). This powers the new <code>testivai</code> Python package (PyPI) and the experimental Java adapter.</li>
</ul>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/totem-shield/</link><pubDate>Tue, 14 Jul 2026 15:11:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.95.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the linting process, ensuring that code adheres to specified architectural rules and best practices. It uses a file-based substrate for storing lessons, a queryable knowledge index, and an LLM-powered compiler and review commands. The tool helps prevent developers from making common mistakes by enforcing architecture guidelines without relying on AI models, maintaining consistency across projects and improving code quality.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.95.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the linting process, ensuring that code adheres to specified architectural rules and best practices. It uses a file-based substrate for storing lessons, a queryable knowledge index, and an LLM-powered compiler and review commands. The tool helps prevent developers from making common mistakes by enforcing architecture guidelines without relying on AI models, maintaining consistency across projects and improving code quality.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>AI Harness Doctor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/ai-harness-doctor/</link><pubDate>Tue, 14 Jul 2026 15:10:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/ai-harness-doctor/</guid><description>Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v0.16.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AI Harness Doctor is an action that automates the process of consolidating scattered agent configurations into a single canonical AGENTS.md file, helping to resolve conflicts and ensure consistent configuration across different projects. It also provides guards to prevent future drift in configuration files. The main purpose of AI Harness Doctor is to improve collaboration and reduce errors by providing a unified version control system for agent configurations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NieZhuZhu/ai-harness-doctor">https://github.com/NieZhuZhu/ai-harness-doctor</a></strong> to version <strong>v0.16.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-harness-doctor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AI Harness Doctor is an action that automates the process of consolidating scattered agent configurations into a single canonical AGENTS.md file, helping to resolve conflicts and ensure consistent configuration across different projects. It also provides guards to prevent future drift in configuration files. The main purpose of AI Harness Doctor is to improve collaboration and reduce errors by providing a unified version control system for agent configurations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(drift): add baseline support to fail only on new drift by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/100">https://github.com/NieZhuZhu/ai-harness-doctor/pull/100</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NieZhuZhu/ai-harness-doctor/compare/v0.15.3...v0.16.0">https://github.com/NieZhuZhu/ai-harness-doctor/compare/v0.15.3...v0.16.0</a></p>
]]></content:encoded></item><item><title>Postman API Onboarding</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/postman-api-onboarding/</link><pubDate>Tue, 14 Jul 2026 15:09:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/postman-api-onboarding/</guid><description>Version updated for https://github.com/postman-cs/postman-api-onboarding-action to version v2.0.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman API Onboarding Action automates the process of setting up a new API repository by bootstrapping a workspace, uploading an OpenAPI specification, generating collections and environments, registering a mock server and monitor, committing artifacts to the repository, and running smoke and contract tests. It solves the problem of automating the onboarding process for APIs in GitHub repositories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-api-onboarding-action">https://github.com/postman-cs/postman-api-onboarding-action</a></strong> to version <strong>v2.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-api-onboarding">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman API Onboarding Action automates the process of setting up a new API repository by bootstrapping a workspace, uploading an OpenAPI specification, generating collections and environments, registering a mock server and monitor, committing artifacts to the repository, and running smoke and contract tests. It solves the problem of automating the onboarding process for APIs in GitHub repositories.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(release): prepare Wave 2 composite v2.0.4 by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/65">https://github.com/postman-cs/postman-api-onboarding-action/pull/65</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.0.3...v2.0.4">https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.0.3...v2.0.4</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Workspace Bootstrap</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/postman-onboarding-workspace-bootstrap/</link><pubDate>Tue, 14 Jul 2026 15:08:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/postman-onboarding-workspace-bootstrap/</guid><description>Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.9.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman Onboarding: Workspace Bootstrap action automates the creation of a Postman workspace by importing an OpenAPI specification, generating essential collections with contract tests, and enforcing adherence to RFCs and standards. This action simplifies the onboarding process by streamlining the setup of test cases for APIs in one step.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-bootstrap-action">https://github.com/postman-cs/postman-bootstrap-action</a></strong> to version <strong>v2.9.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-workspace-bootstrap">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman Onboarding: Workspace Bootstrap action automates the creation of a Postman workspace by importing an OpenAPI specification, generating essential collections with contract tests, and enforcing adherence to RFCs and standards. This action simplifies the onboarding process by streamlining the setup of test cases for APIs in one step.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): bump the npm-minor-patch group with 7 updates by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/70">https://github.com/postman-cs/postman-bootstrap-action/pull/70</a></li>
<li>feat: support local v3 additional collections by @andrewpostymt in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/72">https://github.com/postman-cs/postman-bootstrap-action/pull/72</a></li>
<li>feat: support local v3 additional collections by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/73">https://github.com/postman-cs/postman-bootstrap-action/pull/73</a></li>
<li>fix: reconcile creates with run ownership by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/75">https://github.com/postman-cs/postman-bootstrap-action/pull/75</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.9.1">https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.9.1</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Repo Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/postman-onboarding-repo-sync/</link><pubDate>Tue, 14 Jul 2026 15:07:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/postman-onboarding-repo-sync/</guid><description>Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.1.3.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of synchronizing Postman collections and environments with a repository. It exports these assets into the repository, wires CI, mock servers, and monitors around them. The action is part of the Postman API Onboarding suite and requires a Postman API key or service token to mint one.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-repo-sync-action">https://github.com/postman-cs/postman-repo-sync-action</a></strong> to version <strong>v2.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-repo-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of synchronizing Postman collections and environments with a repository. It exports these assets into the repository, wires CI, mock servers, and monitors around them. The action is part of the Postman API Onboarding suite and requires a Postman API key or service token to mint one.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: preserve verified resource ownership by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/70">https://github.com/postman-cs/postman-repo-sync-action/pull/70</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.2...v2.1.3">https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.2...v2.1.3</a></p>
]]></content:encoded></item><item><title>PR Risk Analyzer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/pr-risk-analyzer/</link><pubDate>Tue, 14 Jul 2026 15:05:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/pr-risk-analyzer/</guid><description>Version updated for https://github.com/rw-core/pr-risk-analyzer to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The PR Risk Analyzer GitHub Action automates the identification of high-risk changes in pull requests by analyzing files against historical data to identify bug hotspots, code volatility, bus factors, and churn metrics. It provides actionable compound risk predictions such as tribal knowledge risk, defect-injection predictor, and clean-up exception, with evidence-based reporting that cites academic studies and explains why flagged metrics matter directly within the PR comment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rw-core/pr-risk-analyzer">https://github.com/rw-core/pr-risk-analyzer</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pr-risk-analyzer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The PR Risk Analyzer GitHub Action automates the identification of high-risk changes in pull requests by analyzing files against historical data to identify bug hotspots, code volatility, bus factors, and churn metrics. It provides actionable compound risk predictions such as tribal knowledge risk, defect-injection predictor, and clean-up exception, with evidence-based reporting that cites academic studies and explains why flagged metrics matter directly within the PR comment.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Rolling release; tracks the latest v1.x. Pin to v1.0.4 for immutability.</p>
]]></content:encoded></item><item><title>PQC Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/pqc-scan/</link><pubDate>Tue, 14 Jul 2026 15:03:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/pqc-scan/</guid><description>Version updated for https://github.com/sachhg/pqc-scan to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The pqc-scan GitHub Action scans your codebase for quantum-vulnerable cryptography and provides detailed reports on which lines are vulnerable. It automates the process of identifying and migrating to post-quantum algorithms, helping developers stay secure against potential quantum attacks. The tool uses tree-sitter AST parsing to ensure accurate detection without relying on brittle regexes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sachhg/pqc-scan">https://github.com/sachhg/pqc-scan</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pqc-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>pqc-scan</code> GitHub Action scans your codebase for quantum-vulnerable cryptography and provides detailed reports on which lines are vulnerable. It automates the process of identifying and migrating to post-quantum algorithms, helping developers stay secure against potential quantum attacks. The tool uses tree-sitter AST parsing to ensure accurate detection without relying on brittle regexes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release of pqc-scan, plus a release to the GitHub MarketPlace</p>
<p><strong>What it does:</strong> Scans your codebase for quantum-vulnerable cryptography
(RSA, ECC, ECDSA, ECDH, DSA, SHA-1, MD5) and surfaces findings as inline
PR annotations via SARIF, or as a CycloneDX Cryptographic Bill of Materials.</p>
<p><strong>Validated against:</strong> pyca/cryptography and certbot/certbot.</p>
<p><strong>Supports:</strong> Python, JavaScript/TypeScript, Java, Go, nginx/apache config files.</p>
<h2 id="quick-start">Quick Start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install pqc-scan
</span></span><span style="display:flex;"><span>pqc-scan scan .
</span></span></code></pre></div><h2 id="github-action">GitHub Action</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sachhg/pqc-scan@v0.1.0</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Console CensorChecker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/console-censorchecker/</link><pubDate>Tue, 14 Jul 2026 15:02:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/console-censorchecker/</guid><description>Version updated for https://github.com/SpaceTimee/Console-CensorChecker to version 1.1.4.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Console CensorChecker is a PowerShell-based script that uses Tcping to batch test and monitor the availability of services, with a focus on detecting network censorship. It can be used for testing TCP latency and monitoring service health in various environments. The tool is designed to help identify potential restrictions or censorship by analyzing response times from target domains.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SpaceTimee/Console-CensorChecker">https://github.com/SpaceTimee/Console-CensorChecker</a></strong> to version <strong>1.1.4.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/console-censorchecker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Console CensorChecker</strong> is a PowerShell-based script that uses Tcping to batch test and monitor the availability of services, with a focus on detecting network censorship. It can be used for testing TCP latency and monitoring service health in various environments. The tool is designed to help identify potential restrictions or censorship by analyzing response times from target domains.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ol>
<li>添加 App 静态字段 root，点源时赋值为模块目录</li>
<li>修改 Target.txt / Provider.js 路径为基于 [App]::root</li>
<li>修改 Start-Process 参数为数组形式传入</li>
<li>移除 ConvertFrom-Json 上多余的 -ErrorAction Stop</li>
<li>修改进程等待为 Wait-Process</li>
<li>修改部分入口脚本编码风格</li>
<li>移除 Copy-Item 的 -Destination 参数名</li>
</ol>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/ssg-static-site-generator/</link><pubDate>Tue, 14 Jul 2026 15:02:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website, handling clean URLs, templates, feeds, search, and more. It supports various deployment options including native support for Cloudflare Pages, GitHub Pages, Netlify, Vercel, FTP, and SFTP.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SSG is a fast static site generator written in Go that converts Markdown with YAML frontmatter into a complete website, handling clean URLs, templates, feeds, search, and more. It supports various deployment options including native support for Cloudflare Pages, GitHub Pages, Netlify, Vercel, FTP, and SFTP.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(1.8.3): template query helpers, image processing, SCSS, skip-links, perf batch by @spagu in <a href="https://github.com/spagu/ssg/pull/23">https://github.com/spagu/ssg/pull/23</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.2...v1.8.3">https://github.com/spagu/ssg/compare/v1.8.2...v1.8.3</a></p>
]]></content:encoded></item><item><title>spek - OpenSpec Static Site</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/spek-openspec-static-site/</link><pubDate>Tue, 14 Jul 2026 15:00:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/spek-openspec-static-site/</guid><description>Version updated for https://github.com/spekhq/spek to version v1.8.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Spek is a lightweight, read-only viewer for OpenSpec content. It provides structured browsing with BDD syntax highlighting, task progress tracking, and full-text search capabilities. The action automates the process of viewing specs, changes, and tasks in an organized manner using OpenSpec data.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spekhq/spek">https://github.com/spekhq/spek</a></strong> to version <strong>v1.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spek-openspec-static-site">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Spek is a lightweight, read-only viewer for OpenSpec content. It provides structured browsing with BDD syntax highlighting, task progress tracking, and full-text search capabilities. The action automates the process of viewing specs, changes, and tasks in an organized manner using OpenSpec data.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li><strong>The Refresh button now actually refreshes.</strong> The circular-arrow button at the bottom of the sidebar — previously labelled &ldquo;Resync&rdquo; — only rebuilt an internal cache. It never re-fetched what was on screen, so if you edited a file and pressed it, nothing happened; you had to navigate away and back before your change showed up. It now re-fetches, and it keeps spinning until the new data has actually arrived instead of stopping before it lands (which made a working refresh look like a broken one). Thanks to <a href="https://github.com/deniskrizanovic">@deniskrizanovic</a> for reporting.</li>
<li><strong>A dead live-update connection is no longer silent (Web).</strong> spek normally refreshes on its own when files change, over a background connection that can drop without any outward sign. When it drops, the sidebar now says so and points you at Refresh, rather than leaving you staring at stale content with no indication that anything is wrong. <strong>Note:</strong> this makes the failure <em>visible</em>; it does not yet make the connection recover on its own. If auto-refresh stops, press Refresh.</li>
<li><strong>IntelliJ: the Refresh button was completely dead.</strong> The plugin&rsquo;s built-in server had no endpoint for it, so every click returned HTTP 404 and the frontend gave up silently. The endpoint now exists, and Refresh no longer depends on it succeeding.</li>
<li><strong>IntelliJ: stopped a pointless background retry loop.</strong> The webview mistook itself for the web app and kept reconnecting, forever, to a path the plugin&rsquo;s server never serves.</li>
</ul>
]]></content:encoded></item><item><title>SFDX Deploy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/sfdx-deploy/</link><pubDate>Tue, 14 Jul 2026 14:59:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/sfdx-deploy/</guid><description>Version updated for https://github.com/svierk/sfdx-deploy to version v1.2.1.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action sfdx-deploy automates Salesforce metadata deployment and validation. It supports various functionalities including source directories, manifest files, metadata component selectors, test levels, dry runs, delta deployments, and handling destructive changes via the sfdx-git-delta plugin. The action is particularly useful for validating deployments on pull requests or deploying metadata to higher environments efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/svierk/sfdx-deploy">https://github.com/svierk/sfdx-deploy</a></strong> to version <strong>v1.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sfdx-deploy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>sfdx-deploy</code> automates Salesforce metadata deployment and validation. It supports various functionalities including source directories, manifest files, metadata component selectors, test levels, dry runs, delta deployments, and handling destructive changes via the sfdx-git-delta plugin. The action is particularly useful for validating deployments on pull requests or deploying metadata to higher environments efficiently.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>describe the human-readable deployment details log group</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/svierk/sfdx-deploy/compare/v1.2.0...v1.2.1">https://github.com/svierk/sfdx-deploy/compare/v1.2.0...v1.2.1</a></p>
]]></content:encoded></item><item><title>SFDX Run Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/sfdx-run-tests/</link><pubDate>Tue, 14 Jul 2026 14:58:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/sfdx-run-tests/</guid><description>Version updated for https://github.com/svierk/sfdx-run-tests to version v1.1.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates running Salesforce Apex, LWC (Jest), and Flow tests from a single step, providing comprehensive coverage reports for each type of test. It supports toggling the execution of each test type, highlights coverage in CLI logs, and writes reports to expected paths for integration with quality tools like SonarQube/SonarCloud or Codecov. The action is particularly useful for streamlining the testing process and ensuring consistent code coverage across different Salesforce projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/svierk/sfdx-run-tests">https://github.com/svierk/sfdx-run-tests</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sfdx-run-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates running Salesforce Apex, LWC (Jest), and Flow tests from a single step, providing comprehensive coverage reports for each type of test. It supports toggling the execution of each test type, highlights coverage in CLI logs, and writes reports to expected paths for integration with quality tools like SonarQube/SonarCloud or Codecov. The action is particularly useful for streamlining the testing process and ensuring consistent code coverage across different Salesforce projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>render readable test results in collapsible log groups</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/svierk/sfdx-run-tests/compare/v1.0.0...v1.1.0">https://github.com/svierk/sfdx-run-tests/compare/v1.0.0...v1.1.0</a></p>
]]></content:encoded></item><item><title>cargo-oxidate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/cargo-oxidate/</link><pubDate>Tue, 14 Jul 2026 14:57:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/cargo-oxidate/</guid><description>Version updated for https://github.com/timweri/cargo-oxidate to version v0.1.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks Cargo.lock for packages that are too new or too old based on age thresholds and flags them as potential vulnerabilities. It automates security audits by identifying outdated dependencies and suggests updates to downgrade known risks. The action can be used directly from the command line or as a cargo subcommand, with options to exclude certain packages, customize timeout settings, and enable caching for improved performance in CI/CD workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/timweri/cargo-oxidate">https://github.com/timweri/cargo-oxidate</a></strong> to version <strong>v0.1.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cargo-oxidate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks <code>Cargo.lock</code> for packages that are too new or too old based on age thresholds and flags them as potential vulnerabilities. It automates security audits by identifying outdated dependencies and suggests updates to downgrade known risks. The action can be used directly from the command line or as a cargo subcommand, with options to exclude certain packages, customize timeout settings, and enable caching for improved performance in CI/CD workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Refactor by @timweri in <a href="https://github.com/timweri/cargo-oxidate/pull/3">https://github.com/timweri/cargo-oxidate/pull/3</a></li>
<li>Improve caching by @timweri in <a href="https://github.com/timweri/cargo-oxidate/pull/4">https://github.com/timweri/cargo-oxidate/pull/4</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/timweri/cargo-oxidate/compare/v0.1.5...v0.1.6">https://github.com/timweri/cargo-oxidate/compare/v0.1.5...v0.1.6</a></p>
]]></content:encoded></item><item><title>New Behavioral Health Practices Weekly</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/new-behavioral-health-practices-weekly/</link><pubDate>Tue, 14 Jul 2026 14:57:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/new-behavioral-health-practices-weekly/</guid><description>Version updated for https://github.com/unitedideas/behavioral-health-practice-leads-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action fetches behavioral-health NPIs from the latest CMS weekly file using the New Behavioral Health Practices Weekly actor. It exports these NPIs as clean JSON in a workflow, with options to run it as a free preview or a full edition that charges $9 per event. The action is designed to help organizations monitor and manage behavioral health practices efficiently within their workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/unitedideas/behavioral-health-practice-leads-action">https://github.com/unitedideas/behavioral-health-practice-leads-action</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/new-behavioral-health-practices-weekly">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action fetches behavioral-health NPIs from the latest CMS weekly file using the New Behavioral Health Practices Weekly actor. It exports these NPIs as clean JSON in a workflow, with options to run it as a free preview or a full edition that charges $9 per event. The action is designed to help organizations monitor and manage behavioral health practices efficiently within their workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Publishes the cost-capped Action to GitHub Marketplace.</p>
<ul>
<li>Preview is the default and returns a deterministic 15-row sample.</li>
<li>Full editions require an explicit $9.25 total-charge cap and charge the $9 weekly-edition event only after validation.</li>
<li>Buyer credentials stay in GitHub Secrets and are sent only in the Apify Authorization header.</li>
<li>Delivered JSON stays in the caller&rsquo;s workflow workspace; the Action does not send messages, commit files, or perform outreach.</li>
</ul>
<p>Store and Actor details: <a href="https://apify.com/actablesite/new-behavioral-health-practices-actor">https://apify.com/actablesite/new-behavioral-health-practices-actor</a></p>
]]></content:encoded></item><item><title>Website Indexability Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/website-indexability-gate/</link><pubDate>Tue, 14 Jul 2026 14:56:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/website-indexability-gate/</guid><description>Version updated for https://github.com/unitedideas/website-indexability-monitor to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action checks a production website’s indexability and returns HTTP status, robots meta, X-Robots-Tag, canonical URL, robots.txt policy, and optional synthetic AI crawler responses. If the homepage is noindex, it fails the job. The check is configured with inputs like fail-on-noindex and can also send synthetic requests to simulate crawler behavior.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/unitedideas/website-indexability-monitor">https://github.com/unitedideas/website-indexability-monitor</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/website-indexability-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action checks a production website&rsquo;s indexability and returns HTTP status, robots meta, <code>X-Robots-Tag</code>, canonical URL, robots.txt policy, and optional synthetic AI crawler responses. If the homepage is noindex, it fails the job. The check is configured with inputs like fail-on-noindex and can also send synthetic requests to simulate crawler behavior.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First Marketplace-ready release. Fail a GitHub Actions job when a public homepage returns noindex, while reporting status, canonical, robots.txt policy, and optional synthetic AI crawler responses. Uses the current actions/checkout runtime in the scheduled template.</p>
]]></content:encoded></item><item><title>Install Task</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/install-task/</link><pubDate>Tue, 14 Jul 2026 14:55:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/install-task/</guid><description>Version updated for https://github.com/yk-lab/setup-task to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The setup-task GitHub Action automates the installation of the Task binary onto the PATH, ensuring secure and reliable downloads with checksum verification and host-pinning. It uses authenticated requests by default and retries transient network failures with exponential backoff to handle potential issues during installation. The action is designed to be a drop-in replacement for arduino/setup-task, supporting versioning and architecture customization options while maintaining compatibility with the Node 24 runtime.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yk-lab/setup-task">https://github.com/yk-lab/setup-task</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-task">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The setup-task GitHub Action automates the installation of the Task binary onto the PATH, ensuring secure and reliable downloads with checksum verification and host-pinning. It uses authenticated requests by default and retries transient network failures with exponential backoff to handle potential issues during installation. The action is designed to be a drop-in replacement for arduino/setup-task, supporting versioning and architecture customization options while maintaining compatibility with the Node 24 runtime.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: setup-task GitHub Action の初回実装 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/6">https://github.com/yk-lab/setup-task/pull/6</a></li>
<li>docs: コミュニティヘルスファイルを追加 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/17">https://github.com/yk-lab/setup-task/pull/17</a></li>
<li>docs: README にステータスバッジを追加 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/20">https://github.com/yk-lab/setup-task/pull/20</a></li>
<li>build(deps): Bump vite and vitest by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/19">https://github.com/yk-lab/setup-task/pull/19</a></li>
<li>build(deps): Bump esbuild and vitest by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/18">https://github.com/yk-lab/setup-task/pull/18</a></li>
<li>build(deps): Bump actions/setup-node from 4 to 6 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/10">https://github.com/yk-lab/setup-task/pull/10</a></li>
<li>build(deps-dev): Bump @eslint/js from 9.39.4 to 10.0.1 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/15">https://github.com/yk-lab/setup-task/pull/15</a></li>
<li>build(deps-dev): Bump vitest from 2.1.9 to 4.1.9 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/14">https://github.com/yk-lab/setup-task/pull/14</a></li>
<li>build(deps): Bump actions/checkout from 4 to 6 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/11">https://github.com/yk-lab/setup-task/pull/11</a></li>
<li>build(deps-dev): Bump eslint from 9.39.4 to 10.5.0 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/13">https://github.com/yk-lab/setup-task/pull/13</a></li>
<li>ci: GitHub Actions を SHA ピンに固定 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/21">https://github.com/yk-lab/setup-task/pull/21</a></li>
<li>build(deps): Bump the actions-toolkit group across 1 directory with 2 updates by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/12">https://github.com/yk-lab/setup-task/pull/12</a></li>
<li>build(deps-dev): Bump @vercel/ncc from 0.38.4 to 0.44.0 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/16">https://github.com/yk-lab/setup-task/pull/16</a></li>
<li>fix(security): repo-token を core.setSecret でマスクする by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/24">https://github.com/yk-lab/setup-task/pull/24</a></li>
<li>test: withRetry のユニットテストを追加する by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/25">https://github.com/yk-lab/setup-task/pull/25</a></li>
<li>test: fetchJson の content-type ガードと createReleaseApi を検証 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/26">https://github.com/yk-lab/setup-task/pull/26</a></li>
<li>test: checksum 改ざん検出の統合テストと self-test 強化 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/27">https://github.com/yk-lab/setup-task/pull/27</a></li>
<li>ci: Codecov でカバレッジ/テスト結果を OIDC アップロードする by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/28">https://github.com/yk-lab/setup-task/pull/28</a></li>
<li>test: cache-hit 経路の self-test を追加する by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/29">https://github.com/yk-lab/setup-task/pull/29</a></li>
<li>fix: レンジ指定で tool-cache を GitHub 解決より優先する by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/30">https://github.com/yk-lab/setup-task/pull/30</a></li>
<li>chore: パッケージマネージャを npm から pnpm へ移行 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/34">https://github.com/yk-lab/setup-task/pull/34</a></li>
<li>build(deps): Bump actions/checkout from 6.0.3 to 7.0.0 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/31">https://github.com/yk-lab/setup-task/pull/31</a></li>
<li>build(deps-dev): Bump typescript from 5.9.3 to 6.0.3 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/32">https://github.com/yk-lab/setup-task/pull/32</a></li>
<li>build(deps-dev): @types/node を ^24 に揃える by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/35">https://github.com/yk-lab/setup-task/pull/35</a></li>
<li>chore: dist/ を main から外しリリース時ビルド方式へ by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/36">https://github.com/yk-lab/setup-task/pull/36</a></li>
<li>ci: Codecov PR コメントを有効化 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/46">https://github.com/yk-lab/setup-task/pull/46</a></li>
<li>ci: Codecov PR コメントをカバレッジ変動時のみ表示 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/47">https://github.com/yk-lab/setup-task/pull/47</a></li>
<li>docs: TODO.md から完了した #8 を移動 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/48">https://github.com/yk-lab/setup-task/pull/48</a></li>
<li>ci: .md のみ変更時は重い CI をスキップしつつ required check を維持 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/49">https://github.com/yk-lab/setup-task/pull/49</a></li>
<li>feat: ジョブサマリに導入結果を出力（NFR-5） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/50">https://github.com/yk-lab/setup-task/pull/50</a></li>
<li>feat: リトライ回数・間隔を input 化（FR-4） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/51">https://github.com/yk-lab/setup-task/pull/51</a></li>
<li>chore: 重複した checksum 改ざんテストを統合（#43） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/52">https://github.com/yk-lab/setup-task/pull/52</a></li>
<li>feat: 取得ホスト/リダイレクト先を検証（NFR-1） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/53">https://github.com/yk-lab/setup-task/pull/53</a></li>
<li>feat: proxy 環境で全 fetch を proxy 経由にする（#54） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/57">https://github.com/yk-lab/setup-task/pull/57</a></li>
<li>docs: テスト規約を stub-fetch unit test の実態に合わせる（#55） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/58">https://github.com/yk-lab/setup-task/pull/58</a></li>
<li>ci: paths-filter で root 直下の .md も docs 扱いにする（#59） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/60">https://github.com/yk-lab/setup-task/pull/60</a></li>
<li>feat: 取得ボディにサイズ上限とタイムアウトを設ける（#56） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/61">https://github.com/yk-lab/setup-task/pull/61</a></li>
<li>test: platform.test.ts を §9 全 os/arch 組合せに拡張（#41） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/62">https://github.com/yk-lab/setup-task/pull/62</a></li>
<li>ci: ワークフロー静的解析（actionlint / zizmor）を追加（#23） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/68">https://github.com/yk-lab/setup-task/pull/68</a></li>
<li>build(deps): Bump dorny/paths-filter from 3.0.2 to 4.0.1 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/64">https://github.com/yk-lab/setup-task/pull/64</a></li>
<li>chore: ESLint から Biome へ一元化（#45） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/70">https://github.com/yk-lab/setup-task/pull/70</a></li>
<li>build(deps): Bump crate-ci/typos from 1.31.1 to 1.47.2 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/63">https://github.com/yk-lab/setup-task/pull/63</a></li>
<li>build(deps): Bump semver from 7.8.4 to 7.8.5 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/67">https://github.com/yk-lab/setup-task/pull/67</a></li>
<li>docs: 移行ガイド拡充 + セキュア路線へポジショニング見直し（#38 / #73） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/72">https://github.com/yk-lab/setup-task/pull/72</a></li>
<li>chore: lefthook で pre-push に CI 相当チェックを仕込む（#9） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/71">https://github.com/yk-lab/setup-task/pull/71</a></li>
<li>chore: TODO.md を GitHub Issues へのポインタに極小化 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/74">https://github.com/yk-lab/setup-task/pull/74</a></li>
<li>build(deps): Bump undici from 6.27.0 to 8.5.0 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/65">https://github.com/yk-lab/setup-task/pull/65</a></li>
<li>feat: リリース自動化ワークフローを追加（#37） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/75">https://github.com/yk-lab/setup-task/pull/75</a></li>
<li>fix: action 名を Marketplace で一意な &ldquo;Setup go-task&rdquo; に変更 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/76">https://github.com/yk-lab/setup-task/pull/76</a></li>
<li>chore: action 名を &ldquo;Install Task&rdquo; に変更（Marketplace 一意性） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/77">https://github.com/yk-lab/setup-task/pull/77</a></li>
<li>feat: 失敗時もジョブサマリに落ちたフェーズ+理由を出力（#78） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/85">https://github.com/yk-lab/setup-task/pull/85</a></li>
<li>build(deps): Bump undici from 8.5.0 to 8.7.0 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/84">https://github.com/yk-lab/setup-task/pull/84</a></li>
<li>build(deps-dev): Bump @vitest/coverage-v8 from 4.1.9 to 4.1.10 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/83">https://github.com/yk-lab/setup-task/pull/83</a></li>
<li>build(deps): Bump dorny/paths-filter from 4.0.1 to 4.0.2 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/81">https://github.com/yk-lab/setup-task/pull/81</a></li>
<li>build(deps-dev): Bump vitest from 4.1.9 to 4.1.10 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/82">https://github.com/yk-lab/setup-task/pull/82</a></li>
<li>build(deps): Bump crate-ci/typos from 1.47.2 to 1.48.0 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/80">https://github.com/yk-lab/setup-task/pull/80</a></li>
<li>build(deps-dev): Bump @vercel/ncc from 0.44.0 to 0.44.1 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/79">https://github.com/yk-lab/setup-task/pull/79</a></li>
<li>docs: 設計判断を ADR 化し日本語仕様書を撤去、FR-N タグを inline 化 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/89">https://github.com/yk-lab/setup-task/pull/89</a></li>
<li>ci(deps): dependabot で vitest 系をグループ化（lockstep 維持） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/86">https://github.com/yk-lab/setup-task/pull/86</a></li>
<li>fix: リリース成果物を self-contained 化（&ndash;source-map 除去 + バンドル検証ガード） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/92">https://github.com/yk-lab/setup-task/pull/92</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@yk-lab made their first contribution in <a href="https://github.com/yk-lab/setup-task/pull/6">https://github.com/yk-lab/setup-task/pull/6</a></li>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/yk-lab/setup-task/pull/19">https://github.com/yk-lab/setup-task/pull/19</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yk-lab/setup-task/commits/v1.1.1">https://github.com/yk-lab/setup-task/commits/v1.1.1</a></p>
]]></content:encoded></item><item><title>kempt-fmt</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/kempt-fmt/</link><pubDate>Tue, 14 Jul 2026 14:53:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/kempt-fmt/</guid><description>Version updated for https://github.com/ZacSweers/kempt to version v0.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary A pre-commit-friendly multi-language source formatting pipeline that automates Kotlin, Java, and Rust code formatting, inserts license headers, and normalizes trailing whitespace. It provides a tailored configuration per repository based on detected languages and supports various tool versions and configurations, including optional license header support.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ZacSweers/kempt">https://github.com/ZacSweers/kempt</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kempt-fmt">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>A pre-commit-friendly multi-language source formatting pipeline that automates Kotlin, Java, and Rust code formatting, inserts license headers, and normalizes trailing whitespace. It provides a tailored configuration per repository based on detected languages and supports various tool versions and configurations, including optional license header support.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="release-notes">Release Notes</h2>
<p><em>2026-07-14</em></p>
<ul>
<li>Keep hook subprocess parsing stable when Git diff customization or JVM
environment-option announcements would otherwise alter captured output.</li>
<li>Add <code>--touched</code> to format or check files changed on the current branch,
including committed, staged, unstaged, and non-ignored untracked files.</li>
<li>Support files, recursive directories, and glob patterns as explicit
<code>format</code> and <code>check</code> targets. These respect global and per-tool path
exclusions unless <code>--force</code> is passed.</li>
</ul>
<h2 id="install-kempt-fmt-030">Install kempt-fmt 0.3.0</h2>
<h3 id="install-prebuilt-binaries-via-shell-script">Install prebuilt binaries via shell script</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>curl --proto <span style="color:#e6db74">&#39;=https&#39;</span> --tlsv1.2 -LsSf https://github.com/ZacSweers/kempt/releases/download/v0.3.0/kempt-fmt-installer.sh | sh
</span></span></code></pre></div><h3 id="install-prebuilt-binaries-via-powershell-script">Install prebuilt binaries via powershell script</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>powershell -ExecutionPolicy Bypass -c <span style="color:#e6db74">&#34;irm https://github.com/ZacSweers/kempt/releases/download/v0.3.0/kempt-fmt-installer.ps1 | iex&#34;</span>
</span></span></code></pre></div><h3 id="install-prebuilt-binaries-via-homebrew">Install prebuilt binaries via Homebrew</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>brew install ZacSweers/tap/kempt-fmt
</span></span></code></pre></div><h2 id="download-kempt-fmt-030">Download kempt-fmt 0.3.0</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/ZacSweers/kempt/releases/download/v0.3.0/kempt-fmt-aarch64-apple-darwin.tar.xz">kempt-fmt-aarch64-apple-darwin.tar.xz</a></td>
          <td>Apple Silicon macOS</td>
          <td><a href="https://github.com/ZacSweers/kempt/releases/download/v0.3.0/kempt-fmt-aarch64-apple-darwin.tar.xz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/ZacSweers/kempt/releases/download/v0.3.0/kempt-fmt-x86_64-apple-darwin.tar.xz">kempt-fmt-x86_64-apple-darwin.tar.xz</a></td>
          <td>Intel macOS</td>
          <td><a href="https://github.com/ZacSweers/kempt/releases/download/v0.3.0/kempt-fmt-x86_64-apple-darwin.tar.xz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/ZacSweers/kempt/releases/download/v0.3.0/kempt-fmt-x86_64-pc-windows-msvc.zip">kempt-fmt-x86_64-pc-windows-msvc.zip</a></td>
          <td>x64 Windows</td>
          <td><a href="https://github.com/ZacSweers/kempt/releases/download/v0.3.0/kempt-fmt-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/ZacSweers/kempt/releases/download/v0.3.0/kempt-fmt-aarch64-unknown-linux-gnu.tar.xz">kempt-fmt-aarch64-unknown-linux-gnu.tar.xz</a></td>
          <td>ARM64 Linux</td>
          <td><a href="https://github.com/ZacSweers/kempt/releases/download/v0.3.0/kempt-fmt-aarch64-unknown-linux-gnu.tar.xz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/ZacSweers/kempt/releases/download/v0.3.0/kempt-fmt-x86_64-unknown-linux-gnu.tar.xz">kempt-fmt-x86_64-unknown-linux-gnu.tar.xz</a></td>
          <td>x64 Linux</td>
          <td><a href="https://github.com/ZacSweers/kempt/releases/download/v0.3.0/kempt-fmt-x86_64-unknown-linux-gnu.tar.xz.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
]]></content:encoded></item><item><title>LazyCat GitHub Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/lazycat-github-action/</link><pubDate>Tue, 14 Jul 2026 08:21:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/lazycat-github-action/</guid><description>Version updated for https://github.com/ca-x/lazycat-github-action to version v1.1.20.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The LazyCat GitHub Action checks Docker image versions, updates explicit LazyCat Manifest targets, builds LPK files, creates update pull requests, and attaches validated LPK files to GitHub Releases. It automates the CI/CD process for creating versioned Release publishing workflows to both stores and preserves Go Template Manifests through a repository Skill.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ca-x/lazycat-github-action">https://github.com/ca-x/lazycat-github-action</a></strong> to version <strong>v1.1.20</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lazycat-github-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The LazyCat GitHub Action checks Docker image versions, updates explicit LazyCat Manifest targets, builds LPK files, creates update pull requests, and attaches validated LPK files to GitHub Releases. It automates the CI/CD process for creating versioned Release publishing workflows to both stores and preserves Go Template Manifests through a repository Skill.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>a6e31e9dd76d537c4b628fd5240b39bccc4b6b37 fix: persist mutable image digest baselines</li>
</ul>
]]></content:encoded></item><item><title>Nitro Client Validate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/nitro-client-validate/</link><pubDate>Tue, 14 Jul 2026 08:19:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/nitro-client-validate/</guid><description>Version updated for https://github.com/ChilliCream/nitro-client-validate to version v16.5.0.
This action is used across all versions by 5 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action validates client operations against the Nitro registry, automating tasks such as ensuring proper authentication and verifying operation validity. It solves problems related to automated testing and validation of client interactions with a Nitro service. Key capabilities include specifying the stage, client ID, API key, and operations file for validation, along with options to control pull request feedback mode through comment or review.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ChilliCream/nitro-client-validate">https://github.com/ChilliCream/nitro-client-validate</a></strong> to version <strong>v16.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nitro-client-validate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action validates client operations against the Nitro registry, automating tasks such as ensuring proper authentication and verifying operation validity. It solves problems related to automated testing and validation of client interactions with a Nitro service. Key capabilities include specifying the stage, client ID, API key, and operations file for validation, along with options to control pull request feedback mode through comment or review.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update Nitro CLI to 16.5.0 (e45b66e)</li>
<li>Update Nitro CLI to 16.5.0-p.18 (3c65cca)</li>
<li>Update Nitro CLI to 16.5.0-p.15 (f5b50f7)</li>
<li>Update Nitro CLI to 16.5.0-p.14 (9464abb)</li>
<li>Update Nitro CLI to 16.5.0-p.13 (d505a7d)</li>
<li>Update Nitro CLI to 16.5.0-p.12 (120e018)</li>
<li>Update Nitro CLI to 16.5.0-p.11 (cb525df)</li>
<li>Update Nitro CLI to 16.5.0-p.10 (ced126d)</li>
<li>Update Nitro CLI to 16.5.0-p.9 (a1b1a82)</li>
<li>Update Nitro CLI to 16.5.0-p.8 (9a6ef8b)</li>
</ul>
]]></content:encoded></item><item><title>IntentGuard PR Alignment Reviewer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/intentguard-pr-alignment-reviewer/</link><pubDate>Tue, 14 Jul 2026 08:18:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/intentguard-pr-alignment-reviewer/</guid><description>Version updated for https://github.com/derrickchiang1024/intentguard to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary IntentGuard automates an AI-driven alignment review of pull requests against linked Linear issues and sprint intentions. It helps ensure that PRs are aligned with the intended product goals, providing clarity on their scope and potential risks. The action uses Anthropic’s Fable 5 to assess whether the PR meets the requirements described in the Linked issue.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/derrickchiang1024/intentguard">https://github.com/derrickchiang1024/intentguard</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/intentguard-pr-alignment-reviewer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>IntentGuard automates an AI-driven alignment review of pull requests against linked Linear issues and sprint intentions. It helps ensure that PRs are aligned with the intended product goals, providing clarity on their scope and potential risks. The action uses Anthropic&rsquo;s Fable 5 to assess whether the PR meets the requirements described in the Linked issue.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>AI coding agents can write code that passes tests but misses the point. IntentGuard reviews every pull request against the linked Linear issue and current sprint intent, then comments whether the PR is <strong>ALIGNED</strong>, <strong>MISALIGNED</strong>, or <strong>UNCLEAR</strong>.</p>
<h2 id="whats-in-v010">What&rsquo;s in v0.1.0</h2>
<ul>
<li><strong>GitHub Action</strong> — runs on <code>pull_request</code> events, posts exactly one verdict comment per PR and updates it in place on every push</li>
<li><strong>CLI</strong> — <code>intentguard check --mock</code> works offline with zero API keys; <code>--pr N --dry-run</code> reviews real PRs without posting</li>
<li><strong>Linear context</strong> — linked issue, active cycle (with team-cycle fallback), and sibling in-progress issues</li>
<li><strong>Anthropic (Fable 5) verdict engine</strong> — strict JSON via a forced tool call, Zod-validated, deterministic UNCLEAR fallback on invalid output</li>
<li><strong>Security-first design</strong> — never checks out or executes PR code, refuses <code>pull_request_target</code>, treats all PR/Linear text as untrusted input with delimiter sandwiching, redacts likely secrets before LLM use, never blocks merge by default, no telemetry, no data storage</li>
</ul>
<h2 id="install">Install</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">on</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">types</span>: [<span style="color:#ae81ff">opened, reopened, synchronize, ready_for_review]</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">issues</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">intentguard</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">derrickchiang1024/intentguard@v0.1.0</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">github-token</span>: <span style="color:#ae81ff">${{ secrets.GITHUB_TOKEN }}</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">linear-api-key</span>: <span style="color:#ae81ff">${{ secrets.LINEAR_API_KEY }}</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">anthropic-api-key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span></code></pre></div><h2 id="try-it-in-60-seconds-no-api-keys">Try it in 60 seconds (no API keys)</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>git clone https://github.com/derrickchiang1024/intentguard.git
</span></span><span style="display:flex;"><span>cd intentguard <span style="color:#f92672">&amp;&amp;</span> npm install <span style="color:#f92672">&amp;&amp;</span> npm run check:mock
</span></span></code></pre></div><p>106 tests, all credential-free. See <a href="https://github.com/derrickchiang1024/intentguard/blob/main/docs/SECURITY.md">SECURITY.md</a> for the full security model.</p>
]]></content:encoded></item><item><title>mcpfold config gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/mcpfold-config-gate/</link><pubDate>Tue, 14 Jul 2026 08:17:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/mcpfold-config-gate/</guid><description>Version updated for https://github.com/dj-pearson/MCPFold to version v1.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of configuring and managing MCP servers, curating toolsets per client and resolving secret references, thus reducing context-window tax and ensuring consistency across clients. It provides a single canonical configuration file that is folded out to each client, minimizing token usage and maintaining security by not hardcoding secrets.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/dj-pearson/MCPFold">https://github.com/dj-pearson/MCPFold</a></strong> to version <strong>v1.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcpfold-config-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of configuring and managing MCP servers, curating toolsets per client and resolving secret references, thus reducing context-window tax and ensuring consistency across clients. It provides a single canonical configuration file that is folded out to each client, minimizing token usage and maintaining security by not hardcoding secrets.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Story/e25 config assistance by @dj-pearson in <a href="https://github.com/dj-pearson/MCPFold/pull/86">https://github.com/dj-pearson/MCPFold/pull/86</a></li>
<li>Version Packages by @github-actions[bot] in <a href="https://github.com/dj-pearson/MCPFold/pull/87">https://github.com/dj-pearson/MCPFold/pull/87</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/dj-pearson/MCPFold/compare/v1.3.0...v1.4.0">https://github.com/dj-pearson/MCPFold/compare/v1.3.0...v1.4.0</a></p>
]]></content:encoded></item><item><title>GitHub Star Tracker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/github-star-tracker/</link><pubDate>Tue, 14 Jul 2026 08:16:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/github-star-tracker/</guid><description>Version updated for https://github.com/fbuireu/github-star-tracker to version v1.22.4.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GitHub Star Tracker automates the tracking of star counts across all repositories, generates visually appealing reports with charts and badges, and sends notifications when changes are detected. It integrates with GitHub workflows to keep track of stars, trends, and comparisons efficiently.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/fbuireu/github-star-tracker">https://github.com/fbuireu/github-star-tracker</a></strong> to version <strong>v1.22.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-star-tracker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>GitHub Star Tracker automates the tracking of star counts across all repositories, generates visually appealing reports with charts and badges, and sends notifications when changes are detected. It integrates with GitHub workflows to keep track of stars, trends, and comparisons efficiently.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1224-2026-07-13"><a href="https://github.com/fbuireu/github-star-tracker/compare/v1.22.3...v1.22.4">1.22.4</a> (2026-07-13)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>retry transient stargazers/repo fetch errors and stop misattributing them to token restrictions (<a href="https://github.com/fbuireu/github-star-tracker/issues/151">#151</a>) (<a href="https://github.com/fbuireu/github-star-tracker/commit/dd43563a50b5e8f46ab752bbe58ce28daf7e8c8a">dd43563</a>)</li>
</ul>
]]></content:encoded></item><item><title>MyREDAXO Installer Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/myredaxo-installer-action/</link><pubDate>Tue, 14 Jul 2026 08:15:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/myredaxo-installer-action/</guid><description>Version updated for https://github.com/FriendsOfREDAXO/installer-action to version 1.3.0.
This action is used across all versions by 341 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of uploading a REDAXO AddOn to myREDAXO’s AddOn store whenever a new release is created on GitHub. It requires MyREDAXO credentials stored as secrets, and uses PHP and Composer to manage dependencies. The action enforces validation using MyREDAXO’s API and can be configured with a description, version, and whether to enforce Redaxo addon validation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/FriendsOfREDAXO/installer-action">https://github.com/FriendsOfREDAXO/installer-action</a></strong> to version <strong>1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>341</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/myredaxo-installer-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of uploading a REDAXO AddOn to myREDAXO&rsquo;s AddOn store whenever a new release is created on GitHub. It requires MyREDAXO credentials stored as secrets, and uses PHP and Composer to manage dependencies. The action enforces validation using MyREDAXO&rsquo;s API and can be configured with a description, version, and whether to enforce Redaxo addon validation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Runs with <code>node24</code> instead of <code>node20</code></li>
</ul>
<h2 id="minor-security-checks-for-packageyml">minor security checks for package.yml</h2>
]]></content:encoded></item><item><title>Validate ProductSpec files</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/validate-productspec-files/</link><pubDate>Tue, 14 Jul 2026 08:14:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/validate-productspec-files/</guid><description>Version updated for https://github.com/gokulrajaram/ProductSpec to version v0.23.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ProductSpec is an open standard and harness that defines what software should build, how it should be completed, and when. It provides a portable way to define intent up front, attach evidence after work starts, and preserve changes when reality disagrees. This action helps teams and agents ensure that their implementations align with the original requirements and provides tools for validating Product Specs and recording work outcomes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/gokulrajaram/ProductSpec">https://github.com/gokulrajaram/ProductSpec</a></strong> to version <strong>v0.23.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/validate-productspec-files">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>ProductSpec is an open standard and harness that defines what software should build, how it should be completed, and when. It provides a portable way to define intent up front, attach evidence after work starts, and preserve changes when reality disagrees. This action helps teams and agents ensure that their implementations align with the original requirements and provides tools for validating Product Specs and recording work outcomes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This release improves parser round-trip fidelity and adds a concrete agent harness demo.</p>
<p>Fixed:</p>
<ul>
<li>Unknown frontmatter preservation now covers all key shapes, not only snake_case keys.</li>
<li>Kebab-case keys, keys with spaces, quoted keys, and non-ASCII keys are preserved under parser_metadata.unknown_frontmatter instead of being silently dropped on serialize.</li>
</ul>
<p>Added:</p>
<ul>
<li>5-minute agent harness demo.</li>
<li>Harness demo example with Product Spec, Agent Run, and Decision Trace.</li>
<li>Contributor guidance for adding example Product Specs.</li>
</ul>
<p>Note: npm publish for @productspec/parser@0.23.0 still needs to be run separately.</p>
]]></content:encoded></item><item><title>Codex Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/codex-action/</link><pubDate>Tue, 14 Jul 2026 08:13:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/codex-action/</guid><description>Version updated for https://github.com/icoretech/codex-action to version v0.9.19.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the integration of OpenAI Codex into CI/CD workflows by running non-interactively within Docker containers. It solves problems related to accessing OpenAI’s API without manual setup, providing options for both API keys and OAuth/device authentication. The action supports custom preferences through a config.toml file for further customization.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/icoretech/codex-action">https://github.com/icoretech/codex-action</a></strong> to version <strong>v0.9.19</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/codex-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the integration of OpenAI Codex into CI/CD workflows by running non-interactively within Docker containers. It solves problems related to accessing OpenAI&rsquo;s API without manual setup, providing options for both API keys and OAuth/device authentication. The action supports custom preferences through a <code>config.toml</code> file for further customization.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="0919-2026-07-13"><a href="https://github.com/icoretech/codex-action/compare/v0.9.18...v0.9.19">0.9.19</a> (2026-07-13)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> update codex-docker image to v0.144.3 (<a href="https://github.com/icoretech/codex-action/issues/52">#52</a>) (<a href="https://github.com/icoretech/codex-action/commit/9c0e045760b6b4207a8ebc5821a09ccd8c5932d7">9c0e045</a>)</li>
</ul>
]]></content:encoded></item><item><title>Dependency Support Policy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/dependency-support-policy/</link><pubDate>Tue, 14 Jul 2026 08:12:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/dependency-support-policy/</guid><description>Version updated for https://github.com/isaac-cf-wong/dependency-support-policy-action to version v0.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action and CLI tool manage rolling minimum-supported versions for Python projects. It evaluates the Scientific Python SPEC 0 support policy against package release history to raise dependency lower bounds and the requires-python floor accordingly, while preserving existing constraints and comments in pyproject.toml. The action supports both standalone use and integration into workflows, making it a valuable tool for maintaining project dependencies.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/isaac-cf-wong/dependency-support-policy-action">https://github.com/isaac-cf-wong/dependency-support-policy-action</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/dependency-support-policy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action and CLI tool manage <strong>rolling minimum-supported versions</strong> for Python projects. It evaluates the Scientific Python SPEC 0 support policy against package release history to raise dependency lower bounds and the <code>requires-python</code> floor accordingly, while preserving existing constraints and comments in <code>pyproject.toml</code>. The action supports both standalone use and integration into workflows, making it a valuable tool for maintaining project dependencies.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="020---2026-07-13"><a href="https://github.com/isaac-cf-wong/dependency-support-policy-action/compare/v0.1.1..v0.2.0">0.2.0</a> - 2026-07-13</h2>
<h3 id="-features">🚀 Features</h3>
<ul>
<li>Expose the CLI as a pre-commit hook (#24) - (<a href="https://github.com/isaac-cf-wong/dependency-support-policy-action/commit/67c09f68141f83263e684ee456b167a8e06d7765">67c09f6</a>)</li>
</ul>
<h3 id="-miscellaneous-tasks">⚙️ Miscellaneous Tasks</h3>
<ul>
<li><em>(deps)</em> Update dependency mypy to &gt;=2.3.0 (#25) - (<a href="https://github.com/isaac-cf-wong/dependency-support-policy-action/commit/450e0f1dc90d5d5241b042117ab332bb35b107f9">450e0f1</a>)</li>
<li>Serialize support floor update runs (#23) - (<a href="https://github.com/isaac-cf-wong/dependency-support-policy-action/commit/75cff0c2be63f607d68a10a79174591fb67a6a40">75cff0c</a>)</li>
</ul>
<hr>
<p><strong>Contributing</strong>: Contributions are welcome! See the <a href="https://github.com/isaac-cf-wong/dependency-support-policy-action/blob/main/CONTRIBUTING.md">Contributing Guide</a>.</p>
<p><strong>Questions?</strong> Open an issue on <a href="https://github.com/isaac-cf-wong/dependency-support-policy-action/issues">GitHub</a>.</p>
]]></content:encoded></item><item><title>detect-git-changes-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/detect-git-changes-action/</link><pubDate>Tue, 14 Jul 2026 08:10:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/detect-git-changes-action/</guid><description>Version updated for https://github.com/isaac-cf-wong/detect-git-changes-action to version v0.0.16.
This action is used across all versions by 9 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action, detect-git-changes-action, automates the detection of changes in a repository compared to a specified base reference. It helps automate tasks like triggering builds or notifications based on changes, and provides options for path filtering to focus only on specific files or directories. This action is lightweight and robust, using git operations locally to perform comparison, ensuring compatibility with repositories that require full history access.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/isaac-cf-wong/detect-git-changes-action">https://github.com/isaac-cf-wong/detect-git-changes-action</a></strong> to version <strong>v0.0.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>9</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/detect-git-changes-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action, detect-git-changes-action, automates the detection of changes in a repository compared to a specified base reference. It helps automate tasks like triggering builds or notifications based on changes, and provides options for path filtering to focus only on specific files or directories. This action is lightweight and robust, using git operations locally to perform comparison, ensuring compatibility with repositories that require full history access.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="0016---2026-07-10"><a href="https://github.com/isaac-cf-wong/detect-git-changes-action/compare/v0.0.15..v0.0.16">0.0.16</a> - 2026-07-10</h2>
<h3 id="-miscellaneous-tasks">⚙️ Miscellaneous Tasks</h3>
<ul>
<li><em>(deps)</em> Update pre-commit hook rbubley/mirrors-prettier to v3.9.5 (<a href="https://github.com/isaac-cf-wong/detect-git-changes-action/issues/43">#43</a>) - (<a href="https://github.com/isaac-cf-wong/detect-git-changes-action/commit/cd2bc7a539b89312d0d7bca70991988083157e21">cd2bc7a</a>)</li>
</ul>
<hr>
<p><strong>Contributing</strong>: We welcome contributions! Please see our <a href="https://github.com/isaac-cf-wong/detect-git-changes-action/blob/main/CONTRIBUTING.md">Contributing Guide</a> for details.</p>
<p><strong>Questions?</strong> Open an issue on <a href="https://github.com/isaac-cf-wong/detect-git-changes-action/issues">GitHub</a> or join our discussions.</p>
]]></content:encoded></item><item><title>jk-publish-test-results</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/jk-publish-test-results/</link><pubDate>Tue, 14 Jul 2026 08:10:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/jk-publish-test-results/</guid><description>Version updated for https://github.com/jedi-knights/publish-test-results to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the publishing of multi-format test results as a drilldownable per-test check-run in GitHub, allowing users to click through individual tests and annotations directly from the files-changed diff. It supports various input dialects, including JUnit XML and other formats, and is optimized for cold start performance, with typical parsing times under a second.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jedi-knights/publish-test-results">https://github.com/jedi-knights/publish-test-results</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jk-publish-test-results">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the publishing of multi-format test results as a drilldownable per-test check-run in GitHub, allowing users to click through individual tests and annotations directly from the files-changed diff. It supports various input dialects, including JUnit XML and other formats, and is optimized for cold start performance, with typical parsing times under a second.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
]]></content:encoded></item><item><title>npm-scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/npm-scan/</link><pubDate>Tue, 14 Jul 2026 08:08:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/npm-scan/</guid><description>Version updated for https://github.com/lateos-ai/npm-scan to version v1.5.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
npm-scan is a comprehensive security tool designed to detect advanced attack vectors not caught by traditional tools like npm audit, Snyk, or Socket. It focuses on identifying obfuscated payloads, credential stealers, kernel rootkits, eBPF hooks, memory extraction, GitHub spoofing, and AI-targeted attacks. The action provides 95%+ confidence in detecting these vulnerabilities and significantly reduces the risk of data breaches, regulatory fines, and financial liability.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lateos-ai/npm-scan">https://github.com/lateos-ai/npm-scan</a></strong> to version <strong>v1.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/npm-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>npm-scan is a comprehensive security tool designed to detect advanced attack vectors not caught by traditional tools like npm audit, Snyk, or Socket. It focuses on identifying obfuscated payloads, credential stealers, kernel rootkits, eBPF hooks, memory extraction, GitHub spoofing, and AI-targeted attacks. The action provides 95%+ confidence in detecting these vulnerabilities and significantly reduces the risk of data breaches, regulatory fines, and financial liability.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="npm-scan-v150">npm-scan v1.5.0</h1>
<h2 id="release-summary">Release Summary</h2>
<ul>
<li><strong>Campaign Detection</strong>: 100% (3/3 real attacks)</li>
<li><strong>False Positive Rate</strong>: 0.0% (0/990 packages)</li>
<li><strong>Tests</strong>: All 671 passing</li>
<li><strong>Code Quality</strong>: 0 linting errors</li>
</ul>
<h2 id="validation-metrics">Validation Metrics</h2>
<ul>
<li>D6 (Version Anomaly): 92% avg confidence</li>
<li>D7 (Obfuscation): 80% avg confidence</li>
<li>D1 (Typosquat): 87.9% avg confidence</li>
</ul>
<p>See <a href="./VALIDATION.md">VALIDATION.md</a> for full metrics.</p>
<p><strong>Published with npm provenance attestation (SLSA Level 2).</strong></p>
]]></content:encoded></item><item><title>ansede-static</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/ansede-static/</link><pubDate>Tue, 14 Jul 2026 08:07:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/ansede-static/</guid><description>Version updated for https://github.com/mattybellx/Ansede to version v6.3.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Ansede Static is a comprehensive static analysis tool designed to detect common security flaws such as CWE-639 IDOR. It provides 100% CVE recall across multiple languages and catches authorization flaws that can lead to data breaches. The action automates the scanning of codebases, including generating SARIF reports for GitHub Code Scanning, diff-only scans for pull requests, and interactive HTML reports. It supports offline operation and is fully customizable with built-in rules for specific security vulnerabilities like IDOR.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mattybellx/Ansede">https://github.com/mattybellx/Ansede</a></strong> to version <strong>v6.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ansede-static">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Ansede Static is a comprehensive static analysis tool designed to detect common security flaws such as CWE-639 IDOR. It provides 100% CVE recall across multiple languages and catches authorization flaws that can lead to data breaches. The action automates the scanning of codebases, including generating SARIF reports for GitHub Code Scanning, diff-only scans for pull requests, and interactive HTML reports. It supports offline operation and is fully customizable with built-in rules for specific security vulnerabilities like IDOR.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="630--2026-07-13">[6.3.0] — 2026-07-13</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>CWE-639 IDOR Detection</strong> — World-first among open-source SAST tools. Detects
Insecure Direct Object Reference patterns across Express/DAO (JS), Django ORM
(Python), Flask-SQLAlchemy (Python), and Spring Boot JPA (Java). Identifies route
parameters used in database queries without session/ownership verification.</li>
<li><strong>Variable propagation in fallback detectors</strong> — All three language analyzers
(JS, Python, Java) now trace taint through variable assignments, enabling detection
of patterns like <code>const x = req.query.file</code> → <code>fs.readFile(x)</code>.</li>
<li><strong>Struts2/Spring parameter binding detection</strong> — Java fallback now recognizes
implicit taint sources from framework parameter binding (setters, <code>@RequestParam</code>,
<code>@PathVariable</code>) in addition to explicit <code>getParameter()</code> calls.</li>
<li><strong>Django ORM <code>.raw()</code> propagation</strong> — Multi-hop taint tracing through string
concatenation assignments: <code>name = request.GET.get('q')</code> → <code>sql = &quot;SELECT...&quot; + name</code>
→ <code>Model.objects.raw(sql)</code>.</li>
</ul>
<h3 id="improved">Improved</h3>
<ul>
<li><strong>Known-vulnerability detection: 88.6% → 91.4%</strong> across 4 test applications
(NodeGoat, goof, pygoat, dvja) covering 35 CWE instances.</li>
<li><strong>Production noise: 0.04 findings/kLOC</strong> — Verified across 16 real production
repositories (366,638 LOC). Scanner correctly identifies well-written production
code as clean.</li>
<li><strong>Python fallback cap</strong> — Increased from 20 to 25 with injection CWE prioritization
to prevent CWE-89/CWE-78 truncation.</li>
<li><strong>Java <code>Runtime.exec()</code> pattern</strong> — Now matches <code>runtime.exec(command)</code> where
<code>command</code> is a variable, not just chained <code>.exec(var + &quot;...&quot;)</code>.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>Confidence pipeline bug</strong> — <code>pattern-rust</code> analysis kind now recognized as
structural evidence, preventing false demotion of legitimate findings.</li>
<li><strong>Paren-location bug</strong> — <code>_arg_contains_taint</code> now correctly locates the opening
parenthesis in regex-matched sink patterns across all three language fallbacks.</li>
<li><strong>SQLAlchemy parameterized query FP</strong> — <code>.execute(text(...), {'key': var})</code> now
correctly identified as safe (parameterized).</li>
<li><strong>CWE-22 method-call FP</strong> — <code>f.read()</code>, <code>obj.write()</code> patterns no longer flagged
as path traversal.</li>
<li><strong>Python CWE-22 secure_filename guard</strong> — Files using <code>werkzeug.utils.secure_filename</code>
are now correctly excluded from path traversal detection.</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li>1,215 tests passing (96.4%)</li>
<li>CVE recall: 100% (164/164 across 5 languages)</li>
<li>16-repo production benchmark: 0.04 findings/kLOC average</li>
</ul>
]]></content:encoded></item><item><title>TestivAI Visual Report</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/testivai-visual-report/</link><pubDate>Tue, 14 Jul 2026 08:05:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/testivai-visual-report/</guid><description>Version updated for https://github.com/mcbuddy/testivai-oss to version @testivai/witness-playwright@1.3.1.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of capturing and diffing screenshots to detect visual regressions in web applications locally. It helps identify render noise instead of false positives, providing a more reliable report by comparing both pixel changes and DOM structure. The action supports multiple frameworks (Playwright, WebdriverIO) and offers an optional cloud upgrade for additional analysis and team approvals.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mcbuddy/testivai-oss">https://github.com/mcbuddy/testivai-oss</a></strong> to version <strong>@testivai/witness-playwright@1.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/testivai-visual-report">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of capturing and diffing screenshots to detect visual regressions in web applications locally. It helps identify render noise instead of false positives, providing a more reliable report by comparing both pixel changes and DOM structure. The action supports multiple frameworks (Playwright, WebdriverIO) and offers an optional cloud upgrade for additional analysis and team approvals.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="patch-changes">Patch Changes</h3>
<ul>
<li>cc6f3eb: Fix per-call <code>ignoreSelectors</code> (and <code>stabilize</code>) being dropped by the config merge. <code>testivai.witness(page, testInfo, 'name', { ignoreSelectors: ['.badge'] })</code> silently ignored the selectors — the elements were neither hidden from the screenshot nor excluded from the DOM snapshot. Long masked by the diff engine&rsquo;s cumulated threshold absorbing the few leaked pixels; surfaced by the text-aware DOM diff correctly flagging the leaked dynamic text.</li>
</ul>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/go-proxy-cache-updater/</link><pubDate>Tue, 14 Jul 2026 08:04:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.23.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Go Proxy Cache Updater Action automates the process of pulling new Go module releases to a specified proxy cache when tags are created. It supports standard and submodule version tags and allows customization of proxy configuration, import paths, and build settings. The action ensures that your module is immediately available on platforms like pkg.go.dev.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.23</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Go Proxy Cache Updater Action automates the process of pulling new Go module releases to a specified proxy cache when tags are created. It supports standard and submodule version tags and allows customization of proxy configuration, import paths, and build settings. The action ensures that your module is immediately available on platforms like pkg.go.dev.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1123-2026-07-14"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.22...v1.1.23">1.1.23</a> (2026-07-14)</h2>
]]></content:encoded></item><item><title>Postman API Onboarding</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/postman-api-onboarding/</link><pubDate>Tue, 14 Jul 2026 08:03:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/postman-api-onboarding/</guid><description>Version updated for https://github.com/postman-cs/postman-api-onboarding-action to version v2.0.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman API Onboarding Action is a comprehensive tool designed to streamline the setup and testing of new APIs in GitHub repositories. It automates the process of creating a workspace, uploading an OpenAPI specification, generating collections for smoke and contract testing, and setting up CI/CD pipelines with JUnit output. The action supports both US and EU data residency options and integrates seamlessly into GitHub workflows to ensure that all aspects of API development are standardized and automated.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-api-onboarding-action">https://github.com/postman-cs/postman-api-onboarding-action</a></strong> to version <strong>v2.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-api-onboarding">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman API Onboarding Action is a comprehensive tool designed to streamline the setup and testing of new APIs in GitHub repositories. It automates the process of creating a workspace, uploading an OpenAPI specification, generating collections for smoke and contract testing, and setting up CI/CD pipelines with JUnit output. The action supports both US and EU data residency options and integrates seamlessly into GitHub workflows to ensure that all aspects of API development are standardized and automated.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: refresh Wave 1 sibling pins by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/64">https://github.com/postman-cs/postman-api-onboarding-action/pull/64</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.0.2...v2.0.3">https://github.com/postman-cs/postman-api-onboarding-action/compare/v2.0.2...v2.0.3</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Insights Linking</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/postman-onboarding-insights-linking/</link><pubDate>Tue, 14 Jul 2026 08:02:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/postman-onboarding-insights-linking/</guid><description>Version updated for https://github.com/postman-cs/postman-insights-onboarding-action to version v2.1.2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the linking of discovered services from the Postman Insights agent to an existing Postman workspace and git repository after deployment. It solves the problem of ensuring that every service discovered by Insights is properly cataloged, linked with a collection, a repo link, and live telemetry in the API Catalog. The action provides capabilities for setting up prerequisites, specifying inputs such as project name, workspace ID, environment ID, and Postman credentials, and linking services from Insights to the catalog.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-insights-onboarding-action">https://github.com/postman-cs/postman-insights-onboarding-action</a></strong> to version <strong>v2.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-insights-linking">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the linking of discovered services from the Postman Insights agent to an existing Postman workspace and git repository after deployment. It solves the problem of ensuring that every service discovered by Insights is properly cataloged, linked with a collection, a repo link, and live telemetry in the API Catalog. The action provides capabilities for setting up prerequisites, specifying inputs such as project name, workspace ID, environment ID, and Postman credentials, and linking services from Insights to the catalog.</p>
<p>The summary highlights that this action does not perform deployment tasks but focuses on linking discovered services with existing infrastructure, integrating insights data into an API Catalog.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: reconcile insights links safely by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/44">https://github.com/postman-cs/postman-insights-onboarding-action/pull/44</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-insights-onboarding-action/compare/v2.1.1...v2.1.2">https://github.com/postman-cs/postman-insights-onboarding-action/compare/v2.1.1...v2.1.2</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Repo Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/postman-onboarding-repo-sync/</link><pubDate>Tue, 14 Jul 2026 08:01:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/postman-onboarding-repo-sync/</guid><description>Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.1.2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of exporting Postman collections and environments into a repository, wiring CI, mock servers, and monitors around them. It solves problems related to manual collection management by providing a streamlined and automated solution that integrates with Postman’s API onboarding suite. The action supports various sync modes and provides inputs for configuring project details, workspace assets, and authentication tokens.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-repo-sync-action">https://github.com/postman-cs/postman-repo-sync-action</a></strong> to version <strong>v2.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-repo-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of exporting Postman collections and environments into a repository, wiring CI, mock servers, and monitors around them. It solves problems related to manual collection management by providing a streamlined and automated solution that integrates with Postman&rsquo;s API onboarding suite. The action supports various sync modes and provides inputs for configuring project details, workspace assets, and authentication tokens.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: reconcile create outcomes safely by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/69">https://github.com/postman-cs/postman-repo-sync-action/pull/69</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.1...v2.1.2">https://github.com/postman-cs/postman-repo-sync-action/compare/v2.1.1...v2.1.2</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Smoke Flow</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/postman-onboarding-smoke-flow/</link><pubDate>Tue, 14 Jul 2026 08:00:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/postman-onboarding-smoke-flow/</guid><description>Version updated for https://github.com/postman-cs/postman-smoke-flow-action to version v2.1.2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Postman Onboarding: Smoke Flow action reshapes a generated Postman Smoke collection to match a curated flow.yaml and can optionally inject runtime auth (OAuth2 or API keys) via the Postman gateway. It automates the process of integrating new smoke collections with a specific workflow structure, ensuring consistency across projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-smoke-flow-action">https://github.com/postman-cs/postman-smoke-flow-action</a></strong> to version <strong>v2.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-smoke-flow">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Postman Onboarding: Smoke Flow action reshapes a generated Postman Smoke collection to match a curated <code>flow.yaml</code> and can optionally inject runtime auth (OAuth2 or API keys) via the Postman gateway. It automates the process of integrating new smoke collections with a specific workflow structure, ensuring consistency across projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: reconcile smoke items by live shape by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/36">https://github.com/postman-cs/postman-smoke-flow-action/pull/36</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-smoke-flow-action/compare/v2.1.1...v2.1.2">https://github.com/postman-cs/postman-smoke-flow-action/compare/v2.1.1...v2.1.2</a></p>
]]></content:encoded></item><item><title>Rust PR Diff Analyzer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/rust-pr-diff-analyzer/</link><pubDate>Tue, 14 Jul 2026 07:57:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/rust-pr-diff-analyzer/</guid><description>Version updated for https://github.com/RAprogramm/rust-prod-diff-checker to version v2.0.1.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the process of analyzing Rust project Pull Requests (PRs) to enforce size limits. It uses Rust AST analysis to count only meaningful production code changes, ignoring tests, benchmarks, and examples. This helps teams maintain cleaner PRs that are easier to review and maintain. The action supports features like semantic analysis, qualified names, line ranges, per-unit stats, smart classification, analysis scope reports, weighted scoring, flexible limits, PR comments, and multiple output formats including GitHub Actions format, JSON for integration, human-readable text, and markdown comments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RAprogramm/rust-prod-diff-checker">https://github.com/RAprogramm/rust-prod-diff-checker</a></strong> to version <strong>v2.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rust-pr-diff-analyzer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the process of analyzing Rust project Pull Requests (PRs) to enforce size limits. It uses Rust AST analysis to count only meaningful production code changes, ignoring tests, benchmarks, and examples. This helps teams maintain cleaner PRs that are easier to review and maintain. The action supports features like semantic analysis, qualified names, line ranges, per-unit stats, smart classification, analysis scope reports, weighted scoring, flexible limits, PR comments, and multiple output formats including GitHub Actions format, JSON for integration, human-readable text, and markdown comments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="201---2026-07-14"><a href="https://github.com/RAprogramm/rust-prod-diff-checker/compare/v2.0.0...v2.0.1">2.0.1</a> - 2026-07-14</h2>
]]></content:encoded></item><item><title>Remyx Outrider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/remyx-outrider/</link><pubDate>Tue, 14 Jul 2026 07:56:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/remyx-outrider/</guid><description>Version updated for https://github.com/remyxai/outrider to version v1.7.23.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the validation and comparison of new research methods against an existing codebase. It helps teams measure changes by scheduling runs or triggering them on demand, using Anthropic Opus or z.ai’s GLM models as backends. The action supports draft PRs with self-reviews, issues for preflight checks, and branch-only mode for exploration without committing to a single candidate.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remyxai/outrider">https://github.com/remyxai/outrider</a></strong> to version <strong>v1.7.23</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/remyx-outrider">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the validation and comparison of new research methods against an existing codebase. It helps teams measure changes by scheduling runs or triggering them on demand, using Anthropic Opus or z.ai&rsquo;s GLM models as backends. The action supports draft PRs with self-reviews, issues for preflight checks, and branch-only mode for exploration without committing to a single candidate.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Closes the loop on the observation that spawned this release: the fleet&rsquo;s continuous mode kept re-picking the same top-relevance paper (WebSwarm) every cron cycle, either via intel-aware selection ignoring the &ldquo;already-dispatched&rdquo; prompt section, or via the fallback path when the selection Claude call failed empty. This release turns that pattern into cheap, auditable skips — with escape hatches for legitimate re-dispatch cases.</p>
<h2 id="whats-in-it">What&rsquo;s in it</h2>
<p><strong>Selection-pass history awareness</strong></p>
<ul>
<li>New &ldquo;Already-dispatched arxivs on this fork&rdquo; section renders in the selection prompt when <code>maintain-state: true</code> is on and the fork has landings in <code>.remyx/repo_intel.yaml</code>. Selection Claude sees the list before picking.</li>
<li>Schema extended with <code>is_re_pick</code> + <code>re_pick_justification</code> fields — model self-flags when it re-picks a prior arxiv, must justify with &ldquo;different mode / different call-site / new coordination signal&rdquo; reasoning.</li>
<li>Server-side detection catches unflagged re-picks: after JSON parse + chosen_index validation, cross-checks the pick&rsquo;s arxiv (versionless-normalized) against the dispatched list. If picked = prior-landing without <code>is_re_pick=true</code>, force the flag + trigger justification coercion.</li>
</ul>
<p><strong>Collision-free branch naming</strong></p>
<ul>
<li>Before <code>git push</code>, checks <code>git/ref/heads/&lt;slug&gt;</code> via GitHub API for a collision.</li>
<li>Applies <code>-v2..-vN</code> suffix hierarchy if the branch already exists; falls back to <code>-YYYYMMDD</code> timestamp for astronomically-unlikely <code>-v20</code>+ exhaustion.</li>
<li>Preserves the <code>-refined</code> convention for <code>start-from-ref</code> runs.</li>
</ul>
<p><strong>Duplicate-work guard at <code>process_target</code></strong></p>
<ul>
<li>Catches picks that bypassed the selection layer&rsquo;s enforcement (e.g. fallback path when <code>_run_claude_oneshot_streaming</code> returns <code>ok=False</code>).</li>
<li>Coerces terminal status to <code>skipped_arxiv_already_landed</code> instead of running a redundant coding session.</li>
<li>Four bypass conditions preserve intentional re-dispatch: <code>INPUT_PIN_ARXIV</code>, <code>INPUT_START_FROM_REF</code>, <code>INPUT_LEAD_CONTENT</code>, or an already-justified <code>is_re_pick</code>. Each bypass surfaces its reason in <code>result[&quot;duplicate_work_guard_bypass_reason&quot;]</code> for telemetry.</li>
</ul>
<p><strong>Selection call resilience</strong></p>
<ul>
<li>Retry-on-empty-output: when the Claude streaming call returns <code>ok=False</code> with truly empty output (observed in the wild on z.ai&rsquo;s Anthropic-compat endpoint), retry once with reduced max-turns before falling back. Preserves the &ldquo;signaled failure → no retry&rdquo; behavior for timeouts / CLI-gone (which return non-empty error text).</li>
</ul>
<h2 id="observed-behavior-on-ag2-continuous-mode">Observed behavior on ag2 continuous mode</h2>
<p>Sequence of two consecutive cron dispatches during release testing:</p>
<ul>
<li>20:26 cron (pre-fix): <code>selection call failed: ; falling back...</code> → picked WebSwarm → produced webswarm-&hellip;-v2 branch → $0.46 spent on duplicate work.</li>
<li>20:50 cron (post-fix): <code>selection call returned empty output... retrying</code> → retry also failed → fallback picked WebSwarm → <code>⚠ duplicate-work guard: picked arxiv 2607.08662 already has a landing... skipping</code> → status <code>skipped_arxiv_already_landed</code> → $0.20 spent, no duplicate branch produced.</li>
</ul>
<h2 id="backward-compatibility">Backward compatibility</h2>
<p>No breaking changes. All new behavior gated on <code>maintain-state: true</code> (default <code>false</code>). Existing dispatches without maintain-state ignore the guard entirely.</p>
<p>Tests: 1036 pass, 1 skipped. Adds 82 new tests specifically for the repo-intel + guard + collision-naming machinery.</p>
]]></content:encoded></item><item><title>Console CensorChecker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/console-censorchecker/</link><pubDate>Tue, 14 Jul 2026 07:55:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/console-censorchecker/</guid><description>Version updated for https://github.com/SpaceTimee/Console-CensorChecker to version 1.1.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Console-CensorChecker 是一个基于 PowerShell 的 Tcping 批量拨测与审查检测脚本，适用于任何平台。它主要用于检查网络中目标主机的延迟情况，并监控服务可用性，旨在帮助用户了解是否有审查设备的存在。该脚本提供了两种安装方式：PowerShell 模块和 GitHub Actions 调用。
What’s Changed Check Check Need Network Censorship</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SpaceTimee/Console-CensorChecker">https://github.com/SpaceTimee/Console-CensorChecker</a></strong> to version <strong>1.1.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/console-censorchecker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Console-CensorChecker 是一个基于 PowerShell 的 Tcping 批量拨测与审查检测脚本，适用于任何平台。它主要用于检查网络中目标主机的延迟情况，并监控服务可用性，旨在帮助用户了解是否有审查设备的存在。该脚本提供了两种安装方式：PowerShell 模块和 GitHub Actions 调用。</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Check Check Need Network Censorship</strong></p>
]]></content:encoded></item><item><title>Set up Rocq</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/set-up-rocq/</link><pubDate>Tue, 14 Jul 2026 07:54:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/set-up-rocq/</guid><description>Version updated for https://github.com/tchajed/setup-rocq to version v1.7.6.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the installation of Rocq, a theorem prover, with OPAM (OCaml Package Manager). It supports caching opam dependencies to speed up future builds and allows for customizing the version of Rocq installed through its inputs. Additionally, it provides options to specify additional Opam repositories and files used in cache generation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tchajed/setup-rocq">https://github.com/tchajed/setup-rocq</a></strong> to version <strong>v1.7.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/set-up-rocq">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the installation of Rocq, a theorem prover, with OPAM (OCaml Package Manager). It supports caching opam dependencies to speed up future builds and allows for customizing the version of Rocq installed through its inputs. Additionally, it provides options to specify additional Opam repositories and files used in cache generation.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s changed</h2>
<ul>
<li>Updated undici to 6.27.0, fixing CVE-2026-12151 (denial of service due to unbounded memory) and several other undici CVEs (#67).</li>
<li>Updated <code>@actions/glob</code> to 0.7.0 (#60).</li>
<li>Updated <code>actions/checkout</code> to v7 in workflows (#65).</li>
<li>Updated development dependencies, including ESLint, Prettier, prettier-eslint, Rollup, and typescript-eslint (#63, #64, #68, #69).</li>
<li>Excluded the generated <code>dist/</code> output from Trivy scans to fix false-positive secret findings in CI.</li>
</ul>
<p>The major version tag <code>v1</code> has been updated to point at this release.</p>
]]></content:encoded></item><item><title>cowork-harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/cowork-harness/</link><pubDate>Tue, 14 Jul 2026 07:54:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/cowork-harness/</guid><description>Version updated for https://github.com/yaniv-golan/cowork-harness to version v1.0.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The cowork-harness action is a test harness designed to reproduce Claude Cowork’s observable runtime contract across various scenarios and CI environments. It automates the testing of skills by simulating the behavior and limitations of the Desktop app without using it directly, allowing for accurate testing in headless environments. The action supports different fidelity tiers that vary in their level of resources required for execution, from a free demo to live tiers that require additional software such as Claude Desktop and a token for real model interactions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yaniv-golan/cowork-harness">https://github.com/yaniv-golan/cowork-harness</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cowork-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The cowork-harness action is a test harness designed to reproduce Claude Cowork&rsquo;s observable runtime contract across various scenarios and CI environments. It automates the testing of skills by simulating the behavior and limitations of the Desktop app without using it directly, allowing for accurate testing in headless environments. The action supports different fidelity tiers that vary in their level of resources required for execution, from a free demo to live tiers that require additional software such as Claude Desktop and a token for real model interactions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Patch: shorten the Action&rsquo;s Marketplace tagline. No runtime/API change.</p>
<h3 id="fixed">Fixed</h3>
<ul>
<li><code>action.yml</code>&rsquo;s <code>description</code> is now under GitHub Marketplace&rsquo;s 125-character limit (the full
token-free-vs-live-lane detail is retained as comments above it), so the packaged Action can be
published to the Marketplace. <code>1.0.1</code>&rsquo;s description was too long and blocked the listing.</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>release: 1.0.2 by @yaniv-golan in <a href="https://github.com/yaniv-golan/cowork-harness/pull/42">https://github.com/yaniv-golan/cowork-harness/pull/42</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.0.2">https://github.com/yaniv-golan/cowork-harness/compare/v1...v1.0.2</a></p>
]]></content:encoded></item><item><title>ATR Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/atr-scan/</link><pubDate>Tue, 14 Jul 2026 02:57:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/atr-scan/</guid><description>Version updated for https://github.com/Agent-Threat-Rule/agent-threat-rules to version v3.5.9.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ATR, an open detection rule format for AI agent security threats, provides a vendor-neutral, machine-readable, peer-reviewable rule format that enables easy integration with any conforming engine. It is used in various applications such as security threat detection and malware signatures, making it analogous to Sigma and YARA for SIEM and malware detection, respectively.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Agent-Threat-Rule/agent-threat-rules">https://github.com/Agent-Threat-Rule/agent-threat-rules</a></strong> to version <strong>v3.5.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/atr-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>ATR, an open detection rule format for AI agent security threats, provides a vendor-neutral, machine-readable, peer-reviewable rule format that enables easy integration with any conforming engine. It is used in various applications such as security threat detection and malware signatures, making it analogous to Sigma and YARA for SIEM and malware detection, respectively.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Auto-published from Threat Cloud flywheel.</p>
<ul>
<li>Previous: v3.5.8</li>
<li>Total rules: 751</li>
<li>Trigger commit: <a href="https://github.com/Agent-Threat-Rule/agent-threat-rules/commit/7dec520d6bc8f647949083252df9777519c32ff2">7dec520d6bc8f647949083252df9777519c32ff2</a></li>
<li>Pipeline: tc-pr-back → safety gate → auto-merge → this release</li>
</ul>
<pre tabindex="0"><code>npm install agent-threat-rules@3.5.9
</code></pre>]]></content:encoded></item><item><title>Cache Go files efficiently</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/cache-go-files-efficiently/</link><pubDate>Tue, 14 Jul 2026 02:56:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/cache-go-files-efficiently/</guid><description>Version updated for https://github.com/capnspacehook/cache-go to version v2.1.1.
This action is used across all versions by 6 repositories. Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action cache-go helps in efficiently caching Go module and build files. It ensures that cached build files are not invalidated by changes in dependencies and avoids the need to restore a stale cache when a newer version of Go is used. The action uses separate keys for restoring and saving these caches, making it easier to manage different versions and environments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/capnspacehook/cache-go">https://github.com/capnspacehook/cache-go</a></strong> to version <strong>v2.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<p>Go to the <a href="https://github.com/marketplace/actions/cache-go-files-efficiently">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>cache-go</code> helps in efficiently caching Go module and build files. It ensures that cached build files are not invalidated by changes in dependencies and avoids the need to restore a stale cache when a newer version of Go is used. The action uses separate keys for restoring and saving these caches, making it easier to manage different versions and environments.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/capnspacehook/cache-go/compare/v2.1.0...v2.1.1">https://github.com/capnspacehook/cache-go/compare/v2.1.0...v2.1.1</a></p>
]]></content:encoded></item><item><title>Contrast AI SmartFix</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/contrast-ai-smartfix/</link><pubDate>Tue, 14 Jul 2026 02:55:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/contrast-ai-smartfix/</guid><description>Version updated for https://github.com/Contrast-Security-OSS/contrast-ai-smartfix-action to version v1.0.20.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 5 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary SmartFix is an AI-powered GitHub Action that automates the remediation of security vulnerabilities identified by Contrast Security. It integrates seamlessly into existing workflows via GitHub Actions, generating Pull Requests (PRs) with proposed fixes. Key benefits include automated remediation, developer-focused PR creation, and accurate vulnerability context. Users can choose from SmartFix’s internal coding agent or integrate with GitHub Copilot or Anthropic’s Claude Code bot for customized vulnerability fixes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Contrast-Security-OSS/contrast-ai-smartfix-action">https://github.com/Contrast-Security-OSS/contrast-ai-smartfix-action</a></strong> to version <strong>v1.0.20</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>5</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/contrast-ai-smartfix">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>SmartFix is an AI-powered GitHub Action that automates the remediation of security vulnerabilities identified by Contrast Security. It integrates seamlessly into existing workflows via GitHub Actions, generating Pull Requests (PRs) with proposed fixes. Key benefits include automated remediation, developer-focused PR creation, and accurate vulnerability context. Users can choose from SmartFix&rsquo;s internal coding agent or integrate with GitHub Copilot or Anthropic&rsquo;s Claude Code bot for customized vulnerability fixes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="contrast-ai-smartfix-release">Contrast AI SmartFix Release</h2>
<p>SmartFix is an AI-powered agent that automatically generates code fixes for vulnerabilities identified by Contrast Assess. It integrates into your developer workflow via GitHub Actions, creating Pull Requests (PRs) with proposed remediations.</p>
<p>Please see our README here: <a href="https://github.com/Contrast-Security-OSS/contrast-ai-smartfix-action">https://github.com/Contrast-Security-OSS/contrast-ai-smartfix-action</a>.</p>
<h2 id="v1020-highlights">v1.0.20 Highlights</h2>
<p>This release adds support for remediating static SAST vulnerabilities found by Contrast Code in a repository for NorthStar-only customers.</p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>AIML-820: SmartFix NorthStar action changes — NS mode label, URL, and identifier support by @JacobMagesHaskinsContrast in <a href="https://github.com/Contrast-Security-OSS/contrast-ai-smartfix-action/pull/175">https://github.com/Contrast-Security-OSS/contrast-ai-smartfix-action/pull/175</a></li>
<li>AIML-885: Log findingType and severity after finding extraction by @JacobMagesHaskinsContrast in <a href="https://github.com/Contrast-Security-OSS/contrast-ai-smartfix-action/pull/178">https://github.com/Contrast-Security-OSS/contrast-ai-smartfix-action/pull/178</a></li>
<li>AIML-999: SAST-only mode — skip app ID requirement for SAST-only repos by @JacobMagesHaskinsContrast in <a href="https://github.com/Contrast-Security-OSS/contrast-ai-smartfix-action/pull/179">https://github.com/Contrast-Security-OSS/contrast-ai-smartfix-action/pull/179</a></li>
<li>AIML-999: send repoUrl on /open reconciliation by @JacobMagesHaskinsContrast in <a href="https://github.com/Contrast-Security-OSS/contrast-ai-smartfix-action/pull/181">https://github.com/Contrast-Security-OSS/contrast-ai-smartfix-action/pull/181</a></li>
<li>AIML-1005: Update docs to document NorthStar-only (SAST-only) mode by @JacobMagesHaskinsContrast in <a href="https://github.com/Contrast-Security-OSS/contrast-ai-smartfix-action/pull/180">https://github.com/Contrast-Security-OSS/contrast-ai-smartfix-action/pull/180</a></li>
<li>AIML-1054 Release version v1.0.20 by @JacobMagesHaskinsContrast in <a href="https://github.com/Contrast-Security-OSS/contrast-ai-smartfix-action/pull/182">https://github.com/Contrast-Security-OSS/contrast-ai-smartfix-action/pull/182</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Contrast-Security-OSS/contrast-ai-smartfix-action/compare/v1...v1.0.20">https://github.com/Contrast-Security-OSS/contrast-ai-smartfix-action/compare/v1...v1.0.20</a></p>
]]></content:encoded></item><item><title>mcpfold config gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/mcpfold-config-gate/</link><pubDate>Tue, 14 Jul 2026 02:54:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/mcpfold-config-gate/</guid><description>Version updated for https://github.com/dj-pearson/MCPFold to version v1.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary mcpfold is a CLI that connects every MCP server without incurring the context-window tax by curating toolsets per client. It reduces the number of tokenized tool schema entries by up to 80% and avoids hardcoding secrets by resolving references. The action simplifies configuration management, making it portable across different clients with a single canonical config file.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/dj-pearson/MCPFold">https://github.com/dj-pearson/MCPFold</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcpfold-config-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><code>mcpfold</code> is a CLI that connects every MCP server without incurring the context-window tax by curating toolsets per client. It reduces the number of tokenized tool schema entries by up to 80% and avoids hardcoding secrets by resolving references. The action simplifies configuration management, making it portable across different clients with a single canonical config file.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(release): run WinGet submit on a Windows runner by @dj-pearson in <a href="https://github.com/dj-pearson/MCPFold/pull/50">https://github.com/dj-pearson/MCPFold/pull/50</a></li>
<li>chore: open-source governance, contribution flow, and triage automation by @dj-pearson in <a href="https://github.com/dj-pearson/MCPFold/pull/51">https://github.com/dj-pearson/MCPFold/pull/51</a></li>
<li>chore: prettier-format MAINTAINERS.md table (fix format:check on main) by @dj-pearson in <a href="https://github.com/dj-pearson/MCPFold/pull/53">https://github.com/dj-pearson/MCPFold/pull/53</a></li>
<li>feat(site): add &ldquo;The Fold&rdquo; scroll-scrubbed hero animation by @dj-pearson in <a href="https://github.com/dj-pearson/MCPFold/pull/73">https://github.com/dj-pearson/MCPFold/pull/73</a></li>
<li>docs: add Open VSX badge to README by @dj-pearson in <a href="https://github.com/dj-pearson/MCPFold/pull/74">https://github.com/dj-pearson/MCPFold/pull/74</a></li>
<li>ci(dependabot): defer major bumps to manual upgrades by @dj-pearson in <a href="https://github.com/dj-pearson/MCPFold/pull/75">https://github.com/dj-pearson/MCPFold/pull/75</a></li>
<li>ci: bump the actions group across 1 directory with 17 updates by @dependabot[bot] in <a href="https://github.com/dj-pearson/MCPFold/pull/52">https://github.com/dj-pearson/MCPFold/pull/52</a></li>
<li>chore(deps): bump the minor-and-patch group across 3 directories with 4 updates by @dependabot[bot] in <a href="https://github.com/dj-pearson/MCPFold/pull/54">https://github.com/dj-pearson/MCPFold/pull/54</a></li>
<li>feat(vscode): inline tool-token-budget CodeLens on mcp.config.jsonc (S21.2) by @dj-pearson in <a href="https://github.com/dj-pearson/MCPFold/pull/76">https://github.com/dj-pearson/MCPFold/pull/76</a></li>
<li>feat: curation intelligence — mcpfold curate + doctor/status surfacing (E23) by @dj-pearson in <a href="https://github.com/dj-pearson/MCPFold/pull/78">https://github.com/dj-pearson/MCPFold/pull/78</a></li>
<li>fix(sync): embed config dir into user-scope shims so GUI clients can launch by @dj-pearson in <a href="https://github.com/dj-pearson/MCPFold/pull/80">https://github.com/dj-pearson/MCPFold/pull/80</a></li>
<li>fix(sync): shim servers with a tools directive so curation takes effect by @dj-pearson in <a href="https://github.com/dj-pearson/MCPFold/pull/81">https://github.com/dj-pearson/MCPFold/pull/81</a></li>
<li>chore(deps): bump the minor-and-patch group across 2 directories with 1 update by @dependabot[bot] in <a href="https://github.com/dj-pearson/MCPFold/pull/82">https://github.com/dj-pearson/MCPFold/pull/82</a></li>
<li>Version Packages by @github-actions[bot] in <a href="https://github.com/dj-pearson/MCPFold/pull/79">https://github.com/dj-pearson/MCPFold/pull/79</a></li>
<li>Story/s24.1 s24.2 curation routing by @dj-pearson in <a href="https://github.com/dj-pearson/MCPFold/pull/83">https://github.com/dj-pearson/MCPFold/pull/83</a></li>
<li>fix(release): idempotent GitHub-release attach + changeset for 1.3.0 by @dj-pearson in <a href="https://github.com/dj-pearson/MCPFold/pull/84">https://github.com/dj-pearson/MCPFold/pull/84</a></li>
<li>Version Packages by @github-actions[bot] in <a href="https://github.com/dj-pearson/MCPFold/pull/85">https://github.com/dj-pearson/MCPFold/pull/85</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/dj-pearson/MCPFold/pull/52">https://github.com/dj-pearson/MCPFold/pull/52</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/dj-pearson/MCPFold/compare/v1.1.0...v1.3.0">https://github.com/dj-pearson/MCPFold/compare/v1.1.0...v1.3.0</a></p>
]]></content:encoded></item><item><title>easySFTP</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/easysftp/</link><pubDate>Tue, 14 Jul 2026 02:53:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/easysftp/</guid><description>Version updated for https://github.com/eiserv/easySFTP to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
This GitHub Action automates secure SFTP file transfers for deploying build output to any SFTP server. It supports fast, secure uploads with options for host key pinning, configurable uploads, delete mode, dry runs, retries, and outputs for monitoring. The action is designed to be simple yet highly customizable, suitable for both small deployments and complex multi-target scenarios.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/eiserv/easySFTP">https://github.com/eiserv/easySFTP</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/easysftp">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>This GitHub Action automates secure SFTP file transfers for deploying build output to any SFTP server. It supports fast, secure uploads with options for host key pinning, configurable uploads, delete mode, dry runs, retries, and outputs for monitoring. The action is designed to be simple yet highly customizable, suitable for both small deployments and complex multi-target scenarios.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/eiserv/easySFTP/commits/v1.0.0">https://github.com/eiserv/easySFTP/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>Sieve Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/sieve-security-scan/</link><pubDate>Tue, 14 Jul 2026 02:51:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/sieve-security-scan/</guid><description>Version updated for https://github.com/fendora-io/sieve-action to version v1.4.4.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
Sieve is a GitHub Action that uses AI-powered security scanning to detect real vulnerabilities in pull requests, with the ability to suppress false positives. The action automatically scans code files and posts relevant comments on PRs, allowing team members to mark findings as either real or false positive. It supports customization via inputs for repo alias and failure behavior during checks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/fendora-io/sieve-action">https://github.com/fendora-io/sieve-action</a></strong> to version <strong>v1.4.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sieve-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>Sieve is a GitHub Action that uses AI-powered security scanning to detect real vulnerabilities in pull requests, with the ability to suppress false positives. The action automatically scans code files and posts relevant comments on PRs, allowing team members to mark findings as either real or false positive. It supports customization via inputs for repo alias and failure behavior during checks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Prepare for OpenSSF Best Practices badge by @mohijalili in <a href="https://github.com/fendora-io/sieve-action/pull/25">https://github.com/fendora-io/sieve-action/pull/25</a></li>
<li>Validate CI/CD metadata in Docker workflow by @mohijalili in <a href="https://github.com/fendora-io/sieve-action/pull/26">https://github.com/fendora-io/sieve-action/pull/26</a></li>
<li>Align branding to Sieve by Fendora and add Best Practices badge by @mohijalili in <a href="https://github.com/fendora-io/sieve-action/pull/27">https://github.com/fendora-io/sieve-action/pull/27</a></li>
<li>Prepare OpenSSF Baseline-2 compliance by @mohijalili in <a href="https://github.com/fendora-io/sieve-action/pull/28">https://github.com/fendora-io/sieve-action/pull/28</a></li>
<li>Prepare OpenSSF Baseline-3 compliance by @mohijalili in <a href="https://github.com/fendora-io/sieve-action/pull/29">https://github.com/fendora-io/sieve-action/pull/29</a></li>
<li>Prepare v1.4.4 release by @mohijalili in <a href="https://github.com/fendora-io/sieve-action/pull/31">https://github.com/fendora-io/sieve-action/pull/31</a></li>
<li>Fix release signing when :latest is present by @mohijalili in <a href="https://github.com/fendora-io/sieve-action/pull/32">https://github.com/fendora-io/sieve-action/pull/32</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/fendora-io/sieve-action/compare/v1.4.3...v1.4.4">https://github.com/fendora-io/sieve-action/compare/v1.4.3...v1.4.4</a></p>
]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/ai-plugin-scanner/</link><pubDate>Tue, 14 Jul 2026 02:50:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.467.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the scanning of AI plugin repositories across various Codex, Claude, Gemini, and OpenCode ecosystems for security, publishability, runtime readiness, and trust signals. It emits structured reports, SARIF files, policy results, and submission metadata, ensuring compliance with main scanner release train standards. The action supports manual scan, lint, verify, and submit modes, with options to specify plugin directories, execution profiles, output formats, and more.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.467</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>18</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the scanning of AI plugin repositories across various Codex, Claude, Gemini, and OpenCode ecosystems for security, publishability, runtime readiness, and trust signals. It emits structured reports, SARIF files, policy results, and submission metadata, ensuring compliance with main scanner release train standards. The action supports manual scan, lint, verify, and submit modes, with options to specify plugin directories, execution profiles, output formats, and more.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/42b148192d120bc4f304136329d29c00e6fd3144">https://github.com/hashgraph-online/hol-guard/tree/42b148192d120bc4f304136329d29c00e6fd3144</a> with plugin-scanner 2.0.1068.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.466...v1.2.467">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.466...v1.2.467</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/hol-codex-plugin-scanner/</link><pubDate>Tue, 14 Jul 2026 02:49:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.467.
This action is used across all versions by 12 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the scanning of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems to ensure security, publishability, runtime readiness, and trust signals. It emits structured reports, SARIF files, policy results, and submission metadata while staying aligned with the main scanner release train.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.467</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>12</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the scanning of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems to ensure security, publishability, runtime readiness, and trust signals. It emits structured reports, SARIF files, policy results, and submission metadata while staying aligned with the main scanner release train.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.467">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.467</a></p>
]]></content:encoded></item><item><title>Alcatraz PII Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/alcatraz-pii-scan/</link><pubDate>Tue, 14 Jul 2026 02:48:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/alcatraz-pii-scan/</guid><description>Version updated for https://github.com/hoophq/alcatraz-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Alcatraz PII Scan GitHub Action detects and reports personal identifiable information (PII) in code, logs, comments, or issues across 12 countries. It uses Alcatraz’s detection engine without any external services or network calls. The action scans PR diffs, log outputs, and comment bodies for PII, annotates the lines, posts a sticky report comment, writes a step summary, and can fail the check until PII is removed or allow-listed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hoophq/alcatraz-action">https://github.com/hoophq/alcatraz-action</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/alcatraz-pii-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Alcatraz PII Scan GitHub Action detects and reports personal identifiable information (PII) in code, logs, comments, or issues across 12 countries. It uses Alcatraz&rsquo;s detection engine without any external services or network calls. The action scans PR diffs, log outputs, and comment bodies for PII, annotates the lines, posts a sticky report comment, writes a step summary, and can fail the check until PII is removed or allow-listed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Fix action description by @matheusfrancisco in <a href="https://github.com/hoophq/alcatraz-action/pull/3">https://github.com/hoophq/alcatraz-action/pull/3</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hoophq/alcatraz-action/compare/v1.0.0...v1.0.1">https://github.com/hoophq/alcatraz-action/compare/v1.0.0...v1.0.1</a></p>
]]></content:encoded></item><item><title>GHAGGA Code Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/ghagga-code-review/</link><pubDate>Tue, 14 Jul 2026 02:47:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/ghagga-code-review/</guid><description>Version updated for https://github.com/JNZader/ghagga to version v3.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GHAGGA is a production AI code review system that automates static analysis and multi-agent decision-making processes to improve code quality and maintainability. It uses 17 deterministic tools for detection of known issues before running a large language model (LLM). The tool learns from past reviews, retains context, and supports five orchestration strategies for different review needs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/JNZader/ghagga">https://github.com/JNZader/ghagga</a></strong> to version <strong>v3.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ghagga-code-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>GHAGGA is a production AI code review system that automates static analysis and multi-agent decision-making processes to improve code quality and maintainability. It uses 17 deterministic tools for detection of known issues before running a large language model (LLM). The tool learns from past reviews, retains context, and supports five orchestration strategies for different review needs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs(readme): visualize review pipeline + fan-out multi-agent mode by @JNZader in <a href="https://github.com/JNZader/ghagga/pull/272">https://github.com/JNZader/ghagga/pull/272</a></li>
<li>test(cli): harden GitLab &ndash;mr live E2E manual gate by @JNZader in <a href="https://github.com/JNZader/ghagga/pull/273">https://github.com/JNZader/ghagga/pull/273</a></li>
<li>docs: bilingual README (refresh EN + add ES) by @JNZader in <a href="https://github.com/JNZader/ghagga/pull/279">https://github.com/JNZader/ghagga/pull/279</a></li>
<li>chore(ci): bump actions/checkout from 9f698171ed81b15d1823a05fc7211befd50c8ae0 to df4cb1c069e1874edd31b4311f1884172cec0e10 by @dependabot[bot] in <a href="https://github.com/JNZader/ghagga/pull/274">https://github.com/JNZader/ghagga/pull/274</a></li>
<li>chore(ci): bump pnpm/action-setup from 6.0.8 to 6.0.9 by @dependabot[bot] in <a href="https://github.com/JNZader/ghagga/pull/275">https://github.com/JNZader/ghagga/pull/275</a></li>
<li>chore(deps)(deps-dev): bump @types/node from 25.9.1 to 26.0.0 by @dependabot[bot] in <a href="https://github.com/JNZader/ghagga/pull/277">https://github.com/JNZader/ghagga/pull/277</a></li>
<li>chore(deps)(deps): bump the minor-and-patch group across 1 directory with 24 updates by @dependabot[bot] in <a href="https://github.com/JNZader/ghagga/pull/280">https://github.com/JNZader/ghagga/pull/280</a></li>
<li>chore(deps): batch safe Dependabot updates (CI actions + minor/patch) by @JNZader in <a href="https://github.com/JNZader/ghagga/pull/288">https://github.com/JNZader/ghagga/pull/288</a></li>
<li>chore(deps): upgrade AI SDK to v7 (coupled #285/#286/#287) by @JNZader in <a href="https://github.com/JNZader/ghagga/pull/289">https://github.com/JNZader/ghagga/pull/289</a></li>
<li>fix: remediate AUDIT-2026-07-10 — 20 findings (3 CRITICAL) by @JNZader in <a href="https://github.com/JNZader/ghagga/pull/290">https://github.com/JNZader/ghagga/pull/290</a></li>
<li>chore(action): rebuild dist to ship ACTION-MEM-001 fix by @JNZader in <a href="https://github.com/JNZader/ghagga/pull/291">https://github.com/JNZader/ghagga/pull/291</a></li>
<li>docs(memory): document semantic-reranking limitation (MEM-HYBRID-006) by @JNZader in <a href="https://github.com/JNZader/ghagga/pull/292">https://github.com/JNZader/ghagga/pull/292</a></li>
<li>feat(core): embedding provider abstraction — semantic-memory PR1/8 by @JNZader in <a href="https://github.com/JNZader/ghagga/pull/293">https://github.com/JNZader/ghagga/pull/293</a></li>
<li>feat(db): per-row embedding metadata columns — semantic-memory PR2/8 by @JNZader in <a href="https://github.com/JNZader/ghagga/pull/301">https://github.com/JNZader/ghagga/pull/301</a></li>
<li>feat(core): SQLite semantic cosine union — semantic-memory PR3/8 by @JNZader in <a href="https://github.com/JNZader/ghagga/pull/295">https://github.com/JNZader/ghagga/pull/295</a></li>
<li>feat(db): Postgres semantic cosine union — semantic-memory PR4/8 by @JNZader in <a href="https://github.com/JNZader/ghagga/pull/296">https://github.com/JNZader/ghagga/pull/296</a></li>
<li>feat(apps): wire embedding provider into 3 contexts — semantic-memory PR5/8 by @JNZader in <a href="https://github.com/JNZader/ghagga/pull/297">https://github.com/JNZader/ghagga/pull/297</a></li>
<li>feat(core): embedding backfill routine + CLI/server — semantic-memory PR6/8 by @JNZader in <a href="https://github.com/JNZader/ghagga/pull/298">https://github.com/JNZader/ghagga/pull/298</a></li>
<li>feat(core): local optional embedding provider — semantic-memory PR7/8 by @JNZader in <a href="https://github.com/JNZader/ghagga/pull/299">https://github.com/JNZader/ghagga/pull/299</a></li>
<li>docs: semantic memory search + config + backfill — semantic-memory PR8/8 by @JNZader in <a href="https://github.com/JNZader/ghagga/pull/300">https://github.com/JNZader/ghagga/pull/300</a></li>
<li>chore(sdd): archive semantic-memory-retrieval + sync specs by @JNZader in <a href="https://github.com/JNZader/ghagga/pull/302">https://github.com/JNZader/ghagga/pull/302</a></li>
<li>chore(typecheck): cover backfill scripts in tsc by @JNZader in <a href="https://github.com/JNZader/ghagga/pull/303">https://github.com/JNZader/ghagga/pull/303</a></li>
<li>chore(ci): bump docker/login-action from 4.2.0 to 4.4.0 by @dependabot[bot] in <a href="https://github.com/JNZader/ghagga/pull/304">https://github.com/JNZader/ghagga/pull/304</a></li>
<li>chore(ci): bump docker/metadata-action from 6.1.0 to 6.2.0 by @dependabot[bot] in <a href="https://github.com/JNZader/ghagga/pull/305">https://github.com/JNZader/ghagga/pull/305</a></li>
<li>chore(ci): bump actions/checkout from 6.0.3 to 7.0.0 by @dependabot[bot] in <a href="https://github.com/JNZader/ghagga/pull/306">https://github.com/JNZader/ghagga/pull/306</a></li>
<li>chore(deps)(deps): bump the minor-and-patch group with 10 updates by @dependabot[bot] in <a href="https://github.com/JNZader/ghagga/pull/307">https://github.com/JNZader/ghagga/pull/307</a></li>
<li>chore(release): close post-3.1.0 readiness gaps by @JNZader in <a href="https://github.com/JNZader/ghagga/pull/310">https://github.com/JNZader/ghagga/pull/310</a></li>
<li>chore(release): version packages for v3.2.0 by @JNZader in <a href="https://github.com/JNZader/ghagga/pull/312">https://github.com/JNZader/ghagga/pull/312</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/JNZader/ghagga/compare/v3.1.0...v3.2.0">https://github.com/JNZader/ghagga/compare/v3.1.0...v3.2.0</a></p>
]]></content:encoded></item><item><title>npm-scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/npm-scan/</link><pubDate>Tue, 14 Jul 2026 02:45:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/npm-scan/</guid><description>Version updated for https://github.com/lateos-ai/npm-scan to version v1.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The npm-scan action detects various types of supply chain threats, including kernel rootkits, memory extraction, and AI-targeted attacks. It provides 95%+ confidence on real campaigns and is 1,875x more cost-effective than traditional tools like npm audit and Snyk.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lateos-ai/npm-scan">https://github.com/lateos-ai/npm-scan</a></strong> to version <strong>v1.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/npm-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>The npm-scan action detects various types of supply chain threats, including kernel rootkits, memory extraction, and AI-targeted attacks. It provides 95%+ confidence on real campaigns and is 1,875x more cost-effective than traditional tools like npm audit and Snyk.</strong></p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="npm-scan-v140">npm-scan v1.4.0</h1>
<h2 id="release-summary">Release Summary</h2>
<ul>
<li><strong>Campaign Detection</strong>: 100% (3/3 real attacks)</li>
<li><strong>False Positive Rate</strong>: 0.0% (0/990 packages)</li>
<li><strong>Tests</strong>: All 671 passing</li>
<li><strong>Code Quality</strong>: 0 linting errors</li>
</ul>
<h2 id="validation-metrics">Validation Metrics</h2>
<ul>
<li>D6 (Version Anomaly): 92% avg confidence</li>
<li>D7 (Obfuscation): 80% avg confidence</li>
<li>D1 (Typosquat): 87.9% avg confidence</li>
</ul>
<p>See <a href="./VALIDATION.md">VALIDATION.md</a> for full metrics.</p>
<p><strong>Published with npm provenance attestation (SLSA Level 2).</strong></p>
]]></content:encoded></item><item><title>agent-bom Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/agent-bom-scan/</link><pubDate>Tue, 14 Jul 2026 02:44:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/agent-bom-scan/</guid><description>Version updated for https://github.com/msaad00/agent-bom to version v0.95.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the scanning of software vulnerabilities using Open Source Security Framework (SARIF) format. It integrates with various security tools such as Snyk, Checkmarx, Veracode, and more to scan code repositories, container images, and APIs. The action generates findings in SARIF format, which can be integrated into existing vulnerability management systems or used for compliance reporting.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/msaad00/agent-bom">https://github.com/msaad00/agent-bom</a></strong> to version <strong>v0.95.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-bom-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the scanning of software vulnerabilities using Open Source Security Framework (SARIF) format. It integrates with various security tools such as Snyk, Checkmarx, Veracode, and more to scan code repositories, container images, and APIs. The action generates findings in SARIF format, which can be integrated into existing vulnerability management systems or used for compliance reporting.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(ci): isolate dashboard no-ui route tests by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3764">https://github.com/msaad00/agent-bom/pull/3764</a></li>
<li>fix(ui): sources overflow and demo watermark on mobile by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3766">https://github.com/msaad00/agent-bom/pull/3766</a></li>
<li>fix(cli): cloud scan alias crashes with TypeError (aws_include_lambda) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3767">https://github.com/msaad00/agent-bom/pull/3767</a></li>
<li>fix(gateway): detect modern secret formats in DLP; correct fail_mode doc by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3768">https://github.com/msaad00/agent-bom/pull/3768</a></li>
<li>fix(cli): harden focused-command formats, unscanned-check gate, friendly findings error, &ndash;aws-deep by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3769">https://github.com/msaad00/agent-bom/pull/3769</a></li>
<li>fix(api): dedupe in-memory findings view, calm graph backpressure, validate findings sort/severity + results push by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3770">https://github.com/msaad00/agent-bom/pull/3770</a></li>
<li>fix(output): surface reachability in JSON findings, warn on malformed manifests, tighten typosquat + git-SHA confidence by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3771">https://github.com/msaad00/agent-bom/pull/3771</a></li>
<li>fix(graph): stop walking inbound trust edges as outbound assume (complete #3761) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3772">https://github.com/msaad00/agent-bom/pull/3772</a></li>
<li>fix(ui): product taxonomy, density pass, and demo clarity by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3773">https://github.com/msaad00/agent-bom/pull/3773</a></li>
<li>fix(ui): un-crash Runtime + Lineage pages, unique findings keys, light-mode + version fixes by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3774">https://github.com/msaad00/agent-bom/pull/3774</a></li>
<li>fix(ui): align Snowflake and cloud vendor logos in workflow diagram by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3776">https://github.com/msaad00/agent-bom/pull/3776</a></li>
<li>feat(ui): add top product bar with canonical agent-bom branding by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3777">https://github.com/msaad00/agent-bom/pull/3777</a></li>
<li>feat(ui): tenant service registry for lock/connect/live states by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3775">https://github.com/msaad00/agent-bom/pull/3775</a></li>
<li>fix(deploy): pilot quickstart db path, SPCS tag sync, dependency CVE floors by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3778">https://github.com/msaad00/agent-bom/pull/3778</a></li>
<li>fix(data): store correctness + output fidelity (tenant audit chain, snowflake fleet, clickhouse ts, sqlite busy_timeout, SBOM/CSV/parquet/prometheus) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3779">https://github.com/msaad00/agent-bom/pull/3779</a></li>
<li>test(ci): de-flake 1M SQLite perf guard + exclude slow tests from required CI by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3780">https://github.com/msaad00/agent-bom/pull/3780</a></li>
<li>fix(security): VCS token off argv, header download token, redact webhook URLs, tenant-scope stores, HEAD gate, MCP write labels, NL skill-exfil, report suggestion by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3781">https://github.com/msaad00/agent-bom/pull/3781</a></li>
<li>docs(diagram): make cloud vendor logos legible on white chips by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3782">https://github.com/msaad00/agent-bom/pull/3782</a></li>
<li>feat(demo): seed showcase catalog, workflow v2, and operator UI polish by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3783">https://github.com/msaad00/agent-bom/pull/3783</a></li>
<li>fix(ui): posture nav, scan targets, and security-graph polish by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3784">https://github.com/msaad00/agent-bom/pull/3784</a></li>
<li>feat(ui): embed live graph investigation on security graph by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3785">https://github.com/msaad00/agent-bom/pull/3785</a></li>
<li>fix(ui): align AI BOM manifest with platform theme and evidence model by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3786">https://github.com/msaad00/agent-bom/pull/3786</a></li>
<li>fix(ui): consolidated operator experience — connectors, jobs DAG, graph readability by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3787">https://github.com/msaad00/agent-bom/pull/3787</a></li>
<li>feat(ui): clarify New Scan scope and connected account picker by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3788">https://github.com/msaad00/agent-bom/pull/3788</a></li>
<li>fix(ui): unblock main E2E graph selector drift by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3791">https://github.com/msaad00/agent-bom/pull/3791</a></li>
<li>chore(deps): bump lucide-react from 1.23.0 to 1.24.0 in /ui by @dependabot[bot] in <a href="https://github.com/msaad00/agent-bom/pull/3790">https://github.com/msaad00/agent-bom/pull/3790</a></li>
<li>feat(brand): BOM manifest mark + agent bill of materials tagline by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3792">https://github.com/msaad00/agent-bom/pull/3792</a></li>
<li>fix(tests): restore release lint hygiene by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3793">https://github.com/msaad00/agent-bom/pull/3793</a></li>
<li>docs(deploy): rollout verification + brand/docs polish by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3794">https://github.com/msaad00/agent-bom/pull/3794</a></li>
<li>chore(typing): bring findings pipeline + store accessors under strict mypy (#1969) by @andres-linero in <a href="https://github.com/msaad00/agent-bom/pull/3796">https://github.com/msaad00/agent-bom/pull/3796</a></li>
<li>fix(ui): agent+BOM brand mark and NIST text tiles by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3797">https://github.com/msaad00/agent-bom/pull/3797</a></li>
<li>feat(graph): first-class AI framework BOM entities by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3798">https://github.com/msaad00/agent-bom/pull/3798</a></li>
<li>fix(platform): harden self-hosted release validation by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3795">https://github.com/msaad00/agent-bom/pull/3795</a></li>
<li>fix(deploy): secrets via files across Postgres and control plane by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3801">https://github.com/msaad00/agent-bom/pull/3801</a></li>
<li>feat(ui): Overview exec briefing; mesh off-home by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3812">https://github.com/msaad00/agent-bom/pull/3812</a></li>
<li>feat(brand): agent HUD in the O, not emoji smile by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3813">https://github.com/msaad00/agent-bom/pull/3813</a></li>
<li>fix(deploy): reset Postgres app-password GUC so it doesn&rsquo;t persist in cleartext by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3817">https://github.com/msaad00/agent-bom/pull/3817</a></li>
<li>fix(ui): topology contrast + drop orphan DashboardAnalytics by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3818">https://github.com/msaad00/agent-bom/pull/3818</a></li>
<li>fix(compliance): never score unevaluated controls as pass by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3819">https://github.com/msaad00/agent-bom/pull/3819</a></li>
<li>fix(secrets): resolve signing PEMs file-first + keyless-lead cloud creds (#3807) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3820">https://github.com/msaad00/agent-bom/pull/3820</a></li>
<li>feat(security): keep DB-tier secrets out of the DSN and rotate audit HMAC keys by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3821">https://github.com/msaad00/agent-bom/pull/3821</a></li>
<li>feat(identity): harden OAuth-AS issuer, JWT aud/iss binding, deprovision by owner by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3822">https://github.com/msaad00/agent-bom/pull/3822</a></li>
<li>fix(findings): match severity filter on string column for backend parity by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3824">https://github.com/msaad00/agent-bom/pull/3824</a></li>
<li>fix(api): offload findings read-path and graph reads off the event loop by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3823">https://github.com/msaad00/agent-bom/pull/3823</a></li>
<li>feat(output): interop schema conformance gate + strict-validity and determinism fixes by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3826">https://github.com/msaad00/agent-bom/pull/3826</a></li>
<li>fix(cli): scan explicit &ndash;project under &ndash;no-discover; guard zero-artifact scans by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3825">https://github.com/msaad00/agent-bom/pull/3825</a></li>
<li>refactor(ast): dedupe shared scanner primitives into ast_signal_utils by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3828">https://github.com/msaad00/agent-bom/pull/3828</a></li>
<li>docs: reconcile drifted capability counts and enforce check-counts in CI by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3827">https://github.com/msaad00/agent-bom/pull/3827</a></li>
<li>chore: remove orphaned back-compat shim and duplicate scripts by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3830">https://github.com/msaad00/agent-bom/pull/3830</a></li>
<li>fix(graph): canonical model node id + emit observes edges by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3829">https://github.com/msaad00/agent-bom/pull/3829</a></li>
<li>fix(auth): count SAML SSO in CLI boot gate and auth-configured checks by @andres-linero in <a href="https://github.com/msaad00/agent-bom/pull/3831">https://github.com/msaad00/agent-bom/pull/3831</a></li>
<li>fix(image): include aws/azure/gcp SDKs so self-hosted BYOC works (#3832) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3836">https://github.com/msaad00/agent-bom/pull/3836</a></li>
<li>fix(correctness): close post-merge audit gaps by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3837">https://github.com/msaad00/agent-bom/pull/3837</a></li>
<li>feat(cli): install-aware upgrade guidance, update/upgrade disambiguation, DB freshness signals by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3838">https://github.com/msaad00/agent-bom/pull/3838</a></li>
<li>ci(demo): automate hosted demo redeploy on release via SSM (#3833) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3839">https://github.com/msaad00/agent-bom/pull/3839</a></li>
<li>fix(secrets): make proxy signing keys file-first by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3840">https://github.com/msaad00/agent-bom/pull/3840</a></li>
<li>docs(deploy): add a verifiable self-hosted BYOC path by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3841">https://github.com/msaad00/agent-bom/pull/3841</a></li>
<li>feat(cli): connect can establish and verify a read-only cloud connection (#3832) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3842">https://github.com/msaad00/agent-bom/pull/3842</a></li>
<li>fix(cli): correct Snowflake connect scan command (points at a removed surface) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3846">https://github.com/msaad00/agent-bom/pull/3846</a></li>
<li>feat(ui): post-scan repo overview with surface chips by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3848">https://github.com/msaad00/agent-bom/pull/3848</a></li>
<li>fix(polish): refresh cloud scans and HUD favicon by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3844">https://github.com/msaad00/agent-bom/pull/3844</a></li>
<li>feat(auth): OIDC auth-code + PKCE browser login foundation by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3849">https://github.com/msaad00/agent-bom/pull/3849</a></li>
<li>docs(readme): Scan → Graph → Serve lanes, brand mark, fresh demo media by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3850">https://github.com/msaad00/agent-bom/pull/3850</a></li>
<li>chore(release): 0.95.0 — enterprise auth, cloud-connect, interop, security hardening by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3851">https://github.com/msaad00/agent-bom/pull/3851</a></li>
<li>docs(release): combine demo, provider onboarding, and SDK maintenance by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3855">https://github.com/msaad00/agent-bom/pull/3855</a></li>
<li>fix(ui): dedupe live-investigation panel, graph readability, HUD mark polish, overview consolidation by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3857">https://github.com/msaad00/agent-bom/pull/3857</a></li>
<li>chore(maintenance): combine UI cleanup and dependency updates by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3862">https://github.com/msaad00/agent-bom/pull/3862</a></li>
<li>fix(ui): leadership-first overview, correlated top risks, drawers, findings drill-down by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3863">https://github.com/msaad00/agent-bom/pull/3863</a></li>
<li>fix(security): confine POST /v1/scan local paths to the same jail as secondary scan endpoints by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3864">https://github.com/msaad00/agent-bom/pull/3864</a></li>
<li>fix(ui): consolidate scan entry points + vocabulary (Connect→Scan→Assess) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3865">https://github.com/msaad00/agent-bom/pull/3865</a></li>
<li>fix(demo): complete + reliable correlated demo-estate seed (agents, exposure paths, identity) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3866">https://github.com/msaad00/agent-bom/pull/3866</a></li>
<li>ci(azure-ingestion): skip scheduled run when Azure OIDC is not configured by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3868">https://github.com/msaad00/agent-bom/pull/3868</a></li>
<li>docs(readme): top-load What-is/Personas/How-It-Works + Connect-first visuals &amp; logo lockup by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3867">https://github.com/msaad00/agent-bom/pull/3867</a></li>
<li>feat(inventory): unified asset-inventory endpoint + Snowflake connection sweep parity by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3869">https://github.com/msaad00/agent-bom/pull/3869</a></li>
<li>fix(ui): pre-release polish — full-width sources/registry + connection drawer CTA dedupe by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3870">https://github.com/msaad00/agent-bom/pull/3870</a></li>
<li>feat(cloud): non-blocking cloud SDK freshness signal by @andres-linero in <a href="https://github.com/msaad00/agent-bom/pull/3872">https://github.com/msaad00/agent-bom/pull/3872</a></li>
<li>feat(mcp): agent-native unified asset-inventory tools by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3871">https://github.com/msaad00/agent-bom/pull/3871</a></li>
<li>feat(platform): combine API route deprecation and dashboard SSO CTA by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3875">https://github.com/msaad00/agent-bom/pull/3875</a></li>
<li>docs: reconcile API-op / route-module / MCP-tool counts for 0.95.0 by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3876">https://github.com/msaad00/agent-bom/pull/3876</a></li>
<li>fix(inventory): facet-filtered list drops rows past the page limit (P1, pre-tag) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3877">https://github.com/msaad00/agent-bom/pull/3877</a></li>
<li>fix(ui): lift dark theme contrast for readable hierarchy by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3878">https://github.com/msaad00/agent-bom/pull/3878</a></li>
<li>fix(compliance): per-framework endpoint reports no_data on zero scans, not score 100 (pre-tag) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3879">https://github.com/msaad00/agent-bom/pull/3879</a></li>
<li>fix(overview): count bulk-ingested findings in posture grade + headline by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3890">https://github.com/msaad00/agent-bom/pull/3890</a></li>
<li>fix(compliance): wire MITRE ATT&amp;CK to its real bundled catalog (#3882) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3891">https://github.com/msaad00/agent-bom/pull/3891</a></li>
<li>fix(api): dedupe /v1/findings to one row per canonical id + normalize identifiers by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3893">https://github.com/msaad00/agent-bom/pull/3893</a></li>
<li>perf(findings): shed heavy /v1/findings reads with 429 under saturation (#3884) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3894">https://github.com/msaad00/agent-bom/pull/3894</a></li>
<li>perf(inventory): serve inventory/summary breakdown from cached snapshot counts (#3885) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3895">https://github.com/msaad00/agent-bom/pull/3895</a></li>
<li>fix(dx): 0.95.0 DX/UX polish bundle (serve &ndash;demo-estate, offline+repo_url guard, per-control no_data, blocklist seed) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3896">https://github.com/msaad00/agent-bom/pull/3896</a></li>
<li>feat(ui): scalable connector gallery on /connections by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3901">https://github.com/msaad00/agent-bom/pull/3901</a></li>
<li>perf(intel): fix full-scan hangs in KEV/advisory lookups (#3912) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3914">https://github.com/msaad00/agent-bom/pull/3914</a></li>
<li>fix(ui): distinguish AI clients from background agents in agent inventory by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3918">https://github.com/msaad00/agent-bom/pull/3918</a></li>
<li>chore(maintenance): combine registry and dependency refreshes by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3919">https://github.com/msaad00/agent-bom/pull/3919</a></li>
<li>perf+fix: sargable hot-table filters + retain alert-webhook tasks (#3911, #3913) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3920">https://github.com/msaad00/agent-bom/pull/3920</a></li>
<li>polish: MCP-catalog freshness line + client/background agent copy by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3921">https://github.com/msaad00/agent-bom/pull/3921</a></li>
<li>fix(ui): light-theme coherence — tokenize agents/registry/overview by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3922">https://github.com/msaad00/agent-bom/pull/3922</a></li>
<li>perf(intel): offload intel routes off the event loop (P1 availability) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3924">https://github.com/msaad00/agent-bom/pull/3924</a></li>
<li>fix(compliance): /v1/compliance scores over evaluated controls, not silent passes by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3925">https://github.com/msaad00/agent-bom/pull/3925</a></li>
<li>docs+ui: release-align nav label, stale counts, CHANGELOG date by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3923">https://github.com/msaad00/agent-bom/pull/3923</a></li>
<li>perf(findings): materialize scan_id + severity index on hub_findings_current by @andres-linero in <a href="https://github.com/msaad00/agent-bom/pull/3928">https://github.com/msaad00/agent-bom/pull/3928</a></li>
<li>perf(intel): make build_daily_brief KEV alias correlation sargable by @andres-linero in <a href="https://github.com/msaad00/agent-bom/pull/3929">https://github.com/msaad00/agent-bom/pull/3929</a></li>
<li>chore(docs): recapture 0.95.0 product screenshots by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3930">https://github.com/msaad00/agent-bom/pull/3930</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/msaad00/agent-bom/compare/v0.94.2...v0.95.0">https://github.com/msaad00/agent-bom/compare/v0.94.2...v0.95.0</a></p>
]]></content:encoded></item><item><title>AgentReady Repository Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/agentready-repository-scanner/</link><pubDate>Tue, 14 Jul 2026 02:43:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/agentready-repository-scanner/</guid><description>Version updated for https://github.com/napetrov/agentready to version v0.3.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentReady is an open-source tool that scans a repository to assess its readiness for AI coding agents, helping teams identify and address potential issues before onboarding autonomous agents. It checks for agent instruction surfaces, repository structure, verification command surfaces, capability surfaces, safety signals, CI workflows, context-efficiency risks, documentation entrypoints, and complements existing checks to provide prioritized improvement plans and stable evidence for CI and enterprise tools.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/napetrov/agentready">https://github.com/napetrov/agentready</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentready-repository-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AgentReady is an open-source tool that scans a repository to assess its readiness for AI coding agents, helping teams identify and address potential issues before onboarding autonomous agents. It checks for agent instruction surfaces, repository structure, verification command surfaces, capability surfaces, safety signals, CI workflows, context-efficiency risks, documentation entrypoints, and complements existing checks to provide prioritized improvement plans and stable evidence for CI and enterprise tools.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add per-category dimension-score rollup to scan reports by @napetrov in <a href="https://github.com/napetrov/agentready/pull/89">https://github.com/napetrov/agentready/pull/89</a></li>
<li>chore(release): v0.3.0 by @napetrov in <a href="https://github.com/napetrov/agentready/pull/91">https://github.com/napetrov/agentready/pull/91</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/napetrov/agentready/compare/v0.2.1...v0.3.0">https://github.com/napetrov/agentready/compare/v0.2.1...v0.3.0</a></p>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/go-proxy-cache-updater/</link><pubDate>Tue, 14 Jul 2026 02:42:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.21.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Go Proxy Cache Updater Action automates the process of pulling new releases of Go modules into a proxy cache when tags are created. It supports standard and submodule version tags, customizes proxy configuration and import paths, allows for configurable Go versions, and includes features like caching and dependency file support. This ensures that module documentation is immediately available on platforms like pkg.go.dev and enhances the reliability of Go dependencies in projects.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.21</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Go Proxy Cache Updater Action automates the process of pulling new releases of Go modules into a proxy cache when tags are created. It supports standard and submodule version tags, customizes proxy configuration and import paths, allows for configurable Go versions, and includes features like caching and dependency file support. This ensures that module documentation is immediately available on platforms like pkg.go.dev and enhances the reliability of Go dependencies in projects.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1121-2026-07-13"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.20...v1.1.21">1.1.21</a> (2026-07-13)</h2>
]]></content:encoded></item><item><title>Postman Onboarding AWS Spec Discovery</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/postman-onboarding-aws-spec-discovery/</link><pubDate>Tue, 14 Jul 2026 02:41:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/postman-onboarding-aws-spec-discovery/</guid><description>Version updated for https://github.com/postman-cs/postman-aws-spec-discovery-action to version v2.0.2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the discovery and export of API specifications from AWS services using existing AWS credentials. It supports zero-config setup, automatically resolves specs in a repo before calling AWS, and integrates seamlessly with Postman’s onboarding suite. The action uses IAM permissions to detect providers and is designed for use in CI/CD pipelines without requiring a GitHub token.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-aws-spec-discovery-action">https://github.com/postman-cs/postman-aws-spec-discovery-action</a></strong> to version <strong>v2.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-aws-spec-discovery">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the discovery and export of API specifications from AWS services using existing AWS credentials. It supports zero-config setup, automatically resolves specs in a repo before calling AWS, and integrates seamlessly with Postman&rsquo;s onboarding suite. The action uses IAM permissions to detect providers and is designed for use in CI/CD pipelines without requiring a GitHub token.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): bump the npm-minor-patch group with 23 updates by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/27">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/27</a></li>
<li>fix(cli): harden Wave 1 entrypoint and input safety by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/30">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/30</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/compare/v2...v2.0.2">https://github.com/postman-cs/postman-aws-spec-discovery-action/compare/v2...v2.0.2</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Smoke Flow</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/postman-onboarding-smoke-flow/</link><pubDate>Tue, 14 Jul 2026 02:40:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/postman-onboarding-smoke-flow/</guid><description>Version updated for https://github.com/postman-cs/postman-smoke-flow-action to version v2.1.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action reshapes a generated Postman Smoke collection into a curated flow.yaml, injecting runtime authentication for OAuth2 and API keys. It automates the process of preparing a smoke test collection for deployment, ensuring it matches a specified flow specification and handles credentials securely through Postman’s gateway token. The action is part of the larger Postman API Onboarding suite and integrates with other actions like postman-bootstrap-action and postman-repo-sync-action.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-smoke-flow-action">https://github.com/postman-cs/postman-smoke-flow-action</a></strong> to version <strong>v2.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-smoke-flow">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action reshapes a generated Postman Smoke collection into a curated <code>flow.yaml</code>, injecting runtime authentication for OAuth2 and API keys. It automates the process of preparing a smoke test collection for deployment, ensuring it matches a specified flow specification and handles credentials securely through Postman&rsquo;s gateway token. The action is part of the larger Postman API Onboarding suite and integrates with other actions like <code>postman-bootstrap-action</code> and <code>postman-repo-sync-action</code>.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>build(deps-dev): bump the npm-minor-patch group with 4 updates by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/32">https://github.com/postman-cs/postman-smoke-flow-action/pull/32</a></li>
<li>fix: Wave 1 CLI refresh safety and strict arg parsing by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/34">https://github.com/postman-cs/postman-smoke-flow-action/pull/34</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-smoke-flow-action/compare/v2.1.0...v2.1.1">https://github.com/postman-cs/postman-smoke-flow-action/compare/v2.1.0...v2.1.1</a></p>
]]></content:encoded></item><item><title>action-semver</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/action-semver/</link><pubDate>Tue, 14 Jul 2026 02:38:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/action-semver/</guid><description>Version updated for https://github.com/quike/action-semantic-release to version v3.13.0.
This action is used across all versions by 5 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the semantic versioning process of software releases using semantic-release, a tool that follows the SemVer guidelines to update versions and generate changelogs. It solves the problem of managing release processes automatically and ensures consistent versioning across multiple repositories. The action provides capabilities for both open-source projects and containerized applications through different workflows.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/quike/action-semantic-release">https://github.com/quike/action-semantic-release</a></strong> to version <strong>v3.13.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/action-semver">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the semantic versioning process of software releases using semantic-release, a tool that follows the SemVer guidelines to update versions and generate changelogs. It solves the problem of managing release processes automatically and ensures consistent versioning across multiple repositories. The action provides capabilities for both open-source projects and containerized applications through different workflows.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="3130-2026-07-13"><a href="https://github.com/quike/action-semantic-release/compare/v3.12.0...v3.13.0">3.13.0</a> (2026-07-13)</h1>
]]></content:encoded></item><item><title>Writing Style Checker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/writing-style-checker/</link><pubDate>Tue, 14 Jul 2026 02:37:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/14/writing-style-checker/</guid><description>Version updated for https://github.com/theserverlessdev/wsc to version v1.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary WSC is a GitHub Action designed to automate the detection of AI-generated text patterns, including problematic writing styles such as weasel words, passive voice, duplicate words, long sentences, nominalizations, hedging, filler adverbs, and AI-specific constructs. It offers real-time feedback in a web editor, can be accessed via an API, integrated into MCP servers, run as a CLI, and is available as a GitHub Action. WSC helps improve writing quality by identifying and correcting common issues without relying on authorship proof.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/theserverlessdev/wsc">https://github.com/theserverlessdev/wsc</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/writing-style-checker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>WSC is a GitHub Action designed to automate the detection of AI-generated text patterns, including problematic writing styles such as weasel words, passive voice, duplicate words, long sentences, nominalizations, hedging, filler adverbs, and AI-specific constructs. It offers real-time feedback in a web editor, can be accessed via an API, integrated into MCP servers, run as a CLI, and is available as a GitHub Action. WSC helps improve writing quality by identifying and correcting common issues without relying on authorship proof.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix(cli,tests): force color via FORCE_COLOR; ANSI test no longer depends on module identity (3240491)</li>
<li>feat(action): move composite action to repo root for Marketplace listing (558cef7)</li>
<li>fix(core,web,mcp,cli): strip mask sentinels from aiTells text, correct stale counts, deterministic ANSI test (2d54f33)</li>
<li>chore(release): wsc-lint 1.3.0, wsc-mcp 2.2.0 (b559496)</li>
<li>feat(site,docs): AI-tells-first positioning, honest-detection statement, scoped privacy claim, freelance credit line (554b19b)</li>
<li>fix(docs,meta): correct Action uses: path, drop phantom MCP tool and dead ai-plugin.json, complete npm metadata (573aae9)</li>
<li>feat(cli): colored output via picocolors, working &ndash;no-color, version from package.json, reject unknown formats (0274017)</li>
<li>feat(web): persisted Markdown-mode toggle in the editor (b597be5)</li>
<li>feat(api,mcp): markdown-aware analysis on every surface; fix MCP version drift (7e708f5)</li>
<li>feat(core): Markdown masking moves into analyzeText with sentinel-based inline masking (d1be05c)</li>
</ul>
]]></content:encoded></item><item><title>Nitro OpenAPI Upload</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/nitro-openapi-upload/</link><pubDate>Mon, 13 Jul 2026 16:45:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/nitro-openapi-upload/</guid><description>Version updated for https://github.com/ChilliCream/nitro-openapi-upload to version v16.5.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Update Nitro CLI to 16.5.0 (f9750d0) Update Nitro CLI to 16.5.0-p.18 (7d03052) Update Nitro CLI to 16.5.0-p.15 (4549360) Update Nitro CLI to 16.5.0-p.14 (7dbe656) Update Nitro CLI to 16.5.0-p.13 (382af64) Update Nitro CLI to 16.5.0-p.12 (4113681) Update Nitro CLI to 16.5.0-p.11 (93b85e4) Update Nitro CLI to 16.5.0-p.10 (fe3b40a) Update Nitro CLI to 16.5.0-p.9 (152ca0e) Update Nitro CLI to 16.5.0-p.8 (d80417a)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ChilliCream/nitro-openapi-upload">https://github.com/ChilliCream/nitro-openapi-upload</a></strong> to version <strong>v16.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nitro-openapi-upload">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update Nitro CLI to 16.5.0 (f9750d0)</li>
<li>Update Nitro CLI to 16.5.0-p.18 (7d03052)</li>
<li>Update Nitro CLI to 16.5.0-p.15 (4549360)</li>
<li>Update Nitro CLI to 16.5.0-p.14 (7dbe656)</li>
<li>Update Nitro CLI to 16.5.0-p.13 (382af64)</li>
<li>Update Nitro CLI to 16.5.0-p.12 (4113681)</li>
<li>Update Nitro CLI to 16.5.0-p.11 (93b85e4)</li>
<li>Update Nitro CLI to 16.5.0-p.10 (fe3b40a)</li>
<li>Update Nitro CLI to 16.5.0-p.9 (152ca0e)</li>
<li>Update Nitro CLI to 16.5.0-p.8 (d80417a)</li>
</ul>
]]></content:encoded></item><item><title>Nitro OpenAPI Validate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/nitro-openapi-validate/</link><pubDate>Mon, 13 Jul 2026 16:44:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/nitro-openapi-validate/</guid><description>Version updated for https://github.com/ChilliCream/nitro-openapi-validate to version v16.5.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Update Nitro CLI to 16.5.0 (74f1bac) Update Nitro CLI to 16.5.0-p.18 (62290b7) Update Nitro CLI to 16.5.0-p.15 (b95aa25) Update Nitro CLI to 16.5.0-p.14 (2fb5557) Update Nitro CLI to 16.5.0-p.13 (cd1e066) Update Nitro CLI to 16.5.0-p.12 (77ff158) Update Nitro CLI to 16.5.0-p.11 (2f0fc69) Update Nitro CLI to 16.5.0-p.10 (2a412d7) Update Nitro CLI to 16.5.0-p.9 (2254fce) Update Nitro CLI to 16.5.0-p.8 (db73650)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ChilliCream/nitro-openapi-validate">https://github.com/ChilliCream/nitro-openapi-validate</a></strong> to version <strong>v16.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nitro-openapi-validate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update Nitro CLI to 16.5.0 (74f1bac)</li>
<li>Update Nitro CLI to 16.5.0-p.18 (62290b7)</li>
<li>Update Nitro CLI to 16.5.0-p.15 (b95aa25)</li>
<li>Update Nitro CLI to 16.5.0-p.14 (2fb5557)</li>
<li>Update Nitro CLI to 16.5.0-p.13 (cd1e066)</li>
<li>Update Nitro CLI to 16.5.0-p.12 (77ff158)</li>
<li>Update Nitro CLI to 16.5.0-p.11 (2f0fc69)</li>
<li>Update Nitro CLI to 16.5.0-p.10 (2a412d7)</li>
<li>Update Nitro CLI to 16.5.0-p.9 (2254fce)</li>
<li>Update Nitro CLI to 16.5.0-p.8 (db73650)</li>
</ul>
]]></content:encoded></item><item><title>Nitro Schema Download</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/nitro-schema-download/</link><pubDate>Mon, 13 Jul 2026 16:44:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/nitro-schema-download/</guid><description>Version updated for https://github.com/ChilliCream/nitro-schema-download to version v16.5.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Update Nitro CLI to 16.5.0 (99e548b) Update Nitro CLI to 16.5.0-p.18 (4675710) Update Nitro CLI to 16.5.0-p.15 (6e863ca) Update Nitro CLI to 16.5.0-p.14 (846f984) Update Nitro CLI to 16.5.0-p.13 (844369e) Update Nitro CLI to 16.5.0-p.12 (f2e6204) Update Nitro CLI to 16.5.0-p.11 (8319e48) Update Nitro CLI to 16.5.0-p.10 (e3e2e92) Update Nitro CLI to 16.5.0-p.9 (588bc3b) Update Nitro CLI to 16.5.0-p.8 (f54d391)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ChilliCream/nitro-schema-download">https://github.com/ChilliCream/nitro-schema-download</a></strong> to version <strong>v16.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nitro-schema-download">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update Nitro CLI to 16.5.0 (99e548b)</li>
<li>Update Nitro CLI to 16.5.0-p.18 (4675710)</li>
<li>Update Nitro CLI to 16.5.0-p.15 (6e863ca)</li>
<li>Update Nitro CLI to 16.5.0-p.14 (846f984)</li>
<li>Update Nitro CLI to 16.5.0-p.13 (844369e)</li>
<li>Update Nitro CLI to 16.5.0-p.12 (f2e6204)</li>
<li>Update Nitro CLI to 16.5.0-p.11 (8319e48)</li>
<li>Update Nitro CLI to 16.5.0-p.10 (e3e2e92)</li>
<li>Update Nitro CLI to 16.5.0-p.9 (588bc3b)</li>
<li>Update Nitro CLI to 16.5.0-p.8 (f54d391)</li>
</ul>
]]></content:encoded></item><item><title>Nitro Schema Publish</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/nitro-schema-publish/</link><pubDate>Mon, 13 Jul 2026 16:43:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/nitro-schema-publish/</guid><description>Version updated for https://github.com/ChilliCream/nitro-schema-publish to version v16.5.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Update Nitro CLI to 16.5.0 (4414fd9) Update Nitro CLI to 16.5.0-p.18 (f0993a9) Update Nitro CLI to 16.5.0-p.15 (087febf) Update Nitro CLI to 16.5.0-p.14 (1610de2) Update Nitro CLI to 16.5.0-p.13 (feb92af) Update Nitro CLI to 16.5.0-p.12 (7b4bd0d) Update Nitro CLI to 16.5.0-p.11 (0f7117b) Update Nitro CLI to 16.5.0-p.10 (9f878a5) Update Nitro CLI to 16.5.0-p.9 (4937267) Update Nitro CLI to 16.5.0-p.8 (a1601ad)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ChilliCream/nitro-schema-publish">https://github.com/ChilliCream/nitro-schema-publish</a></strong> to version <strong>v16.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nitro-schema-publish">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update Nitro CLI to 16.5.0 (4414fd9)</li>
<li>Update Nitro CLI to 16.5.0-p.18 (f0993a9)</li>
<li>Update Nitro CLI to 16.5.0-p.15 (087febf)</li>
<li>Update Nitro CLI to 16.5.0-p.14 (1610de2)</li>
<li>Update Nitro CLI to 16.5.0-p.13 (feb92af)</li>
<li>Update Nitro CLI to 16.5.0-p.12 (7b4bd0d)</li>
<li>Update Nitro CLI to 16.5.0-p.11 (0f7117b)</li>
<li>Update Nitro CLI to 16.5.0-p.10 (9f878a5)</li>
<li>Update Nitro CLI to 16.5.0-p.9 (4937267)</li>
<li>Update Nitro CLI to 16.5.0-p.8 (a1601ad)</li>
</ul>
]]></content:encoded></item><item><title>Nitro Schema Upload</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/nitro-schema-upload/</link><pubDate>Mon, 13 Jul 2026 16:43:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/nitro-schema-upload/</guid><description>Version updated for https://github.com/ChilliCream/nitro-schema-upload to version v16.5.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Update Nitro CLI to 16.5.0 (bb7d11b) Update Nitro CLI to 16.5.0-p.18 (34cd014) Update Nitro CLI to 16.5.0-p.15 (45f94c1) Update Nitro CLI to 16.5.0-p.14 (f435b0c) Update Nitro CLI to 16.5.0-p.13 (2685fa0) Update Nitro CLI to 16.5.0-p.12 (07e75f9) Update Nitro CLI to 16.5.0-p.11 (ece5bd8) Update Nitro CLI to 16.5.0-p.10 (e88a78f) Update Nitro CLI to 16.5.0-p.9 (3954cde) Update Nitro CLI to 16.5.0-p.8 (fa9e5f4)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ChilliCream/nitro-schema-upload">https://github.com/ChilliCream/nitro-schema-upload</a></strong> to version <strong>v16.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nitro-schema-upload">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update Nitro CLI to 16.5.0 (bb7d11b)</li>
<li>Update Nitro CLI to 16.5.0-p.18 (34cd014)</li>
<li>Update Nitro CLI to 16.5.0-p.15 (45f94c1)</li>
<li>Update Nitro CLI to 16.5.0-p.14 (f435b0c)</li>
<li>Update Nitro CLI to 16.5.0-p.13 (2685fa0)</li>
<li>Update Nitro CLI to 16.5.0-p.12 (07e75f9)</li>
<li>Update Nitro CLI to 16.5.0-p.11 (ece5bd8)</li>
<li>Update Nitro CLI to 16.5.0-p.10 (e88a78f)</li>
<li>Update Nitro CLI to 16.5.0-p.9 (3954cde)</li>
<li>Update Nitro CLI to 16.5.0-p.8 (fa9e5f4)</li>
</ul>
]]></content:encoded></item><item><title>Nitro Schema Validate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/nitro-schema-validate/</link><pubDate>Mon, 13 Jul 2026 16:42:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/nitro-schema-validate/</guid><description>Version updated for https://github.com/ChilliCream/nitro-schema-validate to version v16.5.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Update Nitro CLI to 16.5.0 (9fb7d32) Update Nitro CLI to 16.5.0-p.18 (d57239a) Update Nitro CLI to 16.5.0-p.15 (fbdf775) Update Nitro CLI to 16.5.0-p.14 (6248f8c) Update Nitro CLI to 16.5.0-p.13 (028ee21) Update Nitro CLI to 16.5.0-p.12 (8dca63a) Update Nitro CLI to 16.5.0-p.11 (7e335e8) Update Nitro CLI to 16.5.0-p.10 (b1e033b) Update Nitro CLI to 16.5.0-p.9 (840eec6) Update Nitro CLI to 16.5.0-p.8 (c3f8884)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ChilliCream/nitro-schema-validate">https://github.com/ChilliCream/nitro-schema-validate</a></strong> to version <strong>v16.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nitro-schema-validate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update Nitro CLI to 16.5.0 (9fb7d32)</li>
<li>Update Nitro CLI to 16.5.0-p.18 (d57239a)</li>
<li>Update Nitro CLI to 16.5.0-p.15 (fbdf775)</li>
<li>Update Nitro CLI to 16.5.0-p.14 (6248f8c)</li>
<li>Update Nitro CLI to 16.5.0-p.13 (028ee21)</li>
<li>Update Nitro CLI to 16.5.0-p.12 (8dca63a)</li>
<li>Update Nitro CLI to 16.5.0-p.11 (7e335e8)</li>
<li>Update Nitro CLI to 16.5.0-p.10 (b1e033b)</li>
<li>Update Nitro CLI to 16.5.0-p.9 (840eec6)</li>
<li>Update Nitro CLI to 16.5.0-p.8 (c3f8884)</li>
</ul>
]]></content:encoded></item><item><title>shadow-audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/shadow-audit/</link><pubDate>Mon, 13 Jul 2026 16:42:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/shadow-audit/</guid><description>Version updated for https://github.com/darkmaster0345/shadow-Audit to version v0.6.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/darkmaster0345/shadow-Audit">https://github.com/darkmaster0345/shadow-Audit</a></strong> to version <strong>v0.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/shadow-audit">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>DoesQA Trigger</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/doesqa-trigger/</link><pubDate>Mon, 13 Jul 2026 16:42:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/doesqa-trigger/</guid><description>Version updated for https://github.com/Does-QA/action to version v1.1.37.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Security patch: fixed 1 → 1 vulnerabilities via npm audit fix.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Does-QA/action">https://github.com/Does-QA/action</a></strong> to version <strong>v1.1.37</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/doesqa-trigger">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Security patch: fixed 1 → 1 vulnerabilities via <code>npm audit fix</code>.</p>
]]></content:encoded></item><item><title>cargo-deny</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/cargo-deny/</link><pubDate>Mon, 13 Jul 2026 16:41:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/cargo-deny/</guid><description>Version updated for https://github.com/EmbarkStudios/cargo-deny-action to version v2.1.0.
This action is used across all versions by 7,901 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changed PR#881 refactored the CLI, moving some duplicated options/flags into the root and removing several deprecated options/flags/values. See the PR for a full list of changes. Added PR#879 resolved #873 by adding a new bans.std-replacements lint which checks the graph for crates.io sourced crates that have been partially or fully replaced in std and/or core. Fixed PR#880 resolved #765 by respecting non-default build script paths in manifests. PR#881 resolved #874 by cleaning up the CLI, deduplicating some options/flags that caused bug in the list subcommand.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/EmbarkStudios/cargo-deny-action">https://github.com/EmbarkStudios/cargo-deny-action</a></strong> to version <strong>v2.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7,901</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cargo-deny">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li><a href="https://github.com/EmbarkStudios/cargo-deny/pull/881">PR#881</a> refactored the CLI, moving some duplicated options/flags into the root and removing several deprecated options/flags/values. See the PR for a full list of changes.</li>
</ul>
<h3 id="added">Added</h3>
<ul>
<li><a href="https://github.com/EmbarkStudios/cargo-deny/pull/879">PR#879</a> resolved <a href="https://github.com/EmbarkStudios/cargo-deny/issues/873">#873</a> by adding a new <a href="https://embarkstudios.github.io/cargo-deny/checks/bans/cfg.html#the-std-replacements-field-optional"><code>bans.std-replacements</code></a> lint which checks the graph for crates.io sourced crates that have been partially or fully replaced in <code>std</code> and/or <code>core</code>.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><a href="https://github.com/EmbarkStudios/cargo-deny/pull/880">PR#880</a> resolved <a href="https://github.com/EmbarkStudios/cargo-deny/issues/765">#765</a> by respecting non-default build script paths in manifests.</li>
<li><a href="https://github.com/EmbarkStudios/cargo-deny/pull/881">PR#881</a> resolved <a href="https://github.com/EmbarkStudios/cargo-deny/issues/874">#874</a> by cleaning up the CLI, deduplicating some options/flags that caused bug in the <code>list</code> subcommand.</li>
</ul>
]]></content:encoded></item><item><title>EvoOM Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/evoom-guard/</link><pubDate>Mon, 13 Jul 2026 16:40:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/evoom-guard/</guid><description>Version updated for https://github.com/EvoRiseKsa/EvoOM-Guard-m to version v3.4.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Fix static pre-gate assurance metadata for v3.4.3 by @EvoRiseKsa in https://github.com/EvoRiseKsa/EvoOM-Guard-m/pull/51 Full Changelog: https://github.com/EvoRiseKsa/EvoOM-Guard-m/compare/v3.4.2...v3.4.3</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/EvoRiseKsa/EvoOM-Guard-m">https://github.com/EvoRiseKsa/EvoOM-Guard-m</a></strong> to version <strong>v3.4.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/evoom-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Fix static pre-gate assurance metadata for v3.4.3 by @EvoRiseKsa in <a href="https://github.com/EvoRiseKsa/EvoOM-Guard-m/pull/51">https://github.com/EvoRiseKsa/EvoOM-Guard-m/pull/51</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/EvoRiseKsa/EvoOM-Guard-m/compare/v3.4.2...v3.4.3">https://github.com/EvoRiseKsa/EvoOM-Guard-m/compare/v3.4.2...v3.4.3</a></p>
]]></content:encoded></item><item><title>Fallow - Codebase Intelligence</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/fallow-codebase-intelligence/</link><pubDate>Mon, 13 Jul 2026 16:40:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/fallow-codebase-intelligence/</guid><description>Version updated for https://github.com/fallow-rs/fallow to version v3.4.2.
This action is used across all versions by 307 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Suppression governance fallow suppressions: a read-only inventory of every active suppression marker, grouped per file with line, kind, level, and reason, plus project totals and a stale count cross-referenced from this run’s findings. Teams governing tech debt (and agents that should distrust a “clean” verdict) no longer grep for fallow-ignore by hand. Ships with --format json (new suppression-inventory envelope) and full workspace/changed/file scoping; always exits 0. MCP tool list_suppressions exposes the same inventory to agents on the MCP surface, returning the JSON envelope verbatim. Every “To suppress:” hint in the human footer now names a token fallow actually parses. Eight sections printed tokens the parser does not recognize, so following the hint suppressed nothing and then surfaced a stale-suppression finding on top. Hint tokens now derive from the issue registry, backed by a roundtrip guard test. Thanks @slyeargin for catching the unused-files case in #1820. Native GitHub workflow output --format github-annotations and --format github-summary: inline PR annotations (::error / ::warning / ::notice workflow commands) and job-summary markdown straight from the CLI, no bundled action required. Both are log-based, so they render on fork PRs without a write token. fallow report --from &amp;lt;results.json&amp;gt;: analyze once with fallow --format json -o results.json, then render annotations and the job summary from the saved envelope, byte-identical to the direct run. Monorepo CI paths Behavior change: CI-facing formats emit repository-root-relative paths when --root is a subdirectory. GitLab’s Code Quality widget matched nothing and inline review discussions were rejected when the analyzed project lived in a package subdirectory, because codeclimate, review-github, and review-gitlab addressed files relative to --root. All CI formats now share one namespace, detected via the git toplevel; pass --report-path-prefix &amp;#39;&amp;#39; to restore the old output. Single-package repositories are unaffected. See docs/backwards-compatibility.md for the classification rationale. --annotations-path-prefix is now --report-path-prefix and governs every CI-facing format; the old name keeps working as an alias. --diff-file resolves the diff’s path namespace from the diff itself, so changed-file filtering works in monorepo packages for both git diff conventions; a diff that parses but touches no analyzable files filters to zero findings, and an unplaceable diff warns and reports at full scope instead of producing a plausible-looking empty report. Renamed files keep their old_path in review-gitlab. Thanks @Jerc92 for the diagnosis and the patch in #1808. unused-class-members accuracy Four extraction gaps produced false positives on dependency-injection-style code, reported across three issues by adopters running the rule on real codebases:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/fallow-rs/fallow">https://github.com/fallow-rs/fallow</a></strong> to version <strong>v3.4.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>307</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/fallow-codebase-intelligence">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="suppression-governance">Suppression governance</h2>
<ul>
<li><strong><code>fallow suppressions</code></strong>: a read-only inventory of every active suppression marker, grouped per file with line, kind, level, and reason, plus project totals and a stale count cross-referenced from this run&rsquo;s findings. Teams governing tech debt (and agents that should distrust a &ldquo;clean&rdquo; verdict) no longer grep for <code>fallow-ignore</code> by hand. Ships with <code>--format json</code> (new <code>suppression-inventory</code> envelope) and full workspace/changed/file scoping; always exits 0.</li>
<li><strong>MCP tool <code>list_suppressions</code></strong> exposes the same inventory to agents on the MCP surface, returning the JSON envelope verbatim.</li>
<li><strong>Every &ldquo;To suppress:&rdquo; hint in the human footer now names a token fallow actually parses.</strong> Eight sections printed tokens the parser does not recognize, so following the hint suppressed nothing and then surfaced a stale-suppression finding on top. Hint tokens now derive from the issue registry, backed by a roundtrip guard test. Thanks <a href="https://github.com/slyeargin">@slyeargin</a> for catching the unused-files case in <a href="https://github.com/fallow-rs/fallow/pull/1820">#1820</a>.</li>
</ul>
<h2 id="native-github-workflow-output">Native GitHub workflow output</h2>
<ul>
<li><strong><code>--format github-annotations</code> and <code>--format github-summary</code></strong>: inline PR annotations (<code>::error</code> / <code>::warning</code> / <code>::notice</code> workflow commands) and job-summary markdown straight from the CLI, no bundled action required. Both are log-based, so they render on fork PRs without a write token.</li>
<li><strong><code>fallow report --from &lt;results.json&gt;</code></strong>: analyze once with <code>fallow --format json -o results.json</code>, then render annotations and the job summary from the saved envelope, byte-identical to the direct run.</li>
</ul>
<h2 id="monorepo-ci-paths">Monorepo CI paths</h2>
<ul>
<li><strong>Behavior change: CI-facing formats emit repository-root-relative paths when <code>--root</code> is a subdirectory.</strong> GitLab&rsquo;s Code Quality widget matched nothing and inline review discussions were rejected when the analyzed project lived in a package subdirectory, because <code>codeclimate</code>, <code>review-github</code>, and <code>review-gitlab</code> addressed files relative to <code>--root</code>. All CI formats now share one namespace, detected via the git toplevel; pass <code>--report-path-prefix ''</code> to restore the old output. Single-package repositories are unaffected. See <a href="https://github.com/fallow-rs/fallow/blob/main/docs/backwards-compatibility.md">docs/backwards-compatibility.md</a> for the classification rationale.</li>
<li><strong><code>--annotations-path-prefix</code> is now <code>--report-path-prefix</code></strong> and governs every CI-facing format; the old name keeps working as an alias.</li>
<li><strong><code>--diff-file</code> resolves the diff&rsquo;s path namespace from the diff itself</strong>, so changed-file filtering works in monorepo packages for both <code>git diff</code> conventions; a diff that parses but touches no analyzable files filters to zero findings, and an unplaceable diff warns and reports at full scope instead of producing a plausible-looking empty report. Renamed files keep their <code>old_path</code> in <code>review-gitlab</code>. Thanks <a href="https://github.com/Jerc92">@Jerc92</a> for the diagnosis and the patch in <a href="https://github.com/fallow-rs/fallow/pull/1808">#1808</a>.</li>
</ul>
<h2 id="unused-class-members-accuracy">unused-class-members accuracy</h2>
<p>Four extraction gaps produced false positives on dependency-injection-style code, reported across three issues by adopters running the rule on real codebases:</p>
<ul>
<li><code>this.#dep.method()</code> receivers through <code>#</code>-private class fields now credit the target class cross-module, and same-named fields on sibling classes in one module no longer collide on a shared binding key (previously last-write-wins: only the class declared last credited its dependency&rsquo;s members). Thanks <a href="https://github.com/martijnwalraven">@martijnwalraven</a> for the report with its isolation matrix (<a href="https://github.com/fallow-rs/fallow/issues/1821">#1821</a>).</li>
<li>Members reached through a local (non-exported) subclass, factory results read without a named binding (<code>f().member</code>, <code>const { member } = f()</code>), and opaque destructures now credit correctly. Thanks <a href="https://github.com/Jerc92">@Jerc92</a> for the fixes in <a href="https://github.com/fallow-rs/fallow/pull/1811">#1811</a>.</li>
<li>Playwright page-object methods used through a <code>mergeTests(...)</code>-wrapping helper are credited, including imported <code>&lt;base&gt;.extend(...)</code> wrappers. Thanks <a href="https://github.com/committedpazz">@committedpazz</a> for the follow-up report (<a href="https://github.com/fallow-rs/fallow/issues/1795">#1795</a>).</li>
<li>Iteration over array-typed parameters (<code>items: Item[]</code>) and <code>Promise.all(arr.map(cb))</code> results now types the iteration variable, so <code>for...of</code> and <code>.map</code> member accesses credit the class. Thanks <a href="https://github.com/vethman">@vethman</a> for the report (<a href="https://github.com/fallow-rs/fallow/issues/1793">#1793</a>).</li>
</ul>
<h2 id="fixes-and-improvements">Fixes and improvements</h2>
<ul>
<li><strong><code>fallow audit</code>&rsquo;s base-snapshot cache no longer appears in <code>git worktree list</code> or IDE repo views</strong>; snapshots are unregistered immediately after materialization, and entries from earlier versions deregister automatically on the next audit with warm caches preserved. Thanks <a href="https://github.com/AlonMiz">@AlonMiz</a> for the report (<a href="https://github.com/fallow-rs/fallow/issues/1815">#1815</a>).</li>
<li><strong>Generated configs point <code>$schema</code> at the local <code>node_modules/fallow/schema.json</code> when present</strong>: offline, no VS Code trust prompt, always version-aligned. Non-npm installs keep the remote fallback. Thanks <a href="https://github.com/vethman">@vethman</a> for the report (<a href="https://github.com/fallow-rs/fallow/issues/1794">#1794</a>).</li>
<li><strong>The repository Dockerfile&rsquo;s pinned version and checksums now track releases automatically</strong> via a post-release job (<a href="https://github.com/fallow-rs/fallow/issues/1817">#1817</a>).</li>
<li>Reusable analysis sessions share parsed-module storage across warm queries, and contract regeneration promotes committed outputs as a transaction.</li>
<li>The <code>fallow</code> npm launcher and Node bindings now require Node.js 22 or later.</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/fallow-rs/fallow/compare/v3.3.0...v3.4.2">https://github.com/fallow-rs/fallow/compare/v3.3.0...v3.4.2</a></p>
]]></content:encoded></item><item><title>GitHub Star Tracker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/github-star-tracker/</link><pubDate>Mon, 13 Jul 2026 16:39:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/github-star-tracker/</guid><description>Version updated for https://github.com/fbuireu/github-star-tracker to version v1.22.3.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.22.3 (2026-07-13) Bug Fixes tolerate stargazer page failures and stop swallowing fetch errors (#150) (a302833)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/fbuireu/github-star-tracker">https://github.com/fbuireu/github-star-tracker</a></strong> to version <strong>v1.22.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-star-tracker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1223-2026-07-13"><a href="https://github.com/fbuireu/github-star-tracker/compare/v1.22.2...v1.22.3">1.22.3</a> (2026-07-13)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>tolerate stargazer page failures and stop swallowing fetch errors (<a href="https://github.com/fbuireu/github-star-tracker/issues/150">#150</a>) (<a href="https://github.com/fbuireu/github-star-tracker/commit/a3028339b0ea465528e0733c983731dbc9558797">a302833</a>)</li>
</ul>
]]></content:encoded></item><item><title>GHA Bump Tag</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/gha-bump-tag/</link><pubDate>Mon, 13 Jul 2026 16:39:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/gha-bump-tag/</guid><description>Version updated for https://github.com/gha-actions/bump-tag to version 0.4.0.
This action is used across all versions by 9 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Enable RELEASE_CREATE in bump workflow by @jaynath-d in https://github.com/gha-actions/bump-tag/pull/5 Full Changelog: https://github.com/gha-actions/bump-tag/compare/0.3.0...0.4.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/gha-actions/bump-tag">https://github.com/gha-actions/bump-tag</a></strong> to version <strong>0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>9</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gha-bump-tag">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Enable RELEASE_CREATE in bump workflow by @jaynath-d in <a href="https://github.com/gha-actions/bump-tag/pull/5">https://github.com/gha-actions/bump-tag/pull/5</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/gha-actions/bump-tag/compare/0.3.0...0.4.0">https://github.com/gha-actions/bump-tag/compare/0.3.0...0.4.0</a></p>
]]></content:encoded></item><item><title>action-ecr-publish</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/action-ecr-publish/</link><pubDate>Mon, 13 Jul 2026 16:38:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/action-ecr-publish/</guid><description>Version updated for https://github.com/heronlabs/action-ecr-publish to version v6.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [skip ci] bump v6.0.3 (1f89ae4) build(deps): bump the actions group with 2 updates (#27) (1af0aef) [skip ci] bump v6.0.2 (43d9c12) chore: migrate supera.json to 2.x schema (#28) (2a5ab83) [skip ci] bump v6.0.1 (35506d7) chore: update bats-core action to use version 4.0.0 (200cf9e) [skip ci] bump v6.0.0 (08a376d) [skip ci] bump v5.0.7 (b34355d) chore: polish metadata, docs, gitignore, and SHA-to-tag refs (5a45df3) [skip ci] bump v5.0.6 (03a1d51)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/heronlabs/action-ecr-publish">https://github.com/heronlabs/action-ecr-publish</a></strong> to version <strong>v6.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/action-ecr-publish">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>[skip ci] bump v6.0.3 (1f89ae4)</li>
<li>build(deps): bump the actions group with 2 updates (#27) (1af0aef)</li>
<li>[skip ci] bump v6.0.2 (43d9c12)</li>
<li>chore: migrate supera.json to 2.x schema (#28) (2a5ab83)</li>
<li>[skip ci] bump v6.0.1 (35506d7)</li>
<li>chore: update bats-core action to use version 4.0.0 (200cf9e)</li>
<li>[skip ci] bump v6.0.0 (08a376d)</li>
<li>[skip ci] bump v5.0.7 (b34355d)</li>
<li>chore: polish metadata, docs, gitignore, and SHA-to-tag refs (5a45df3)</li>
<li>[skip ci] bump v5.0.6 (03a1d51)</li>
</ul>
]]></content:encoded></item><item><title>borderlint AI Data-Residency Lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/borderlint-ai-data-residency-lint/</link><pubDate>Mon, 13 Jul 2026 16:38:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/borderlint-ai-data-residency-lint/</guid><description>Version updated for https://github.com/iolairus/borderlint to version v1.10.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed borderlint init — interactive wizard that scaffolds residency.json: home-base and data-class interview, inventory-grounded jurisdiction walk, overwrite guard (--force), non-interactive --home/--classes for CI. --format badge — shields.io endpoint JSON for READMEs and CI dashboards: green clean, red failures, yellow warn-only, blue inventory; non-gating export.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/iolairus/borderlint">https://github.com/iolairus/borderlint</a></strong> to version <strong>v1.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/borderlint-ai-data-residency-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li><strong><code>borderlint init</code></strong> — interactive wizard that scaffolds <code>residency.json</code>: home-base and data-class interview, inventory-grounded jurisdiction walk, overwrite guard (<code>--force</code>), non-interactive <code>--home</code>/<code>--classes</code> for CI.</li>
<li><strong><code>--format badge</code></strong> — shields.io endpoint JSON for READMEs and CI dashboards: green clean, red failures, yellow warn-only, blue inventory; non-gating export.</li>
</ul>
]]></content:encoded></item><item><title>AI Smoke Test</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/ai-smoke-test/</link><pubDate>Mon, 13 Jul 2026 16:37:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/ai-smoke-test/</guid><description>Version updated for https://github.com/JFolberth/ai-smoketest to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Update action description for clarity on smoke testing multiple agents by @JFolberth in https://github.com/JFolberth/ai-smoketest/pull/5 Update copilot instructions and publishing guidelines for Marketplace… by @JFolberth in https://github.com/JFolberth/ai-smoketest/pull/6 docs: rename Azure AI Foundry to Microsoft Foundry by @JFolberth in https://github.com/JFolberth/ai-smoketest/pull/7 Full Changelog: https://github.com/JFolberth/ai-smoketest/compare/v1.0...v1.0.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/JFolberth/ai-smoketest">https://github.com/JFolberth/ai-smoketest</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-smoke-test">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Update action description for clarity on smoke testing multiple agents by @JFolberth in <a href="https://github.com/JFolberth/ai-smoketest/pull/5">https://github.com/JFolberth/ai-smoketest/pull/5</a></li>
<li>Update copilot instructions and publishing guidelines for Marketplace… by @JFolberth in <a href="https://github.com/JFolberth/ai-smoketest/pull/6">https://github.com/JFolberth/ai-smoketest/pull/6</a></li>
<li>docs: rename Azure AI Foundry to Microsoft Foundry by @JFolberth in <a href="https://github.com/JFolberth/ai-smoketest/pull/7">https://github.com/JFolberth/ai-smoketest/pull/7</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/JFolberth/ai-smoketest/compare/v1.0...v1.0.1">https://github.com/JFolberth/ai-smoketest/compare/v1.0...v1.0.1</a></p>
]]></content:encoded></item><item><title>JFrog Boost</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/jfrog-boost/</link><pubDate>Mon, 13 Jul 2026 16:37:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/jfrog-boost/</guid><description>Version updated for https://github.com/jfrog/boost to version v0.9.3.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 2 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Release v0.7.23 by @yahav-ohana in https://github.com/jfrog/boost/pull/41 Release v0.7.25 by @menachemm-byte in https://github.com/jfrog/boost/pull/44 docs(readme): simplify mascot, focus on token savings, add report commands by @yahav-ohana in https://github.com/jfrog/boost/pull/47 docs(readme): update release badge to v0.8.6 and stars to 258 by @yahav-ohana in https://github.com/jfrog/boost/pull/48 New Contributors @menachemm-byte made their first contribution in https://github.com/jfrog/boost/pull/44 Full Changelog: https://github.com/jfrog/boost/compare/v0.7.23...v0.9.3</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jfrog/boost">https://github.com/jfrog/boost</a></strong> to version <strong>v0.9.3</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>2</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jfrog-boost">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Release v0.7.23 by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/41">https://github.com/jfrog/boost/pull/41</a></li>
<li>Release v0.7.25 by @menachemm-byte in <a href="https://github.com/jfrog/boost/pull/44">https://github.com/jfrog/boost/pull/44</a></li>
<li>docs(readme): simplify mascot, focus on token savings, add report commands by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/47">https://github.com/jfrog/boost/pull/47</a></li>
<li>docs(readme): update release badge to v0.8.6 and stars to 258 by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/48">https://github.com/jfrog/boost/pull/48</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@menachemm-byte made their first contribution in <a href="https://github.com/jfrog/boost/pull/44">https://github.com/jfrog/boost/pull/44</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jfrog/boost/compare/v0.7.23...v0.9.3">https://github.com/jfrog/boost/compare/v0.7.23...v0.9.3</a></p>
]]></content:encoded></item><item><title>gha-mergify-ci</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/gha-mergify-ci/</link><pubDate>Mon, 13 Jul 2026 16:36:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/gha-mergify-ci/</guid><description>Version updated for https://github.com/Mergifyio/gha-mergify-ci to version v23.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 2 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: expose test_results_upload output for junit-process by @jd in https://github.com/Mergifyio/gha-mergify-ci/pull/257 refactor: install Mergify CLI via Mergifyio/setup-cli action by @sileht in https://github.com/Mergifyio/gha-mergify-ci/pull/263 feat(scopes): add all_scopes input to flag a PR as impacting all scopes by @jd in https://github.com/Mergifyio/gha-mergify- Full Changelog: https://github.com/Mergifyio/gha-mergify-ci/compare/v22...v23</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Mergifyio/gha-mergify-ci">https://github.com/Mergifyio/gha-mergify-ci</a></strong> to version <strong>v23</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>2</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gha-mergify-ci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at main -->
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: expose test_results_upload output for junit-process by @jd in <a href="https://github.com/Mergifyio/gha-mergify-ci/pull/257">https://github.com/Mergifyio/gha-mergify-ci/pull/257</a></li>
<li>refactor: install Mergify CLI via Mergifyio/setup-cli action by @sileht in <a href="https://github.com/Mergifyio/gha-mergify-ci/pull/263">https://github.com/Mergifyio/gha-mergify-ci/pull/263</a></li>
<li>feat(scopes): add all_scopes input to flag a PR as impacting all scopes by @jd in <a href="https://github.com/Mergifyio/gha-mergify-">https://github.com/Mergifyio/gha-mergify-</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Mergifyio/gha-mergify-ci/compare/v22...v23">https://github.com/Mergifyio/gha-mergify-ci/compare/v22...v23</a></p>
]]></content:encoded></item><item><title>AI Harness Doctor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/ai-harness-doctor/</link><pubDate>Mon, 13 Jul 2026 16:35:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/ai-harness-doctor/</guid><description>Version updated for https://github.com/NieZhuZhu/ai-harness-doctor to version v0.13.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix(action): propagate wrapper failures by @NieZhuZhu in https://github.com/NieZhuZhu/ai-harness-doctor/pull/89 fix(docs): escape Node badge alt text by @NieZhuZhu in https://github.com/NieZhuZhu/ai-harness-doctor/pull/90 Full Changelog: https://github.com/NieZhuZhu/ai-harness-doctor/compare/v0.13.2...v0.13.3</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NieZhuZhu/ai-harness-doctor">https://github.com/NieZhuZhu/ai-harness-doctor</a></strong> to version <strong>v0.13.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-harness-doctor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(action): propagate wrapper failures by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/89">https://github.com/NieZhuZhu/ai-harness-doctor/pull/89</a></li>
<li>fix(docs): escape Node badge alt text by @NieZhuZhu in <a href="https://github.com/NieZhuZhu/ai-harness-doctor/pull/90">https://github.com/NieZhuZhu/ai-harness-doctor/pull/90</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/NieZhuZhu/ai-harness-doctor/compare/v0.13.2...v0.13.3">https://github.com/NieZhuZhu/ai-harness-doctor/compare/v0.13.2...v0.13.3</a></p>
]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/rumdl-action/</link><pubDate>Mon, 13 Jul 2026 16:35:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.32.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed md032: stop flagging ordered lists nested in MkDocs admonitions (80f896e) md013: recognize sentence boundaries followed by footnote references (04a8c78) md036,md023: skip admonition and content tab bodies under MkDocs flavor (e8d1421) md040: recognize py and py3 as Python language aliases (6e7f8bf) md057: anchor URL extraction so links cannot borrow a sibling’s destination (5a643ca) Performance reflow: skip pulldown-cmark parses when a span kind cannot be present (66d7f7b) Downloads File Platform Checksum rumdl-v0.2.32-x86_64-unknown-linux-gnu.tar.gz Linux x86_64 checksum rumdl-v0.2.32-x86_64-unknown-linux-musl.tar.gz Linux x86_64 (musl) checksum rumdl-v0.2.32-aarch64-unknown-linux-gnu.tar.gz Linux ARM64 checksum rumdl-v0.2.32-aarch64-unknown-linux-musl.tar.gz Linux ARM64 (musl) checksum rumdl-v0.2.32-x86_64-apple-darwin.tar.gz macOS x86_64 checksum rumdl-v0.2.32-aarch64-apple-darwin.tar.gz macOS ARM64 (Apple Silicon) checksum rumdl-v0.2.32-x86_64-pc-windows-msvc.zip Windows x86_64 checksum Installation Using uv (Recommended) uv tool install rumdl Using pip pip install rumdl Using pipx pipx install rumdl Direct Download Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.32</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>md032</strong>: stop flagging ordered lists nested in MkDocs admonitions (<a href="https://github.com/rvben/rumdl/commit/80f896e61d6e64afbce115b84b934a5e6325db54">80f896e</a>)</li>
<li><strong>md013</strong>: recognize sentence boundaries followed by footnote references (<a href="https://github.com/rvben/rumdl/commit/04a8c78e53cbcf8c6aa0df5114f2f630e4a5b9ba">04a8c78</a>)</li>
<li><strong>md036,md023</strong>: skip admonition and content tab bodies under MkDocs flavor (<a href="https://github.com/rvben/rumdl/commit/e8d14213c6c2d726110c5acbe72f23b37aa61c0d">e8d1421</a>)</li>
<li><strong>md040</strong>: recognize py and py3 as Python language aliases (<a href="https://github.com/rvben/rumdl/commit/6e7f8bfc2a572e469f1eeef0e24de0a8cf8173d3">6e7f8bf</a>)</li>
<li><strong>md057</strong>: anchor URL extraction so links cannot borrow a sibling&rsquo;s destination (<a href="https://github.com/rvben/rumdl/commit/5a643ca46c781dc87ced08fec6fc6ebcf0128d71">5a643ca</a>)</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li><strong>reflow</strong>: skip pulldown-cmark parses when a span kind cannot be present (<a href="https://github.com/rvben/rumdl/commit/66d7f7b412625f6efb7d5ede5be3e807efd7f26b">66d7f7b</a>)</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.32/rumdl-v0.2.32-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.32-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.32/rumdl-v0.2.32-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.32/rumdl-v0.2.32-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.32-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.32/rumdl-v0.2.32-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.32/rumdl-v0.2.32-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.32-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.32/rumdl-v0.2.32-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.32/rumdl-v0.2.32-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.32-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.32/rumdl-v0.2.32-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.32/rumdl-v0.2.32-x86_64-apple-darwin.tar.gz">rumdl-v0.2.32-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.32/rumdl-v0.2.32-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.32/rumdl-v0.2.32-aarch64-apple-darwin.tar.gz">rumdl-v0.2.32-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.32/rumdl-v0.2.32-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.32/rumdl-v0.2.32-x86_64-pc-windows-msvc.zip">rumdl-v0.2.32-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.32/rumdl-v0.2.32-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>Setup Sema</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/setup-sema/</link><pubDate>Mon, 13 Jul 2026 16:34:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/setup-sema/</guid><description>Version updated for https://github.com/sema-lisp/setup-sema to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Docs-only patch: fix the header badge layout on the GitHub Marketplace listing (badges were stacking into a column instead of a row) and absolutize the LICENSE link. No functional changes to the action — identical to v1.0.0 in behavior.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sema-lisp/setup-sema">https://github.com/sema-lisp/setup-sema</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-sema">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Docs-only patch: fix the header badge layout on the GitHub Marketplace listing (badges were stacking into a column instead of a row) and absolutize the LICENSE link. No functional changes to the action — identical to v1.0.0 in behavior.</p>
]]></content:encoded></item><item><title>pipguard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/pipguard/</link><pubDate>Mon, 13 Jul 2026 16:34:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/pipguard/</guid><description>Version updated for https://github.com/shenxianpeng/pipguard to version v0.4.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 🐛 Bug fixes Fix scan-feed: resilient per-entry download by @shenxianpeng in #65 Full Changelog: https://github.com/shenxianpeng/pipguard/compare/v0.4.0...v0.4.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/shenxianpeng/pipguard">https://github.com/shenxianpeng/pipguard</a></strong> to version <strong>v0.4.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pipguard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Optional: add a release summary here -->
<h2 id="-bug-fixes">🐛 Bug fixes</h2>
<ul>
<li>Fix scan-feed: resilient per-entry download by @shenxianpeng in #65</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/shenxianpeng/pipguard/compare/v0.4.0...v0.4.1">https://github.com/shenxianpeng/pipguard/compare/v0.4.0...v0.4.1</a></p>
]]></content:encoded></item><item><title>Deploy to Vercel</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/deploy-to-vercel/</link><pubDate>Mon, 13 Jul 2026 16:33:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/deploy-to-vercel/</guid><description>Version updated for https://github.com/Spectra010s/d-vercel to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added prebuilt input option — deploy prebuilt assets using --prebuilt, skipping vercel pull (#4) sticky-comment input option — choose between updating a single sticky PR comment or posting a new one on each change (#3) CONTRIBUTING.md — developer onboarding guide (#8) prettier added to devDependencies for consistent formatting on fresh checkouts (#8) Linked contributing guide in README and updated compiled dist (#11) Removed marker input — internalized as a constant; users no longer need to configure it</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Spectra010s/d-vercel">https://github.com/Spectra010s/d-vercel</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-to-vercel">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="added">Added</h2>
<ul>
<li><code>prebuilt</code> input option — deploy prebuilt assets using <code>--prebuilt</code>, skipping <code>vercel pull</code> (<a href="https://github.com/Spectra010s/d-vercel/pull/6">#4</a>)</li>
<li><code>sticky-comment</code> input option — choose between updating a single sticky PR comment or posting a new one on each change (<a href="https://github.com/Spectra010s/d-vercel/pull/5">#3</a>)</li>
<li><a href="./CONTRIBUTING.md">CONTRIBUTING.md</a> — developer onboarding guide (<a href="https://github.com/Spectra010s/d-vercel/pull/8">#8</a>)</li>
<li><code>prettier</code> added to <code>devDependencies</code> for consistent formatting on fresh checkouts (<a href="https://github.com/Spectra010s/d-vercel/pull/8">#8</a>)</li>
<li>Linked contributing guide in README and updated compiled dist (<a href="https://github.com/Spectra010s/d-vercel/pull/11">#11</a>)</li>
</ul>
<h2 id="removed">Removed</h2>
<ul>
<li><code>marker</code> input — internalized as a constant; users no longer need to configure it</li>
</ul>
]]></content:encoded></item><item><title>pinprick-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/pinprick-action/</link><pubDate>Mon, 13 Jul 2026 16:33:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/pinprick-action/</guid><description>Version updated for https://github.com/starhaven-io/pinprick-action to version v0.4.3.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Pins pinprick 0.22.0 as the default engine version.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/starhaven-io/pinprick-action">https://github.com/starhaven-io/pinprick-action</a></strong> to version <strong>v0.4.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pinprick-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Pins pinprick 0.22.0 as the default engine version.</p>
]]></content:encoded></item><item><title>graph-sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/graph-sync/</link><pubDate>Mon, 13 Jul 2026 16:32:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/graph-sync/</guid><description>Version updated for https://github.com/wordlift/graph-sync to version v6.11.5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/wordlift/graph-sync/compare/v6.11.4...v6.11.5</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wordlift/graph-sync">https://github.com/wordlift/graph-sync</a></strong> to version <strong>v6.11.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/graph-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/wordlift/graph-sync/compare/v6.11.4...v6.11.5">https://github.com/wordlift/graph-sync/compare/v6.11.4...v6.11.5</a></p>
]]></content:encoded></item><item><title>CCW Extension Deployment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/ccw-extension-deployment/</link><pubDate>Mon, 13 Jul 2026 11:55:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/ccw-extension-deployment/</guid><description>Version updated for https://github.com/BenPaoDeXiaoZhi/ccw-extension-deploy to version v1.0.1.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary 这个 GitHub Action 主要功能是将 Gandi 扩展文件部署到 CCW 的 OSS，并自动更新项目资产列表中的扩展引用。它还提供了一个简单的步骤指南，帮助用户设置和使用该 Action。
What’s Changed v1.0.1: add dep: teamwork (287a1db) v1.0.0: 支持了协作作品 (1ebcdf9) v0.2.5: 忘了build了… (ad6fc09) v0.2.5: 忽略过时警告 (cb0081e) v0.2.4: 添加警告 (4cda2f9) v0.2.3: update (4117714) v0.2.2: fix gandi maybe undefined (5f812d3) v0.2.1: add dep: jszip (716309f) v0.2.0: bundle with more deps (ba40831) v0.1.1: 增加icon (9adb457)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/BenPaoDeXiaoZhi/ccw-extension-deploy">https://github.com/BenPaoDeXiaoZhi/ccw-extension-deploy</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ccw-extension-deployment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>这个 GitHub Action 主要功能是将 Gandi 扩展文件部署到 CCW 的 OSS，并自动更新项目资产列表中的扩展引用。它还提供了一个简单的步骤指南，帮助用户设置和使用该 Action。</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>v1.0.1: add dep: teamwork (287a1db)</li>
<li>v1.0.0: 支持了协作作品 (1ebcdf9)</li>
<li>v0.2.5: 忘了build了&hellip; (ad6fc09)</li>
<li>v0.2.5: 忽略过时警告 (cb0081e)</li>
<li>v0.2.4: 添加警告 (4cda2f9)</li>
<li>v0.2.3: update (4117714)</li>
<li>v0.2.2: fix gandi maybe undefined (5f812d3)</li>
<li>v0.2.1: add dep: jszip (716309f)</li>
<li>v0.2.0: bundle with more deps (ba40831)</li>
<li>v0.1.1: 增加icon (9adb457)</li>
</ul>
]]></content:encoded></item><item><title>BouncerFox Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/bouncerfox-scan/</link><pubDate>Mon, 13 Jul 2026 11:54:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/bouncerfox-scan/</guid><description>Version updated for https://github.com/BouncerFox/cli to version v0.9.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary BouncerFox CLI is a command-line tool that scans AI agent configuration files for security, quality, and compliance issues. It analyzes files such as .md files containing skill definitions and Claude context, rule configurations, and plugin manifests to identify potential vulnerabilities and best practices. The tool runs entirely offline, ensuring no data leaves the user’s machine, and supports various output formats including JSON and SARIF for integration with IDEs and CI systems.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/BouncerFox/cli">https://github.com/BouncerFox/cli</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bouncerfox-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>BouncerFox CLI is a command-line tool that scans AI agent configuration files for security, quality, and compliance issues. It analyzes files such as <code>.md</code> files containing skill definitions and Claude context, rule configurations, and plugin manifests to identify potential vulnerabilities and best practices. The tool runs entirely offline, ensuring no data leaves the user&rsquo;s machine, and supports various output formats including JSON and SARIF for integration with IDEs and CI systems.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Make JSON and SARIF finding paths checkout-relative and portable, with deterministic multi-root namespacing and fingerprints stable across checkout directories and operating systems.</li>
<li>Improve SARIF output with URL-encoded artifact URIs and correct release-binary version metadata.</li>
<li>Fix config resolution so discovery follows the requested scan root, <code>--config</code> loads the exact file, inheritance remains predictable, and invalid profiles or options exit with usage status 2.</li>
<li>Enable validated local <code>custom_rules</code> from <code>.bouncerfox.yml</code>, including documented <code>CUSTOM_NNN</code> IDs and project overrides.</li>
<li>Harden parsing and limits for malformed YAML/JSON, CRLF input, YAML anchors/aliases/merge keys, the 1 MiB content boundary, and the 500-file boundary.</li>
<li>Improve governed-file routing, globs, relative paths, code frames, credential checks, and CI coverage on Windows.</li>
</ul>
<h2 id="upgrade-notes">Upgrade notes</h2>
<ul>
<li>Evidence-path normalization intentionally changes fingerprints generated by v0.8.0 once. Fingerprints are then stable across checkout roots and operating systems.</li>
<li>The built-in rules contract is now <code>1.0.1</code>.</li>
<li>Connected mode remains deliberately disabled in release builds while the CLI/platform policy and integration contract are completed.</li>
</ul>
<h2 id="known-limitation">Known limitation</h2>
<p>The Docker-based GitHub Action still compiles its embedded version as <code>dev</code>, so Action version output and SARIF driver metadata do not report <code>0.9.0</code>. Downloadable release binaries report <code>0.9.0</code> correctly, and scanning behavior is unaffected. Revisit this during Action/release build-parity hardening.</p>
]]></content:encoded></item><item><title>AI Blog Post Generator — roadtrip-blogger</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/ai-blog-post-generator-roadtrip-blogger/</link><pubDate>Mon, 13 Jul 2026 11:53:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/ai-blog-post-generator-roadtrip-blogger/</guid><description>Version updated for https://github.com/cazerme/blog-marketing-skills to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action generates and optimizes blog posts using the roadtrip-blogger agent, which creates North American road-trip blog posts that are unique and verified. It integrates with Claude’s skills to generate content and ensures that the blog remains SEO-optimized and GEO-focused by checking for duplicates and facts already published. The action can be triggered by a schedule or manually and generates posts in the user’s site’s format, ensuring no duplication and factual accuracy.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/cazerme/blog-marketing-skills">https://github.com/cazerme/blog-marketing-skills</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-blog-post-generator-roadtrip-blogger">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action generates and optimizes blog posts using the <code>roadtrip-blogger</code> agent, which creates North American road-trip blog posts that are unique and verified. It integrates with Claude&rsquo;s skills to generate content and ensures that the blog remains SEO-optimized and GEO-focused by checking for duplicates and facts already published. The action can be triggered by a schedule or manually and generates posts in the user&rsquo;s site&rsquo;s format, ensuring no duplication and factual accuracy.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Three GitHub Actions, all verified green in CI self-tests (generate / optimize / pipeline suites):</p>
<ul>
<li><strong><code>cazerme/blog-marketing-skills@v1</code></strong> — generates one non-duplicating road-trip blog post per run (roadtrip-blogger agent: site-format discovery, coverage-ledger dedup gate, primary-source fact verification) and opens it as a PR</li>
<li><strong><code>cazerme/blog-marketing-skills/optimize@v1</code></strong> — SEO/GEO-optimizes an existing post (blog-seo-geo skill over aaron-marketing: fail-closed engine, number-fabrication guard); the optimization report becomes the PR body; idempotent</li>
<li><strong><code>cazerme/blog-marketing-skills/pipeline@v1</code></strong> — the full loop in one step: generate → optimize → one born-optimized PR</li>
</ul>
<p><strong>Auth</strong>: <code>claude_code_oauth_token</code> (Claude Pro/Max subscription — no API credits needed) or <code>anthropic_api_key</code> (Console billing; needs a tier whose ITPM fits an agent session).</p>
<p>Consumer recipes (daily cron, permissions, concurrency lock) in the <a href="https://github.com/cazerme/blog-marketing-skills#github-action--scheduled-blog-generation">README</a> (<a href="https://github.com/cazerme/blog-marketing-skills/blob/main/README.zh-CN.md">中文</a>). Also in this repo: the blog-marketing Claude Code plugin (the skill + agent these actions run).</p>
<p>🤖 Generated with <a href="https://claude.com/claude-code">Claude Code</a></p>
]]></content:encoded></item><item><title>mcpconform</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/mcpconform/</link><pubDate>Mon, 13 Jul 2026 11:52:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/mcpconform/</guid><description>Version updated for https://github.com/cejor6/mcpconform to version v0.2.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The mcpconform GitHub Action is a static linter that checks MCP setup correctness. It validates tool definitions, server manifests, and client configuration files against the MCP spec and provider profiles. The action supports auto-detection of artifact types, target providers, and output formats like SARIF for integration with code scanning tools.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/cejor6/mcpconform">https://github.com/cejor6/mcpconform</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcpconform">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>mcpconform</code> GitHub Action is a static linter that checks MCP setup correctness. It validates tool definitions, server manifests, and client configuration files against the MCP spec and provider profiles. The action supports auto-detection of artifact types, target providers, and output formats like SARIF for integration with code scanning tools.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Docs / packaging release — <strong>no behavior change</strong>. Republished so the refreshed README reaches the <a href="https://www.npmjs.com/package/mcpconform">npm package page</a>.</p>
<p><code>npm i -g mcpconform</code> or <code>npx mcpconform</code>, or use the Action: <code>uses: cejor6/mcpconform@v1</code>.</p>
<h2 id="whats-new">What&rsquo;s new</h2>
<ul>
<li><strong>README curb-appeal for public visibility</strong> — status badges (npm version, CI, license, Node), a copy-pasteable <strong>&ldquo;Lint your MCP server in 30 seconds&rdquo;</strong> quickstart at the top, a real example-output block, a clean-run example, and a prominent npm link.</li>
<li><strong>CI self-lint (dogfood) job</strong> — the linter now runs against the <code>examples/</code> fixtures on every push/PR, asserting the bad fixtures surface a known seeded finding (not merely a non-zero exit) and the good fixtures pass clean.</li>
<li><strong>Bug-report issue form</strong> + <code>config.yml</code> routing (security → policy, questions → README).</li>
</ul>
<p>No rules, profiles, or CLI behavior changed since v0.2.0. Full notes in <a href="https://github.com/cejor6/mcpconform/blob/main/CHANGELOG.md">CHANGELOG.md</a>.</p>
]]></content:encoded></item><item><title>.NET Build/Test/Pack/Push</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/.net-build/test/pack/push/</link><pubDate>Mon, 13 Jul 2026 11:51:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/.net-build/test/pack/push/</guid><description>Version updated for https://github.com/f2calv/gha-dotnet-nuget to version v2.1.1.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action builds and packages .NET class libraries, pushing them to both the official NuGet feed and GitHub Packages. It automates the process of creating and publishing NuGet packages, including handling versioning, configuration options, and integration with GitHub Packages using a GitHub token or NuGet API key.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/f2calv/gha-dotnet-nuget">https://github.com/f2calv/gha-dotnet-nuget</a></strong> to version <strong>v2.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/net-build-test-pack-push">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action builds and packages .NET class libraries, pushing them to both the official NuGet feed and GitHub Packages. It automates the process of creating and publishing NuGet packages, including handling versioning, configuration options, and integration with GitHub Packages using a GitHub token or NuGet API key.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>2026-04 maintenance: scoped instruction files, checkout@v7 by @f2calv in <a href="https://github.com/f2calv/gha-dotnet-nuget/pull/63">https://github.com/f2calv/gha-dotnet-nuget/pull/63</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/f2calv/gha-dotnet-nuget/compare/v2.1...v2.1.1">https://github.com/f2calv/gha-dotnet-nuget/compare/v2.1...v2.1.1</a></p>
]]></content:encoded></item><item><title>gha-release-versioning</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/gha-release-versioning/</link><pubDate>Mon, 13 Jul 2026 11:49:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/gha-release-versioning/</guid><description>Version updated for https://github.com/f2calv/gha-release-versioning to version v1.3.7.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action calculates and releases a semantic version of a repository using GitVersion, with options to customize the version and tagging behavior. It automatically detects the required GitVersion configuration file version and handles both v5 and v6 configurations. The action supports generating release notes from merged PRs since the last release.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/f2calv/gha-release-versioning">https://github.com/f2calv/gha-release-versioning</a></strong> to version <strong>v1.3.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gha-release-versioning">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action calculates and releases a semantic version of a repository using GitVersion, with options to customize the version and tagging behavior. It automatically detects the required GitVersion configuration file version and handles both v5 and v6 configurations. The action supports generating release notes from merged PRs since the last release.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>2026-06 maintenance: scoped instruction files, checkout@v7 by @f2calv in <a href="https://github.com/f2calv/gha-release-versioning/pull/33">https://github.com/f2calv/gha-release-versioning/pull/33</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/f2calv/gha-release-versioning/compare/v1...v1.3.7">https://github.com/f2calv/gha-release-versioning/compare/v1...v1.3.7</a></p>
]]></content:encoded></item><item><title>GitHub Star Tracker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/github-star-tracker/</link><pubDate>Mon, 13 Jul 2026 11:48:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/github-star-tracker/</guid><description>Version updated for https://github.com/fbuireu/github-star-tracker to version v1.22.2.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary GitHub Star Tracker is a GitHub Action that tracks the star counts of all repositories across your organization on a schedule. It generates visual reports with animated SVG charts, badges, and markdown/HTML reports to help you monitor repository popularity and growth trends. Key capabilities include automatic dark/light mode support, configurable retention, smart filtering options, stargazer tracking, email notifications, and CSV export for machine-readable data.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/fbuireu/github-star-tracker">https://github.com/fbuireu/github-star-tracker</a></strong> to version <strong>v1.22.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-star-tracker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>GitHub Star Tracker is a GitHub Action that tracks the star counts of all repositories across your organization on a schedule. It generates visual reports with animated SVG charts, badges, and markdown/HTML reports to help you monitor repository popularity and growth trends. Key capabilities include automatic dark/light mode support, configurable retention, smart filtering options, stargazer tracking, email notifications, and CSV export for machine-readable data.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1222-2026-07-13"><a href="https://github.com/fbuireu/github-star-tracker/compare/v1.22.1...v1.22.2">1.22.2</a> (2026-07-13)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>stop fabricating star history for repos with unreachable stargazers (<a href="https://github.com/fbuireu/github-star-tracker/issues/149">#149</a>) (<a href="https://github.com/fbuireu/github-star-tracker/commit/8b7335da56e7558f6d66fb1153a233f6231b1337">8b7335d</a>)</li>
</ul>
]]></content:encoded></item><item><title>Setup Flutter SDK</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/setup-flutter-sdk/</link><pubDate>Mon, 13 Jul 2026 11:47:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/setup-flutter-sdk/</guid><description>Version updated for https://github.com/flutter-actions/setup-flutter to version v4.3.
This action is used across all versions by 822 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action installs and sets up the Flutter SDK for use in actions by downloading it, adding flutter and dart commands to the path, supporting caching of pub dependencies and the installed SDK, and automating the publishing of packages to Pub.dev. The action takes inputs for specifying a Flutter version, release channel, and cache options.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/flutter-actions/setup-flutter">https://github.com/flutter-actions/setup-flutter</a></strong> to version <strong>v4.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>822</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-flutter-sdk">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action installs and sets up the Flutter SDK for use in actions by downloading it, adding <code>flutter</code> and <code>dart</code> commands to the path, supporting caching of pub dependencies and the installed SDK, and automating the publishing of packages to Pub.dev. The action takes inputs for specifying a Flutter version, release channel, and cache options.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Pin <code>actions/cache</code> to <code>55cc834</code> or <code>v6.1.0</code> by @socheatsok78 in <a href="https://github.com/flutter-actions/setup-flutter/pull/18">https://github.com/flutter-actions/setup-flutter/pull/18</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/flutter-actions/setup-flutter/compare/v4.2...v4.3">https://github.com/flutter-actions/setup-flutter/compare/v4.2...v4.3</a></p>
]]></content:encoded></item><item><title>shipready Quality Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/shipready-quality-gate/</link><pubDate>Mon, 13 Jul 2026 11:46:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/shipready-quality-gate/</guid><description>Version updated for https://github.com/formalness/shipready to version v1.5.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
shipready is a CLI tool designed to help developers identify and fix common issues in AI-generated code projects. It scans the project for hardcoded secrets, missing .env.example files, debug logs, unfinished TODOs, and broken repo hygiene. The tool provides an automated way to check and optionally fix these issues before releasing the application. shipready is particularly useful for AI coding tools, as it detects common pitfalls that can be harmful to security and maintainability once deployed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/formalness/shipready">https://github.com/formalness/shipready</a></strong> to version <strong>v1.5.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/shipready-quality-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>shipready is a CLI tool designed to help developers identify and fix common issues in AI-generated code projects. It scans the project for hardcoded secrets, missing <code>.env.example</code> files, debug logs, unfinished TODOs, and broken repo hygiene. The tool provides an automated way to check and optionally fix these issues before releasing the application. shipready is particularly useful for AI coding tools, as it detects common pitfalls that can be harmful to security and maintainability once deployed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>New: BENCHMARK.md - head-to-head vs gitleaks v8.24.3 on a 7-leak/10-bait corpus: shipready 7/7 with 0 error-level false positives, gitleaks 4/7 with 1. Full methodology, fairness notes, and reproduction steps included. The benchmark also found two real gaps, fixed here: committed .env.backup files were silently skipped by a too-broad .env* exemption (now scanned), and unquoted dotenv-style assignments (JWT_SECRET=c8f3&hellip; without quotes) were missed (now caught). 181 tests.</p>
]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/ai-plugin-scanner/</link><pubDate>Mon, 13 Jul 2026 11:45:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.464.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the scanning of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems. It identifies security, publishability, runtime readiness, and trust signals in plugins, emitting structured reports, SARIF files, policy results, and submission metadata. The action is compatible with GitHub Marketplace workflows and supports different execution modes, formats, and reporting options.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.464</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>18</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the scanning of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems. It identifies security, publishability, runtime readiness, and trust signals in plugins, emitting structured reports, SARIF files, policy results, and submission metadata. The action is compatible with GitHub Marketplace workflows and supports different execution modes, formats, and reporting options.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/667f0bb797aa56b4d4d2fad61c0d7ae7d62839d8">https://github.com/hashgraph-online/hol-guard/tree/667f0bb797aa56b4d4d2fad61c0d7ae7d62839d8</a> with plugin-scanner 2.0.1065.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.463...v1.2.464">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.463...v1.2.464</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/hol-codex-plugin-scanner/</link><pubDate>Mon, 13 Jul 2026 11:44:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.464.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates the security, publishability, runtime readiness, and trust signals of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems. It emits structured reports, SARIF, policy results, and submission metadata while staying aligned with the main scanner release train. The action is designed to handle both local repository content and live network probing for verify mode, providing flexibility for different integration needs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.464</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates the security, publishability, runtime readiness, and trust signals of AI plugin repositories across Codex, Claude, Gemini, and OpenCode ecosystems. It emits structured reports, SARIF, policy results, and submission metadata while staying aligned with the main scanner release train. The action is designed to handle both local repository content and live network probing for <code>verify</code> mode, providing flexibility for different integration needs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.464">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.464</a></p>
]]></content:encoded></item><item><title>Supply Chain Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/supply-chain-guard/</link><pubDate>Mon, 13 Jul 2026 11:43:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/supply-chain-guard/</guid><description>Version updated for https://github.com/homeofe/supply-chain-guard to version v5.12.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary supply-chain-guard is an open-source supply-chain security scanner that detects malware campaigns, fake AI tool repos, and other threats across various ecosystems like npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, Terraform, VS Code extensions, GitHub Actions, and repositories. It generates CycloneDX SBOMs with real dependency inventories, verifies SLSA provenance, and correlates findings into attack-chain incidents.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/homeofe/supply-chain-guard">https://github.com/homeofe/supply-chain-guard</a></strong> to version <strong>v5.12.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/supply-chain-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>supply-chain-guard is an open-source supply-chain security scanner that detects malware campaigns, fake AI tool repos, and other threats across various ecosystems like npm, PyPI, Cargo, Go, RubyGems, Composer, NuGet, Docker, Terraform, VS Code extensions, GitHub Actions, and repositories. It generates CycloneDX SBOMs with real dependency inventories, verifies SLSA provenance, and correlates findings into attack-chain incidents.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="v5122-2026-07-13">v5.12.2 (2026-07-13)</h3>
<p><strong>Threat-intel: Injective Labs SDK npm compromise (July 2026)</strong></p>
<ul>
<li>Added IOCs for the Injective Labs SDK supply-chain attack (The Hacker News /
BleepingComputer / Socket / Aikido, 2026-07-08 to 07-10). The Injective Labs
SDK GitHub repo was compromised and its trusted-publisher (OIDC) pipeline
abused to publish <code>@injectivelabs/sdk-ts@1.20.21</code> carrying &ldquo;fake telemetry&rdquo;
that captures wallet private keys and mnemonic seed phrases when SDK key
generation/import functions run, base64-encodes them, and HTTPS-POSTs to a
lookalike exfil host. Version 1.20.21 was pinned across 17 dependent
<code>@injectivelabs</code> scoped packages (18 total; ~310 downloads before it was
deprecated). Clean version: 1.20.23.</li>
<li>All 18 package entries are version-pinned (only 1.20.21 matches) - these are
legitimate packages, so the bare names are intentionally NOT blocked.</li>
<li>Added the fake-telemetry exfil domain (the full specific hostname is matched,
never a broad <code>injective[.]network</code> block, so legitimate SDK endpoints are
not flagged) and the two SHA-256 hashes of the infostealer files to
<code>ioc-blocklist.ts</code> and <code>BUNDLED_FEED</code>, plus a campaign test block.</li>
<li>Source excerpts came from the arena.elvatis.com feed; the exact indicators
were confirmed against the linked primary reports before being added.</li>
</ul>
]]></content:encoded></item><item><title>borderlint AI Data-Residency Lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/borderlint-ai-data-residency-lint/</link><pubDate>Mon, 13 Jul 2026 11:41:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/borderlint-ai-data-residency-lint/</guid><description>Version updated for https://github.com/iolairus/borderlint to version v1.9.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
borderlint is a static linter designed to scan AI data and model traffic within a repository, evaluating it against residency, sovereignty, and provenance dimensions. It supports multiple programming languages (Python, TypeScript/JavaScript, Java/Kotlin) and can generate reports in various formats such as JSON, SARIF, SBOM, evidence packs, and HTML. The action automatically checks for compliance with predefined policies and provides detailed audit reports to ensure data and model traffic adhere to specified regulations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/iolairus/borderlint">https://github.com/iolairus/borderlint</a></strong> to version <strong>v1.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/borderlint-ai-data-residency-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>borderlint is a static linter designed to scan AI data and model traffic within a repository, evaluating it against residency, sovereignty, and provenance dimensions. It supports multiple programming languages (Python, TypeScript/JavaScript, Java/Kotlin) and can generate reports in various formats such as JSON, SARIF, SBOM, evidence packs, and HTML. The action automatically checks for compliance with predefined policies and provides detailed audit reports to ensure data and model traffic adhere to specified regulations.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li><strong>Java/Kotlin detection</strong> — <code>.java</code>/<code>.kt</code>/<code>.kts</code> imports resolved via the new per-provider <code>jvm</code> KB key (official OpenAI, Anthropic, Bedrock, Vertex, Azure OpenAI, Gemini, Cohere, SageMaker, ollama4j SDKs — incl. the AWS SDK for Kotlin namespaces), with LangChain4j and Spring AI as runtime-routed aggregators. Endpoint literals, OpenAI-compatible call paths, config keys, inline waivers, and model-reference binding all apply to JVM sources.</li>
<li>Validated against real codebases (Vespa, Pastefy, langchain4j-examples, spring-ai-examples, anthropic-sdk-java, openai-java, aws-doc-sdk-examples) before release.</li>
</ul>
]]></content:encoded></item><item><title>Aeroflare CI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/aeroflare-ci/</link><pubDate>Mon, 13 Jul 2026 11:40:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/aeroflare-ci/</guid><description>Version updated for https://github.com/ItzEmoji/aeroflare to version v1.8.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action automates the caching and pushing of Nix build outputs to an OCI registry from CI. It uses the aeroflare tool to generate OCI images with store paths as tags, enabling fast lookups in container registries. This action streamlines the process for developers by handling cache management and OCI image creation automatically.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ItzEmoji/aeroflare">https://github.com/ItzEmoji/aeroflare</a></strong> to version <strong>v1.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aeroflare-ci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action automates the caching and pushing of Nix build outputs to an OCI registry from CI. It uses the <code>aeroflare</code> tool to generate OCI images with store paths as tags, enabling fast lookups in container registries. This action streamlines the process for developers by handling cache management and OCI image creation automatically.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="180-2026-07-13"><a href="https://github.com/ItzEmoji/aeroflare/compare/v1.7.0...v1.8.0">1.8.0</a> (2026-07-13)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>action:</strong> add composite action entrypoint (<a href="https://github.com/ItzEmoji/aeroflare/commit/eb60e0489ddf6f7c87cee5127ec437ac5052cfbe">eb60e04</a>)</li>
<li><strong>action:</strong> add shared shell helpers for the composite action (<a href="https://github.com/ItzEmoji/aeroflare/commit/8662c0b0ac96c8706182633fa8c1b4d5b9461d28">8662c0b</a>)</li>
<li><strong>action:</strong> download and verify the attested aeroflare-ci binary (<a href="https://github.com/ItzEmoji/aeroflare/commit/0821f3e62a4c434982dcc029ddbcb1a00347b1bc">0821f3e</a>)</li>
<li><strong>action:</strong> publish a JSON Schema for .aeroflare-ci.yaml (<a href="https://github.com/ItzEmoji/aeroflare/commit/5e2c89df1028ac10fa98a92c91f31db84bc596d5">5e2c89d</a>)</li>
<li><strong>action:</strong> validate action modes and build the aeroflare-ci argv (<a href="https://github.com/ItzEmoji/aeroflare/commit/734058cb5220b9f49c657238d53d72f6f61331d7">734058c</a>)</li>
<li>add cmdutil.Factory, error sentinels, and test helpers (<a href="https://github.com/ItzEmoji/aeroflare/commit/0f697da7485d688ac16cb6604cbd55f6d3797323">0f697da</a>)</li>
<li>add install and install-release tasks with PREFIX support (<a href="https://github.com/ItzEmoji/aeroflare/commit/37743ee846586783d14e087c795323a4f45fc316">37743ee</a>)</li>
<li>add pkg/iostreams to replace package-level print helpers (<a href="https://github.com/ItzEmoji/aeroflare/commit/8dbd7a18161279824aae67c6987f1135c7225e84">8dbd7a1</a>)</li>
<li>bake version into binary via ldflags instead of embedded JSON (<a href="https://github.com/ItzEmoji/aeroflare/commit/9e86ef72e2b0a5ac491dc5d030dd153feb8a9fe7">9e86ef7</a>)</li>
<li><strong>cache:</strong> add Group for querying several upstream caches as one (<a href="https://github.com/ItzEmoji/aeroflare/commit/a5638f4d5d2fbb0dbc47f7566730a7990c553704">a5638f4</a>)</li>
<li>ci action (<a href="https://github.com/ItzEmoji/aeroflare/commit/c4ff07afe8ed2cb49e9ee235f133bfd507eb6460">c4ff07a</a>)</li>
<li><strong>ci:</strong> accept a list of upstream caches in config and inputs (<a href="https://github.com/ItzEmoji/aeroflare/commit/b84c14413ca68d82a0be5c6b4743f58706f67119">b84c144</a>)</li>
<li><strong>ci:</strong> accept http(s):// scheme in cache registry (<a href="https://github.com/ItzEmoji/aeroflare/commit/964b474f86f6981a3a3d37ecc03c75f0b2713ecd">964b474</a>)</li>
<li><strong>ci:</strong> add aeroflare-ci command entry point (<a href="https://github.com/ItzEmoji/aeroflare/commit/aefd5152bda8dfdbb8201c4211a0f80ff2607639">aefd515</a>)</li>
<li><strong>ci:</strong> add plain CI reporter (<a href="https://github.com/ItzEmoji/aeroflare/commit/bc1f103462593aa0164897379d09bccd2cbbfbd6">bc1f103</a>)</li>
<li><strong>ci:</strong> build installables and scrape store paths (<a href="https://github.com/ItzEmoji/aeroflare/commit/ef156614c26f102061f06a4f652ba219064c73d3">ef15661</a>)</li>
<li><strong>ci:</strong> load config file and merge inline inputs (<a href="https://github.com/ItzEmoji/aeroflare/commit/9ed791d329fa02174f8c896ca66d823097b3aa41">9ed791d</a>)</li>
<li><strong>ci:</strong> make &ndash;upstream-cache repeatable (<a href="https://github.com/ItzEmoji/aeroflare/commit/756de43c1b45ba49381b28c0aabb8f550a3cdb5a">756de43</a>)</li>
<li><strong>ci:</strong> orchestrate builds and multi-cache pushes (<a href="https://github.com/ItzEmoji/aeroflare/commit/1a3976c00fa78844a281689428de035c24ebbc49">1a3976c</a>)</li>
<li><strong>ci:</strong> parse cache specs and resolve per-host tokens (<a href="https://github.com/ItzEmoji/aeroflare/commit/156f5fea653898e73c7017dceb76dbbe5e98b2bd">156f5fe</a>)</li>
<li><strong>ci:</strong> proxy-accelerated build, prepare-once, push-to-all pipeline (<a href="https://github.com/ItzEmoji/aeroflare/commit/15412979eb01ead4f6b7df394195bfe857c57967">1541297</a>)</li>
<li><strong>ci:</strong> reject build entries that are mis-indented action inputs (<a href="https://github.com/ItzEmoji/aeroflare/commit/98dfd4a0883984f92eb4ed5113d5e7ad66c36d0b">98dfd4a</a>)</li>
<li><strong>ci:</strong> resolve signing key from env material or path (<a href="https://github.com/ItzEmoji/aeroflare/commit/553203784fe9c9e68fe02eba1352bf84042bed98">5532037</a>)</li>
<li><strong>ci:</strong> route builds through proxy and dedup store paths (<a href="https://github.com/ItzEmoji/aeroflare/commit/a28ef6e112f53bab3b747fa1b356f48b301b97c4">a28ef6e</a>)</li>
<li><strong>ci:</strong> skip build outputs already served by an upstream cache (<a href="https://github.com/ItzEmoji/aeroflare/commit/a37ef022e0bd3abcdcda63d537cb9d20fd704224">a37ef02</a>)</li>
<li><strong>oci:</strong> add a go-containerregistry auth seam (<a href="https://github.com/ItzEmoji/aeroflare/commit/0c01f9f89004f0f8de28e7ef5501474e8b255580">0c01f9f</a>)</li>
<li>print build date in aeroflare version output (<a href="https://github.com/ItzEmoji/aeroflare/commit/15ce46e9a5178b802f6b02c7c360181d3bee4dc1">15ce46e</a>)</li>
<li><strong>push:</strong> add prepare-once / push-to-many engine split (<a href="https://github.com/ItzEmoji/aeroflare/commit/93f3b263631d68704eb460aa24dbaef7eafcd26f">93f3b26</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>action scripts and ci pipeline in order to provide a better user experience (<a href="https://github.com/ItzEmoji/aeroflare/commit/d78ce38d99cde3e868930d9d7930f8de6674dfa2">d78ce38</a>)</li>
<li><strong>action:</strong> split upstream-cache into one flag per entry (<a href="https://github.com/ItzEmoji/aeroflare/commit/519eb9d607969236d3a32c53f8edb1e3eb913eb0">519eb9d</a>)</li>
<li>bind &ndash;cache-url against root&rsquo;s flags, not the invoked subcommand&rsquo;s (<a href="https://github.com/ItzEmoji/aeroflare/commit/8273f41ef51b34b777f7c3e84db26666fb858aa9">8273f41</a>)</li>
<li><strong>ci:</strong> push the CI credential as a password, not a bearer token (<a href="https://github.com/ItzEmoji/aeroflare/commit/c2f17804d52fd44326877374395347703fdcb594">c2f1780</a>)</li>
<li><strong>ci:</strong> scope proxy lifetime to the build phase only (<a href="https://github.com/ItzEmoji/aeroflare/commit/16253629e3294be5913532f40f082405ef9301f8">1625362</a>)</li>
<li><strong>ci:</strong> stop reporting a filtered closure as the full closure (<a href="https://github.com/ItzEmoji/aeroflare/commit/6309ab8ef5ceb7a1de629e258af8a776f8c6a253">6309ab8</a>)</li>
<li><strong>ci:</strong> upload only paths absent from every upstream cache (<a href="https://github.com/ItzEmoji/aeroflare/commit/b5655ac1ab6d7d65ddfe86fee73384cf60ef7da5">b5655ac</a>)</li>
<li>correct dotfile depth-check and tar-write atomicity in script/build.go (<a href="https://github.com/ItzEmoji/aeroflare/commit/675c7e2c1bf2819fbdd2a3ea171e3c4a4c3112dd">675c7e2</a>)</li>
<li>extract aeroflare-ci from the bin/ path inside release archives (<a href="https://github.com/ItzEmoji/aeroflare/commit/c435e38119c8db9f7cdbcc422c11df4e7c346852">c435e38</a>)</li>
<li>keep the &ldquo;no value found&rdquo; context when auth get fails to resolve a field (<a href="https://github.com/ItzEmoji/aeroflare/commit/72e13843f89afb058cc12d4d0cc26b103ed0cf63">72e1384</a>)</li>
<li>restore the global viper binding so &ndash;cache-url and AEROFLARE_* work again (<a href="https://github.com/ItzEmoji/aeroflare/commit/2c41e3844d5e563b1fd63ce8d79ab8d1762d74dd">2c41e38</a>)</li>
<li>restore usage output on flag and argument errors (<a href="https://github.com/ItzEmoji/aeroflare/commit/4bbb66a2440affdf187693de0a1be679799027bc">4bbb66a</a>)</li>
<li>return an error from GetRegistryAndRepository instead of exiting the process (<a href="https://github.com/ItzEmoji/aeroflare/commit/5fb8c015ccfcd5849d1065c39fb44da817883006">5fb8c01</a>)</li>
<li>show usage on argument errors for auth get, set, and remove (<a href="https://github.com/ItzEmoji/aeroflare/commit/d4c01172e3ba05f6fb3034f0181f9945647eaa6d">d4c0117</a>)</li>
</ul>
]]></content:encoded></item><item><title>Agent Guard Secret Guardrails</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/agent-guard-secret-guardrails/</link><pubDate>Mon, 13 Jul 2026 11:39:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/agent-guard-secret-guardrails/</guid><description>Version updated for https://github.com/JeongJaeSoon/agent-guard to version v1.10.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Summary:
Agent Guard is a deterministic guardrail that blocks AI coding agents from accidentally exposing secrets during tool calls. It uses gitleaks for detection and plain shell scripts for integration. It runs at the agent’s tool boundary to block common secret exposure methods, such as reading .env files or writing sensitive values. Agent Guard pairs with commit/CI scanning for defense in depth. It is not a vault or credential rotator but provides real-time protection before secrets are exposed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/JeongJaeSoon/agent-guard">https://github.com/JeongJaeSoon/agent-guard</a></strong> to version <strong>v1.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-guard-secret-guardrails">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Summary:</strong></p>
<p>Agent Guard is a deterministic guardrail that blocks AI coding agents from accidentally exposing secrets during tool calls. It uses <code>gitleaks</code> for detection and plain shell scripts for integration. It runs at the agent&rsquo;s tool boundary to block common secret exposure methods, such as reading <code>.env</code> files or writing sensitive values. Agent Guard pairs with commit/CI scanning for defense in depth. It is not a vault or credential rotator but provides real-time protection before secrets are exposed.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Promote Codex setup and command guard to v1.10.0 by @JeongJaeSoon in <a href="https://github.com/JeongJaeSoon/agent-guard/pull/108">https://github.com/JeongJaeSoon/agent-guard/pull/108</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/JeongJaeSoon/agent-guard/compare/v1.9.0...v1.10.0">https://github.com/JeongJaeSoon/agent-guard/compare/v1.9.0...v1.10.0</a></p>
]]></content:encoded></item><item><title>pytest Benchmark Baseline Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/pytest-benchmark-baseline-check/</link><pubDate>Mon, 13 Jul 2026 11:38:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/pytest-benchmark-baseline-check/</guid><description>Version updated for https://github.com/LennardZuendorf/pytest-bench-action to version v1.0.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary This GitHub Action automates performance benchmarking using pytest-benchmark. It compares test results against per-branch baselines, allowing developers to track and report changes in performance over time. Key features include automatic baseline management, tolerance-based threshold checking, and the ability to override regressions for specific PRs. The action is particularly useful for maintaining consistent performance metrics across different environments and detecting unexpected performance regressions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/LennardZuendorf/pytest-bench-action">https://github.com/LennardZuendorf/pytest-bench-action</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pytest-benchmark-baseline-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>This GitHub Action automates performance benchmarking using <code>pytest-benchmark</code>. It compares test results against per-branch baselines, allowing developers to track and report changes in performance over time. Key features include automatic baseline management, tolerance-based threshold checking, and the ability to override regressions for specific PRs. The action is particularly useful for maintaining consistent performance metrics across different environments and detecting unexpected performance regressions.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="pytest-benchmark-baseline-check--v101-general-availability">pytest Benchmark Baseline Check — v1.0.1 (General Availability)</h1>
<p>A reusable GitHub Action that runs <code>pytest-benchmark</code>, manages per-branch baselines committed to your repository, gates PRs on regressions, and posts a formatted results comment — with no Docker, no external services, and no third-party Python dependencies in its own scripts.</p>
<p>The action performs its own checkout — it&rsquo;s the only step you need in the job. See <a href="docs/example-workflow.yml"><code>docs/example-workflow.yml</code></a> for a complete job (triggers, permissions, runner).</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li>
<p>🖥️ <strong>Hardware-aware comparison</strong>
Comparability is judged by a CPU/system fingerprint (<code>cpu.brand_raw</code> + architecture + core count + system) rather than the runner hostname, since hosted runners randomize the node name on every job.</p>
<ul>
<li>Same CPU model → compares cleanly across jobs.</li>
<li>Genuinely different hardware → rejected, never silently mis-compared.</li>
<li><code>enforce-same-node</code> (default <code>&quot;false&quot;</code>): <code>&quot;false&quot;</code> skips a hardware mismatch with a <code>::warning::</code> and <code>comparison-skipped=true</code>; <code>&quot;true&quot;</code> hard-fails the job — the right setting for stable/self-hosted runners.</li>
</ul>
</li>
<li>
<p>📈 <strong>Dual baseline comparison</strong></p>
<ul>
<li>PR vs. target-branch baseline, gated by <code>cross-branch-tolerance</code> (default <code>20%</code>).</li>
<li>Sequential comparison vs. <code>HEAD~1</code>.</li>
<li>Missing benchmarks fail the run; new benchmarks (not yet in the baseline) pass.</li>
</ul>
</li>
<li>
<p>🧬 <strong>Baselines committed to your repository</strong></p>
<ul>
<li>Versioned, diffable JSON per branch under <code>baselines-dir</code> (default <code>.benchmarks/baselines</code>).</li>
<li>Raw sample arrays stripped from stats — roughly 99% smaller than raw <code>pytest-benchmark</code> output.</li>
<li>During a PR run, the action checks out the PR&rsquo;s own head branch, compares against the <strong>target branch&rsquo;s</strong> committed baseline, and — if drift exceeds <code>update-tolerance</code> (default <code>5%</code>) — stages the updated baseline file <strong>on the PR branch itself</strong>, tagged <code>[skip ci]</code>.</li>
<li>Lands on the target branch automatically when the PR merges. No separate post-merge push, no rerun, and never a direct write to a protected branch.</li>
<li>Same-repo PRs only — forks can&rsquo;t push a baseline update (no write access), but still get the comparison and PR comment.</li>
</ul>
</li>
<li>
<p>🏷️ <strong>Per-PR regression override</strong>
Add the <code>override-label</code> (default <code>benchmark-override</code>) to a PR to waive a detected regression for that PR only. The regression still shows in the comment (<code>regression-overridden=true</code>) but doesn&rsquo;t fail the job. Scoped per-PR, self-clearing (remove the label to re-enforce), and never loosens the repository-wide tolerance.</p>
</li>
<li>
<p>📊 <strong>One clean PR comment per run</strong>
Results table, per-test thresholds, and both baseline comparisons in a single comment. Previous bot comments (matching the <code>## 📊 Performance Benchmark Results</code> header) are deleted before posting a new one — no stacking.</p>
</li>
<li>
<p>🔒 <strong>Fail loudly, pass quietly</strong>
The PR comment and results artifact are always published first; a detected regression fails the job afterward, so you always get the full report regardless of outcome.</p>
</li>
<li>
<p>⚙️ <strong>Per-test thresholds</strong>
<code>threshold-map</code> maps a test-name substring to a max-seconds ceiling (first match wins); tests not covered default to <code>1.0s</code>.</p>
</li>
<li>
<p>📦 <strong>No extra dependencies for the action itself</strong>
All internal scripts (<code>scripts/benchmark_baseline.py</code>, <code>scripts/benchmark_compare.py</code>) are Python stdlib only — <code>json</code>, <code>pathlib</code>, <code>sys</code>. Your job still needs <code>pytest-benchmark</code> installed via <code>setup-command</code>.</p>
</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/LennardZuendorf/pytest-bench-action/compare/v0.0.1...v1.0.1">https://github.com/LennardZuendorf/pytest-bench-action/compare/v0.0.1...v1.0.1</a></p>
]]></content:encoded></item><item><title>Dependabit - AI-Powered Dependency Tracker</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/dependabit-ai-powered-dependency-tracker/</link><pubDate>Mon, 13 Jul 2026 11:37:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/dependabit-ai-powered-dependency-tracker/</guid><description>Version updated for https://github.com/pradeepmouli/dependabit to version @dependabit/utils@0.1.17.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Dependabit is an AI-powered dependency tracking action that automatically discovers, tracks, and monitors external dependencies referenced in a codebase. It uses LLMs to intelligently detect dependencies like GitHub repos, documentation sites, API references, research papers, and more. Dependabit provides features for automatic updates, change monitoring, and flexible configuration, making it a powerful tool for managing software dependencies effectively.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pradeepmouli/dependabit">https://github.com/pradeepmouli/dependabit</a></strong> to version <strong>@dependabit/utils@0.1.17</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/dependabit-ai-powered-dependency-tracker">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Dependabit is an AI-powered dependency tracking action that automatically discovers, tracks, and monitors external dependencies referenced in a codebase. It uses LLMs to intelligently detect dependencies like GitHub repos, documentation sites, API references, research papers, and more. Dependabit provides features for automatic updates, change monitoring, and flexible configuration, making it a powerful tool for managing software dependencies effectively.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="patch-changes">Patch Changes</h3>
<ul>
<li><a href="https://github.com/pradeepmouli/dependabit/pull/127">#127</a> <a href="https://github.com/pradeepmouli/dependabit/commit/74aac50256e0ac601779e68b5360cba4369db997"><code>74aac50</code></a> Thanks <a href="https://github.com/pradeepmouli">@pradeepmouli</a>! - - chore: also drop .github/agents, prompts, skills, copilot from master
<ul>
<li>chore: also drop specs/, .claude-plugin/ from master</li>
<li>chore: drop AI tooling files from master</li>
</ul>
</li>
</ul>
]]></content:encoded></item><item><title>ActionScope</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/actionscope/</link><pubDate>Mon, 13 Jul 2026 11:36:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/actionscope/</guid><description>Version updated for https://github.com/r12habh/ActionScope to version v0.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary ActionScope is a GitHub Action that scans your CI/CD workflows to identify and report potential security risks in AWS permissions. It provides plain-English explanations of what your workflows can do if compromised, including actions like role escalation, privilege escalation, and data exfiltration. The action also detects known-compromised actions, OIDC trust policy misconfigurations, script injection, artifact poisoning, AI agent prompt injection surfaces, unpinned actions with SHA resolution, local recursion in reusable workflows, and correlated exposure paths.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/r12habh/ActionScope">https://github.com/r12habh/ActionScope</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/actionscope">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>ActionScope</strong> is a GitHub Action that scans your CI/CD workflows to identify and report potential security risks in AWS permissions. It provides plain-English explanations of what your workflows can do if compromised, including actions like role escalation, privilege escalation, and data exfiltration. The action also detects known-compromised actions, OIDC trust policy misconfigurations, script injection, artifact poisoning, AI agent prompt injection surfaces, unpinned actions with SHA resolution, local recursion in reusable workflows, and correlated exposure paths.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="actionscope-v040">ActionScope v0.4.0</h2>
<h3 id="install">Install</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install actionscope<span style="color:#f92672">==</span>0.4.0
</span></span></code></pre></div><h3 id="whats-new">What&rsquo;s New</h3>
<p>See <a href="CHANGELOG.md">CHANGELOG.md</a> for details.</p>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/agentauditkit-mcp-security-scan/</link><pubDate>Mon, 13 Jul 2026 11:34:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.49.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary AgentAuditKit is a security scanner specifically designed to audit AI agent pipelines, automating the identification of potential misconfigurations, hardcoded secrets, and other security issues. It offers full offline determinism to ensure consistent findings across different runs, producing auditor-ready compliance-evidence packs including SARIF for GitHub Security tabs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.49</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>AgentAuditKit is a security scanner specifically designed to audit AI agent pipelines, automating the identification of potential misconfigurations, hardcoded secrets, and other security issues. It offers full offline determinism to ensure consistent findings across different runs, producing auditor-ready compliance-evidence packs including SARIF for GitHub Security tabs.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.49
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.49
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.49</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(rules): MCP 2026-07-28 deprecation pack — AAK-MCP-DEPRECATED-* + AAK-OAUTH-006 by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/427">https://github.com/sattyamjjain/agent-audit-kit/pull/427</a></li>
<li>fix(rules): 2026-07 MCP CVE backlog — 8 version-pin rules (238→246) by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/428">https://github.com/sattyamjjain/agent-audit-kit/pull/428</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.48...v0.3.49">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.48...v0.3.49</a></p>
]]></content:encoded></item><item><title>Setup Sema</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/setup-sema/</link><pubDate>Mon, 13 Jul 2026 11:33:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/setup-sema/</guid><description>Version updated for https://github.com/sema-lisp/setup-sema to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The Sema setup action automates the installation of the Sema Lisp language in GitHub Actions workflows. It supports cross-platform installations, checksum verification, and tool caching to improve performance. The main functionality is to set up the Sema interpreter and provide options for pinning versions and custom download URLs. Users can specify the version they want to use via inputs or rely on default settings from .sema-version or .tool-versions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sema-lisp/setup-sema">https://github.com/sema-lisp/setup-sema</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-sema">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The Sema setup action automates the installation of the Sema Lisp language in GitHub Actions workflows. It supports cross-platform installations, checksum verification, and tool caching to improve performance. The main functionality is to set up the Sema interpreter and provide options for pinning versions and custom download URLs. Users can specify the version they want to use via inputs or rely on default settings from <code>.sema-version</code> or <code>.tool-versions</code>.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release of <strong>setup-sema</strong> — install the <a href="https://sema-lang.com">Sema</a> language in GitHub Actions.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sema-lisp/setup-sema@v1</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">run</span>: <span style="color:#ae81ff">sema my-script.sema</span>
</span></span></code></pre></div><h3 id="highlights">Highlights</h3>
<ul>
<li><strong>Cross-platform</strong>: Linux x64/arm64, macOS Intel + Apple Silicon, Windows x64.</li>
<li><strong>Checksum-verified, fail-closed</strong> installs — resolves assets from cargo-dist&rsquo;s <code>dist-manifest.json</code>; a missing/mismatched checksum aborts.</li>
<li><strong>Tool-cached</strong> — re-runs of the same version skip the download.</li>
<li><strong>Version pinning</strong> via input, <code>.sema-version</code>, or <code>.tool-versions</code>.</li>
<li>Hardened against version path-traversal; the API token is never sent to asset downloads.</li>
</ul>
<p>See the <a href="https://github.com/sema-lisp/setup-sema#readme">README</a> for all inputs/outputs, caching, security, and troubleshooting.</p>
]]></content:encoded></item><item><title>Sentinel Git Secrets Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/sentinel-git-secrets-scanner/</link><pubDate>Mon, 13 Jul 2026 11:32:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/sentinel-git-secrets-scanner/</guid><description>Version updated for https://github.com/sentinel-cli/sentinel to version v2.0.7.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Sentinel is a high-performance, zero-dependency Git pre-commit secret scanner and credentials detector written in Go. It automatically blocks accidental commits of sensitive information such as API keys, SSH private keys, and cloud credentials before they enter version control. Sentinel uses a three-tier detection pipeline to efficiently scan for secrets, with support for pattern matching, entropy analysis, and context classification.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sentinel-cli/sentinel">https://github.com/sentinel-cli/sentinel</a></strong> to version <strong>v2.0.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sentinel-git-secrets-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p><strong>Sentinel</strong> is a high-performance, zero-dependency Git pre-commit secret scanner and credentials detector written in Go. It automatically blocks accidental commits of sensitive information such as API keys, SSH private keys, and cloud credentials before they enter version control. Sentinel uses a three-tier detection pipeline to efficiently scan for secrets, with support for pattern matching, entropy analysis, and context classification.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sentinel-cli/sentinel/compare/v2.0.6...v2.0.7">https://github.com/sentinel-cli/sentinel/compare/v2.0.6...v2.0.7</a></p>
]]></content:encoded></item><item><title>Skaphos Oiax</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/skaphos-oiax/</link><pubDate>Mon, 13 Jul 2026 11:31:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/skaphos-oiax/</guid><description>Version updated for https://github.com/skaphos/oiax to version v1.0.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The GitHub Action skaphos/oiax@v1 automates the reconciliation of Git branches in a GitOps repository, ensuring that changes are promoted through a defined graph of environments. It validates the promotion graph, plans the actions required to reconcile it, and applies those actions by creating, updating, and closing pull requests between branches. The Action is designed for Linux runners on x64 and ARM64 platforms, with release binaries available for other platforms.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/skaphos/oiax">https://github.com/skaphos/oiax</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skaphos-oiax">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The GitHub Action <code>skaphos/oiax@v1</code> automates the reconciliation of Git branches in a GitOps repository, ensuring that changes are promoted through a defined graph of environments. It validates the promotion graph, plans the actions required to reconcile it, and applies those actions by creating, updating, and closing pull requests between branches. The Action is designed for Linux runners on x64 and ARM64 platforms, with release binaries available for other platforms.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>See <a href="https://github.com/skaphos/oiax/blob/v1.0.2/CHANGELOG.md">CHANGELOG.md</a> for the full release notes.</p>
]]></content:encoded></item><item><title>spek - OpenSpec Static Site</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/spek-openspec-static-site/</link><pubDate>Mon, 13 Jul 2026 11:29:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/spek-openspec-static-site/</guid><description>Version updated for https://github.com/spekhq/spek to version v1.7.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Spek is a lightweight, read-only viewer designed to explore OpenSpec content. It provides structured browsing with BDD syntax highlighting, task progress tracking, and full-text search capabilities. spek turns your local OpenSpec directory into an accessible interface, enabling users to browse specs, changes, and tasks in a hierarchical manner. The action automates the process of aggregating multiple git worktrees into one view, offering a comprehensive overview of project changes and tasks.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spekhq/spek">https://github.com/spekhq/spek</a></strong> to version <strong>v1.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spek-openspec-static-site">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Spek is a lightweight, read-only viewer designed to explore OpenSpec content. It provides structured browsing with BDD syntax highlighting, task progress tracking, and full-text search capabilities. spek turns your local OpenSpec directory into an accessible interface, enabling users to browse specs, changes, and tasks in a hierarchical manner. The action automates the process of aggregating multiple git worktrees into one view, offering a comprehensive overview of project changes and tasks.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li><strong>spek has moved to the <code>spekhq</code> GitHub organization</strong> — the repository is now <a href="https://github.com/spekhq/spek"><code>spekhq/spek</code></a>. Clones, links, issues, and stars redirect automatically, so for most users there is nothing to do. <strong>Two things do not redirect:</strong>
<ul>
<li><strong>GitHub Action users must update their workflows</strong> — change <code>uses: kewang/spek@v1</code> to <code>uses: spekhq/spek@v1</code>. GitHub deliberately does not redirect action references (a redirect would let a rename hijack someone else&rsquo;s action), so the old path now fails with <code>repository not found</code>.</li>
<li><strong>The live demo and the README badges moved</strong> to <code>https://spekhq.github.io/spek/</code>. GitHub Pages is not redirected after a transfer, so the old <code>kewang.github.io/spek/</code> URLs are gone for good.</li>
</ul>
</li>
<li><strong>GitHub Action: fixed a build failure that hit every run</strong> — the action never built <code>@spekjs/ui</code> explicitly; it got that package&rsquo;s <code>dist</code> for free from an install-time hook that <code>npm ci</code> happened to run. When the hook moved to publish time (so <code>npm ci</code> would stop failing in the publish pipelines), the action silently lost its <code>@spekjs/ui</code> build and every run died resolving <code>@spekjs/ui/styles.css</code>. Pinning an older tag did not help — the action builds spek from <code>master</code> by default, so the breakage reached everyone at once. The action now builds <code>@spekjs/ui</code> explicitly.</li>
</ul>
]]></content:encoded></item><item><title>vibestats</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/vibestats/</link><pubDate>Mon, 13 Jul 2026 11:28:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/vibestats/</guid><description>Version updated for https://github.com/stephenleo/vibestats to version v2.4.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary VibeStats is a GitHub Action that tracks and stores Claude Code and Codex session statistics in your private GitHub repo. It provides a live heatmap on your GitHub profile and a full analytics dashboard, allowing you to track historical usage data beyond the default 30-day limit set by Claude Code. The action ensures privacy by storing small JSON aggregates before the cleanup process occurs, making it survive machine wipes and reinstalls.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stephenleo/vibestats">https://github.com/stephenleo/vibestats</a></strong> to version <strong>v2.4.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibestats">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>VibeStats is a GitHub Action that tracks and stores Claude Code and Codex session statistics in your private GitHub repo. It provides a live heatmap on your GitHub profile and a full analytics dashboard, allowing you to track historical usage data beyond the default 30-day limit set by Claude Code. The action ensures privacy by storing small JSON aggregates before the cleanup process occurs, making it survive machine wipes and reinstalls.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>chore: bump to 2.4.3 (#142) (1526711)</li>
<li>fix(installer): emit valid JSON from Codex hooks (#141) (f71c77b)</li>
<li>fix(installer): stop faking VIBESTATS_TOKEN auto-provisioning (#137) (#140) (fd225e4)</li>
<li>chore: bump to 2.4.2 (#139) (e8d1fb3)</li>
<li>fix installer Codex hooks feature flag (#138) (f015245)</li>
<li>fix(dashboard): rename model donut &ldquo;Other&rdquo; slice to &ldquo;Others&rdquo; (30cbda4)</li>
<li>fix(dashboard): show &ldquo;Other&rdquo; slice in model donut legend (#134) (5d8b703)</li>
<li>Align weekly bar charts to heatmap&rsquo;s calendar weeks (#133) (3808e9b)</li>
<li>docs(readme): refresh dashboard screenshots to orange redesign (#132) (37e6acc)</li>
<li>fix(site): show docs <pre> text in light mode (6e967a2)</li>
</ul>
]]></content:encoded></item><item><title>Commit Pet</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/commit-pet/</link><pubDate>Mon, 13 Jul 2026 11:27:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/commit-pet/</guid><description>Version updated for https://github.com/yukurash/commit-pet to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
Action Summary Commit Pet is a GitHub Action that visualizes the growth of your commit activity in your GitHub profile README. It generates an SVG pet with three species (slime, cat, ghost) that change mood based on your recent commits and levels up as you contribute more. The action supports customization options like species, name, output file, and theme.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yukurash/commit-pet">https://github.com/yukurash/commit-pet</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/commit-pet">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>Commit Pet is a GitHub Action that visualizes the growth of your commit activity in your GitHub profile README. It generates an SVG pet with three species (slime, cat, ghost) that change mood based on your recent commits and levels up as you contribute more. The action supports customization options like species, name, output file, and theme.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Pet-update commits are now always authored/committed as <code>github-actions[bot]</code>, so they no longer appear on your GitHub contribution graph.</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yukurash/commit-pet/compare/v1.0.1...v1.0.2">https://github.com/yukurash/commit-pet/compare/v1.0.1...v1.0.2</a></p>
]]></content:encoded></item><item><title>Build ZeroPress Pages</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/build-zeropress-pages/</link><pubDate>Mon, 13 Jul 2026 11:26:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/build-zeropress-pages/</guid><description>Version updated for https://github.com/zeropress-app/zeropress-build-pages to version v0.6.13.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
Action Summary The @zeropress/build-pages GitHub Action automates the process of converting Markdown files and public assets into a static ZeroPress site. It performs the following key capabilities:
It builds the static output, suitable for deployment to modern hosting platforms such as GitHub Pages, Cloudflare Pages, Netlify, or Vercel. The generated output consists of plain static files that can be deployed at the origin root of a static hosting provider. Build Pages serves as the Markdown-source document publishing entry point for ZeroPress and is used by other workflows to build from preview-data.json and a theme, or publish after managed authoring workflows in ZeroPress Studio. The action generates preview-data.json, stages public files, and prepares the site data, ultimately providing static HTML pages and assets that can be deployed using a hosting provider’s deployment action.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zeropress-app/zeropress-build-pages">https://github.com/zeropress-app/zeropress-build-pages</a></strong> to version <strong>v0.6.13</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/build-zeropress-pages">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="action-summary">Action Summary</h2>
<p>The <code>@zeropress/build-pages</code> GitHub Action automates the process of converting Markdown files and public assets into a static ZeroPress site. It performs the following key capabilities:</p>
<ol>
<li>It builds the static output, suitable for deployment to modern hosting platforms such as GitHub Pages, Cloudflare Pages, Netlify, or Vercel.</li>
<li>The generated output consists of plain static files that can be deployed at the origin root of a static hosting provider.</li>
<li>Build Pages serves as the Markdown-source document publishing entry point for ZeroPress and is used by other workflows to build from <code>preview-data.json</code> and a theme, or publish after managed authoring workflows in ZeroPress Studio.</li>
</ol>
<p>The action generates <code>preview-data.json</code>, stages public files, and prepares the site data, ultimately providing static HTML pages and assets that can be deployed using a hosting provider&rsquo;s deployment action.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>0.6.13 (2d2c613)</li>
<li>fix: build-pages no longer produces menuitem.type in the middle. (34063f2)</li>
<li>build(deps): bump @zeropress/build to 0.6.13 (e67d1ed)</li>
<li>chore: Exclude dist/ files when creating npm tarball. (a91d470)</li>
<li>0.6.12 (ae84366)</li>
<li>refactor: fix. (ddf38de)</li>
<li>fix(bundled-theme): remove vertical-align style. (f445af4)</li>
<li>fix(bundled-theme): refined. (74191e9)</li>
<li>fix: default <code>site.description</code> from &lsquo;A documentation site.&rsquo; to &rsquo;&rsquo; (ac5f42e)</li>
<li>feat: front matter <code>featured_image</code> (f7382d9)</li>
</ul>
]]></content:encoded></item><item><title>fish-shop/install-plugin</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/fish-shop/install-plugin/</link><pubDate>Mon, 13 Jul 2026 06:27:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/fish-shop/install-plugin/</guid><description>Version updated for https://github.com/fish-shop/install-plugin to version v2.3.114.
This action is used across all versions by 32 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump the version-updates group with 8 updates by @dependabot[bot] in https://github.com/fish-shop/install-plugin/pull/419 Full Changelog: https://github.com/fish-shop/install-plugin/compare/v2.3.113...v2.3.114</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/fish-shop/install-plugin">https://github.com/fish-shop/install-plugin</a></strong> to version <strong>v2.3.114</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>32</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/fish-shop-install-plugin">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump the version-updates group with 8 updates by @dependabot[bot] in <a href="https://github.com/fish-shop/install-plugin/pull/419">https://github.com/fish-shop/install-plugin/pull/419</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/fish-shop/install-plugin/compare/v2.3.113...v2.3.114">https://github.com/fish-shop/install-plugin/compare/v2.3.113...v2.3.114</a></p>
]]></content:encoded></item><item><title>fish-shop/run-fishtape-tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/fish-shop/run-fishtape-tests/</link><pubDate>Mon, 13 Jul 2026 06:26:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/fish-shop/run-fishtape-tests/</guid><description>Version updated for https://github.com/fish-shop/run-fishtape-tests to version v2.3.114.
This action is used across all versions by 36 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump the version-updates group with 8 updates by @dependabot[bot] in https://github.com/fish-shop/run-fishtape-tests/pull/406 Full Changelog: https://github.com/fish-shop/run-fishtape-tests/compare/v2.3.113...v2.3.114</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/fish-shop/run-fishtape-tests">https://github.com/fish-shop/run-fishtape-tests</a></strong> to version <strong>v2.3.114</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>36</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/fish-shop-run-fishtape-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump the version-updates group with 8 updates by @dependabot[bot] in <a href="https://github.com/fish-shop/run-fishtape-tests/pull/406">https://github.com/fish-shop/run-fishtape-tests/pull/406</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/fish-shop/run-fishtape-tests/compare/v2.3.113...v2.3.114">https://github.com/fish-shop/run-fishtape-tests/compare/v2.3.113...v2.3.114</a></p>
]]></content:encoded></item><item><title>fish-shop/syntax-check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/fish-shop/syntax-check/</link><pubDate>Mon, 13 Jul 2026 06:26:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/fish-shop/syntax-check/</guid><description>Version updated for https://github.com/fish-shop/syntax-check to version v2.2.110.
This action is used across all versions by 32 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump the version-updates group with 7 updates by @dependabot[bot] in https://github.com/fish-shop/syntax-check/pull/380 Full Changelog: https://github.com/fish-shop/syntax-check/compare/v2.2.109...v2.2.110</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/fish-shop/syntax-check">https://github.com/fish-shop/syntax-check</a></strong> to version <strong>v2.2.110</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>32</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/fish-shop-syntax-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump the version-updates group with 7 updates by @dependabot[bot] in <a href="https://github.com/fish-shop/syntax-check/pull/380">https://github.com/fish-shop/syntax-check/pull/380</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/fish-shop/syntax-check/compare/v2.2.109...v2.2.110">https://github.com/fish-shop/syntax-check/compare/v2.2.109...v2.2.110</a></p>
]]></content:encoded></item><item><title>shipready Quality Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/shipready-quality-gate/</link><pubDate>Mon, 13 Jul 2026 06:25:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/shipready-quality-gate/</guid><description>Version updated for https://github.com/formalness/shipready to version v1.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Complete secret scanner rewrite: Shannon entropy gate for generic credentials, high/medium confidence levels (errors vs warnings), automatic downgrade in test/fixture paths, 12 new providers (GitLab, DigitalOcean, Hugging Face, Shopify, Mailchimp, Airtable, Fly.io, Cloudflare, Heroku, Discord, webhook URLs, AWS secret keys), repeat/sequence filters, template detection, and bundle guard. 115 tests.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/formalness/shipready">https://github.com/formalness/shipready</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/shipready-quality-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Complete secret scanner rewrite: Shannon entropy gate for generic credentials, high/medium confidence levels (errors vs warnings), automatic downgrade in test/fixture paths, 12 new providers (GitLab, DigitalOcean, Hugging Face, Shopify, Mailchimp, Airtable, Fly.io, Cloudflare, Heroku, Discord, webhook URLs, AWS secret keys), repeat/sequence filters, template detection, and bundle guard. 115 tests.</p>
]]></content:encoded></item><item><title>forsakringskassan/eslint-config</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/forsakringskassan/eslint-config/</link><pubDate>Mon, 13 Jul 2026 06:25:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/forsakringskassan/eslint-config/</guid><description>Version updated for https://github.com/Forsakringskassan/eslint-config to version v15.3.5.
This action is used across all versions by 23 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 15.3.5 (2026-07-12) Bug Fixes deps: update dependency @vitest/eslint-plugin to v1.6.22 (#208) 2d1044d</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Forsakringskassan/eslint-config">https://github.com/Forsakringskassan/eslint-config</a></strong> to version <strong>v15.3.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>23</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/forsakringskassan-eslint-config">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1535-2026-07-12">15.3.5 (2026-07-12)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> update dependency @vitest/eslint-plugin to v1.6.22 (<a href="undefined/Forsakringskassan/eslint-config/issues/208">#208</a>) 2d1044d</li>
</ul>
]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/ai-plugin-scanner/</link><pubDate>Mon, 13 Jul 2026 06:24:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.463.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/58249800fa432261d8ac0afb7a06ab4ca85ebcb1 with plugin-scanner 2.0.1064.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.462...v1.2.463</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.463</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>18</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/58249800fa432261d8ac0afb7a06ab4ca85ebcb1">https://github.com/hashgraph-online/hol-guard/tree/58249800fa432261d8ac0afb7a06ab4ca85ebcb1</a> with plugin-scanner 2.0.1064.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.462...v1.2.463">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.462...v1.2.463</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/hol-codex-plugin-scanner/</link><pubDate>Mon, 13 Jul 2026 06:24:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.463.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.463</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.463</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.463">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.463</a></p>
]]></content:encoded></item><item><title>Gemini code review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/gemini-code-review/</link><pubDate>Mon, 13 Jul 2026 06:23:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/gemini-code-review/</guid><description>Version updated for https://github.com/jgunnink/gemini-review-bot to version v1.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s changed New instructions action input — extra review guidance can now be passed directly in the workflow under with:, mirroring how model works. It overrides the instructions key in .github/gemini-review.yml when both are set. (#8, fixes #7) No more hallucinated “this version doesn’t exist” findings — the prompt now forbids flagging version numbers, action tags, dependency versions, or model ids as nonexistent or outdated, since the model can’t verify them against current release info. (#8, fixes #7) Clearer configuration docs — the README now spells out the workflow-inputs vs config-file split (and the near-identical filenames one directory apart), with an inputs table. Note for existing setups If your workflow already had an instructions: key under with:, it was previously ignored with a warning — it now takes effect, and wins over the config file. That’s almost certainly what you intended, but if you have different values in both places, the workflow input is the one that applies.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jgunnink/gemini-review-bot">https://github.com/jgunnink/gemini-review-bot</a></strong> to version <strong>v1.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gemini-code-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s changed</h2>
<ul>
<li><strong>New <code>instructions</code> action input</strong> — extra review guidance can now be passed directly in the workflow under <code>with:</code>, mirroring how <code>model</code> works. It overrides the <code>instructions</code> key in <code>.github/gemini-review.yml</code> when both are set. (#8, fixes #7)</li>
<li><strong>No more hallucinated &ldquo;this version doesn&rsquo;t exist&rdquo; findings</strong> — the prompt now forbids flagging version numbers, action tags, dependency versions, or model ids as nonexistent or outdated, since the model can&rsquo;t verify them against current release info. (#8, fixes #7)</li>
<li><strong>Clearer configuration docs</strong> — the README now spells out the workflow-inputs vs config-file split (and the near-identical filenames one directory apart), with an inputs table.</li>
</ul>
<h2 id="note-for-existing-setups">Note for existing setups</h2>
<p>If your workflow already had an <code>instructions:</code> key under <code>with:</code>, it was previously ignored with a warning — it now takes effect, and wins over the config file. That&rsquo;s almost certainly what you intended, but if you have different values in both places, the workflow input is the one that applies.</p>
]]></content:encoded></item><item><title>auto-issue-review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/auto-issue-review/</link><pubDate>Mon, 13 Jul 2026 06:23:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/auto-issue-review/</guid><description>Version updated for https://github.com/kldhsh123/auto-issue-review to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/kldhsh123/auto-issue-review/compare/v0.1.0...v0.1.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kldhsh123/auto-issue-review">https://github.com/kldhsh123/auto-issue-review</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/auto-issue-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/kldhsh123/auto-issue-review/compare/v0.1.0...v0.1.1">https://github.com/kldhsh123/auto-issue-review/compare/v0.1.0...v0.1.1</a></p>
]]></content:encoded></item><item><title>cargo-rail</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/cargo-rail/</link><pubDate>Mon, 13 Jul 2026 06:22:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/cargo-rail/</guid><description>Version updated for https://github.com/loadingalias/cargo-rail-action to version v5.1.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/loadingalias/cargo-rail-action/compare/v5.0.0...v5.1.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/loadingalias/cargo-rail-action">https://github.com/loadingalias/cargo-rail-action</a></strong> to version <strong>v5.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cargo-rail">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/loadingalias/cargo-rail-action/compare/v5.0.0...v5.1.0">https://github.com/loadingalias/cargo-rail-action/compare/v5.0.0...v5.1.0</a></p>
]]></content:encoded></item><item><title>LumaTrack Report Run</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/lumatrack-report-run/</link><pubDate>Mon, 13 Jul 2026 06:22:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/lumatrack-report-run/</guid><description>Version updated for https://github.com/LumaTrack/report-run to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed This action reports a workflow run to LumaTrack (https://lumatrack.io) so you can track what your CI/CD automation actually saves you. I built LumaTrack because every automation tool grades its own homework; this is the neutral ledger version, where failures count against you and every number can be traced back to the runs that produced it.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/LumaTrack/report-run">https://github.com/LumaTrack/report-run</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lumatrack-report-run">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This action reports a workflow run to LumaTrack (<a href="https://lumatrack.io">https://lumatrack.io</a>) so you can track what your CI/CD automation actually saves you. I built LumaTrack because every automation tool grades its own homework; this is the neutral ledger version, where failures count against you and every number can be traced back to the runs that produced it.</p>
<pre tabindex="0"><code>- name: Report run to LumaTrack
  if: always()
  uses: LumaTrack/report-run@v1
  with:
    base-url: ${{ vars.LUMATRACK_URL }}
    api-key: ${{ secrets.LUMATRACK_KEY }}
    automation: deploy-pipeline
    status: ${{ job.status }}
</code></pre><p>Use <code>if: always()</code> so failures get reported too. Failed runs cost money and save nothing, and pretending they didn&rsquo;t happen is how these numbers stop being believable.</p>
<p>A few implementation details:</p>
<ul>
<li>You can pass <code>${{ job.status }}</code> directly. <code>cancelled</code> and <code>skipped</code> get recorded as failures with the reason kept, since a run that didn&rsquo;t finish didn&rsquo;t do the work.</li>
<li>Reporting is idempotent. The external id defaults to run id + attempt, so retrying a step won&rsquo;t double-count.</li>
<li>By default the action won&rsquo;t fail your job if LumaTrack is unreachable. It warns and moves on. Set <code>fail-on-error: true</code> if you want it strict.</li>
<li>There&rsquo;s also <code>units</code> (for batch jobs valued per item), <code>duration-seconds</code>, <code>failure-reason</code>, and a <code>metadata</code> JSON field.</li>
</ul>
<p>Needs a LumaTrack workspace (free tier is fine) and an API key.</p>
]]></content:encoded></item><item><title>Jira Release Link</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/jira-release-link/</link><pubDate>Mon, 13 Jul 2026 06:21:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/jira-release-link/</guid><description>Version updated for https://github.com/mantasmatij/jira-release-link to version v3.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat!: node24 and other upgrades across the board by @skirsdeda in https://github.com/mantasmatij/jira-release-link/pull/2 New Contributors @skirsdeda made their first contribution in https://github.com/mantasmatij/jira-release-link/pull/2 Full Changelog: https://github.com/mantasmatij/jira-release-link/compare/2...v3.0.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mantasmatij/jira-release-link">https://github.com/mantasmatij/jira-release-link</a></strong> to version <strong>v3.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jira-release-link">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat!: node24 and other upgrades across the board by @skirsdeda in <a href="https://github.com/mantasmatij/jira-release-link/pull/2">https://github.com/mantasmatij/jira-release-link/pull/2</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@skirsdeda made their first contribution in <a href="https://github.com/mantasmatij/jira-release-link/pull/2">https://github.com/mantasmatij/jira-release-link/pull/2</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mantasmatij/jira-release-link/compare/2...v3.0.0">https://github.com/mantasmatij/jira-release-link/compare/2...v3.0.0</a></p>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/totem-shield/</link><pubDate>Mon, 13 Jul 2026 06:20:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.94.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Cohort-link bump (no direct package changes). See .changeset/config.json for the fixed-cohort definition.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.94.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/go-proxy-cache-updater/</link><pubDate>Mon, 13 Jul 2026 06:20:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.20.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.1.20 (2026-07-13)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.20</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1120-2026-07-13"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.19...v1.1.20">1.1.20</a> (2026-07-13)</h2>
]]></content:encoded></item><item><title>PixelVault — Upload Screenshots</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/pixelvault-upload-screenshots/</link><pubDate>Mon, 13 Jul 2026 06:19:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/pixelvault-upload-screenshots/</guid><description>Version updated for https://github.com/pixelvault-dev/screenshots-action to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First release of the PixelVault Upload Screenshots GitHub Action.
Host CI screenshots (visual-regression diffs, Playwright/Cypress failures) on PixelVault and drop them into the pull request — no more digging through zip artifacts.
- uses: pixelvault-dev/screenshots-action@v1 if: failure() with: api-key: ${{ secrets.PIXELVAULT_API_KEY }} path: test-results pattern: &amp;#34;*-diff.png&amp;#34; visibility: private Globs screenshots → uploads into one PixelVault collection via POST /v1/images/batch (chunked, idempotent by collection-name). Private by default → signed URLs; posts a sticky PR comment with a diff table. Zero runtime dependencies (runner Node built-ins only). Reference @v1 for the moving major tag, or @v0.1.0 to pin.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pixelvault-dev/screenshots-action">https://github.com/pixelvault-dev/screenshots-action</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pixelvault-upload-screenshots">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release of the PixelVault <strong>Upload Screenshots</strong> GitHub Action.</p>
<p>Host CI screenshots (visual-regression diffs, Playwright/Cypress failures) on PixelVault and drop them into the pull request — no more digging through zip artifacts.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">pixelvault-dev/screenshots-action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">if</span>: <span style="color:#ae81ff">failure()</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.PIXELVAULT_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">path</span>: <span style="color:#ae81ff">test-results</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">pattern</span>: <span style="color:#e6db74">&#34;*-diff.png&#34;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">visibility</span>: <span style="color:#ae81ff">private</span>
</span></span></code></pre></div><ul>
<li>Globs screenshots → uploads into one PixelVault <strong>collection</strong> via <code>POST /v1/images/batch</code> (chunked, idempotent by <code>collection-name</code>).</li>
<li>Private by default → signed URLs; posts a <strong>sticky PR comment</strong> with a diff table.</li>
<li>Zero runtime dependencies (runner Node built-ins only).</li>
</ul>
<p>Reference <code>@v1</code> for the moving major tag, or <code>@v0.1.0</code> to pin.</p>
]]></content:encoded></item><item><title>Multi-Style Contribution Snake</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/multi-style-contribution-snake/</link><pubDate>Mon, 13 Jul 2026 06:19:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/multi-style-contribution-snake/</guid><description>Version updated for https://github.com/Pro-Bandey/multi-style-snake-contribution-grid to version v13.07.26.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 🐍 Multi-Style Snake Daily Update Automated daily release to the GitHub Marketplace.
Version Details:
Tag: v13.07.26 Release Date: $(date +’%A, %B %d, 20%y&amp;#39;) Included Features:
5 Unique Snake Styles (Blocks, Rounds, Triangles, Stars, Diamonds) Automated Month Labels above grids Dynamic Username Detection Auto-generated Asset Gallery</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Pro-Bandey/multi-style-snake-contribution-grid">https://github.com/Pro-Bandey/multi-style-snake-contribution-grid</a></strong> to version <strong>v13.07.26</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/multi-style-contribution-snake">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-multi-style-snake-daily-update">🐍 Multi-Style Snake Daily Update</h2>
<p>Automated daily release to the GitHub Marketplace.</p>
<p><strong>Version Details:</strong></p>
<ul>
<li><strong>Tag:</strong> <code>v13.07.26</code></li>
<li><strong>Release Date:</strong> $(date +&rsquo;%A, %B %d, 20%y')</li>
</ul>
<p><strong>Included Features:</strong></p>
<ul>
<li>5 Unique Snake Styles (Blocks, Rounds, Triangles, Stars, Diamonds)</li>
<li>Automated Month Labels above grids</li>
<li>Dynamic Username Detection</li>
<li>Auto-generated Asset Gallery</li>
</ul>
]]></content:encoded></item><item><title>Remyx Outrider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/remyx-outrider/</link><pubDate>Mon, 13 Jul 2026 06:18:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/remyx-outrider/</guid><description>Version updated for https://github.com/remyxai/outrider to version v1.7.20.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fix Pre-PR fidelity gate’s remediation pass now inherits the coding session’s self_review mode context. Under v1.7.19 and earlier, the remediation pass (after _attempt_pre_pr_fidelity_patch applied edits) called _run_pre_pr_fidelity_check without self_review, silently defaulting to Mode 1 with no substitutions or scope-outs. Any Mode-2 refinement that triggered the fidelity gate on the first pass then had its documented substitutions wrongly re-flagged as fabrication on the second pass — hard-to-shift outcome for legitimate Mode-2 diffs.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remyxai/outrider">https://github.com/remyxai/outrider</a></strong> to version <strong>v1.7.20</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/remyx-outrider">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="fix">Fix</h2>
<p><strong>Pre-PR fidelity gate&rsquo;s remediation pass now inherits the coding session&rsquo;s <code>self_review</code> mode context.</strong> Under v1.7.19 and earlier, the remediation pass (after <code>_attempt_pre_pr_fidelity_patch</code> applied edits) called <code>_run_pre_pr_fidelity_check</code> without <code>self_review</code>, silently defaulting to Mode 1 with no substitutions or scope-outs. Any Mode-2 refinement that triggered the fidelity gate on the first pass then had its documented substitutions wrongly re-flagged as fabrication on the second pass — hard-to-shift outcome for legitimate Mode-2 diffs.</p>
<p>Same architectural pattern as v1.7.17&rsquo;s integration-check test-file exemption: coding sessions have grown mode / substitution / scope-out semantics; downstream chain gates need to inherit that context.</p>
<h3 id="evidence">Evidence</h3>
<p>Surfaced on the v1.7.19 E2E validation run against <code>smellslikeml/atropos</code> (RLMF, arxiv:2606.32032v1). The coding session declared Mode 2 with 2 substitutions + 4 scope-outs, all architecturally justified (paper&rsquo;s trainer-level GRPO advantage-scaling → reward-level group shaping; paper&rsquo;s LLM self-judge → optional <code>&lt;meta_confidence&gt;</code> XML tag with graceful degradation). First fidelity check: <code>mode-2, subs=2, scoped_out=4</code> → 14 items needs-judgment. Patch attempt applied edits. Second fidelity check: <code>mode-1, subs=0, scoped_out=0</code> → 10 items still flagged. Run correctly routed to <code>skipped_fidelity_fabrication_after_patch</code>, but for the wrong reason: the coding session&rsquo;s self_review still cited Mode 2 with the same substitutions at end-of-run — only the fidelity gate switched check contexts.</p>
<h3 id="fix-1">Fix</h3>
<p>Pass <code>self_review=review</code> to the remediation-pass <code>_run_pre_pr_fidelity_check</code> call in <code>process_target</code>, matching the first-pass kwargs verbatim. One-line change; ships with a source-code regression test guarding both invocation sites against future refactors dropping the kwarg.</p>
<h2 id="tests">Tests</h2>
<p>929 tests pass. New:</p>
<ul>
<li><code>test_classify_mode_cited_defaults_to_none_on_missing_self_review</code> — documents the bug&rsquo;s blast radius</li>
<li><code>test_classify_mode_cited_reads_mode_2_from_self_review</code> — Mode-2 correctly detected when self_review present</li>
<li><code>test_process_target_source_passes_self_review_to_both_fidelity_calls</code> — source-code check asserting both invocation sites pass <code>self_review=</code></li>
</ul>
<h2 id="migration">Migration</h2>
<p><strong>No action required</strong> — backward-compatible one-line change. All existing dispatches benefit immediately.</p>
]]></content:encoded></item><item><title>Commit Health Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/commit-health-gate/</link><pubDate>Mon, 13 Jul 2026 06:18:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/commit-health-gate/</guid><description>Version updated for https://github.com/rw-core/commit-health-gate to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Rolling release; tracks the latest v1.x. Pin to v1.0.0 for immutability.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rw-core/commit-health-gate">https://github.com/rw-core/commit-health-gate</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/commit-health-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Rolling release; tracks the latest v1.x. Pin to v1.0.0 for immutability.</p>
]]></content:encoded></item><item><title>Validate Syscribe Model</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/validate-syscribe-model/</link><pubDate>Mon, 13 Jul 2026 06:17:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/validate-syscribe-model/</guid><description>Version updated for https://github.com/sjames/syscribe to version v0.31.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: suspect-link detection via content baselines by @sjames in https://github.com/sjames/syscribe/pull/85 feat: release baselines — frozen, git-anchored release snapshots by @sjames in https://github.com/sjames/syscribe/pull/86 Full Changelog: https://github.com/sjames/syscribe/compare/v0...v0.31.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sjames/syscribe">https://github.com/sjames/syscribe</a></strong> to version <strong>v0.31.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/validate-syscribe-model">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: suspect-link detection via content baselines by @sjames in <a href="https://github.com/sjames/syscribe/pull/85">https://github.com/sjames/syscribe/pull/85</a></li>
<li>feat: release baselines — frozen, git-anchored release snapshots by @sjames in <a href="https://github.com/sjames/syscribe/pull/86">https://github.com/sjames/syscribe/pull/86</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sjames/syscribe/compare/v0...v0.31.0">https://github.com/sjames/syscribe/compare/v0...v0.31.0</a></p>
]]></content:encoded></item><item><title>spek - OpenSpec Static Site</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/spek-openspec-static-site/</link><pubDate>Mon, 13 Jul 2026 06:17:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/spek-openspec-static-site/</guid><description>Version updated for https://github.com/spekhq/spek to version v1.6.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed TOC navigation lands on the section you clicked — clicking a table-of-contents entry, or opening a #hash deep link, on a Change or Spec detail page no longer scrolls the target heading behind the sticky header, which made it look like the click had jumped one section too far. The offset is now measured from the header that is actually rendered instead of an assumed 80px, and the entry you clicked is the one the TOC highlights. Schema badge under worktree aggregation — when changes are aggregated across worktrees, each change’s schema is now compared against the default schema of the worktree it actually lives in, rather than the main worktree’s. A change that uses its own worktree’s default no longer shows a badge, and the list and detail views agree on this. Scanning also reads each worktree’s openspec/config.yaml once instead of once per change. Thanks to @nthansen (Norman Hansen) for both.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spekhq/spek">https://github.com/spekhq/spek</a></strong> to version <strong>v1.6.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spek-openspec-static-site">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li><strong>TOC navigation lands on the section you clicked</strong> — clicking a table-of-contents entry, or opening a <code>#hash</code> deep link, on a Change or Spec detail page no longer scrolls the target heading behind the sticky header, which made it look like the click had jumped one section too far. The offset is now measured from the header that is actually rendered instead of an assumed 80px, and the entry you clicked is the one the TOC highlights.</li>
<li><strong>Schema badge under worktree aggregation</strong> — when changes are aggregated across worktrees, each change&rsquo;s schema is now compared against the default schema of the worktree it actually lives in, rather than the main worktree&rsquo;s. A change that uses its own worktree&rsquo;s default no longer shows a badge, and the list and detail views agree on this. Scanning also reads each worktree&rsquo;s <code>openspec/config.yaml</code> once instead of once per change.</li>
</ul>
<p>Thanks to <a href="https://github.com/nthansen">@nthansen</a> (Norman Hansen) for both.</p>
]]></content:encoded></item><item><title>Podcast Generator By Abuzar</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/podcast-generator-by-abuzar/</link><pubDate>Mon, 13 Jul 2026 06:16:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/podcast-generator-by-abuzar/</guid><description>Version updated for https://github.com/syedabuzar/podcast-generator to version V1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/syedabuzar/podcast-generator/commits/V1.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/syedabuzar/podcast-generator">https://github.com/syedabuzar/podcast-generator</a></strong> to version <strong>V1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/podcast-generator-by-abuzar">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/syedabuzar/podcast-generator/commits/V1.0">https://github.com/syedabuzar/podcast-generator/commits/V1.0</a></p>
]]></content:encoded></item><item><title>Install komac</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/install-komac/</link><pubDate>Mon, 13 Jul 2026 06:15:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/install-komac/</guid><description>Version updated for https://github.com/UnownPlain/install-komac to version 1.4.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog Fetch latest version from repository variable Full Changelog: https://github.com/UnownPlain/install-komac/compare/1.3...1.4</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/UnownPlain/install-komac">https://github.com/UnownPlain/install-komac</a></strong> to version <strong>1.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-komac">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>Fetch latest version from repository variable</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/UnownPlain/install-komac/compare/1.3...1.4">https://github.com/UnownPlain/install-komac/compare/1.3...1.4</a></p>
]]></content:encoded></item><item><title>Setup Vamposer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/setup-vamposer/</link><pubDate>Mon, 13 Jul 2026 06:15:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/setup-vamposer/</guid><description>Version updated for https://github.com/ValaFoundation/vamposer to version v0.7.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changes From v0.7.0 to v0.7.1:
[Update] meson version 0.7.1 with support github action (8ec8783) by @JanGalek [Add] example vamposer install to github action (9f72f70) by @JanGalek fixup! [Add] github action (d69d1e0) by @JanGalek fixup! [Add] github action (6ba06c3) by @JanGalek [Update] checkout action version in README example (bf7b552) by @JanGalek [Add] github action (7a4013c) by @JanGalek Full Changelog: https://github.com/ValaFoundation/vamposer/compare/v0.7.0...v0.7.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ValaFoundation/vamposer">https://github.com/ValaFoundation/vamposer</a></strong> to version <strong>v0.7.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-vamposer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changes">Changes</h2>
<p>From v0.7.0 to v0.7.1:</p>
<ul>
<li>[Update] meson version 0.7.1 with support github action (8ec8783) by @JanGalek</li>
<li>[Add] example vamposer install to github action (9f72f70) by @JanGalek</li>
<li>fixup! [Add] github action (d69d1e0) by @JanGalek</li>
<li>fixup! [Add] github action (6ba06c3) by @JanGalek</li>
<li>[Update] checkout action version in README example (bf7b552) by @JanGalek</li>
<li>[Add] github action (7a4013c) by @JanGalek</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ValaFoundation/vamposer/compare/v0.7.0...v0.7.1">https://github.com/ValaFoundation/vamposer/compare/v0.7.0...v0.7.1</a></p>
]]></content:encoded></item><item><title>Symfony Security Auditor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/symfony-security-auditor/</link><pubDate>Mon, 13 Jul 2026 06:14:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/symfony-security-auditor/</guid><description>Version updated for https://github.com/vinceAmstoutz/symfony-security-auditor to version 1.13.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps): bump codecov/codecov-action from 5 to 7 by @dependabot in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/82 chore(deps): bump actions/cache from 5 to 6 by @dependabot in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/83 chore(deps-dev): update ergebnis/phpunit-agent-reporter requirement from ^0.3 to ^1.0 by @dependabot in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/79 ci: drop run-cancelling concurrency by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/84 ci: fix unset secret blocking mutation report by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/85 feat(command): add show-scanned option to audit:run by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/87 feat(infrastructure): source LLM pricing from symfony/models-dev catalog by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/89 ci: tighten PHPStan with stricter opt-in checks by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/92 fix(tests): drop redundant always-false coverage guard by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/94 feat(config): support when env blocks in the config schema by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/93 docs(config): use schema for editor completion by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/95 feat: add standalone executable by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/91 docs(examples): drop prompt_caching from examples by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/96 docs(extending): remaining domain ports by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/97 feat(domain): map vulnerabilities to OWASP Top 10:2025 by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/98 chore(ci): release:bump task and tag-push pin guard by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/101 feat(scan): detect committed secrets in root dotenv files by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/99 feat(pipeline): parse instead of regexes by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/104 feat(command): add junit output format by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/100 feat(scan): support API Platform by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/105 feat(pipeline): skip baselined findings before review by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/103 feat(scan): support Symfony UX Live Components by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/106 refactor(prompt): split prompt builders by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/107 fix(scan): stop –since from dropping changed dotfiles by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/108 fix(scan): match DOTALL pre-scan patterns across lines by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/109 feat(scan): detect file-upload vulnerabilities as a dedicated attacker skill by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/118 refactor(domain): extract ProjectFile type classification by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/121 fix(report): strip xml-illegal from junit output by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/110 feat(report): add GitHub Actions annotations output format by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/122 refactor(agent): extract shared structured-collection wiring for chunk/review analyzers by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/124 refactor(pipeline): make DI port defaults non-nullable by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/125 feat(domain): add CWE alongside OWASP mapping by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/127 fix(llm): match status codes as tokens in transient failure classifier by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/111 fix: retry concurrent tool conversations by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/120 fix(scan): redact unquoted secret values in inline config assignments by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/112 fix(rate-limit): reconcile each concurrent acquire against its own estimate by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/113 fix(cache): invalidate attacker cache when code-slicing configuration changes by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/114 fix(llm): clamp the rate limiter’s Retry-After pause by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/115 fix(scan): flag non-constant-time signature by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/116 fix(bundle): repair stale escalation attacker wiring by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/117 feat(scan): support Twig extensions by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/119 feat(report): mark baselined findings as suppressed in SARIF output by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/123 feat(command): add audit:diff to compare reports by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/126 test: close mutation-coverage gaps by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/128 test: raise slow-test threshold for bundle boot test to match observed duration by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/129 refactor(command): remove dead code by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/130 fix: harden audit pipeline and correct CWE/OWASP by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/131 chore(deps): bump actions/checkout from 4 to 7 by @dependabot in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/132 chore(deps): bump DavidAnson/markdownlint-cli2-action from 23 to 24 by @dependabot in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/133 fix: batch of audit-loop hardening fixes by @vinceAmstoutz in https://github.com/vinceAmstoutz/symfony-security-auditor/pull/134 Full Changelog: https://github.com/vinceAmstoutz/symfony-security-auditor/compare/1.12.0...1.13.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vinceAmstoutz/symfony-security-auditor">https://github.com/vinceAmstoutz/symfony-security-auditor</a></strong> to version <strong>1.13.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/symfony-security-auditor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): bump codecov/codecov-action from 5 to 7 by @dependabot in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/82">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/82</a></li>
<li>chore(deps): bump actions/cache from 5 to 6 by @dependabot in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/83">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/83</a></li>
<li>chore(deps-dev): update ergebnis/phpunit-agent-reporter requirement from ^0.3 to ^1.0 by @dependabot in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/79">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/79</a></li>
<li>ci: drop run-cancelling concurrency by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/84">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/84</a></li>
<li>ci: fix unset secret blocking mutation report by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/85">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/85</a></li>
<li>feat(command): add show-scanned option to audit:run by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/87">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/87</a></li>
<li>feat(infrastructure): source LLM pricing from symfony/models-dev catalog by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/89">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/89</a></li>
<li>ci: tighten PHPStan with stricter opt-in checks by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/92">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/92</a></li>
<li>fix(tests): drop redundant always-false coverage guard by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/94">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/94</a></li>
<li>feat(config): support when env blocks in the config schema by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/93">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/93</a></li>
<li>docs(config): use schema for editor completion by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/95">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/95</a></li>
<li>feat: add standalone executable by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/91">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/91</a></li>
<li>docs(examples): drop prompt_caching from examples by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/96">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/96</a></li>
<li>docs(extending): remaining domain ports by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/97">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/97</a></li>
<li>feat(domain): map vulnerabilities to OWASP Top 10:2025 by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/98">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/98</a></li>
<li>chore(ci): release:bump task and tag-push pin guard by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/101">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/101</a></li>
<li>feat(scan): detect committed secrets in root dotenv files by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/99">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/99</a></li>
<li>feat(pipeline): parse instead of regexes by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/104">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/104</a></li>
<li>feat(command): add junit output format by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/100">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/100</a></li>
<li>feat(scan): support API Platform by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/105">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/105</a></li>
<li>feat(pipeline): skip baselined findings before review by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/103">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/103</a></li>
<li>feat(scan): support Symfony UX Live Components by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/106">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/106</a></li>
<li>refactor(prompt): split prompt builders by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/107">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/107</a></li>
<li>fix(scan): stop &ndash;since from dropping changed dotfiles by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/108">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/108</a></li>
<li>fix(scan): match DOTALL pre-scan patterns across lines by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/109">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/109</a></li>
<li>feat(scan): detect file-upload vulnerabilities as a dedicated attacker skill by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/118">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/118</a></li>
<li>refactor(domain): extract ProjectFile type classification by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/121">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/121</a></li>
<li>fix(report): strip xml-illegal from junit output by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/110">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/110</a></li>
<li>feat(report): add GitHub Actions annotations output format by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/122">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/122</a></li>
<li>refactor(agent): extract shared structured-collection wiring for chunk/review analyzers by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/124">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/124</a></li>
<li>refactor(pipeline): make DI port defaults non-nullable by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/125">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/125</a></li>
<li>feat(domain): add CWE alongside OWASP mapping by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/127">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/127</a></li>
<li>fix(llm): match status codes as tokens in transient failure classifier by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/111">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/111</a></li>
<li>fix: retry concurrent tool conversations by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/120">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/120</a></li>
<li>fix(scan): redact unquoted secret values in inline config assignments by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/112">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/112</a></li>
<li>fix(rate-limit): reconcile each concurrent acquire against its own estimate by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/113">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/113</a></li>
<li>fix(cache): invalidate attacker cache when code-slicing configuration changes by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/114">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/114</a></li>
<li>fix(llm): clamp the rate limiter&rsquo;s Retry-After pause by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/115">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/115</a></li>
<li>fix(scan): flag non-constant-time signature by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/116">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/116</a></li>
<li>fix(bundle): repair stale escalation attacker wiring by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/117">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/117</a></li>
<li>feat(scan): support Twig extensions by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/119">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/119</a></li>
<li>feat(report): mark baselined findings as suppressed in SARIF output by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/123">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/123</a></li>
<li>feat(command): add audit:diff to compare reports by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/126">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/126</a></li>
<li>test: close mutation-coverage gaps by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/128">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/128</a></li>
<li>test: raise slow-test threshold for bundle boot test to match observed duration by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/129">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/129</a></li>
<li>refactor(command): remove dead code by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/130">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/130</a></li>
<li>fix: harden audit pipeline and correct CWE/OWASP by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/131">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/131</a></li>
<li>chore(deps): bump actions/checkout from 4 to 7 by @dependabot in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/132">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/132</a></li>
<li>chore(deps): bump DavidAnson/markdownlint-cli2-action from 23 to 24 by @dependabot in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/133">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/133</a></li>
<li>fix: batch of audit-loop hardening fixes by @vinceAmstoutz in <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/pull/134">https://github.com/vinceAmstoutz/symfony-security-auditor/pull/134</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vinceAmstoutz/symfony-security-auditor/compare/1.12.0...1.13.0">https://github.com/vinceAmstoutz/symfony-security-auditor/compare/1.12.0...1.13.0</a></p>
]]></content:encoded></item><item><title>a2a-lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/a2a-lint/</link><pubDate>Mon, 13 Jul 2026 06:14:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/a2a-lint/</guid><description>Version updated for https://github.com/vivek24290/a2a-lint to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First public release of a2a-lint — conformance tooling for A2A protocol agents. (Supersedes v1.1.0, whose publish pipeline was misconfigured.)
Highlights CLI: a2a-lint &amp;lt;agent-url&amp;gt; --live — validates the agent card against the spec and performs live message/send (and, when the card declares streaming, message/stream SSE) round trips. CI-friendly exit codes: 0 conformant / 1 findings / 2 unreachable. GitHub Action: uses: vivek24290/a2a-lint@v1.1.1 — conformance checks on every push. Playground (Docker): inspect, grade and talk to any A2A agent interactively; shareable permalinks; SSE stream viewer; live conformance badge endpoint. a2a-watch monitor (MVP): register deployed agents, scheduled probes with uptime history, webhook alerts on down/recovered. Install pip install a2a-lint or run the playground: docker compose up --build -d → http://localhost:8090</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vivek24290/a2a-lint">https://github.com/vivek24290/a2a-lint</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/a2a-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release of <strong>a2a-lint</strong> — conformance tooling for <a href="https://a2a-protocol.org">A2A protocol</a> agents. (Supersedes v1.1.0, whose publish pipeline was misconfigured.)</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>CLI</strong>: <code>a2a-lint &lt;agent-url&gt; --live</code> — validates the agent card against the spec and performs live <code>message/send</code> (and, when the card declares streaming, <code>message/stream</code> SSE) round trips. CI-friendly exit codes: 0 conformant / 1 findings / 2 unreachable.</li>
<li><strong>GitHub Action</strong>: <code>uses: vivek24290/a2a-lint@v1.1.1</code> — conformance checks on every push.</li>
<li><strong>Playground</strong> (Docker): inspect, grade and talk to any A2A agent interactively; shareable permalinks; SSE stream viewer; live conformance badge endpoint.</li>
<li><strong>a2a-watch monitor (MVP)</strong>: register deployed agents, scheduled probes with uptime history, webhook alerts on down/recovered.</li>
</ul>
<h2 id="install">Install</h2>
<pre tabindex="0"><code>pip install a2a-lint
</code></pre><p>or run the playground: <code>docker compose up --build -d</code> → http://localhost:8090</p>
]]></content:encoded></item><item><title>PromptShield AI Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/promptshield-ai-security/</link><pubDate>Mon, 13 Jul 2026 06:13:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/promptshield-ai-security/</guid><description>Version updated for https://github.com/Zero-Harm-AI-LLC/promptshield to version v1.0.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed PromptShield AI Security v1.0.6 This release adds optional AI-mode support for zero-harm-ai-detectors while preserving the current default heuristic behavior.
What’s new added ai-mode input to the GitHub Action added --ai-mode flag to the CLI PromptShield now enables AI mode by constructing AIConfig() for zero-harm-ai-detectors when requested default behavior remains unchanged: if ai-mode is not enabled, PromptShield continues to use heuristic mode improved compatibility so existing detector integrations and tests continue to work in default mode Usage GitHub Action:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Zero-Harm-AI-LLC/promptshield">https://github.com/Zero-Harm-AI-LLC/promptshield</a></strong> to version <strong>v1.0.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/promptshield-ai-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="promptshield-ai-security-v106">PromptShield AI Security v1.0.6</h2>
<p>This release adds optional AI-mode support for <code>zero-harm-ai-detectors</code> while preserving the current default heuristic behavior.</p>
<h3 id="whats-new">What’s new</h3>
<ul>
<li>added <code>ai-mode</code> input to the GitHub Action</li>
<li>added <code>--ai-mode</code> flag to the CLI</li>
<li>PromptShield now enables AI mode by constructing <code>AIConfig()</code> for <code>zero-harm-ai-detectors</code> when requested</li>
<li>default behavior remains unchanged: if <code>ai-mode</code> is not enabled, PromptShield continues to use heuristic mode</li>
<li>improved compatibility so existing detector integrations and tests continue to work in default mode</li>
</ul>
<h3 id="usage">Usage</h3>
<p>GitHub Action:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Zero-Harm-AI-LLC/promptshield@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">ai-mode</span>: <span style="color:#66d9ef">true</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Livvie Code Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/livvie-code-review/</link><pubDate>Mon, 13 Jul 2026 00:15:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/livvie-code-review/</guid><description>Version updated for https://github.com/4itworks/livvie_code_review to version v2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2 Release Retry empty LLM response bodies; classify retries by HTTP status Stop truncating large patches; skip oversized diffs to preserve line mapping Track failed file fetches and exclude from review Reject files exceeding per-file token budget instead of overflowing batches Remove outer pipeline concurrency wrapper to avoid double-gating Track failed batches separately and build rawFindings only from successes Add string-literal-aware JSON repair and stricter finding validation Half-open circuit breaker single-flight probe Template-literal handling in suggestion balance check Cross-file context truncation with marker token reservation Add configurable inputs: cross-file-budget, safety-margin, circuit-breaker-threshold Require node &amp;gt;=24</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/4itworks/livvie_code_review">https://github.com/4itworks/livvie_code_review</a></strong> to version <strong>v2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/livvie-code-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v2-release">v2 Release</h2>
<ul>
<li>Retry empty LLM response bodies; classify retries by HTTP status</li>
<li>Stop truncating large patches; skip oversized diffs to preserve line mapping</li>
<li>Track failed file fetches and exclude from review</li>
<li>Reject files exceeding per-file token budget instead of overflowing batches</li>
<li>Remove outer pipeline concurrency wrapper to avoid double-gating</li>
<li>Track failed batches separately and build rawFindings only from successes</li>
<li>Add string-literal-aware JSON repair and stricter finding validation</li>
<li>Half-open circuit breaker single-flight probe</li>
<li>Template-literal handling in suggestion balance check</li>
<li>Cross-file context truncation with marker token reservation</li>
<li>Add configurable inputs: cross-file-budget, safety-margin, circuit-breaker-threshold</li>
<li>Require node &gt;=24</li>
</ul>
]]></content:encoded></item><item><title>Data Hogo Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/data-hogo-security-scan/</link><pubDate>Mon, 13 Jul 2026 00:15:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/data-hogo-security-scan/</guid><description>Version updated for https://github.com/datahogo/datahogo to version v0.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First public release of the Data Hogo GitHub Action.
Runs the open-source Data Hogo security scanner on your repository in CI — 300+ checks across JS/TS, Python, Go, Java, PHP, C#, mobile, and Supabase. Everything runs locally in your runner; nothing is uploaded. Findings are uploaded to your repository’s Security tab as SARIF.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/datahogo/datahogo">https://github.com/datahogo/datahogo</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/data-hogo-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release of the Data Hogo GitHub Action.</p>
<p>Runs the open-source Data Hogo security scanner on your repository in CI —
300+ checks across JS/TS, Python, Go, Java, PHP, C#, mobile, and Supabase.
Everything runs locally in your runner; nothing is uploaded. Findings are
uploaded to your repository&rsquo;s Security tab as SARIF.</p>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">datahogo/datahogo@v0.1.0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>mcpfold config gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/mcpfold-config-gate/</link><pubDate>Mon, 13 Jul 2026 00:14:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/mcpfold-config-gate/</guid><description>Version updated for https://github.com/dj-pearson/MCPFold to version v1.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix(ci): resolve env-drift, docs link, and formatting failures by @dj-pearson in https://github.com/dj-pearson/MCPFold/pull/42 Benchmark: add exact per-model token counts + VS Code extension dev harness by @dj-pearson in https://github.com/dj-pearson/MCPFold/pull/43 Add E22 code-review findings epic to prd.json by @dj-pearson in https://github.com/dj-pearson/MCPFold/pull/44 fix(secrets): pass win32 keychain target out-of-band to kill PowerShell injection (S22.1) by @dj-pearson in https://github.com/dj-pearson/MCPFold/pull/45 feat(cli): terminal color + info/update management commands by @dj-pearson in https://github.com/dj-pearson/MCPFold/pull/46 feat(cli): terminal color + info/update management commands by @dj-pearson in https://github.com/dj-pearson/MCPFold/pull/47 fix(cli): adopt untouched init scaffold on import; add test --timeout by @dj-pearson in https://github.com/dj-pearson/MCPFold/pull/48 docs: add VS Code Marketplace badge to README by @dj-pearson in https://github.com/dj-pearson/MCPFold/pull/49 Version Packages by @github-actions[bot] in https://github.com/dj-pearson/MCPFold/pull/41 Full Changelog: https://github.com/dj-pearson/MCPFold/compare/v1.0.2...v1.1.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/dj-pearson/MCPFold">https://github.com/dj-pearson/MCPFold</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcpfold-config-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(ci): resolve env-drift, docs link, and formatting failures by @dj-pearson in <a href="https://github.com/dj-pearson/MCPFold/pull/42">https://github.com/dj-pearson/MCPFold/pull/42</a></li>
<li>Benchmark: add exact per-model token counts + VS Code extension dev harness by @dj-pearson in <a href="https://github.com/dj-pearson/MCPFold/pull/43">https://github.com/dj-pearson/MCPFold/pull/43</a></li>
<li>Add E22 code-review findings epic to prd.json by @dj-pearson in <a href="https://github.com/dj-pearson/MCPFold/pull/44">https://github.com/dj-pearson/MCPFold/pull/44</a></li>
<li>fix(secrets): pass win32 keychain target out-of-band to kill PowerShell injection (S22.1) by @dj-pearson in <a href="https://github.com/dj-pearson/MCPFold/pull/45">https://github.com/dj-pearson/MCPFold/pull/45</a></li>
<li>feat(cli): terminal color + <code>info</code>/<code>update</code> management commands by @dj-pearson in <a href="https://github.com/dj-pearson/MCPFold/pull/46">https://github.com/dj-pearson/MCPFold/pull/46</a></li>
<li>feat(cli): terminal color + <code>info</code>/<code>update</code> management commands by @dj-pearson in <a href="https://github.com/dj-pearson/MCPFold/pull/47">https://github.com/dj-pearson/MCPFold/pull/47</a></li>
<li>fix(cli): adopt untouched init scaffold on import; add <code>test --timeout</code> by @dj-pearson in <a href="https://github.com/dj-pearson/MCPFold/pull/48">https://github.com/dj-pearson/MCPFold/pull/48</a></li>
<li>docs: add VS Code Marketplace badge to README by @dj-pearson in <a href="https://github.com/dj-pearson/MCPFold/pull/49">https://github.com/dj-pearson/MCPFold/pull/49</a></li>
<li>Version Packages by @github-actions[bot] in <a href="https://github.com/dj-pearson/MCPFold/pull/41">https://github.com/dj-pearson/MCPFold/pull/41</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/dj-pearson/MCPFold/compare/v1.0.2...v1.1.0">https://github.com/dj-pearson/MCPFold/compare/v1.0.2...v1.1.0</a></p>
]]></content:encoded></item><item><title>AgentGuard Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/agentguard-security-scan/</link><pubDate>Mon, 13 Jul 2026 00:14:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/agentguard-security-scan/</guid><description>Version updated for https://github.com/dockfixlabs/agentguard to version v0.8.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Add research paper: 6,173 Security Findings in 10 AI Agent Frameworks by @dockfixlabs in https://github.com/dockfixlabs/agentguard/pull/15 Fix broken CLI + add main.py by @dockfixlabs in https://github.com/dockfixlabs/agentguard/pull/16 fix: replace circular benchmark claims with honest language by @dockfixlabs in https://github.com/dockfixlabs/agentguard/pull/17 v0.8.1: Independent Precision Validation (88%) by @dockfixlabs in https://github.com/dockfixlabs/agentguard/pull/18 Full Changelog: https://github.com/dockfixlabs/agentguard/compare/v0.7.0...v0.8.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/dockfixlabs/agentguard">https://github.com/dockfixlabs/agentguard</a></strong> to version <strong>v0.8.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentguard-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add research paper: 6,173 Security Findings in 10 AI Agent Frameworks by @dockfixlabs in <a href="https://github.com/dockfixlabs/agentguard/pull/15">https://github.com/dockfixlabs/agentguard/pull/15</a></li>
<li>Fix broken CLI + add <strong>main</strong>.py by @dockfixlabs in <a href="https://github.com/dockfixlabs/agentguard/pull/16">https://github.com/dockfixlabs/agentguard/pull/16</a></li>
<li>fix: replace circular benchmark claims with honest language by @dockfixlabs in <a href="https://github.com/dockfixlabs/agentguard/pull/17">https://github.com/dockfixlabs/agentguard/pull/17</a></li>
<li>v0.8.1: Independent Precision Validation (88%) by @dockfixlabs in <a href="https://github.com/dockfixlabs/agentguard/pull/18">https://github.com/dockfixlabs/agentguard/pull/18</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/dockfixlabs/agentguard/compare/v0.7.0...v0.8.1">https://github.com/dockfixlabs/agentguard/compare/v0.7.0...v0.8.1</a></p>
]]></content:encoded></item><item><title>EvoOM Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/evoom-guard/</link><pubDate>Mon, 13 Jul 2026 00:13:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/evoom-guard/</guid><description>Version updated for https://github.com/EvoRiseKsa/EvoOM-Guard-m to version v3.3.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed v3.3.1 — close the v3.3.0 fail-open policy interactions (schema 1.7) by @EvoRiseKsa in https://github.com/EvoRiseKsa/EvoOM-Guard-m/pull/41 Full Changelog: https://github.com/EvoRiseKsa/EvoOM-Guard-m/compare/v3.3.0...v3.3.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/EvoRiseKsa/EvoOM-Guard-m">https://github.com/EvoRiseKsa/EvoOM-Guard-m</a></strong> to version <strong>v3.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/evoom-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>v3.3.1 — close the v3.3.0 fail-open policy interactions (schema 1.7) by @EvoRiseKsa in <a href="https://github.com/EvoRiseKsa/EvoOM-Guard-m/pull/41">https://github.com/EvoRiseKsa/EvoOM-Guard-m/pull/41</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/EvoRiseKsa/EvoOM-Guard-m/compare/v3.3.0...v3.3.1">https://github.com/EvoRiseKsa/EvoOM-Guard-m/compare/v3.3.0...v3.3.1</a></p>
]]></content:encoded></item><item><title>fish-shop/install-plugin-manager</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/fish-shop/install-plugin-manager/</link><pubDate>Mon, 13 Jul 2026 00:12:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/fish-shop/install-plugin-manager/</guid><description>Version updated for https://github.com/fish-shop/install-plugin-manager to version v2.3.112.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump the version-updates group with 7 updates by @dependabot[bot] in https://github.com/fish-shop/install-plugin-manager/pull/382 Full Changelog: https://github.com/fish-shop/install-plugin-manager/compare/v2.3.111...v2.3.112</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/fish-shop/install-plugin-manager">https://github.com/fish-shop/install-plugin-manager</a></strong> to version <strong>v2.3.112</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/fish-shop-install-plugin-manager">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump the version-updates group with 7 updates by @dependabot[bot] in <a href="https://github.com/fish-shop/install-plugin-manager/pull/382">https://github.com/fish-shop/install-plugin-manager/pull/382</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/fish-shop/install-plugin-manager/compare/v2.3.111...v2.3.112">https://github.com/fish-shop/install-plugin-manager/compare/v2.3.111...v2.3.112</a></p>
]]></content:encoded></item><item><title>Setup Livreur</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/setup-livreur/</link><pubDate>Mon, 13 Jul 2026 00:12:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/setup-livreur/</guid><description>Version updated for https://github.com/getlivreur/setup-livreur to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/getlivreur/setup-livreur/compare/v1.0.1...v1.0.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/getlivreur/setup-livreur">https://github.com/getlivreur/setup-livreur</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-livreur">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/getlivreur/setup-livreur/compare/v1.0.1...v1.0.2">https://github.com/getlivreur/setup-livreur/compare/v1.0.1...v1.0.2</a></p>
]]></content:encoded></item><item><title>mcpscore — MCP server audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/mcpscore-mcp-server-audit/</link><pubDate>Mon, 13 Jul 2026 00:11:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/mcpscore-mcp-server-audit/</guid><description>Version updated for https://github.com/mcp-box/mcpscore-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First release of the mcpscore GitHub Action — Lighthouse for MCP in your CI.
Audit an MCP server on every pull request, fail the build when quality drops below a threshold you set, and get the report as a PR comment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mcp-box/mcpscore-action">https://github.com/mcp-box/mcpscore-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcpscore-mcp-server-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release of the <strong>mcpscore</strong> GitHub Action — <a href="https://docs.mcpscore.dev">Lighthouse for MCP</a> in your CI.</p>
<p>Audit an MCP server on every pull request, fail the build when quality drops below a threshold you set, and get the report as a PR comment.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">mcp-box/mcpscore-action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">target</span>: <span style="color:#ae81ff">https://your-server.example/mcp</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">min-score</span>: <span style="color:#ae81ff">80</span>
</span></span></code></pre></div><p>What it does</p>
<ul>
<li>Score gate — fail the job when the main score falls below min-score (a percentage).</li>
<li>Readiness gate — optionally require readiness for the upcoming MCP 2026-07-28 spec via min-readiness (reported separately, never mixed into the main score).</li>
<li>PR comment — posts one report comment and updates it in place on re-runs: score, a pass/fail breakdown by severity, spec version and era, and every failed check by rule_id.</li>
<li>Job summary + outputs — the same report in the run summary, the raw JSON on disk, and every number exposed as a step output (score, percentage, era, readiness-*, &hellip;).</li>
<li>Deterministic — no API keys, no LLM calls; the same server state always produces the same result, in seconds.</li>
</ul>
<p>Works against remote servers (Streamable HTTP / SSE) and local .py / .js servers.</p>
<p>Links:</p>
<ul>
<li>Documentation: <a href="https://docs.mcpscore.dev/github-action">https://docs.mcpscore.dev/github-action</a></li>
<li>Scoring methodology: <a href="https://docs.mcpscore.dev/methodology">https://docs.mcpscore.dev/methodology</a></li>
<li>mcpscore CLI: <a href="https://github.com/mcp-box/mcpscore">https://github.com/mcp-box/mcpscore</a></li>
</ul>
<p>Full changelog: <a href="https://github.com/mcp-box/mcpscore-action/commits/v1.0.0">https://github.com/mcp-box/mcpscore-action/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>Go - Test Suites</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/go-test-suites/</link><pubDate>Mon, 13 Jul 2026 00:11:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/go-test-suites/</guid><description>Version updated for https://github.com/mvrahden/go-test to version v1.25.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Add blog articles by @mvrahden in https://github.com/mvrahden/go-test/pull/85 improve project documentation by @mvrahden in https://github.com/mvrahden/go-test/pull/86 Add Nil/NotNil assertions with defense-in-depth type guards by @mvrahden in https://github.com/mvrahden/go-test/pull/87 Replace unmaintained YAML dependency by @mvrahden in https://github.com/mvrahden/go-test/pull/89 Resilient Go SDK discovery in VSCode extension by @mvrahden in https://github.com/mvrahden/go-test/pull/88 Surface race detector and panic output that was silently dropped by @mvrahden in https://github.com/mvrahden/go-test/pull/91 Add blog posts: migration guide improvements and “Why Your Go Tests Are Slow” by @mvrahden in https://github.com/mvrahden/go-test/pull/90 Clean up internal duplication and dead code by @mvrahden in https://github.com/mvrahden/go-test/pull/92 Full Changelog: https://github.com/mvrahden/go-test/compare/v1...v1.25.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mvrahden/go-test">https://github.com/mvrahden/go-test</a></strong> to version <strong>v1.25.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-test-suites">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add blog articles by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/85">https://github.com/mvrahden/go-test/pull/85</a></li>
<li>improve project documentation by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/86">https://github.com/mvrahden/go-test/pull/86</a></li>
<li>Add Nil/NotNil assertions with defense-in-depth type guards by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/87">https://github.com/mvrahden/go-test/pull/87</a></li>
<li>Replace unmaintained YAML dependency by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/89">https://github.com/mvrahden/go-test/pull/89</a></li>
<li>Resilient Go SDK discovery in VSCode extension by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/88">https://github.com/mvrahden/go-test/pull/88</a></li>
<li>Surface race detector and panic output that was silently dropped by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/91">https://github.com/mvrahden/go-test/pull/91</a></li>
<li>Add blog posts: migration guide improvements and &ldquo;Why Your Go Tests Are Slow&rdquo; by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/90">https://github.com/mvrahden/go-test/pull/90</a></li>
<li>Clean up internal duplication and dead code by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/92">https://github.com/mvrahden/go-test/pull/92</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mvrahden/go-test/compare/v1...v1.25.0">https://github.com/mvrahden/go-test/compare/v1...v1.25.0</a></p>
]]></content:encoded></item><item><title>Docker Compose Cache</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/docker-compose-cache/</link><pubDate>Mon, 13 Jul 2026 00:10:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/docker-compose-cache/</guid><description>Version updated for https://github.com/seijikohara/docker-compose-cache-action to version v1.8.17.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps): lock file maintenance by @renovate[bot] in https://github.com/seijikohara/docker-compose-cache-action/pull/305 Full Changelog: https://github.com/seijikohara/docker-compose-cache-action/compare/v1.8.16...v1.8.17</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/seijikohara/docker-compose-cache-action">https://github.com/seijikohara/docker-compose-cache-action</a></strong> to version <strong>v1.8.17</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/docker-compose-cache">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/305">https://github.com/seijikohara/docker-compose-cache-action/pull/305</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/seijikohara/docker-compose-cache-action/compare/v1.8.16...v1.8.17">https://github.com/seijikohara/docker-compose-cache-action/compare/v1.8.16...v1.8.17</a></p>
]]></content:encoded></item><item><title>PR Comment - Create &amp; Edit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/pr-comment-create-edit/</link><pubDate>Mon, 13 Jul 2026 00:09:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/pr-comment-create-edit/</guid><description>Version updated for https://github.com/spicyparrot/pr-comment-action to version v1.0.5.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/spicyparrot/pr-comment-action/compare/v1.0.3...v1.0.5</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spicyparrot/pr-comment-action">https://github.com/spicyparrot/pr-comment-action</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pr-comment-create-edit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at v1.0.5 -->
<p><strong>Full Changelog</strong>: <a href="https://github.com/spicyparrot/pr-comment-action/compare/v1.0.3...v1.0.5">https://github.com/spicyparrot/pr-comment-action/compare/v1.0.3...v1.0.5</a></p>
]]></content:encoded></item><item><title>grype_me</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/grype_me/</link><pubDate>Mon, 13 Jul 2026 00:09:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/13/grype_me/</guid><description>Version updated for https://github.com/TomTonic/grype_me to version v1.3.17-release.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v1.3.17-release Source Code Updates Go toolchain updated 1.26.4 → 1.26.5. This release includes two upstream Go security fixes:
CVE-2026-39822 — os.Root symlink escape: on Unix, opening a path ending in / inside an os.Root could follow a symlink to a location outside the root if the final path component was itself a symlink (e.g. root.Open(&amp;#34;symlink/&amp;#34;) would open symlink even though it points outside the root). CVE-2026-42505 — crypto/tls Encrypted Client Hello (ECH) privacy leak. grype_me does not use os.Root or ECH directly, but the fix ships automatically via the toolchain bump and is recommended for all users building or running this action.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TomTonic/grype_me">https://github.com/TomTonic/grype_me</a></strong> to version <strong>v1.3.17-release</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/grype_me">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v1317-release">v1.3.17-release</h1>
<h2 id="source-code-updates">Source Code Updates</h2>
<ul>
<li>
<p><strong>Go toolchain updated 1.26.4 → 1.26.5.</strong> This release includes two upstream Go security fixes:</p>
<ul>
<li><strong>CVE-2026-39822</strong> — <code>os.Root</code> symlink escape: on Unix, opening a path ending in <code>/</code> inside an <code>os.Root</code> could follow a symlink to a location outside the root if the final path component was itself a symlink (e.g. <code>root.Open(&quot;symlink/&quot;)</code> would open <code>symlink</code> even though it points outside the root).</li>
<li><strong>CVE-2026-42505</strong> — <code>crypto/tls</code> Encrypted Client Hello (ECH) privacy leak.</li>
</ul>
<p><code>grype_me</code> does not use <code>os.Root</code> or ECH directly, but the fix ships automatically via the toolchain bump and is recommended for all users building or running this action.</p>
</li>
<li>
<p><strong>Indirect dependency refresh</strong> (all transitive via <code>go-git</code>, used for repository scanning): <code>golang.org/x/crypto</code> 0.52.0 → 0.54.0, <code>golang.org/x/net</code> 0.55.0 → 0.57.0, <code>golang.org/x/sys</code> 0.46.0 → 0.47.0, <code>golang.org/x/term</code> 0.43.0 → 0.45.0, <code>golang.org/x/text</code> 0.37.0 → 0.40.0, <code>cloudflare/circl</code> 1.6.3 → 1.6.4, <code>cyphar/filepath-securejoin</code> 0.6.1 → 0.7.0, <code>klauspost/cpuid/v2</code> 2.3.0 → 2.4.0. These are routine patch-level refreshes; no additional CVEs beyond those already remediated in prior releases were identified as fixed specifically within these increments.</p>
</li>
</ul>
<h2 id="ci-updates">CI Updates</h2>
<ul>
<li>Bumped GitHub Actions: <code>actions/checkout</code> v6.0.3 → v7.0.0, <code>actions/setup-go</code> v6.4.0 → v6.5.0, <code>actions/setup-python</code> v6.2.0 → v6.3.0, <code>docker/build-push-action</code> v7.2.0 → v7.3.0, <code>docker/login-action</code> v4.2.0 → v4.4.0, <code>docker/setup-buildx-action</code> v4.1.0 → v4.2.0, <code>golangci-lint-action</code> v9.2.1 → v9.3.0, <code>github/codeql-action</code> v4.36.2 → v4.37.0, <code>step-security/harden-runner</code> v2.19.4 → v2.20.0.</li>
<li>Refreshed base image digests for the <code>golang:1.26.x-bookworm</code> build stage and <code>alpine:3.24</code> runtime stage in the Dockerfile.</li>
<li>Updated the <code>typing-extensions</code> Python dependency (used by the yamllint tooling) 4.15.0 → 4.16.0.</li>
</ul>
<h2 id="changed-behavior">Changed Behavior</h2>
<p>None.</p>
<h2 id="new-features">New Features</h2>
<p>None.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/TomTonic/grype_me/compare/v1.3.16-release...v1.3.17-release">https://github.com/TomTonic/grype_me/compare/v1.3.16-release...v1.3.17-release</a></p>
]]></content:encoded></item><item><title>OAuthLint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/oauthlint/</link><pubDate>Sun, 12 Jul 2026 19:24:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/oauthlint/</guid><description>Version updated for https://github.com/Auspeo/oauthlint to version oauthlint@0.10.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Re-pins the bundled rule pack to 0.7.0, so oauthlint scan ships the new NestJS and Fastify rules.
Changed Bundled rule pack updated to oauthlint-rules 0.7.0. Docs: https://oauthlint.dev/docs/cli · Full changelog: https://github.com/Auspeo/oauthlint/compare/oauthlint@0.10.0...oauthlint@0.10.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Auspeo/oauthlint">https://github.com/Auspeo/oauthlint</a></strong> to version <strong><a href="mailto:oauthlint@0.10.1">oauthlint@0.10.1</a></strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/oauthlint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Re-pins the bundled rule pack to 0.7.0, so <code>oauthlint scan</code> ships the new NestJS and Fastify rules.</p>
<h3 id="changed">Changed</h3>
<ul>
<li>Bundled rule pack updated to oauthlint-rules 0.7.0.</li>
</ul>
<p><strong>Docs:</strong> <a href="https://oauthlint.dev/docs/cli">https://oauthlint.dev/docs/cli</a> · <strong>Full changelog:</strong> <a href="https://github.com/Auspeo/oauthlint/compare/oauthlint@0.10.0...oauthlint@0.10.1">https://github.com/Auspeo/oauthlint/compare/oauthlint@0.10.0...oauthlint@0.10.1</a></p>
]]></content:encoded></item><item><title>super-release</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/super-release/</link><pubDate>Sun, 12 Jul 2026 19:23:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/super-release/</guid><description>Version updated for https://github.com/BowlingX/super-release to version super-release/v1.12.1.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [1.12.1] - 2026-07-12 🐛 Bug Fixes Reduced binary size; stripped unused features (#32) by @BowlingX in #32 ⚙️ Miscellaneous Tasks Bumped packages 👥 Contributors @BowlingX Full Changelog: https://github.com/BowlingX/super-release/compare/super-release/v1.12.0...super-release/v1.12.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/BowlingX/super-release">https://github.com/BowlingX/super-release</a></strong> to version <strong>super-release/v1.12.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/super-release">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1121---2026-07-12">[1.12.1] - 2026-07-12</h2>
<h3 id="-bug-fixes">🐛 Bug Fixes</h3>
<ul>
<li>Reduced binary size; stripped unused features (#32) by @BowlingX in <a href="https://github.com/BowlingX/super-release/pull/32">#32</a></li>
</ul>
<h3 id="-miscellaneous-tasks">⚙️ Miscellaneous Tasks</h3>
<ul>
<li>Bumped packages</li>
</ul>
<h3 id="-contributors">👥 Contributors</h3>
<ul>
<li>@BowlingX</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/BowlingX/super-release/compare/super-release/v1.12.0...super-release/v1.12.1">https://github.com/BowlingX/super-release/compare/super-release/v1.12.0...super-release/v1.12.1</a></p>
]]></content:encoded></item><item><title>Capawesome Cloud Build Action for GitHub Actions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/capawesome-cloud-build-action-for-github-actions/</link><pubDate>Sun, 12 Jul 2026 19:23:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/capawesome-cloud-build-action-for-github-actions/</guid><description>Version updated for https://github.com/capawesome-team/cloud-build-action to version v0.1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed https://github.com/capawesome-team/cloud-build-action/blob/main/CHANGELOG.md#012-2026-07-12</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/capawesome-team/cloud-build-action">https://github.com/capawesome-team/cloud-build-action</a></strong> to version <strong>v0.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/capawesome-cloud-build-action-for-github-actions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><a href="https://github.com/capawesome-team/cloud-build-action/blob/main/CHANGELOG.md#012-2026-07-12">https://github.com/capawesome-team/cloud-build-action/blob/main/CHANGELOG.md#012-2026-07-12</a></p>
]]></content:encoded></item><item><title>Dazbos Gemini Review &amp; Triage</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/dazbos-gemini-review-triage/</link><pubDate>Sun, 12 Jul 2026 19:22:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/dazbos-gemini-review-triage/</guid><description>Version updated for https://github.com/derailed-dash/gemini-review-action to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changes Add class docstrings to all structured Pydantic models. Add authentication logging showing which credentials are used for both GitHub API and Google GenAI. Support configurable request timeout via a new timeout action input (defaults to 60s). Clean up legacy typing.List usage to conform to PEP 585 (Python 3.12+).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/derailed-dash/gemini-review-action">https://github.com/derailed-dash/gemini-review-action</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/dazbo-s-gemini-review-triage">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="changes">Changes</h3>
<ul>
<li>Add class docstrings to all structured Pydantic models.</li>
<li>Add authentication logging showing which credentials are used for both GitHub API and Google GenAI.</li>
<li>Support configurable request timeout via a new <code>timeout</code> action input (defaults to 60s).</li>
<li>Clean up legacy <code>typing.List</code> usage to conform to PEP 585 (Python 3.12+).</li>
</ul>
]]></content:encoded></item><item><title>Cloudflare Subpath Deploy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/cloudflare-subpath-deploy/</link><pubDate>Sun, 12 Jul 2026 19:22:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/cloudflare-subpath-deploy/</guid><description>Version updated for https://github.com/dytsou/cloudflare-subpath-deploy to version v1.0.0.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/dytsou/cloudflare-subpath-deploy/compare/v0...v1.0.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/dytsou/cloudflare-subpath-deploy">https://github.com/dytsou/cloudflare-subpath-deploy</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cloudflare-subpath-deploy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/dytsou/cloudflare-subpath-deploy/compare/v0...v1.0.0">https://github.com/dytsou/cloudflare-subpath-deploy/compare/v0...v1.0.0</a></p>
]]></content:encoded></item><item><title>402coffee Certify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/402coffee-certify/</link><pubDate>Sun, 12 Jul 2026 19:21:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/402coffee-certify/</guid><description>Version updated for https://github.com/englishdoggy/certify-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Certify your x402 paying agent against 402.coffee in CI. On every push it runs the real conformance test (a real, gasless USDC payment on Base), writes the result to the job summary, and can fail the build if the agent’s risk-score tier drops. Use it as englishdoggy/certify-action@v1 — the README has the full workflow snippet, inputs, outputs, and costs. Every result is a fact observed on-chain; it drives the real payment flow, nothing is faked.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/englishdoggy/certify-action">https://github.com/englishdoggy/certify-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/402coffee-certify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Certify your x402 paying agent against 402.coffee in CI. On every push it runs the real conformance test (a real, gasless USDC payment on Base), writes the result to the job summary, and can fail the build if the agent&rsquo;s risk-score tier drops. Use it as <code>englishdoggy/certify-action@v1</code> — the README has the full workflow snippet, inputs, outputs, and costs. Every result is a fact observed on-chain; it drives the real payment flow, nothing is faked.</p>
]]></content:encoded></item><item><title>LegacyLint Delphi Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/legacylint-delphi-scan/</link><pubDate>Sun, 12 Jul 2026 19:21:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/legacylint-delphi-scan/</guid><description>Version updated for https://github.com/Gert-JanDev/LegacyLint to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Static analysis for Delphi/Pascal that runs in CI and comments findings directly on your pull requests: inline annotations on the changed lines plus a single summary comment, with configurable fail-on gating (error / warning / none).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Gert-JanDev/LegacyLint">https://github.com/Gert-JanDev/LegacyLint</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/legacylint-delphi-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Static analysis for Delphi/Pascal that runs in CI and comments findings directly
on your pull requests: inline annotations on the changed lines plus a single
summary comment, with configurable fail-on gating (error / warning / none).</p>
<p>Usage:</p>
<ul>
<li>uses: Gert-JanDev/LegacyLint@v1
with:
api-key: ${{ secrets.LEGACYLINT_API_KEY }}
project-key: your-project-key</li>
</ul>
<p>Requires a LegacyLint project API key (create one in your dashboard).</p>
]]></content:encoded></item><item><title>Provenant Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/provenant-scan/</link><pubDate>Sun, 12 Jul 2026 19:20:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/provenant-scan/</guid><description>Version updated for https://github.com/getprovenant/provenant-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First release of the Provenant GitHub Action — run the Provenant license, copyright, and SBOM scanner in a workflow.
Highlights Scan the checked-out repo (or specific paths) and emit any Provenant output format. Changed-file PR scans via paths-file (feed it git diff --name-only). CI license gating: license-policy + fail-on (error|warning) fails the build on a disallowed license. SARIF output (sarif-file) for pull-request and code-scanning alerts. The action always runs the latest published Provenant release; pin the action with @v1.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/getprovenant/provenant-action">https://github.com/getprovenant/provenant-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/provenant-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release of the Provenant GitHub Action — run the <a href="https://github.com/getprovenant/provenant">Provenant</a> license, copyright, and SBOM scanner in a workflow.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Scan the checked-out repo (or specific <code>paths</code>) and emit any Provenant output format.</li>
<li><strong>Changed-file PR scans</strong> via <code>paths-file</code> (feed it <code>git diff --name-only</code>).</li>
<li><strong>CI license gating</strong>: <code>license-policy</code> + <code>fail-on</code> (error|warning) fails the build on a disallowed license.</li>
<li><strong>SARIF</strong> output (<code>sarif-file</code>) for pull-request and code-scanning alerts.</li>
</ul>
<p>The action always runs the latest published Provenant release; pin the action with <code>@v1</code>.</p>
]]></content:encoded></item><item><title>Temple Scope Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/temple-scope-guard/</link><pubDate>Sun, 12 Jul 2026 19:19:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/temple-scope-guard/</guid><description>Version updated for https://github.com/goweft/temple to version v0.3.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s new The dependency check now understands Go. Previous versions only recognized pyproject.toml and requirements.txt, so on this repo — and any other Go repo — max_deps silently went unenforced. temple check now reads go.mod (direct requires only; // indirect doesn’t count). A declared max_deps with no parseable manifest is now a failure, not a silent pass. A check that couldn’t run is not a check that passed. The GitHub Action verifies checksums before running anything. It previously downloaded and executed a release tarball with no integrity check. It now verifies against that release’s checksums.txt and fails if the asset is missing or doesn’t match. The action installs to a scratch directory, not your checkout, and defaults to pinning the exact release version instead of a floating latest. The action’s display name is now “Temple Scope Guard” (Marketplace listing requirement — a bare temple collided with an existing GitHub user). Usage is unchanged: uses: goweft/temple@v0.3.1. Upgrading No breaking changes to the contract format. If your temple.toml declares max_deps and your repo is Go, this release may surface a finding that was previously silent — that’s the fix working as intended.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/goweft/temple">https://github.com/goweft/temple</a></strong> to version <strong>v0.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/temple-scope-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new">What&rsquo;s new</h2>
<ul>
<li><strong>The dependency check now understands Go.</strong> Previous versions only recognized
<code>pyproject.toml</code> and <code>requirements.txt</code>, so on this repo — and any other Go
repo — <code>max_deps</code> silently went unenforced. <code>temple check</code> now reads <code>go.mod</code>
(direct requires only; <code>// indirect</code> doesn&rsquo;t count).</li>
<li><strong>A declared <code>max_deps</code> with no parseable manifest is now a failure, not a
silent pass.</strong> A check that couldn&rsquo;t run is not a check that passed.</li>
<li><strong>The GitHub Action verifies checksums before running anything.</strong> It
previously downloaded and executed a release tarball with no integrity
check. It now verifies against that release&rsquo;s <code>checksums.txt</code> and fails if
the asset is missing or doesn&rsquo;t match.</li>
<li><strong>The action installs to a scratch directory</strong>, not your checkout, and
defaults to pinning the exact release version instead of a floating <code>latest</code>.</li>
<li>The action&rsquo;s display name is now &ldquo;Temple Scope Guard&rdquo; (Marketplace listing
requirement — a bare <code>temple</code> collided with an existing GitHub user).
Usage is unchanged: <code>uses: goweft/temple@v0.3.1</code>.</li>
</ul>
<h2 id="upgrading">Upgrading</h2>
<p>No breaking changes to the contract format. If your <code>temple.toml</code> declares
<code>max_deps</code> and your repo is Go, this release may surface a finding that was
previously silent — that&rsquo;s the fix working as intended.</p>
<p>Full diff: <a href="https://github.com/goweft/temple/compare/v0.3.0...v0.3.1">https://github.com/goweft/temple/compare/v0.3.0...v0.3.1</a></p>
]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/ai-plugin-scanner/</link><pubDate>Sun, 12 Jul 2026 19:19:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.462.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/065f7c87e69fbdbc8e597047ba05916e6e0d8c18 with plugin-scanner 2.0.1063.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.461...v1.2.462</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.462</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>18</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/065f7c87e69fbdbc8e597047ba05916e6e0d8c18">https://github.com/hashgraph-online/hol-guard/tree/065f7c87e69fbdbc8e597047ba05916e6e0d8c18</a> with plugin-scanner 2.0.1063.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.461...v1.2.462">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.461...v1.2.462</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/hol-codex-plugin-scanner/</link><pubDate>Sun, 12 Jul 2026 19:18:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.462.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.462</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.462</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.462">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.462</a></p>
]]></content:encoded></item><item><title>Write .env file from secrets</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/write-.env-file-from-secrets/</link><pubDate>Sun, 12 Jul 2026 19:18:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/write-.env-file-from-secrets/</guid><description>Version updated for https://github.com/horlakz/secretenv to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Add exclusions and safe dotenv warnings</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/horlakz/secretenv">https://github.com/horlakz/secretenv</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/write-env-file-from-secrets">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Add exclusions and safe dotenv warnings</p>
]]></content:encoded></item><item><title>JFrog Boost</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/jfrog-boost/</link><pubDate>Sun, 12 Jul 2026 19:17:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/jfrog-boost/</guid><description>Version updated for https://github.com/jfrog/boost to version v0.9.2.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 2 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Release v0.7.23 by @yahav-ohana in https://github.com/jfrog/boost/pull/41 Release v0.7.25 by @menachemm-byte in https://github.com/jfrog/boost/pull/44 docs(readme): simplify mascot, focus on token savings, add report commands by @yahav-ohana in https://github.com/jfrog/boost/pull/47 docs(readme): update release badge to v0.8.6 and stars to 258 by @yahav-ohana in https://github.com/jfrog/boost/pull/48 New Contributors @menachemm-byte made their first contribution in https://github.com/jfrog/boost/pull/44 Full Changelog: https://github.com/jfrog/boost/compare/v0.7.23...v0.9.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jfrog/boost">https://github.com/jfrog/boost</a></strong> to version <strong>v0.9.2</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>2</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jfrog-boost">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Release v0.7.23 by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/41">https://github.com/jfrog/boost/pull/41</a></li>
<li>Release v0.7.25 by @menachemm-byte in <a href="https://github.com/jfrog/boost/pull/44">https://github.com/jfrog/boost/pull/44</a></li>
<li>docs(readme): simplify mascot, focus on token savings, add report commands by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/47">https://github.com/jfrog/boost/pull/47</a></li>
<li>docs(readme): update release badge to v0.8.6 and stars to 258 by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/48">https://github.com/jfrog/boost/pull/48</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@menachemm-byte made their first contribution in <a href="https://github.com/jfrog/boost/pull/44">https://github.com/jfrog/boost/pull/44</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jfrog/boost/compare/v0.7.23...v0.9.2">https://github.com/jfrog/boost/compare/v0.7.23...v0.9.2</a></p>
]]></content:encoded></item><item><title>Run AER Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/run-aer-tests/</link><pubDate>Sun, 12 Jul 2026 19:17:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/run-aer-tests/</guid><description>Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.14.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Version v1.2.14
Preserve Query-Row State On Clone And Check Empty Stub Query Rows
Move Cache Root To Dedicated Subdirectory So Sweep Cannot Delete License Key
Format And Parse Dates For Every Locale</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/octoberswimmer/aer-dist">https://github.com/octoberswimmer/aer-dist</a></strong> to version <strong>v1.2.14</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-aer-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Version v1.2.14</p>
<ul>
<li>
<p>Preserve Query-Row State On Clone And Check Empty Stub Query Rows</p>
</li>
<li>
<p>Move Cache Root To Dedicated Subdirectory So Sweep Cannot Delete License Key</p>
</li>
<li>
<p>Format And Parse Dates For Every Locale</p>
</li>
</ul>
]]></content:encoded></item><item><title>Remyx Outrider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/remyx-outrider/</link><pubDate>Sun, 12 Jul 2026 19:16:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/remyx-outrider/</guid><description>Version updated for https://github.com/remyxai/outrider to version v1.7.16.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s new start-from-ref — new workflow input that names a branch/tag/SHA on the target fork. When set, the coding session begins with that ref’s diff already applied to the workspace, so lead-content phrasing like “add tests for X” or “refactor Y” acts on real state instead of being advisory.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remyxai/outrider">https://github.com/remyxai/outrider</a></strong> to version <strong>v1.7.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/remyx-outrider">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new">What&rsquo;s new</h2>
<p><strong><code>start-from-ref</code></strong> — new workflow input that names a branch/tag/SHA on the target fork. When set, the coding session begins with that ref&rsquo;s diff already applied to the workspace, so <code>lead-content</code> phrasing like &ldquo;add tests for X&rdquo; or &ldquo;refactor Y&rdquo; acts on real state instead of being advisory.</p>
<p>Unlocks the <strong>two-pass workflow</strong> — a cheap GLM branch-mode scout produces a reference branch, then an Anthropic-tier follow-up refines it into a shippable PR without rewriting the paper from scratch. See the README&rsquo;s <em>Examples</em> section for <a href="https://github.com/smellslikeml/OLMo-core/pull/13">OLMo-core #13</a> as a landed reference case.</p>
<h3 id="usage">Usage</h3>
<p>Add <code>start-from-ref</code> to your fork&rsquo;s <code>outrider.yml</code> under <code>workflow_dispatch:</code> and thread it to the action:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">remyxai/outrider@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#ae81ff">...</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">start-from-ref</span>: <span style="color:#ae81ff">${{ inputs.start-from-ref }}</span>
</span></span></code></pre></div><p>Then dispatch:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>gh workflow run outrider.yml --repo &lt;fork&gt; --ref main <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>    -f provider<span style="color:#f92672">=</span>anthropic -f pin-arxiv<span style="color:#f92672">=</span>&lt;same-arxiv&gt; <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>    -f start-from-ref<span style="color:#f92672">=</span>&lt;prior-branch&gt;
</span></span></code></pre></div><p>Pushes to <code>&lt;paper-slug&gt;-refined</code>, PR opens with <code>base=&lt;default-branch&gt;</code> showing the full baseline+refinement state.</p>
<h3 id="fixes">Fixes</h3>
<ul>
<li><code>detect_default_branch</code> now resolves via <code>refs/remotes/origin/HEAD</code> (the remote&rsquo;s default, stable across local checkouts) rather than the local <code>HEAD</code> symbolic ref. Without this fix, <code>start-from-ref</code> runs would open PRs with <code>base=&lt;ref&gt;</code> instead of <code>base=main</code>, hiding the baseline diff.</li>
</ul>
<h3 id="tests">Tests</h3>
<p>877 tests pass. New coverage in <code>tests/test_start_from_ref.py</code> covers the branch-name suffix behavior, the checkout-post-clone plumbing, the default-branch resolution, and the classic no-ref-set flow.</p>
]]></content:encoded></item><item><title>Kamal Accessories Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/kamal-accessories-updater/</link><pubDate>Sun, 12 Jul 2026 19:16:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/kamal-accessories-updater/</guid><description>Version updated for https://github.com/robfrank/kamal-accessories-updater to version v26.7.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Merge pull request #20 from robfrank/dependabot/github_actions/github-actions-e8041ce7a0 (43b1e7b) Bump the github-actions group across 1 directory with 2 updates (db9b6c4) Merge pull request #19 from robfrank/dependabot/github_actions/actions/checkout-7.0.0 (40c1558) Bump actions/checkout from 6.0.3 to 7.0.0 (febf81f) Bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions group [skip ci] (2132e70) Bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions group (5d62ccf) Merge pull request #16 from robfrank/dependabot/github_actions/softprops/action-gh-release-3.0.0 (f22259c) Bump softprops/action-gh-release from 2.5.0 to 3.0.0 (58df647) Usage To use this version in your workflows:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/robfrank/kamal-accessories-updater">https://github.com/robfrank/kamal-accessories-updater</a></strong> to version <strong>v26.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kamal-accessories-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Merge pull request #20 from robfrank/dependabot/github_actions/github-actions-e8041ce7a0 (43b1e7b)</li>
<li>Bump the github-actions group across 1 directory with 2 updates (db9b6c4)</li>
<li>Merge pull request #19 from robfrank/dependabot/github_actions/actions/checkout-7.0.0 (40c1558)</li>
<li>Bump actions/checkout from 6.0.3 to 7.0.0 (febf81f)</li>
<li>Bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions group [skip ci] (2132e70)</li>
<li>Bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions group (5d62ccf)</li>
<li>Merge pull request #16 from robfrank/dependabot/github_actions/softprops/action-gh-release-3.0.0 (f22259c)</li>
<li>Bump softprops/action-gh-release from 2.5.0 to 3.0.0 (58df647)</li>
</ul>
<h2 id="usage">Usage</h2>
<p>To use this version in your workflows:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">name</span>: <span style="color:#ae81ff">Update Kamal accessories</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">robfrank/kamal-accessories-updater@v26.7.0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">config-dir</span>: <span style="color:#ae81ff">config</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">mode</span>: <span style="color:#ae81ff">update-all</span>
</span></span></code></pre></div><p><strong>Full Changelog</strong>: <a href="https://github.com/robfrank/kamal-accessories-updater/compare/v26.4.0...v26.7.0">https://github.com/robfrank/kamal-accessories-updater/compare/v26.4.0...v26.7.0</a></p>
]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/rumdl-action/</link><pubDate>Sun, 12 Jul 2026 19:15:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.31.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added action: install rumdl from GitHub Releases instead of pip (7f69695) Performance reflow: optimize inline code mask calculation using pre-extracted spans (27e5507) Downloads File Platform Checksum rumdl-v0.2.31-x86_64-unknown-linux-gnu.tar.gz Linux x86_64 checksum rumdl-v0.2.31-x86_64-unknown-linux-musl.tar.gz Linux x86_64 (musl) checksum rumdl-v0.2.31-aarch64-unknown-linux-gnu.tar.gz Linux ARM64 checksum rumdl-v0.2.31-aarch64-unknown-linux-musl.tar.gz Linux ARM64 (musl) checksum rumdl-v0.2.31-x86_64-apple-darwin.tar.gz macOS x86_64 checksum rumdl-v0.2.31-aarch64-apple-darwin.tar.gz macOS ARM64 (Apple Silicon) checksum rumdl-v0.2.31-x86_64-pc-windows-msvc.zip Windows x86_64 checksum Installation Using uv (Recommended) uv tool install rumdl Using pip pip install rumdl Using pipx pipx install rumdl Direct Download Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.31</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>action</strong>: install rumdl from GitHub Releases instead of pip (<a href="https://github.com/rvben/rumdl/commit/7f69695238e1ebffba75a82cf8336e777a965f4a">7f69695</a>)</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li><strong>reflow</strong>: optimize inline code mask calculation using pre-extracted spans (<a href="https://github.com/rvben/rumdl/commit/27e55072be01e075a8b6f72b7409c4b29c5f56e1">27e5507</a>)</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.31/rumdl-v0.2.31-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.31-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.31/rumdl-v0.2.31-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.31/rumdl-v0.2.31-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.31-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.31/rumdl-v0.2.31-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.31/rumdl-v0.2.31-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.31-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.31/rumdl-v0.2.31-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.31/rumdl-v0.2.31-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.31-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.31/rumdl-v0.2.31-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.31/rumdl-v0.2.31-x86_64-apple-darwin.tar.gz">rumdl-v0.2.31-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.31/rumdl-v0.2.31-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.31/rumdl-v0.2.31-aarch64-apple-darwin.tar.gz">rumdl-v0.2.31-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.31/rumdl-v0.2.31-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.31/rumdl-v0.2.31-x86_64-pc-windows-msvc.zip">rumdl-v0.2.31-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.31/rumdl-v0.2.31-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>Shieldly — AI-Powered Security Analysis</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/shieldly-ai-powered-security-analysis/</link><pubDate>Sun, 12 Jul 2026 19:14:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/shieldly-ai-powered-security-analysis/</guid><description>Version updated for https://github.com/shieldly-io/action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed See https://github.com/shieldly-io/shieldly for full changelog.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/shieldly-io/action">https://github.com/shieldly-io/action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/shieldly-ai-powered-security-analysis">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>See <a href="https://github.com/shieldly-io/shieldly">https://github.com/shieldly-io/shieldly</a> for full changelog.</p>
]]></content:encoded></item><item><title>PR Comment - Create &amp; Edit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/pr-comment-create-edit/</link><pubDate>Sun, 12 Jul 2026 19:14:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/pr-comment-create-edit/</guid><description>Version updated for https://github.com/spicyparrot/pr-comment-action to version v1.0.4.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/spicyparrot/pr-comment-action/compare/v1.0.3...v1.0.4</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spicyparrot/pr-comment-action">https://github.com/spicyparrot/pr-comment-action</a></strong> to version <strong>v1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pr-comment-create-edit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at v1.0.4 -->
<p><strong>Full Changelog</strong>: <a href="https://github.com/spicyparrot/pr-comment-action/compare/v1.0.3...v1.0.4">https://github.com/spicyparrot/pr-comment-action/compare/v1.0.3...v1.0.4</a></p>
]]></content:encoded></item><item><title>Azure Static Web Apps Deploy (small)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/azure-static-web-apps-deploy-small/</link><pubDate>Sun, 12 Jul 2026 19:13:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/azure-static-web-apps-deploy-small/</guid><description>Version updated for https://github.com/svrooij/azure-static-web-app-deploy-action to version v1.3.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Deployment token is no longer leaked to the environment by @svrooij in https://github.com/svrooij/azure-static-web-app-deploy-action/pull/7 Full Changelog: https://github.com/svrooij/azure-static-web-app-deploy-action/compare/v1.3.0...v1.3.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/svrooij/azure-static-web-app-deploy-action">https://github.com/svrooij/azure-static-web-app-deploy-action</a></strong> to version <strong>v1.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/azure-static-web-apps-deploy-small">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Deployment token is no longer leaked to the environment by @svrooij in <a href="https://github.com/svrooij/azure-static-web-app-deploy-action/pull/7">https://github.com/svrooij/azure-static-web-app-deploy-action/pull/7</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/svrooij/azure-static-web-app-deploy-action/compare/v1.3.0...v1.3.1">https://github.com/svrooij/azure-static-web-app-deploy-action/compare/v1.3.0...v1.3.1</a></p>
]]></content:encoded></item><item><title>Package MicroPythonOS App</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/package-micropythonos-app/</link><pubDate>Sun, 12 Jul 2026 19:13:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/package-micropythonos-app/</guid><description>Version updated for https://github.com/tjorim/mpos-package-mpk to version v1.0.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Deterministic .mpk packaging for MicroPythonOS apps, built with pure-Python zipfile (no zip/find/touch dependency — runs on Linux, macOS, and native Windows runners). Follows the layout and reproducibility recipe from docs.micropythonos.com/apps/bundling-apps: fixed timestamps, sorted entries, stored/uncompressed, app folder first.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tjorim/mpos-package-mpk">https://github.com/tjorim/mpos-package-mpk</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/package-micropythonos-app">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Deterministic .mpk packaging for MicroPythonOS apps, built with pure-Python zipfile (no zip/find/touch dependency — runs on Linux, macOS, and native Windows runners). Follows the layout and reproducibility recipe from docs.micropythonos.com/apps/bundling-apps: fixed timestamps, sorted entries, stored/uncompressed, app folder first.</p>
]]></content:encoded></item><item><title>void sync branch</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/void-sync-branch/</link><pubDate>Sun, 12 Jul 2026 19:12:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/void-sync-branch/</guid><description>Version updated for https://github.com/voidmason/branch-sync-action to version v1.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump actions/checkout from 6 to 7 in the actions group across 1 directory by @dependabot[bot] in https://github.com/voidmason/branch-sync-action/pull/1 New Contributors @dependabot[bot] made their first contribution in https://github.com/voidmason/branch-sync-action/pull/1 Full Changelog: https://github.com/voidmason/branch-sync-action/commits/v1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/voidmason/branch-sync-action">https://github.com/voidmason/branch-sync-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/void-sync-branch">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump actions/checkout from 6 to 7 in the actions group across 1 directory by @dependabot[bot] in <a href="https://github.com/voidmason/branch-sync-action/pull/1">https://github.com/voidmason/branch-sync-action/pull/1</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/voidmason/branch-sync-action/pull/1">https://github.com/voidmason/branch-sync-action/pull/1</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/voidmason/branch-sync-action/commits/v1">https://github.com/voidmason/branch-sync-action/commits/v1</a></p>
]]></content:encoded></item><item><title>void rust bump</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/void-rust-bump/</link><pubDate>Sun, 12 Jul 2026 19:12:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/void-rust-bump/</guid><description>Version updated for https://github.com/voidmason/bump-release-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/voidmason/bump-release-action/commits/v1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/voidmason/bump-release-action">https://github.com/voidmason/bump-release-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/void-rust-bump">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/voidmason/bump-release-action/commits/v1">https://github.com/voidmason/bump-release-action/commits/v1</a></p>
]]></content:encoded></item><item><title>YGM Alipay Mini Program Upload</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/ygm-alipay-mini-program-upload/</link><pubDate>Sun, 12 Jul 2026 19:11:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/ygm-alipay-mini-program-upload/</guid><description>Version updated for https://github.com/YGM-Studio/alipay-miniprogram-upload-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial stable release. Uploads a built Alipay Mini Program with the official minidev SDK, validates the complete development tool identity config, supports experience versions, and removes the temporary identity key after upload.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YGM-Studio/alipay-miniprogram-upload-action">https://github.com/YGM-Studio/alipay-miniprogram-upload-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ygm-alipay-mini-program-upload">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial stable release. Uploads a built Alipay Mini Program with the official minidev SDK, validates the complete development tool identity config, supports experience versions, and removes the temporary identity key after upload.</p>
]]></content:encoded></item><item><title>YGM WeChat Mini Program Upload</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/ygm-wechat-mini-program-upload/</link><pubDate>Sun, 12 Jul 2026 19:11:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/ygm-wechat-mini-program-upload/</guid><description>Version updated for https://github.com/YGM-Studio/wechat-miniprogram-upload-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial stable release. Uploads a built WeChat Mini Program with the official miniprogram-ci SDK, validates inputs, reads the version from package.json, and removes the temporary private key after upload.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YGM-Studio/wechat-miniprogram-upload-action">https://github.com/YGM-Studio/wechat-miniprogram-upload-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ygm-wechat-mini-program-upload">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial stable release. Uploads a built WeChat Mini Program with the official miniprogram-ci SDK, validates inputs, reads the version from package.json, and removes the temporary private key after upload.</p>
]]></content:encoded></item><item><title>Install Task</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/install-task/</link><pubDate>Sun, 12 Jul 2026 19:10:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/install-task/</guid><description>Version updated for https://github.com/yk-lab/setup-task to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: setup-task GitHub Action の初回実装 by @yk-lab in https://github.com/yk-lab/setup-task/pull/6 docs: コミュニティヘルスファイルを追加 by @yk-lab in https://github.com/yk-lab/setup-task/pull/17 docs: README にステータスバッジを追加 by @yk-lab in https://github.com/yk-lab/setup-task/pull/20 build(deps): Bump vite and vitest by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/19 build(deps): Bump esbuild and vitest by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/18 build(deps): Bump actions/setup-node from 4 to 6 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/10 build(deps-dev): Bump @eslint/js from 9.39.4 to 10.0.1 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/15 build(deps-dev): Bump vitest from 2.1.9 to 4.1.9 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/14 build(deps): Bump actions/checkout from 4 to 6 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/11 build(deps-dev): Bump eslint from 9.39.4 to 10.5.0 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/13 ci: GitHub Actions を SHA ピンに固定 by @yk-lab in https://github.com/yk-lab/setup-task/pull/21 build(deps): Bump the actions-toolkit group across 1 directory with 2 updates by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/12 build(deps-dev): Bump @vercel/ncc from 0.38.4 to 0.44.0 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/16 fix(security): repo-token を core.setSecret でマスクする by @yk-lab in https://github.com/yk-lab/setup-task/pull/24 test: withRetry のユニットテストを追加する by @yk-lab in https://github.com/yk-lab/setup-task/pull/25 test: fetchJson の content-type ガードと createReleaseApi を検証 by @yk-lab in https://github.com/yk-lab/setup-task/pull/26 test: checksum 改ざん検出の統合テストと self-test 強化 by @yk-lab in https://github.com/yk-lab/setup-task/pull/27 ci: Codecov でカバレッジ/テスト結果を OIDC アップロードする by @yk-lab in https://github.com/yk-lab/setup-task/pull/28 test: cache-hit 経路の self-test を追加する by @yk-lab in https://github.com/yk-lab/setup-task/pull/29 fix: レンジ指定で tool-cache を GitHub 解決より優先する by @yk-lab in https://github.com/yk-lab/setup-task/pull/30 chore: パッケージマネージャを npm から pnpm へ移行 by @yk-lab in https://github.com/yk-lab/setup-task/pull/34 build(deps): Bump actions/checkout from 6.0.3 to 7.0.0 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/31 build(deps-dev): Bump typescript from 5.9.3 to 6.0.3 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/32 build(deps-dev): @types/node を ^24 に揃える by @yk-lab in https://github.com/yk-lab/setup-task/pull/35 chore: dist/ を main から外しリリース時ビルド方式へ by @yk-lab in https://github.com/yk-lab/setup-task/pull/36 ci: Codecov PR コメントを有効化 by @yk-lab in https://github.com/yk-lab/setup-task/pull/46 ci: Codecov PR コメントをカバレッジ変動時のみ表示 by @yk-lab in https://github.com/yk-lab/setup-task/pull/47 docs: TODO.md から完了した #8 を移動 by @yk-lab in https://github.com/yk-lab/setup-task/pull/48 ci: .md のみ変更時は重い CI をスキップしつつ required check を維持 by @yk-lab in https://github.com/yk-lab/setup-task/pull/49 feat: ジョブサマリに導入結果を出力（NFR-5） by @yk-lab in https://github.com/yk-lab/setup-task/pull/50 feat: リトライ回数・間隔を input 化（FR-4） by @yk-lab in https://github.com/yk-lab/setup-task/pull/51 chore: 重複した checksum 改ざんテストを統合（#43） by @yk-lab in https://github.com/yk-lab/setup-task/pull/52 feat: 取得ホスト/リダイレクト先を検証（NFR-1） by @yk-lab in https://github.com/yk-lab/setup-task/pull/53 feat: proxy 環境で全 fetch を proxy 経由にする（#54） by @yk-lab in https://github.com/yk-lab/setup-task/pull/57 docs: テスト規約を stub-fetch unit test の実態に合わせる（#55） by @yk-lab in https://github.com/yk-lab/setup-task/pull/58 ci: paths-filter で root 直下の .md も docs 扱いにする（#59） by @yk-lab in https://github.com/yk-lab/setup-task/pull/60 feat: 取得ボディにサイズ上限とタイムアウトを設ける（#56） by @yk-lab in https://github.com/yk-lab/setup-task/pull/61 test: platform.test.ts を §9 全 os/arch 組合せに拡張（#41） by @yk-lab in https://github.com/yk-lab/setup-task/pull/62 ci: ワークフロー静的解析（actionlint / zizmor）を追加（#23） by @yk-lab in https://github.com/yk-lab/setup-task/pull/68 build(deps): Bump dorny/paths-filter from 3.0.2 to 4.0.1 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/64 chore: ESLint から Biome へ一元化（#45） by @yk-lab in https://github.com/yk-lab/setup-task/pull/70 build(deps): Bump crate-ci/typos from 1.31.1 to 1.47.2 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/63 build(deps): Bump semver from 7.8.4 to 7.8.5 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/67 docs: 移行ガイド拡充 + セキュア路線へポジショニング見直し（#38 / #73） by @yk-lab in https://github.com/yk-lab/setup-task/pull/72 chore: lefthook で pre-push に CI 相当チェックを仕込む（#9） by @yk-lab in https://github.com/yk-lab/setup-task/pull/71 chore: TODO.md を GitHub Issues へのポインタに極小化 by @yk-lab in https://github.com/yk-lab/setup-task/pull/74 build(deps): Bump undici from 6.27.0 to 8.5.0 by @dependabot[bot] in https://github.com/yk-lab/setup-task/pull/65 feat: リリース自動化ワークフローを追加（#37） by @yk-lab in https://github.com/yk-lab/setup-task/pull/75 fix: action 名を Marketplace で一意な “Setup go-task” に変更 by @yk-lab in https://github.com/yk-lab/setup-task/pull/76 chore: action 名を “Install Task” に変更（Marketplace 一意性） by @yk-lab in https://github.com/yk-lab/setup-task/pull/77 New Contributors @yk-lab made their first contribution in https://github.com/yk-lab/setup-task/pull/6 @dependabot[bot] made their first contribution in https://github.com/yk-lab/setup-task/pull/19 Full Changelog: https://github.com/yk-lab/setup-task/commits/v1.0.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yk-lab/setup-task">https://github.com/yk-lab/setup-task</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-task">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: setup-task GitHub Action の初回実装 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/6">https://github.com/yk-lab/setup-task/pull/6</a></li>
<li>docs: コミュニティヘルスファイルを追加 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/17">https://github.com/yk-lab/setup-task/pull/17</a></li>
<li>docs: README にステータスバッジを追加 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/20">https://github.com/yk-lab/setup-task/pull/20</a></li>
<li>build(deps): Bump vite and vitest by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/19">https://github.com/yk-lab/setup-task/pull/19</a></li>
<li>build(deps): Bump esbuild and vitest by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/18">https://github.com/yk-lab/setup-task/pull/18</a></li>
<li>build(deps): Bump actions/setup-node from 4 to 6 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/10">https://github.com/yk-lab/setup-task/pull/10</a></li>
<li>build(deps-dev): Bump @eslint/js from 9.39.4 to 10.0.1 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/15">https://github.com/yk-lab/setup-task/pull/15</a></li>
<li>build(deps-dev): Bump vitest from 2.1.9 to 4.1.9 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/14">https://github.com/yk-lab/setup-task/pull/14</a></li>
<li>build(deps): Bump actions/checkout from 4 to 6 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/11">https://github.com/yk-lab/setup-task/pull/11</a></li>
<li>build(deps-dev): Bump eslint from 9.39.4 to 10.5.0 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/13">https://github.com/yk-lab/setup-task/pull/13</a></li>
<li>ci: GitHub Actions を SHA ピンに固定 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/21">https://github.com/yk-lab/setup-task/pull/21</a></li>
<li>build(deps): Bump the actions-toolkit group across 1 directory with 2 updates by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/12">https://github.com/yk-lab/setup-task/pull/12</a></li>
<li>build(deps-dev): Bump @vercel/ncc from 0.38.4 to 0.44.0 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/16">https://github.com/yk-lab/setup-task/pull/16</a></li>
<li>fix(security): repo-token を core.setSecret でマスクする by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/24">https://github.com/yk-lab/setup-task/pull/24</a></li>
<li>test: withRetry のユニットテストを追加する by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/25">https://github.com/yk-lab/setup-task/pull/25</a></li>
<li>test: fetchJson の content-type ガードと createReleaseApi を検証 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/26">https://github.com/yk-lab/setup-task/pull/26</a></li>
<li>test: checksum 改ざん検出の統合テストと self-test 強化 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/27">https://github.com/yk-lab/setup-task/pull/27</a></li>
<li>ci: Codecov でカバレッジ/テスト結果を OIDC アップロードする by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/28">https://github.com/yk-lab/setup-task/pull/28</a></li>
<li>test: cache-hit 経路の self-test を追加する by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/29">https://github.com/yk-lab/setup-task/pull/29</a></li>
<li>fix: レンジ指定で tool-cache を GitHub 解決より優先する by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/30">https://github.com/yk-lab/setup-task/pull/30</a></li>
<li>chore: パッケージマネージャを npm から pnpm へ移行 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/34">https://github.com/yk-lab/setup-task/pull/34</a></li>
<li>build(deps): Bump actions/checkout from 6.0.3 to 7.0.0 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/31">https://github.com/yk-lab/setup-task/pull/31</a></li>
<li>build(deps-dev): Bump typescript from 5.9.3 to 6.0.3 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/32">https://github.com/yk-lab/setup-task/pull/32</a></li>
<li>build(deps-dev): @types/node を ^24 に揃える by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/35">https://github.com/yk-lab/setup-task/pull/35</a></li>
<li>chore: dist/ を main から外しリリース時ビルド方式へ by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/36">https://github.com/yk-lab/setup-task/pull/36</a></li>
<li>ci: Codecov PR コメントを有効化 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/46">https://github.com/yk-lab/setup-task/pull/46</a></li>
<li>ci: Codecov PR コメントをカバレッジ変動時のみ表示 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/47">https://github.com/yk-lab/setup-task/pull/47</a></li>
<li>docs: TODO.md から完了した #8 を移動 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/48">https://github.com/yk-lab/setup-task/pull/48</a></li>
<li>ci: .md のみ変更時は重い CI をスキップしつつ required check を維持 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/49">https://github.com/yk-lab/setup-task/pull/49</a></li>
<li>feat: ジョブサマリに導入結果を出力（NFR-5） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/50">https://github.com/yk-lab/setup-task/pull/50</a></li>
<li>feat: リトライ回数・間隔を input 化（FR-4） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/51">https://github.com/yk-lab/setup-task/pull/51</a></li>
<li>chore: 重複した checksum 改ざんテストを統合（#43） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/52">https://github.com/yk-lab/setup-task/pull/52</a></li>
<li>feat: 取得ホスト/リダイレクト先を検証（NFR-1） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/53">https://github.com/yk-lab/setup-task/pull/53</a></li>
<li>feat: proxy 環境で全 fetch を proxy 経由にする（#54） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/57">https://github.com/yk-lab/setup-task/pull/57</a></li>
<li>docs: テスト規約を stub-fetch unit test の実態に合わせる（#55） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/58">https://github.com/yk-lab/setup-task/pull/58</a></li>
<li>ci: paths-filter で root 直下の .md も docs 扱いにする（#59） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/60">https://github.com/yk-lab/setup-task/pull/60</a></li>
<li>feat: 取得ボディにサイズ上限とタイムアウトを設ける（#56） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/61">https://github.com/yk-lab/setup-task/pull/61</a></li>
<li>test: platform.test.ts を §9 全 os/arch 組合せに拡張（#41） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/62">https://github.com/yk-lab/setup-task/pull/62</a></li>
<li>ci: ワークフロー静的解析（actionlint / zizmor）を追加（#23） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/68">https://github.com/yk-lab/setup-task/pull/68</a></li>
<li>build(deps): Bump dorny/paths-filter from 3.0.2 to 4.0.1 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/64">https://github.com/yk-lab/setup-task/pull/64</a></li>
<li>chore: ESLint から Biome へ一元化（#45） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/70">https://github.com/yk-lab/setup-task/pull/70</a></li>
<li>build(deps): Bump crate-ci/typos from 1.31.1 to 1.47.2 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/63">https://github.com/yk-lab/setup-task/pull/63</a></li>
<li>build(deps): Bump semver from 7.8.4 to 7.8.5 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/67">https://github.com/yk-lab/setup-task/pull/67</a></li>
<li>docs: 移行ガイド拡充 + セキュア路線へポジショニング見直し（#38 / #73） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/72">https://github.com/yk-lab/setup-task/pull/72</a></li>
<li>chore: lefthook で pre-push に CI 相当チェックを仕込む（#9） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/71">https://github.com/yk-lab/setup-task/pull/71</a></li>
<li>chore: TODO.md を GitHub Issues へのポインタに極小化 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/74">https://github.com/yk-lab/setup-task/pull/74</a></li>
<li>build(deps): Bump undici from 6.27.0 to 8.5.0 by @dependabot[bot] in <a href="https://github.com/yk-lab/setup-task/pull/65">https://github.com/yk-lab/setup-task/pull/65</a></li>
<li>feat: リリース自動化ワークフローを追加（#37） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/75">https://github.com/yk-lab/setup-task/pull/75</a></li>
<li>fix: action 名を Marketplace で一意な &ldquo;Setup go-task&rdquo; に変更 by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/76">https://github.com/yk-lab/setup-task/pull/76</a></li>
<li>chore: action 名を &ldquo;Install Task&rdquo; に変更（Marketplace 一意性） by @yk-lab in <a href="https://github.com/yk-lab/setup-task/pull/77">https://github.com/yk-lab/setup-task/pull/77</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@yk-lab made their first contribution in <a href="https://github.com/yk-lab/setup-task/pull/6">https://github.com/yk-lab/setup-task/pull/6</a></li>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/yk-lab/setup-task/pull/19">https://github.com/yk-lab/setup-task/pull/19</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yk-lab/setup-task/commits/v1.0.2">https://github.com/yk-lab/setup-task/commits/v1.0.2</a></p>
]]></content:encoded></item><item><title>MCP Admit admission scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/mcp-admit-admission-scan/</link><pubDate>Sun, 12 Jul 2026 14:52:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/mcp-admit-admission-scan/</guid><description>Version updated for https://github.com/aolune/mcp-admit to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed MCP Admit v0.3.0 is the first public release of a static-first, no-exec-by-default admission gate for MCP servers and agent tools.
Highlights Approval-aware admission decisions and explicit approval workflows Static scanning without executing MCP servers Toxic-flow composition detection MCP Registry metadata and supply-chain checks Risk scoring and explainable policy recommendations JSON, Markdown and SARIF reports Inventory, discovery, review packs and GitHub Actions integration Security properties Scanned MCP commands are not executed by default Secret values are redacted from reports Definition and capability drift require renewed approval Explicit approval cannot override deny or quarantine decisions Breaking changes Renamed mcp-guard to mcp-admit Renamed the admission command to decide Migrated schemas and baselines to the mcp-admit.* namespace Install from GitHub pipx install &amp;#34;git+https://github.com/aolune/mcp-admit.git@v0.3.0&amp;#34; Or run without installation:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/aolune/mcp-admit">https://github.com/aolune/mcp-admit</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcp-admit-admission-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>MCP Admit v0.3.0 is the first public release of a static-first,
no-exec-by-default admission gate for MCP servers and agent tools.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Approval-aware admission decisions and explicit approval workflows</li>
<li>Static scanning without executing MCP servers</li>
<li>Toxic-flow composition detection</li>
<li>MCP Registry metadata and supply-chain checks</li>
<li>Risk scoring and explainable policy recommendations</li>
<li>JSON, Markdown and SARIF reports</li>
<li>Inventory, discovery, review packs and GitHub Actions integration</li>
</ul>
<h2 id="security-properties">Security properties</h2>
<ul>
<li>Scanned MCP commands are not executed by default</li>
<li>Secret values are redacted from reports</li>
<li>Definition and capability drift require renewed approval</li>
<li>Explicit approval cannot override deny or quarantine decisions</li>
</ul>
<h2 id="breaking-changes">Breaking changes</h2>
<ul>
<li>Renamed <code>mcp-guard</code> to <code>mcp-admit</code></li>
<li>Renamed the <code>admission</code> command to <code>decide</code></li>
<li>Migrated schemas and baselines to the <code>mcp-admit.*</code> namespace</li>
</ul>
<h2 id="install-from-github">Install from GitHub</h2>
<pre tabindex="0"><code>pipx install &#34;git+https://github.com/aolune/mcp-admit.git@v0.3.0&#34;
</code></pre><p>Or run without installation:</p>
<pre tabindex="0"><code>uvx --from &#34;git+https://github.com/aolune/mcp-admit.git@v0.3.0&#34; mcp-admit --version
</code></pre><p>See <a href="https://github.com/aolune/mcp-admit/blob/main/CHANGELOG.md">CHANGELOG.md</a> for the complete release notes.</p>
]]></content:encoded></item><item><title>ZeroFS Volume</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/zerofs-volume/</link><pubDate>Sun, 12 Jul 2026 14:51:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/zerofs-volume/</guid><description>Version updated for https://github.com/Barre/ZeroFS to version v2.0.10.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Refactor and harden deterministic simulation tests by @Barre in https://github.com/Barre/ZeroFS/pull/529 Retry transient storage compatibility checks by @Barre in https://github.com/Barre/ZeroFS/pull/530 Make graceful shutdown seal, flush, and close atomically by @Barre in https://github.com/Barre/ZeroFS/pull/535 Add fallocate support to FUSE client by @Barre in https://github.com/Barre/ZeroFS/pull/534 Migrate webui to shared client by @Barre in https://github.com/Barre/ZeroFS/pull/536 Full Changelog: https://github.com/Barre/ZeroFS/compare/v2.0.9...v2.0.10</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Barre/ZeroFS">https://github.com/Barre/ZeroFS</a></strong> to version <strong>v2.0.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zerofs-volume">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Refactor and harden deterministic simulation tests by @Barre in <a href="https://github.com/Barre/ZeroFS/pull/529">https://github.com/Barre/ZeroFS/pull/529</a></li>
<li>Retry transient storage compatibility checks by @Barre in <a href="https://github.com/Barre/ZeroFS/pull/530">https://github.com/Barre/ZeroFS/pull/530</a></li>
<li>Make graceful shutdown seal, flush, and close atomically by @Barre in <a href="https://github.com/Barre/ZeroFS/pull/535">https://github.com/Barre/ZeroFS/pull/535</a></li>
<li>Add fallocate support to FUSE client by @Barre in <a href="https://github.com/Barre/ZeroFS/pull/534">https://github.com/Barre/ZeroFS/pull/534</a></li>
<li>Migrate webui to shared client by @Barre in <a href="https://github.com/Barre/ZeroFS/pull/536">https://github.com/Barre/ZeroFS/pull/536</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Barre/ZeroFS/compare/v2.0.9...v2.0.10">https://github.com/Barre/ZeroFS/compare/v2.0.9...v2.0.10</a></p>
]]></content:encoded></item><item><title>makepkg for ArchLinux - Build and Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/makepkg-for-archlinux-build-and-check/</link><pubDate>Sun, 12 Jul 2026 14:50:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/makepkg-for-archlinux-build-and-check/</guid><description>Version updated for https://github.com/bodsch/pkgbuild-action to version v2.0.2.
This action is used across all versions by 3 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/bodsch/pkgbuild-action/compare/v2.0.1...v2.0.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/bodsch/pkgbuild-action">https://github.com/bodsch/pkgbuild-action</a></strong> to version <strong>v2.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/makepkg-for-archlinux-build-and-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/bodsch/pkgbuild-action/compare/v2.0.1...v2.0.2">https://github.com/bodsch/pkgbuild-action/compare/v2.0.1...v2.0.2</a></p>
]]></content:encoded></item><item><title>Capawesome Cloud Build Action for GitHub Actions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/capawesome-cloud-build-action-for-github-actions/</link><pubDate>Sun, 12 Jul 2026 14:50:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/capawesome-cloud-build-action-for-github-actions/</guid><description>Version updated for https://github.com/capawesome-team/cloud-build-action to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed https://github.com/capawesome-team/cloud-build-action/blob/main/CHANGELOG.md#011-2026-07-12</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/capawesome-team/cloud-build-action">https://github.com/capawesome-team/cloud-build-action</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/capawesome-cloud-build-action-for-github-actions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><a href="https://github.com/capawesome-team/cloud-build-action/blob/main/CHANGELOG.md#011-2026-07-12">https://github.com/capawesome-team/cloud-build-action/blob/main/CHANGELOG.md#011-2026-07-12</a></p>
]]></content:encoded></item><item><title>Outcome Receipts Verify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/outcome-receipts-verify/</link><pubDate>Sun, 12 Jul 2026 14:49:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/outcome-receipts-verify/</guid><description>Version updated for https://github.com/ChelseaKR/outcome-receipts to version v0.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First beta release of the offline-first reporting trust chain.
What ships deterministic SQLite metric computation with a receipt for every figure fail-closed numeric grounding before and after suppression CMS-modeled small-cell and complementary suppression controls mandatory human approval before export funder-readable trace view, machine-readable receipts, sealed bundles, and a hash-chained ledger fail-closed metric-mapping review queue for anonymized schemas English and Spanish report output optional policy-gated Bedrock prose drafting, off by default reusable GitHub Action for receipt-drift verification Start here Run the five-minute synthetic housing demo: https://github.com/ChelseaKR/outcome-receipts/blob/main/docs/TRY_THE_DEMO.md</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ChelseaKR/outcome-receipts">https://github.com/ChelseaKR/outcome-receipts</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/outcome-receipts-verify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First beta release of the offline-first reporting trust chain.</p>
<h2 id="what-ships">What ships</h2>
<ul>
<li>deterministic SQLite metric computation with a receipt for every figure</li>
<li>fail-closed numeric grounding before and after suppression</li>
<li>CMS-modeled small-cell and complementary suppression controls</li>
<li>mandatory human approval before export</li>
<li>funder-readable trace view, machine-readable receipts, sealed bundles, and a hash-chained ledger</li>
<li>fail-closed metric-mapping review queue for anonymized schemas</li>
<li>English and Spanish report output</li>
<li>optional policy-gated Bedrock prose drafting, off by default</li>
<li>reusable GitHub Action for receipt-drift verification</li>
</ul>
<h2 id="start-here">Start here</h2>
<p>Run the five-minute synthetic housing demo:
<a href="https://github.com/ChelseaKR/outcome-receipts/blob/main/docs/TRY_THE_DEMO.md">https://github.com/ChelseaKR/outcome-receipts/blob/main/docs/TRY_THE_DEMO.md</a></p>
<p>The normal path is network-free and has no runtime dependencies. The release passed 327 tests with 94.68% branch coverage. Wheel, source distribution, SHA256SUMS, and a CycloneDX SBOM are attached. Build provenance and the SBOM are signed through GitHub artifact attestations.</p>
<h2 id="important-boundaries">Important boundaries</h2>
<p>The model never supplies report figures. The included suppression defaults are a demonstration policy, not a compliance determination for a specific report. Do not post service rows or client identifiers in public feedback.</p>
<p>See CHANGELOG.md for the detailed history and SECURITY.md for the supported-version policy.</p>
]]></content:encoded></item><item><title>Dazbos Gemini Review &amp; Triage</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/dazbos-gemini-review-triage/</link><pubDate>Sun, 12 Jul 2026 14:49:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/dazbos-gemini-review-triage/</guid><description>Version updated for https://github.com/derailed-dash/gemini-review-action to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 🔎 Dazbo’s Gemini Review &amp;amp; Triage Action Automated, Google Gemini-based Pull Request reviews and Issue Triaging for all your GitHub repositories and CI/CD pipelines.
[!IMPORTANT] Migrating from deprecated Gemini tools? This action is built as a direct, drop-in replacement for run-gemini-cli, as well as any workflows previously built on the deprecated Gemini CLI or Gemini Agent Assist products.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/derailed-dash/gemini-review-action">https://github.com/derailed-dash/gemini-review-action</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/dazbo-s-gemini-review-triage">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-dazbos-gemini-review--triage-action">🔎 Dazbo&rsquo;s Gemini Review &amp; Triage Action</h2>
<p>Automated, Google Gemini-based Pull Request reviews and Issue Triaging for all your GitHub repositories and CI/CD pipelines.</p>
<blockquote>
<p>[!IMPORTANT]
<strong>Migrating from deprecated Gemini tools?</strong> This action is built as a direct, drop-in replacement for <strong><code>run-gemini-cli</code></strong>, as well as any workflows previously built on the deprecated <strong>Gemini CLI</strong> or <strong>Gemini Agent Assist</strong> products.</p>
</blockquote>
<h3 id="key-features">Key Features</h3>
<ul>
<li>🚀 <strong>Drop-in Migration:</strong> Fully compatible replacement for legacy <code>run-gemini-cli</code> workflows.</li>
<li>🧠 <strong>AI-Powered Code Reviews:</strong> Automated, constructive line-specific feedback on Pull Requests using Google Gemini (Gemini 3.5 Flash by default).</li>
<li>🌍 <strong>Configurable Language:</strong> Get review comments written in your preferred language (defaults to <code>English (UK)</code>).</li>
<li>🏷️ <strong>Automated Issue Triage:</strong> Dynamically labels, prioritizes, and categorizes incoming issues based on their title and body context.</li>
<li>🔒 <strong>Enterprise-Grade Security:</strong> Supports flexible authentication via either a Gemini API Key (from AI Studio) or Google Cloud Workload Identity Federation (WIF).</li>
<li>💬 <strong>Interactive Suggestions:</strong> Formats code recommendations inside native GitHub <code>```suggestion</code> blocks for one-click merge applications on Pull Requests.</li>
<li>🛠️ <strong>Customisable Prompts:</strong> Supports repository-specific overrides for both reviews and triaging via simple TOML config files.</li>
</ul>
<h3 id="getting-started">Getting Started</h3>
<p>To add this Action to your repository workflow, please check the step-by-step setup guides and configuration options in the <a href="https://github.com/derailed-dash/gemini-review-action#readme">project&rsquo;s README</a>.</p>
]]></content:encoded></item><item><title>Fork Shepherd</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/fork-shepherd/</link><pubDate>Sun, 12 Jul 2026 14:48:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/fork-shepherd/</guid><description>Version updated for https://github.com/FasterApiWeb/fork-shepherd to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/FasterApiWeb/fork-shepherd/compare/v1...v1.1.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/FasterApiWeb/fork-shepherd">https://github.com/FasterApiWeb/fork-shepherd</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/fork-shepherd">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/FasterApiWeb/fork-shepherd/compare/v1...v1.1.1">https://github.com/FasterApiWeb/fork-shepherd/compare/v1...v1.1.1</a></p>
]]></content:encoded></item><item><title>Signal Diff Crawl</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/signal-diff-crawl/</link><pubDate>Sun, 12 Jul 2026 14:48:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/signal-diff-crawl/</guid><description>Version updated for https://github.com/funkysi1701/signal-diff-action to version v1.10.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/funkysi1701/signal-diff-action/compare/v1.9...v1.10</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/funkysi1701/signal-diff-action">https://github.com/funkysi1701/signal-diff-action</a></strong> to version <strong>v1.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/signal-diff-crawl">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/funkysi1701/signal-diff-action/compare/v1.9...v1.10">https://github.com/funkysi1701/signal-diff-action/compare/v1.9...v1.10</a></p>
]]></content:encoded></item><item><title>Poolsim Capacity Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/poolsim-capacity-gate/</link><pubDate>Sun, 12 Jul 2026 14:47:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/poolsim-capacity-gate/</guid><description>Version updated for https://github.com/gregorian-09/poolsim-capacity-gate to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Poolsim Capacity Gate v0.3.0 poolsim-capacity-gate is a GitHub Action for backend teams that want connection-pool sizing checks in CI. It installs poolsim-cli, runs poolsim gate, prints the JSON gate report, and fails the workflow when your configured policy says the current traffic, latency, or pool assumptions are unsafe.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/gregorian-09/poolsim-capacity-gate">https://github.com/gregorian-09/poolsim-capacity-gate</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/poolsim-capacity-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="poolsim-capacity-gate-v030">Poolsim Capacity Gate v0.3.0</h2>
<p><code>poolsim-capacity-gate</code> is a GitHub Action for backend teams that want connection-pool sizing checks in CI. It installs <code>poolsim-cli</code>, runs <code>poolsim gate</code>, prints the JSON gate report, and fails the workflow when your configured policy says the current traffic, latency, or pool assumptions are unsafe.</p>
<p>Use this action when connection-pool changes should be reviewed with the same discipline as schema changes, replica-count changes, database <code>max_connections</code> changes, or production traffic assumptions.</p>
<h2 id="why-this-exists">Why This Exists</h2>
<p>Connection pools are easy to mis-size:</p>
<ul>
<li>A pool that is too small can increase queue wait and p99 latency under load.</li>
<li>A pool that is too large can waste database connections and starve other services.</li>
<li>A change that is safe at normal traffic can become unsafe at peak or incident traffic.</li>
<li>A CI review often sees a numeric pool setting but not the queueing risk behind it.</li>
</ul>
<p>Poolsim turns those assumptions into a repeatable capacity gate. This action makes that gate easy to run on pull requests and deployment pipelines.</p>
<h2 id="what-the-action-does">What The Action Does</h2>
<ul>
<li>Installs a pinned <code>poolsim-cli</code> version from crates.io.</li>
<li>Runs <code>poolsim --format json gate</code>.</li>
<li>Supports checked-in telemetry config files with <code>source: telemetry</code>.</li>
<li>Supports captured Prometheus response bundles with <code>source: prometheus</code>.</li>
<li>Uses a TOML capacity policy to decide whether the pool assumptions are safe.</li>
<li>Fails the GitHub Actions job when the gate policy fails.</li>
<li>Leaves application code, deployment manifests, database settings, and runtime pool settings unchanged.</li>
</ul>
<p>This is a CI guard. It is not a runtime pool implementation and not a runtime enforcer.</p>
<h2 id="whats-included-in-v030">What&rsquo;s Included In v0.3.0</h2>
<ul>
<li>First Marketplace-ready release of the action.</li>
<li>Default <code>poolsim-cli</code> version set to <code>0.3.0</code>.</li>
<li>Telemetry-source support for existing Poolsim telemetry JSON/TOML files.</li>
<li>Prometheus-response-file support for offline Prometheus query snapshots.</li>
<li>Configurable policy path, service name, observation window, current pool size, server connection cap, connection overhead, and candidate size bounds.</li>
<li><code>extra-args</code> input for controlled advanced <code>poolsim gate</code> flags.</li>
<li>Detailed README usage examples for telemetry and Prometheus workflows.</li>
</ul>
<h2 id="quick-start-telemetry-config">Quick Start: Telemetry Config</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">Capacity Gate</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">on</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">push</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">branches</span>: [<span style="color:#ae81ff">main]</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">poolsim</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">dtolnay/rust-toolchain@stable</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">gregorian-09/poolsim-capacity-gate@v0.3.0</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">version</span>: <span style="color:#e6db74">&#34;0.3.0&#34;</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">policy</span>: <span style="color:#ae81ff">capacity-policy.toml</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">source</span>: <span style="color:#ae81ff">telemetry</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">telemetry-config</span>: <span style="color:#ae81ff">telemetry.json</span>
</span></span></code></pre></div><p>Equivalent CLI command:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>poolsim --format json gate <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  --policy capacity-policy.toml <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  telemetry <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  --config telemetry.json
</span></span></code></pre></div><h2 id="quick-start-prometheus-response-file">Quick Start: Prometheus Response File</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">Capacity Gate</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">on</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">poolsim</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">dtolnay/rust-toolchain@stable</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">gregorian-09/poolsim-capacity-gate@v0.3.0</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">version</span>: <span style="color:#e6db74">&#34;0.3.0&#34;</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">policy</span>: <span style="color:#ae81ff">capacity-policy.toml</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">source</span>: <span style="color:#ae81ff">prometheus</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">prometheus-response-file</span>: <span style="color:#ae81ff">prometheus-responses.json</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">service-name</span>: <span style="color:#ae81ff">checkout-api</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">window</span>: <span style="color:#ae81ff">5m</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">current-pool-size</span>: <span style="color:#e6db74">&#34;8&#34;</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">max-server-connections</span>: <span style="color:#e6db74">&#34;100&#34;</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">connection-overhead-ms</span>: <span style="color:#e6db74">&#34;2&#34;</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">min</span>: <span style="color:#e6db74">&#34;2&#34;</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">max</span>: <span style="color:#e6db74">&#34;20&#34;</span>
</span></span></code></pre></div><p>Equivalent CLI command:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>poolsim --format json gate <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  --policy capacity-policy.toml <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  prometheus <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  --response-file prometheus-responses.json <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  --service-name checkout-api <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  --window 5m <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  --current-pool-size <span style="color:#ae81ff">8</span> <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  --max-server-connections <span style="color:#ae81ff">100</span> <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  --connection-overhead-ms <span style="color:#ae81ff">2</span> <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  --min <span style="color:#ae81ff">2</span> <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>  --max <span style="color:#ae81ff">20</span>
</span></span></code></pre></div><h2 id="inputs">Inputs</h2>
<table>
  <thead>
      <tr>
          <th>Input</th>
          <th>Required</th>
          <th>Default</th>
          <th>Description</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>version</code></td>
          <td>No</td>
          <td><code>0.3.0</code></td>
          <td><code>poolsim-cli</code> version to install from crates.io. Pin this for reproducible CI.</td>
      </tr>
      <tr>
          <td><code>policy</code></td>
          <td>Yes</td>
          <td>none</td>
          <td>Path to the Poolsim gate policy TOML file.</td>
      </tr>
      <tr>
          <td><code>source</code></td>
          <td>No</td>
          <td><code>telemetry</code></td>
          <td>Input source kind. Supported values: <code>telemetry</code> and <code>prometheus</code>.</td>
      </tr>
      <tr>
          <td><code>telemetry-config</code></td>
          <td>Required for <code>source=telemetry</code></td>
          <td>empty</td>
          <td>Path to a Poolsim telemetry JSON or TOML config file.</td>
      </tr>
      <tr>
          <td><code>prometheus-response-file</code></td>
          <td>Required for <code>source=prometheus</code></td>
          <td>empty</td>
          <td>Path to captured Prometheus query responses.</td>
      </tr>
      <tr>
          <td><code>service-name</code></td>
          <td>No</td>
          <td><code>service</code></td>
          <td>Service name used for Prometheus-derived reports.</td>
      </tr>
      <tr>
          <td><code>window</code></td>
          <td>No</td>
          <td><code>5m</code></td>
          <td>Observation window label used for Prometheus-derived reports.</td>
      </tr>
      <tr>
          <td><code>current-pool-size</code></td>
          <td>No</td>
          <td><code>8</code></td>
          <td>Current configured pool size for Prometheus-derived reports.</td>
      </tr>
      <tr>
          <td><code>max-server-connections</code></td>
          <td>No</td>
          <td><code>100</code></td>
          <td>Database connection cap visible to this service.</td>
      </tr>
      <tr>
          <td><code>connection-overhead-ms</code></td>
          <td>No</td>
          <td><code>0</code></td>
          <td>Connection overhead assumption in milliseconds.</td>
      </tr>
      <tr>
          <td><code>min</code></td>
          <td>No</td>
          <td><code>2</code></td>
          <td>Minimum candidate pool size.</td>
      </tr>
      <tr>
          <td><code>max</code></td>
          <td>No</td>
          <td><code>20</code></td>
          <td>Maximum candidate pool size.</td>
      </tr>
      <tr>
          <td><code>extra-args</code></td>
          <td>No</td>
          <td>empty</td>
          <td>Additional arguments inserted after <code>--policy</code> and before the gate source subcommand. Keep this controlled by maintainers.</td>
      </tr>
  </tbody>
</table>
<h2 id="gate-policy-example">Gate Policy Example</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-toml" data-lang="toml"><span style="display:flex;"><span><span style="color:#a6e22e">max_saturation</span> = <span style="color:#e6db74">&#34;Warning&#34;</span>
</span></span><span style="display:flex;"><span><span style="color:#a6e22e">max_pool_increase_percent</span> = <span style="color:#ae81ff">100</span>
</span></span><span style="display:flex;"><span><span style="color:#a6e22e">max_additional_connections</span> = <span style="color:#ae81ff">10</span>
</span></span><span style="display:flex;"><span><span style="color:#a6e22e">max_recommended_pool_size</span> = <span style="color:#ae81ff">20</span>
</span></span><span style="display:flex;"><span><span style="color:#a6e22e">max_recommended_p99_queue_wait_ms</span> = <span style="color:#ae81ff">80</span>
</span></span><span style="display:flex;"><span><span style="color:#a6e22e">max_recommended_mean_queue_wait_ms</span> = <span style="color:#ae81ff">20</span>
</span></span><span style="display:flex;"><span><span style="color:#a6e22e">max_recommended_rho</span> = <span style="color:#ae81ff">0.90</span>
</span></span><span style="display:flex;"><span><span style="color:#a6e22e">max_current_p99_queue_wait_ms</span> = <span style="color:#ae81ff">100</span>
</span></span><span style="display:flex;"><span><span style="color:#a6e22e">max_current_mean_queue_wait_ms</span> = <span style="color:#ae81ff">25</span>
</span></span><span style="display:flex;"><span><span style="color:#a6e22e">max_current_rho</span> = <span style="color:#ae81ff">0.95</span>
</span></span></code></pre></div><p>The policy file defines what your team considers safe. If Poolsim predicts a recommendation or current pool state outside those limits, the action fails the job.</p>
<h2 id="telemetry-config-example">Telemetry Config Example</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-json" data-lang="json"><span style="display:flex;"><span>{
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">&#34;telemetry&#34;</span>: {
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">&#34;service_name&#34;</span>: <span style="color:#e6db74">&#34;checkout-api&#34;</span>,
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">&#34;window&#34;</span>: <span style="color:#e6db74">&#34;1h&#34;</span>,
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">&#34;observed_at&#34;</span>: <span style="color:#e6db74">&#34;2026-05-15T10:00:00Z&#34;</span>,
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">&#34;current_pool_size&#34;</span>: <span style="color:#ae81ff">8</span>,
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">&#34;workload&#34;</span>: {
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">&#34;requests_per_second&#34;</span>: <span style="color:#ae81ff">180.0</span>,
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">&#34;latency_p50_ms&#34;</span>: <span style="color:#ae81ff">8.0</span>,
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">&#34;latency_p95_ms&#34;</span>: <span style="color:#ae81ff">30.0</span>,
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">&#34;latency_p99_ms&#34;</span>: <span style="color:#ae81ff">70.0</span>
</span></span><span style="display:flex;"><span>    },
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">&#34;pool&#34;</span>: {
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">&#34;max_server_connections&#34;</span>: <span style="color:#ae81ff">100</span>,
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">&#34;connection_overhead_ms&#34;</span>: <span style="color:#ae81ff">2.0</span>,
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">&#34;idle_timeout_ms&#34;</span>: <span style="color:#ae81ff">120000</span>,
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">&#34;min_pool_size&#34;</span>: <span style="color:#ae81ff">2</span>,
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">&#34;max_pool_size&#34;</span>: <span style="color:#ae81ff">20</span>
</span></span><span style="display:flex;"><span>    }
</span></span><span style="display:flex;"><span>  },
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">&#34;options&#34;</span>: {
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">&#34;iterations&#34;</span>: <span style="color:#ae81ff">1200</span>,
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">&#34;seed&#34;</span>: <span style="color:#ae81ff">9</span>,
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">&#34;distribution&#34;</span>: <span style="color:#e6db74">&#34;LogNormal&#34;</span>,
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">&#34;queue_model&#34;</span>: <span style="color:#e6db74">&#34;MMC&#34;</span>,
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">&#34;target_wait_p99_ms&#34;</span>: <span style="color:#ae81ff">40.0</span>,
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">&#34;max_acceptable_rho&#34;</span>: <span style="color:#ae81ff">0.85</span>
</span></span><span style="display:flex;"><span>  }
</span></span><span style="display:flex;"><span>}
</span></span></code></pre></div><h2 id="exit-behavior">Exit Behavior</h2>
<p>The action follows <code>poolsim gate</code> behavior:</p>
<ul>
<li>Exit <code>0</code>: policy passed and the assumptions are considered safe.</li>
<li>Non-zero exit: policy failed, inputs were invalid, or the CLI could not run.</li>
</ul>
<p>A non-zero exit is not necessarily an action bug. It usually means Poolsim found capacity assumptions that violate your policy. Review the JSON output in the workflow logs to see which check failed.</p>
<h2 id="recommended-ci-pattern">Recommended CI Pattern</h2>
<p>Run this action on pull requests that change:</p>
<ul>
<li>service pool configuration,</li>
<li>traffic assumptions,</li>
<li>latency assumptions,</li>
<li>database connection budgets,</li>
<li>deployment replica counts,</li>
<li>telemetry fixtures used for capacity planning,</li>
<li>capacity policy files.</li>
</ul>
<p>Example path-filtered workflow:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">on</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">paths</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#e6db74">&#34;capacity/**&#34;</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#e6db74">&#34;deploy/**&#34;</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#e6db74">&#34;telemetry/**&#34;</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#e6db74">&#34;.github/workflows/capacity.yml&#34;</span>
</span></span></code></pre></div><h2 id="security-notes">Security Notes</h2>
<ul>
<li>Do not put database passwords or application secrets in telemetry files.</li>
<li>Treat Prometheus exports as internal operational data.</li>
<li>Pin <code>version</code> for reproducible CI.</li>
<li>Review policy changes like production configuration changes.</li>
<li>Keep <code>extra-args</code> controlled by repository maintainers, not untrusted contributors.</li>
<li>Prefer running this on trusted pull request contexts when capacity files may contain sensitive operational data.</li>
</ul>
<h2 id="troubleshooting">Troubleshooting</h2>
<h3 id="cargo-command-not-found"><code>cargo: command not found</code></h3>
<p>Install Rust before the action:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">dtolnay/rust-toolchain@stable</span>
</span></span></code></pre></div><h3 id="telemetry-config-is-required-when-sourcetelemetry"><code>telemetry-config is required when source=telemetry</code></h3>
<p>Set <code>telemetry-config</code>, or switch to <code>source: prometheus</code>.</p>
<h3 id="prometheus-response-file-is-required-when-sourceprometheus"><code>prometheus-response-file is required when source=prometheus</code></h3>
<p>Set <code>prometheus-response-file</code>, or switch to <code>source: telemetry</code>.</p>
<h3 id="source-must-be-telemetry-or-prometheus"><code>source must be telemetry or prometheus</code></h3>
<p>The only supported source values are <code>telemetry</code> and <code>prometheus</code>.</p>
<h3 id="the-gate-failed-but-the-action-installed-and-ran-correctly">The gate failed, but the action installed and ran correctly</h3>
<p>That means the capacity policy failed. Inspect the JSON report in the action logs and either fix the pool assumptions, update the telemetry input, or intentionally change the policy through review.</p>
<h3 id="poolsim-cli-install-failed"><code>poolsim-cli</code> install failed</h3>
<p>Confirm the requested <code>version</code> exists on crates.io and that the runner can access crates.io. This release defaults to <code>0.3.0</code>.</p>
<h2 id="related-links">Related Links</h2>
<ul>
<li>Main Poolsim repository: <a href="https://github.com/gregorian-09/poolsim">https://github.com/gregorian-09/poolsim</a></li>
<li>Poolsim documentation: <a href="https://github.com/gregorian-09/poolsim/tree/main/docs">https://github.com/gregorian-09/poolsim/tree/main/docs</a></li>
<li>Poolsim CLI crate: <a href="https://crates.io/crates/poolsim-cli">https://crates.io/crates/poolsim-cli</a></li>
<li>Issues: <a href="https://github.com/gregorian-09/poolsim/issues">https://github.com/gregorian-09/poolsim/issues</a></li>
</ul>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/hol-codex-plugin-scanner/</link><pubDate>Sun, 12 Jul 2026 14:46:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.460.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.460</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.460</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.460">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.460</a></p>
]]></content:encoded></item><item><title>auto-issue-review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/auto-issue-review/</link><pubDate>Sun, 12 Jul 2026 14:46:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/auto-issue-review/</guid><description>Version updated for https://github.com/kldhsh123/auto-issue-review to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v0.1.0
Full Changelog: https://github.com/kldhsh123/auto-issue-review/commits/v0.1.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kldhsh123/auto-issue-review">https://github.com/kldhsh123/auto-issue-review</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/auto-issue-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>v0.1.0</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/kldhsh123/auto-issue-review/commits/v0.1.0">https://github.com/kldhsh123/auto-issue-review/commits/v0.1.0</a></p>
]]></content:encoded></item><item><title>Airlock RLS — CI Gate for Supabase</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/airlock-rls-ci-gate-for-supabase/</link><pubDate>Sun, 12 Jul 2026 14:45:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/airlock-rls-ci-gate-for-supabase/</guid><description>Version updated for https://github.com/mateuszingano/airlock-rls to version v0.1.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed The CI gate for Supabase RLS. Fails your build when a table ships without RLS, a policy is permissive (USING (true)), or anon can read/write without scoping — the class of bug scanners miss because they check presence, not logic.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mateuszingano/airlock-rls">https://github.com/mateuszingano/airlock-rls</a></strong> to version <strong>v0.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/airlock-rls-ci-gate-for-supabase">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>The CI gate for Supabase RLS.</strong> Fails your build when a table ships without RLS, a policy is permissive (<code>USING (true)</code>), or anon can read/write without scoping — the class of bug scanners miss because they check <em>presence</em>, not <em>logic</em>.</p>
<p>Add it to any workflow:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">mateuszingano/airlock-rls@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">db-url</span>: <span style="color:#ae81ff">${{ secrets.SUPABASE_DB_URL }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">allow</span>: <span style="color:#e6db74">&#34;public_status_select&#34;</span>   <span style="color:#75715e"># optional: intentionally-public policies</span>
</span></span></code></pre></div><h3 id="what-it-checks">What it checks</h3>
<ul>
<li>Tables without RLS, <code>USING (true)</code>, writes without <code>WITH CHECK</code></li>
<li><code>SECURITY DEFINER</code> functions anon can execute, views that bypass RLS, Storage/Realtime exposure</li>
<li><strong>DAST</strong>: actually reads <em>and</em> writes with the anon key to prove exposure (safe — empty payload never persists)</li>
</ul>
<h3 id="since-v010">Since v0.1.0</h3>
<ul>
<li>fix: connect to Supabase over SSL without cert-chain failure</li>
<li>fix: <code>write_unchecked</code> false positive on scoped <code>ALL</code> policies</li>
<li>add: gated integration test running <code>audit()</code> against a real Postgres</li>
<li>add: repository metadata + <code>SECURITY.md</code></li>
</ul>
<p>Also on npm: <code>npx airlock-rls@0.1.2</code>. MIT. Not affiliated with Supabase.</p>
]]></content:encoded></item><item><title>Miso PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/miso-pr-review/</link><pubDate>Sun, 12 Jul 2026 14:45:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/miso-pr-review/</guid><description>Version updated for https://github.com/misospace/pr-reviewer-action to version v2.1.3.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed ci(github-action): update action misospace/pr-reviewer-action (v2.1.1 → v2.1.2) by @its-miso[bot] in https://github.com/misospace/pr-reviewer-action/pull/407 fix: omit Linked Issue Context / Evidence Providers headers when empty by @Tanguille in https://github.com/misospace/pr-reviewer-action/pull/410 fix(security): reject artifact symlinks by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/411 fix(impact): avoid awk broken pipe by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/412 New Contributors @Tanguille made their first contribution in https://github.com/misospace/pr-reviewer-action/pull/410 Full Changelog: https://github.com/misospace/pr-reviewer-action/compare/v2.1.2...v2.1.3</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/misospace/pr-reviewer-action">https://github.com/misospace/pr-reviewer-action</a></strong> to version <strong>v2.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/miso-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(github-action): update action misospace/pr-reviewer-action (v2.1.1 → v2.1.2) by @its-miso[bot] in <a href="https://github.com/misospace/pr-reviewer-action/pull/407">https://github.com/misospace/pr-reviewer-action/pull/407</a></li>
<li>fix: omit Linked Issue Context / Evidence Providers headers when empty by @Tanguille in <a href="https://github.com/misospace/pr-reviewer-action/pull/410">https://github.com/misospace/pr-reviewer-action/pull/410</a></li>
<li>fix(security): reject artifact symlinks by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/411">https://github.com/misospace/pr-reviewer-action/pull/411</a></li>
<li>fix(impact): avoid awk broken pipe by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/412">https://github.com/misospace/pr-reviewer-action/pull/412</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@Tanguille made their first contribution in <a href="https://github.com/misospace/pr-reviewer-action/pull/410">https://github.com/misospace/pr-reviewer-action/pull/410</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/misospace/pr-reviewer-action/compare/v2.1.2...v2.1.3">https://github.com/misospace/pr-reviewer-action/compare/v2.1.2...v2.1.3</a></p>
]]></content:encoded></item><item><title>Ansible SecOps Linter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/ansible-secops-linter/</link><pubDate>Sun, 12 Jul 2026 14:44:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/ansible-secops-linter/</guid><description>Version updated for https://github.com/semx/ansible-secops-linter to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First release of ansible-secops-linter — security-focused static analysis for Ansible playbooks and roles.
Checks: disabled TLS/host-key verification, hardcoded credentials, remote-script-to-shell execution, world-writable file modes, disabled package signature checks, and secret-handling tasks missing no_log. Text and SARIF output.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/semx/ansible-secops-linter">https://github.com/semx/ansible-secops-linter</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ansible-secops-linter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release of <strong>ansible-secops-linter</strong> — security-focused static analysis for Ansible playbooks and roles.</p>
<p><strong>Checks:</strong> disabled TLS/host-key verification, hardcoded credentials, remote-script-to-shell execution, world-writable file modes, disabled package signature checks, and secret-handling tasks missing <code>no_log</code>. Text and SARIF output.</p>
<p><strong>Use as a GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">semx/ansible-secops-linter@v0.1.0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">paths</span>: <span style="color:#ae81ff">playbooks roles</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">error</span>
</span></span></code></pre></div><p><strong>Use as a CLI:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install git+https://github.com/semx/ansible-secops-linter.git
</span></span><span style="display:flex;"><span>ansible-secops-linter lint path/to/playbooks
</span></span></code></pre></div>]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/bernstein-multi-agent-orchestration/</link><pubDate>Sun, 12 Jul 2026 14:44:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.4.4.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v3.4.4 Released 2026-07-12.
A capability release that adds the experimental MCP Tasks protocol surface to the Bernstein MCP server, plus release-pipeline hardening.
MCP Tasks extension Long-running runs are now exposed through the experimental MCP Tasks protocol. A task-capable MCP client (Claude Code, Cursor, Cline, and others) can start a run with bernstein_run, receive a CreateTaskResult, and then poll status and retrieve the result asynchronously through the get_task, get_task_result, list_tasks, and cancel_task handlers without holding a blocking session open. The task handle embeds the run’s audit-chain head hash ({task_id}:{head_hash}) so a stateless client can still tie a progress claim back to the signed chain.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.4.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v344">v3.4.4</h1>
<p>Released 2026-07-12.</p>
<p>A capability release that adds the experimental MCP Tasks protocol surface to
the Bernstein MCP server, plus release-pipeline hardening.</p>
<h2 id="mcp-tasks-extension">MCP Tasks extension</h2>
<ul>
<li>
<p>Long-running runs are now exposed through the experimental MCP Tasks protocol.
A task-capable MCP client (Claude Code, Cursor, Cline, and others) can start a
run with <code>bernstein_run</code>, receive a <code>CreateTaskResult</code>, and then poll status
and retrieve the result asynchronously through the <code>get_task</code>,
<code>get_task_result</code>, <code>list_tasks</code>, and <code>cancel_task</code> handlers without holding a
blocking session open. The task handle embeds the run&rsquo;s audit-chain head hash
(<code>{task_id}:{head_hash}</code>) so a stateless client can still tie a progress claim
back to the signed chain.</p>
</li>
<li>
<p>W3C trace-context (<code>traceparent</code>, <code>tracestate</code>, <code>baggage</code>) is ingested from
the incoming request and propagated to the spawned agent, scoped per task so a
run without trace-context never inherits another run&rsquo;s context.</p>
</li>
<li>
<p>Every task status projects to a terminal MCP status on completion, and
<code>get_task_result</code> reports an error for terminal-error and in-flight tasks
instead of reporting success.</p>
<p>Thanks to @Amanmeena0 for contributing the MCP Tasks protocol implementation
and the trace-context propagation.</p>
</li>
</ul>
<h2 id="release-pipeline">Release pipeline</h2>
<ul>
<li>The MCP registry listing publish is now idempotent: a version that is already
live is treated as success instead of failing the release on a re-run or a
tag-push/dispatch race. (#2466)</li>
</ul>
<h2 id="housekeeping">Housekeeping</h2>
<ul>
<li>Refreshed the packaged adapter last-green projection and its docs table from
the nightly conformance canary; every row stays anchored to its attesting
receipt.</li>
</ul>
]]></content:encoded></item><item><title>Publish to BadgeHub</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/publish-to-badgehub/</link><pubDate>Sun, 12 Jul 2026 14:43:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/publish-to-badgehub/</guid><description>Version updated for https://github.com/tjorim/mpos-badgehub-publish to version v1.0.11.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Cleanup, no behavior change. CPython’s `stderr` is always line-buffered/unbuffered by default regardless of tty status — `fail()`’s messages (the ones that mattered while chasing `v1.0.6`-`v1.0.9`’s bugs) never actually needed explicit flushing. `stdout` is what block-buffers when piped to a CI log, and that’s handled globally now via `python3 -u` in `action.yml`’s invocation, rather than `flush=True` hand-added to every individual print call (easy to forget on a new one).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tjorim/mpos-badgehub-publish">https://github.com/tjorim/mpos-badgehub-publish</a></strong> to version <strong>v1.0.11</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/publish-to-badgehub">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Cleanup, no behavior change. CPython&rsquo;s `stderr` is always line-buffered/unbuffered by default regardless of tty status — `fail()`&rsquo;s messages (the ones that mattered while chasing `v1.0.6`-`v1.0.9`&rsquo;s bugs) never actually needed explicit flushing. `stdout` is what block-buffers when piped to a CI log, and that&rsquo;s handled globally now via `python3 -u` in `action.yml`&rsquo;s invocation, rather than `flush=True` hand-added to every individual print call (easy to forget on a new one).</p>
]]></content:encoded></item><item><title>Publish to FlatPark</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/publish-to-flatpark/</link><pubDate>Sun, 12 Jul 2026 06:18:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/publish-to-flatpark/</guid><description>Version updated for https://github.com/flatpark/publish-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First public release of Publish to FlatPark 🎉
Add five lines to your release workflow and your Linux users get the Flatpak update the same day you publish a release — no tokens, no manifest, no build infrastructure:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/flatpark/publish-action">https://github.com/flatpark/publish-action</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/publish-to-flatpark">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release of <strong>Publish to FlatPark</strong> 🎉</p>
<p>Add five lines to your release workflow and your Linux users get the Flatpak update the same day you publish a release — no tokens, no manifest, no build infrastructure:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">on</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">release</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">types</span>: [<span style="color:#ae81ff">published]</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">flatpak</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#75715e"># A FlatPark hiccup should never fail your release.</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">continue-on-error</span>: <span style="color:#66d9ef">true</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">flatpark/publish-action@v1</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">app-id</span>: <span style="color:#ae81ff">com.example.MyApp</span>
</span></span></code></pre></div><h2 id="what-it-does">What it does</h2>
<p>On release, the action notifies <a href="https://flatpark.org">FlatPark</a>, which re-resolves your latest release artifacts and ships the update to its Flatpak repository — where <code>flatpak update</code> delivers it to every installed user.</p>
<h2 id="no-secrets-required">No secrets required</h2>
<p>The webhook trusts nothing at face value: it verifies the app id against FlatPark&rsquo;s public catalog, confirms this repository is the app&rsquo;s registered upstream, and checks the tag exists as a real GitHub release — only then does FlatPark trigger its own pipeline with its own credentials. Nobody can use this endpoint to publish releases for a repository they don&rsquo;t control.</p>
<h2 id="requirements">Requirements</h2>
<p>Your app must be listed on FlatPark first — <a href="https://github.com/flatpark/flatpark/issues">open an issue</a> to get it added. Apps shipping official Linux binaries (AppImage, deb, zip, tarball) usually take a day to package.</p>
<hr>
<p><em>v1.0.1 fixes the action metadata for Marketplace listing; functionally identical to v1.0.0. Pin <code>@v1</code> to always get the latest v1.x.</em></p>
]]></content:encoded></item><item><title>Actionlint Setup</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/actionlint-setup/</link><pubDate>Sun, 12 Jul 2026 06:17:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/actionlint-setup/</guid><description>Version updated for https://github.com/freerangebytes/setup-actionlint to version v0.1.2.
This action is used across all versions by 9 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore: add dependabot for the devcontainer dockerfile by @ersmith in https://github.com/freerangebytes/setup-actionlint/pull/15 docs: updated readme to discuss the benefits of the action by @ersmith in https://github.com/freerangebytes/setup-actionlint/pull/16 Misc updates by @ersmith in https://github.com/freerangebytes/setup-actionlint/pull/17 ci: add permissions to workflows by @ersmith in https://github.com/freerangebytes/setup-actionlint/pull/18 ci: switch versioning workflow by @ersmith in https://github.com/freerangebytes/setup-actionlint/pull/19 ci: switch to relying on version workflow for updates by @ersmith in https://github.com/freerangebytes/setup-actionlint/pull/20 ci: fix tag and release action name by @ersmith in https://github.com/freerangebytes/setup-actionlint/pull/21 ci: fix version calculation outputs by @ersmith in https://github.com/freerangebytes/setup-actionlint/pull/22 build(deps): bump freerangebytes/auto-tag-and-release from 0.2.0 to 0.2.1 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/23 build(deps-dev): bump @commitlint/config-conventional from 20.2.0 to 20.5.0 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/46 build(deps-dev): bump @commitlint/format from 20.2.0 to 20.5.0 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/44 build(deps-dev): bump conventional-changelog-atom from 5.0.0 to 5.1.0 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/40 build(deps): bump freerangebytes/auto-tag-and-release from 0.2.1 to 0.3.0 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/24 chore(commitlint): fix commitlint so it matches expected format by @ersmith in https://github.com/freerangebytes/setup-actionlint/pull/47 build(deps-dev): bump @commitlint/cli from 20.2.0 to 20.5.0 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/45 build(deps): bump actions/github-script from 8 to 9 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/48 build(deps-dev): bump @commitlint/config-conventional from 20.5.0 to 20.5.3 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/50 build(deps-dev): bump @commitlint/cli from 20.5.0 to 20.5.3 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/51 build(deps-dev): bump @commitlint/config-conventional from 20.5.3 to 21.0.0 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/53 build(deps-dev): bump @commitlint/cli from 20.5.3 to 21.0.1 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/54 build(deps-dev): bump @commitlint/format from 20.5.0 to 21.0.1 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/52 build(deps-dev): bump @commitlint/cli from 21.0.1 to 21.0.2 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/58 build(deps-dev): bump @commitlint/config-conventional from 21.0.0 to 21.1.0 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/59 build(deps): bump actions/checkout from 6 to 7 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/65 build(deps): bump ghcr.io/devcontainers/features/docker-in-docker from 2.17.0 to 4.0.0 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/63 build(deps): bump actions/setup-python from 6 to 6.2.0 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/64 build(deps): bump devcontainers/base from ubuntu-22.04 to ubuntu-24.04 in /.devcontainer by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/62 build(deps-dev): bump @commitlint/cli from 21.0.2 to 21.1.0 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/68 build(deps): bump actions/setup-python from 6.2.0 to 6.3.0 by @dependabot[bot] in https://github.com/freerangebytes/setup-actionlint/pull/66 fix: switch to shas for gha dependencies by @ersmith in https://github.com/freerangebytes/setup-actionlint/pull/69 Full Changelog: https://github.com/freerangebytes/setup-actionlint/compare/v0.1.1...v0.1.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/freerangebytes/setup-actionlint">https://github.com/freerangebytes/setup-actionlint</a></strong> to version <strong>v0.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>9</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/actionlint-setup">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: add dependabot for the devcontainer dockerfile by @ersmith in <a href="https://github.com/freerangebytes/setup-actionlint/pull/15">https://github.com/freerangebytes/setup-actionlint/pull/15</a></li>
<li>docs: updated readme to discuss the benefits of the action by @ersmith in <a href="https://github.com/freerangebytes/setup-actionlint/pull/16">https://github.com/freerangebytes/setup-actionlint/pull/16</a></li>
<li>Misc updates by @ersmith in <a href="https://github.com/freerangebytes/setup-actionlint/pull/17">https://github.com/freerangebytes/setup-actionlint/pull/17</a></li>
<li>ci: add permissions to workflows by @ersmith in <a href="https://github.com/freerangebytes/setup-actionlint/pull/18">https://github.com/freerangebytes/setup-actionlint/pull/18</a></li>
<li>ci: switch versioning workflow by @ersmith in <a href="https://github.com/freerangebytes/setup-actionlint/pull/19">https://github.com/freerangebytes/setup-actionlint/pull/19</a></li>
<li>ci: switch to relying on version workflow for updates by @ersmith in <a href="https://github.com/freerangebytes/setup-actionlint/pull/20">https://github.com/freerangebytes/setup-actionlint/pull/20</a></li>
<li>ci: fix tag and release action name by @ersmith in <a href="https://github.com/freerangebytes/setup-actionlint/pull/21">https://github.com/freerangebytes/setup-actionlint/pull/21</a></li>
<li>ci: fix version calculation outputs by @ersmith in <a href="https://github.com/freerangebytes/setup-actionlint/pull/22">https://github.com/freerangebytes/setup-actionlint/pull/22</a></li>
<li>build(deps): bump freerangebytes/auto-tag-and-release from 0.2.0 to 0.2.1 by @dependabot[bot] in <a href="https://github.com/freerangebytes/setup-actionlint/pull/23">https://github.com/freerangebytes/setup-actionlint/pull/23</a></li>
<li>build(deps-dev): bump @commitlint/config-conventional from 20.2.0 to 20.5.0 by @dependabot[bot] in <a href="https://github.com/freerangebytes/setup-actionlint/pull/46">https://github.com/freerangebytes/setup-actionlint/pull/46</a></li>
<li>build(deps-dev): bump @commitlint/format from 20.2.0 to 20.5.0 by @dependabot[bot] in <a href="https://github.com/freerangebytes/setup-actionlint/pull/44">https://github.com/freerangebytes/setup-actionlint/pull/44</a></li>
<li>build(deps-dev): bump conventional-changelog-atom from 5.0.0 to 5.1.0 by @dependabot[bot] in <a href="https://github.com/freerangebytes/setup-actionlint/pull/40">https://github.com/freerangebytes/setup-actionlint/pull/40</a></li>
<li>build(deps): bump freerangebytes/auto-tag-and-release from 0.2.1 to 0.3.0 by @dependabot[bot] in <a href="https://github.com/freerangebytes/setup-actionlint/pull/24">https://github.com/freerangebytes/setup-actionlint/pull/24</a></li>
<li>chore(commitlint): fix commitlint so it matches expected format by @ersmith in <a href="https://github.com/freerangebytes/setup-actionlint/pull/47">https://github.com/freerangebytes/setup-actionlint/pull/47</a></li>
<li>build(deps-dev): bump @commitlint/cli from 20.2.0 to 20.5.0 by @dependabot[bot] in <a href="https://github.com/freerangebytes/setup-actionlint/pull/45">https://github.com/freerangebytes/setup-actionlint/pull/45</a></li>
<li>build(deps): bump actions/github-script from 8 to 9 by @dependabot[bot] in <a href="https://github.com/freerangebytes/setup-actionlint/pull/48">https://github.com/freerangebytes/setup-actionlint/pull/48</a></li>
<li>build(deps-dev): bump @commitlint/config-conventional from 20.5.0 to 20.5.3 by @dependabot[bot] in <a href="https://github.com/freerangebytes/setup-actionlint/pull/50">https://github.com/freerangebytes/setup-actionlint/pull/50</a></li>
<li>build(deps-dev): bump @commitlint/cli from 20.5.0 to 20.5.3 by @dependabot[bot] in <a href="https://github.com/freerangebytes/setup-actionlint/pull/51">https://github.com/freerangebytes/setup-actionlint/pull/51</a></li>
<li>build(deps-dev): bump @commitlint/config-conventional from 20.5.3 to 21.0.0 by @dependabot[bot] in <a href="https://github.com/freerangebytes/setup-actionlint/pull/53">https://github.com/freerangebytes/setup-actionlint/pull/53</a></li>
<li>build(deps-dev): bump @commitlint/cli from 20.5.3 to 21.0.1 by @dependabot[bot] in <a href="https://github.com/freerangebytes/setup-actionlint/pull/54">https://github.com/freerangebytes/setup-actionlint/pull/54</a></li>
<li>build(deps-dev): bump @commitlint/format from 20.5.0 to 21.0.1 by @dependabot[bot] in <a href="https://github.com/freerangebytes/setup-actionlint/pull/52">https://github.com/freerangebytes/setup-actionlint/pull/52</a></li>
<li>build(deps-dev): bump @commitlint/cli from 21.0.1 to 21.0.2 by @dependabot[bot] in <a href="https://github.com/freerangebytes/setup-actionlint/pull/58">https://github.com/freerangebytes/setup-actionlint/pull/58</a></li>
<li>build(deps-dev): bump @commitlint/config-conventional from 21.0.0 to 21.1.0 by @dependabot[bot] in <a href="https://github.com/freerangebytes/setup-actionlint/pull/59">https://github.com/freerangebytes/setup-actionlint/pull/59</a></li>
<li>build(deps): bump actions/checkout from 6 to 7 by @dependabot[bot] in <a href="https://github.com/freerangebytes/setup-actionlint/pull/65">https://github.com/freerangebytes/setup-actionlint/pull/65</a></li>
<li>build(deps): bump ghcr.io/devcontainers/features/docker-in-docker from 2.17.0 to 4.0.0 by @dependabot[bot] in <a href="https://github.com/freerangebytes/setup-actionlint/pull/63">https://github.com/freerangebytes/setup-actionlint/pull/63</a></li>
<li>build(deps): bump actions/setup-python from 6 to 6.2.0 by @dependabot[bot] in <a href="https://github.com/freerangebytes/setup-actionlint/pull/64">https://github.com/freerangebytes/setup-actionlint/pull/64</a></li>
<li>build(deps): bump devcontainers/base from ubuntu-22.04 to ubuntu-24.04 in /.devcontainer by @dependabot[bot] in <a href="https://github.com/freerangebytes/setup-actionlint/pull/62">https://github.com/freerangebytes/setup-actionlint/pull/62</a></li>
<li>build(deps-dev): bump @commitlint/cli from 21.0.2 to 21.1.0 by @dependabot[bot] in <a href="https://github.com/freerangebytes/setup-actionlint/pull/68">https://github.com/freerangebytes/setup-actionlint/pull/68</a></li>
<li>build(deps): bump actions/setup-python from 6.2.0 to 6.3.0 by @dependabot[bot] in <a href="https://github.com/freerangebytes/setup-actionlint/pull/66">https://github.com/freerangebytes/setup-actionlint/pull/66</a></li>
<li>fix: switch to shas for gha dependencies by @ersmith in <a href="https://github.com/freerangebytes/setup-actionlint/pull/69">https://github.com/freerangebytes/setup-actionlint/pull/69</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/freerangebytes/setup-actionlint/compare/v0.1.1...v0.1.2">https://github.com/freerangebytes/setup-actionlint/compare/v0.1.1...v0.1.2</a></p>
]]></content:encoded></item><item><title>RunRight CI Resource Monitor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/runright-ci-resource-monitor/</link><pubDate>Sun, 12 Jul 2026 06:17:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/runright-ci-resource-monitor/</guid><description>Version updated for https://github.com/gbudjeakp/run-right to version v1.6.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Remove Azure provider; RunRight focuses on AWS, GCP, and GitHub-hosted runners</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/gbudjeakp/run-right">https://github.com/gbudjeakp/run-right</a></strong> to version <strong>v1.6.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/runright-ci-resource-monitor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Remove Azure provider; RunRight focuses on AWS, GCP, and GitHub-hosted runners</li>
</ul>
]]></content:encoded></item><item><title>Pedant - Lint and Format</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/pedant-lint-and-format/</link><pubDate>Sun, 12 Jul 2026 06:16:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/pedant-lint-and-format/</guid><description>Version updated for https://github.com/goeselt/pedant to version v1.4.3.
This action is used across all versions by 2 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps): bump the all group with 2 updates by @dependabot[bot] in https://github.com/goeselt/pedant/pull/27 fix: update dependencies by @goeselt in https://github.com/goeselt/pedant/pull/29 Full Changelog: https://github.com/goeselt/pedant/compare/v1.4...v1.4.3</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/goeselt/pedant">https://github.com/goeselt/pedant</a></strong> to version <strong>v1.4.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pedant-lint-and-format">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): bump the all group with 2 updates by @dependabot[bot] in <a href="https://github.com/goeselt/pedant/pull/27">https://github.com/goeselt/pedant/pull/27</a></li>
<li>fix: update dependencies by @goeselt in <a href="https://github.com/goeselt/pedant/pull/29">https://github.com/goeselt/pedant/pull/29</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/goeselt/pedant/compare/v1.4...v1.4.3">https://github.com/goeselt/pedant/compare/v1.4...v1.4.3</a></p>
]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/ai-plugin-scanner/</link><pubDate>Sun, 12 Jul 2026 06:16:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.456.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/d7060399ddf8b69773a84973870f5e086227c6b6 with plugin-scanner 2.0.1057.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.455...v1.2.456</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.456</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>18</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/d7060399ddf8b69773a84973870f5e086227c6b6">https://github.com/hashgraph-online/hol-guard/tree/d7060399ddf8b69773a84973870f5e086227c6b6</a> with plugin-scanner 2.0.1057.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.455...v1.2.456">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.455...v1.2.456</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/hol-codex-plugin-scanner/</link><pubDate>Sun, 12 Jul 2026 06:15:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.456.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.456</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.456</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.456">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.456</a></p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/neurolink-ai/</link><pubDate>Sun, 12 Jul 2026 06:14:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v9.86.4.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 9.86.4 (2026-07-11) Bug Fixes (generate): stop treating ai@6 raw-text output echo as parsed schema output (dc23936)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v9.86.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="9864-2026-07-11"><a href="https://github.com/juspay/neurolink/compare/v9.86.3...v9.86.4">9.86.4</a> (2026-07-11)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(generate):</strong>  stop treating ai@6 raw-text output echo as parsed schema output (<a href="https://github.com/juspay/neurolink/commit/dc23936d1feec5e4089ba5eb8338983b5a7ceee3">dc23936</a>)</li>
</ul>
]]></content:encoded></item><item><title>riskratchet</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/riskratchet/</link><pubDate>Sun, 12 Jul 2026 06:14:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/riskratchet/</guid><description>Version updated for https://github.com/KayhanB21/riskratchet-action to version v1.0.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Bumps the composite delegation to KayhanB21/riskratchet@v0.2.15, which brings TypeScript slices 4–5 (cyclomatic complexity, barrel-aware public surface, and native JSON/SARIF output with token-stable identity groundwork). TypeScript remains informational-only and opt-in; the Python path is unchanged.
This wrapper stays a thin passthrough — action.yml in the main repo is the single source of truth for inputs and behavior.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/KayhanB21/riskratchet-action">https://github.com/KayhanB21/riskratchet-action</a></strong> to version <strong>v1.0.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/riskratchet">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Bumps the composite delegation to <a href="https://github.com/KayhanB21/riskratchet/releases/tag/v0.2.15"><code>KayhanB21/riskratchet@v0.2.15</code></a>, which brings TypeScript slices 4–5 (cyclomatic complexity, barrel-aware public surface, and native JSON/SARIF output with token-stable identity groundwork). TypeScript remains informational-only and opt-in; the Python path is unchanged.</p>
<p>This wrapper stays a thin passthrough — <code>action.yml</code> in the main repo is the single source of truth for inputs and behavior.</p>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">on</span>: [<span style="color:#ae81ff">pull_request]</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">riskratchet</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 </span> <span style="color:#75715e"># v4.2.2</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">KayhanB21/riskratchet-action@v1</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">coverage</span>: <span style="color:#ae81ff">coverage.json</span>
</span></span></code></pre></div><p>See the <a href="https://github.com/KayhanB21/riskratchet#github-action">main repository</a> for the full inputs table.</p>
<hr>
<p><code>v1.0.3</code>–<code>v1.0.5</code> were tag-only delegation bumps (v0.2.12 → v0.2.14) with no formal release; this release resumes cutting Release notes. The floating <code>v1</code> tag now points here.</p>
]]></content:encoded></item><item><title>cargo-rail</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/cargo-rail/</link><pubDate>Sun, 12 Jul 2026 06:13:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/cargo-rail/</guid><description>Version updated for https://github.com/loadingalias/cargo-rail-action to version v5.0.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/loadingalias/cargo-rail-action/compare/v4...v5.0.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/loadingalias/cargo-rail-action">https://github.com/loadingalias/cargo-rail-action</a></strong> to version <strong>v5.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cargo-rail">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/loadingalias/cargo-rail-action/compare/v4...v5.0.0">https://github.com/loadingalias/cargo-rail-action/compare/v4...v5.0.0</a></p>
]]></content:encoded></item><item><title>tofu-garnish</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/tofu-garnish/</link><pubDate>Sun, 12 Jul 2026 06:13:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/tofu-garnish/</guid><description>Version updated for https://github.com/lowlydba/tofu-garnish to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Make footer cuter with emojis and smaller text by @lowlydba in https://github.com/lowlydba/tofu-garnish/pull/4 Full Changelog: https://github.com/lowlydba/tofu-garnish/compare/v1.0.0...v1.0.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lowlydba/tofu-garnish">https://github.com/lowlydba/tofu-garnish</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tofu-garnish">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Make footer cuter with emojis and smaller text by @lowlydba in <a href="https://github.com/lowlydba/tofu-garnish/pull/4">https://github.com/lowlydba/tofu-garnish/pull/4</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/lowlydba/tofu-garnish/compare/v1.0.0...v1.0.1">https://github.com/lowlydba/tofu-garnish/compare/v1.0.0...v1.0.1</a></p>
]]></content:encoded></item><item><title>Rust Build, Package and Release Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/rust-build-package-and-release-action/</link><pubDate>Sun, 12 Jul 2026 06:12:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/rust-build-package-and-release-action/</guid><description>Version updated for https://github.com/michaelklishin/rust-build-package-release-action to version v3.1.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v3.1.0 (Jul 11, 2026) Bug Fixes test-deb and test-rpm now work in clean distro containers. The action previously failed with cargo: command not found because it always compiled itself from source. It now downloads a prebuilt MUSL-based static binary when no Rust toolchain is present publish-crate with publish-dry-run: true now works on PRs and branch pushes. Previously it tried to validate the ref as a version tag and failed on refs like 14/merge</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/michaelklishin/rust-build-package-release-action">https://github.com/michaelklishin/rust-build-package-release-action</a></strong> to version <strong>v3.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rust-build-package-and-release-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v310-jul-11-2026">v3.1.0 (Jul 11, 2026)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><code>test-deb</code> and <code>test-rpm</code> now work in clean distro containers.
The action previously failed with <code>cargo: command not found</code> because it always compiled itself from source.
It now downloads a prebuilt MUSL-based static binary when no Rust toolchain is present</li>
<li><code>publish-crate</code> with <code>publish-dry-run: true</code> now works on PRs and branch pushes. Previously it tried to validate the ref as a version tag and failed on refs like <code>14/merge</code></li>
</ul>
]]></content:encoded></item><item><title>Star History Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/star-history-action/</link><pubDate>Sun, 12 Jul 2026 06:12:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/star-history-action/</guid><description>Version updated for https://github.com/narayann7/star-history-action to version v1.0.2.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added font-family input. Set it to any Google Fonts family (for example Patrick Hand) and the renderer downloads that font at run time and applies it to the PNG chart. It reads the font’s real internal name so it matches even when that differs from the family string, and non-Latin families such as Noto Sans SC work. Empty input keeps the bundled Comic Neue with no network call, and any download failure falls back to Comic Neue without failing the run. This affects the PNG only, since GitHub strips @font-face from README-embedded SVGs. Optional watch: types: [started] trigger, documented alongside the cron schedule and workflow_dispatch, so a chart can refresh right after a new star. It supplements the schedule rather than replacing it: watch fires on new stars only, never on unstars, and does not refresh the time axis on quiet days. Compatibility The change-detection signature now includes the requested font, so changing only font-family invalidates the cache and re-renders. As a side effect the signature format changed, so the first run after upgrading regenerates the chart once even when the star count is unchanged. Full changelog: https://github.com/narayann7/star-history-action/blob/main/CHANGELOG.md</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/narayann7/star-history-action">https://github.com/narayann7/star-history-action</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/star-history-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="added">Added</h2>
<ul>
<li><code>font-family</code> input. Set it to any Google Fonts family (for example <code>Patrick Hand</code>) and the renderer downloads that font at run time and applies it to the PNG chart. It reads the font&rsquo;s real internal name so it matches even when that differs from the family string, and non-Latin families such as <code>Noto Sans SC</code> work. Empty input keeps the bundled Comic Neue with no network call, and any download failure falls back to Comic Neue without failing the run. This affects the PNG only, since GitHub strips <code>@font-face</code> from README-embedded SVGs.</li>
<li>Optional <code>watch: types: [started]</code> trigger, documented alongside the cron schedule and <code>workflow_dispatch</code>, so a chart can refresh right after a new star. It supplements the schedule rather than replacing it: <code>watch</code> fires on new stars only, never on unstars, and does not refresh the time axis on quiet days.</li>
</ul>
<h2 id="compatibility">Compatibility</h2>
<ul>
<li>The change-detection signature now includes the requested font, so changing only <code>font-family</code> invalidates the cache and re-renders. As a side effect the signature format changed, so the first run after upgrading regenerates the chart once even when the star count is unchanged.</li>
</ul>
<p><strong>Full changelog:</strong> <a href="https://github.com/narayann7/star-history-action/blob/main/CHANGELOG.md">https://github.com/narayann7/star-history-action/blob/main/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>Translink GTFS Schedule to SQLite</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/translink-gtfs-schedule-to-sqlite/</link><pubDate>Sun, 12 Jul 2026 06:11:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/translink-gtfs-schedule-to-sqlite/</guid><description>Version updated for https://github.com/quackers19/Translink-GTFS-Schedule-Pipeline to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial Release</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/quackers19/Translink-GTFS-Schedule-Pipeline">https://github.com/quackers19/Translink-GTFS-Schedule-Pipeline</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/translink-gtfs-schedule-to-sqlite">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial Release</p>
]]></content:encoded></item><item><title>YTMusicDisplayWidget</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/ytmusicdisplaywidget/</link><pubDate>Sun, 12 Jul 2026 06:10:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/ytmusicdisplaywidget/</guid><description>Version updated for https://github.com/rakshithp7/ytmusic-display-widget to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial release of YTMusicDisplayWidget — render a YouTube Music ’now playing’ SVG card for your README.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rakshithp7/ytmusic-display-widget">https://github.com/rakshithp7/ytmusic-display-widget</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ytmusicdisplaywidget">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial release of YTMusicDisplayWidget — render a YouTube Music &rsquo;now playing&rsquo; SVG card for your README.</p>
]]></content:encoded></item><item><title>RHFest Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/rhfest-action/</link><pubDate>Sun, 12 Jul 2026 06:09:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/rhfest-action/</guid><description>Version updated for https://github.com/RotorHazard/rhfest-action to version v3.1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s changed To receive a notification on new releases, click on Watch &amp;gt; Custom &amp;gt; Releases on the top.
✨ New features #296 feat: Add domain validation @klaasnicolaas 🧰 Maintenance #234 Add extractVersion for Python in renovate.json @klaasnicolaas #237 Fix extractVersion for Python base version in renovate.json @klaasnicolaas #238 Refactor extractVersion for Python dependency in renovate.json @klaasnicolaas ⬆️ Dependency updates 51 changes #235 ⬆️ Update dependency ruff to v0.15.8 @renovate[bot] #241 ⬆️ Lock file maintenance @renovate[bot] #240 ⬆️ Update astral-sh/setup-uv action to v8 @renovate[bot] #242 ⬆️ Update dependency ruff to v0.15.9 @renovate[bot] #243 ⬆️ Update docker/login-action action to v4.1.0 @renovate[bot] #244 ⬆️ Lock file maintenance @renovate[bot] #245 ⬆️ Update dependency ruff to v0.15.10 @renovate[bot] #246 ⬆️ Update release-drafter/release-drafter action to v7.2.0 @renovate[bot] #248 ⬆️ Lock file maintenance @renovate[bot] #247 ⬆️ Update docker/build-push-action action to v7.1.0 @renovate[bot] #249 ⬆️ Lock file maintenance @renovate[bot] #250 ⬆️ Update dependency ruff to v0.15.11 @renovate[bot] #252 ⬆️ Lock file maintenance @renovate[bot] #251 ⬆️ Update astral-sh/setup-uv action to v8.1.0 @renovate[bot] #253 ⬆️ Update dependency pre-commit to v4.6.0 @renovate[bot] #254 ⬆️ Update dependency ruff to v0.15.12 @renovate[bot] #255 ⬆️ Lock file maintenance @renovate[bot] #256 ⬆️ Update release-drafter/release-drafter action to v7.2.1 @renovate[bot] #257 ⬆️ Update klaasnicolaas/action-pr-labels action to v3.1.1 @renovate[bot] #258 ⬆️ Update release-drafter/release-drafter action to v7.3.0 @renovate[bot] #259 ⬆️ Update dependency ruff to v0.15.13 @renovate[bot] #260 ⬆️ Lock file maintenance @renovate[bot] #262 ⬆️ Update docker/build-push-action action to v7.2.0 @renovate[bot] #261 ⬆️ Update dependency ruff to v0.15.14 @renovate[bot] #263 ⬆️ Update docker/login-action action to v4.2.0 @renovate[bot] #264 ⬆️ Update docker/metadata-action action to v6.1.0 @renovate[bot] #265 ⬆️ Update docker/setup-buildx-action action to v4.1.0 @renovate[bot] #266 ⬆️ Update release-drafter/release-drafter action to v7.3.1 @renovate[bot] #267 ⬆️ Update dependency ruff to v0.15.15 @renovate[bot] #268 ⬆️ Update actions/checkout action to v6.0.3 @renovate[bot] #270 ⬆️ Update astral-sh/setup-uv action to v8.2.0 @renovate[bot] #271 ⬆️ Update dependency ruff to v0.15.16 @renovate[bot] #272 ⬆️ Lock file maintenance @renovate[bot] #273 ⬆️ Update dependency ruff to v0.15.17 @renovate[bot] #274 ⬆️ Lock file maintenance @renovate[bot] #275 ⬆️ Update release-drafter/release-drafter action to v7.4.0 @renovate[bot] #276 ⬆️ Update dependency ruff to v0.15.18 @renovate[bot] #278 ⬆️ Lock file maintenance @renovate[bot] #283 ⬆️ Update dependency ruff to v0.15.19 @renovate[bot] #277 ⬆️ Update actions/checkout action to v7 @renovate[bot] #285 ⬆️ Update dependency ruff to v0.15.20 @renovate[bot] #286 ⬆️ Update release-drafter/release-drafter action to v7.5.1 @renovate[bot] #287 ⬆️ Update docker/build-push-action action to v7.3.0 @renovate[bot] #288 ⬆️ Update docker/login-action action to v4.3.0 @renovate[bot] #289 ⬆️ Update docker/metadata-action action to v6.2.0 @renovate[bot] #290 ⬆️ Update docker/setup-buildx-action action to v4.2.0 @renovate[bot] #291 ⬆️ Update astral-sh/setup-uv action to v8.3.0 @renovate[bot] #292 ⬆️ Update docker/login-action action to v4.4.0 @renovate[bot] #293 ⬆️ Update astral-sh/setup-uv action to v8.3.1 @renovate[bot] #294 ⬆️ Update astral-sh/setup-uv action to v8.3.2 @renovate[bot] #295 ⬆️ Update dependency ruff to v0.15.21 @renovate[bot] Full Changelog: https://github.com/RotorHazard/rhfest-action/compare/v3.0.1...v3.1.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RotorHazard/rhfest-action">https://github.com/RotorHazard/rhfest-action</a></strong> to version <strong>v3.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rhfest-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s changed</h2>
<p><em>To receive a notification on new releases, click on <strong>Watch</strong> &gt; <strong>Custom</strong> &gt; <strong>Releases</strong> on the top.</em></p>
<h2 id="-new-features">✨ New features</h2>
<ul>
<li>#296 feat: Add domain validation @klaasnicolaas</li>
</ul>
<h2 id="-maintenance">🧰 Maintenance</h2>
<ul>
<li>#234 Add extractVersion for Python in renovate.json @klaasnicolaas</li>
<li>#237 Fix extractVersion for Python base version in renovate.json @klaasnicolaas</li>
<li>#238 Refactor extractVersion for Python dependency in renovate.json @klaasnicolaas</li>
</ul>
<h2 id="-dependency-updates">⬆️ Dependency updates</h2>
<details>
<summary>51 changes</summary>
<ul>
<li>#235 ⬆️ Update dependency ruff to v0.15.8 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#241 ⬆️ Lock file maintenance @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#240 ⬆️ Update astral-sh/setup-uv action to v8 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#242 ⬆️ Update dependency ruff to v0.15.9 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#243 ⬆️ Update docker/login-action action to v4.1.0 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#244 ⬆️ Lock file maintenance @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#245 ⬆️ Update dependency ruff to v0.15.10 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#246 ⬆️ Update release-drafter/release-drafter action to v7.2.0 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#248 ⬆️ Lock file maintenance @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#247 ⬆️ Update docker/build-push-action action to v7.1.0 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#249 ⬆️ Lock file maintenance @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#250 ⬆️ Update dependency ruff to v0.15.11 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#252 ⬆️ Lock file maintenance @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#251 ⬆️ Update astral-sh/setup-uv action to v8.1.0 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#253 ⬆️ Update dependency pre-commit to v4.6.0 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#254 ⬆️ Update dependency ruff to v0.15.12 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#255 ⬆️ Lock file maintenance @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#256 ⬆️ Update release-drafter/release-drafter action to v7.2.1 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#257 ⬆️ Update klaasnicolaas/action-pr-labels action to v3.1.1 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#258 ⬆️ Update release-drafter/release-drafter action to v7.3.0 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#259 ⬆️ Update dependency ruff to v0.15.13 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#260 ⬆️ Lock file maintenance @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#262 ⬆️ Update docker/build-push-action action to v7.2.0 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#261 ⬆️ Update dependency ruff to v0.15.14 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#263 ⬆️ Update docker/login-action action to v4.2.0 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#264 ⬆️ Update docker/metadata-action action to v6.1.0 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#265 ⬆️ Update docker/setup-buildx-action action to v4.1.0 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#266 ⬆️ Update release-drafter/release-drafter action to v7.3.1 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#267 ⬆️ Update dependency ruff to v0.15.15 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#268 ⬆️ Update actions/checkout action to v6.0.3 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#270 ⬆️ Update astral-sh/setup-uv action to v8.2.0 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#271 ⬆️ Update dependency ruff to v0.15.16 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#272 ⬆️ Lock file maintenance @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#273 ⬆️ Update dependency ruff to v0.15.17 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#274 ⬆️ Lock file maintenance @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#275 ⬆️ Update release-drafter/release-drafter action to v7.4.0 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#276 ⬆️ Update dependency ruff to v0.15.18 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#278 ⬆️ Lock file maintenance @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#283 ⬆️ Update dependency ruff to v0.15.19 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#277 ⬆️ Update actions/checkout action to v7 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#285 ⬆️ Update dependency ruff to v0.15.20 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#286 ⬆️ Update release-drafter/release-drafter action to v7.5.1 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#287 ⬆️ Update docker/build-push-action action to v7.3.0 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#288 ⬆️ Update docker/login-action action to v4.3.0 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#289 ⬆️ Update docker/metadata-action action to v6.2.0 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#290 ⬆️ Update docker/setup-buildx-action action to v4.2.0 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#291 ⬆️ Update astral-sh/setup-uv action to v8.3.0 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#292 ⬆️ Update docker/login-action action to v4.4.0 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#293 ⬆️ Update astral-sh/setup-uv action to v8.3.1 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#294 ⬆️ Update astral-sh/setup-uv action to v8.3.2 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
<li>#295 ⬆️ Update dependency ruff to v0.15.21 @<a href="https://github.com/apps/renovate">renovate[bot]</a></li>
</ul>
</details>
<p><strong>Full Changelog</strong>: <a href="https://github.com/RotorHazard/rhfest-action/compare/v3.0.1...v3.1.0">https://github.com/RotorHazard/rhfest-action/compare/v3.0.1...v3.1.0</a></p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/bernstein-multi-agent-orchestration/</link><pubDate>Sun, 12 Jul 2026 06:09:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.4.2.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v3.4.2 Released 2026-07-12.
A patch release on top of v3.4.1. It wires the cost-aware batch and cache policies into the live run loop, runs the adapter conformance suite on a real Windows CI runner, and makes the packaged distribution image verifiable. There are no breaking changes and no configuration migration is required.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.4.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v342">v3.4.2</h1>
<p>Released 2026-07-12.</p>
<p>A patch release on top of v3.4.1. It wires the cost-aware batch and cache
policies into the live run loop, runs the adapter conformance suite on a real
Windows CI runner, and makes the packaged distribution image verifiable. There
are no breaking changes and no configuration migration is required.</p>
<h2 id="cost-aware-scheduling-now-live-in-the-run-loop">Cost-aware scheduling now live in the run loop</h2>
<ul>
<li>Batch routing is enforced during dispatch. Before a single-task batch is
spawned, the run resolves the adapter that would run the task and takes the
capability-gated routing decision: a batch-eligible task reaches a provider
batch endpoint only on an adapter that has one, a task that is not
batch-eligible never routes to batch, and a batch-eligible task on an adapter
with no batch surface runs interactively rather than being faked onto a batch
path that does not exist. Each routing decision is recorded as a verifiable
<code>cost.batch_route</code> audit-chain entry.</li>
<li>Cache-window fan-out is wired into the tournament fan-out. When the resolved
adapter supports a prompt-cache window and the operator has opted in, one
warm-up call primes the shared prompt prefix before the sibling attempts
spawn, so each attempt hits the warm cache instead of racing to write it. The
feature stays off by default.</li>
</ul>
<h2 id="windows-conformance-on-a-real-windows-runner">Windows conformance on a real Windows runner</h2>
<ul>
<li>The adapter conformance suite for the claude, codex, and gemini adapters now
runs on a <code>windows-latest</code> CI runner and exercises the real spawn, stop, and
restart contract against a cross-platform fake-CLI harness, alongside the
Windows worktree-isolation contract. This replaces the previous mock-only
Windows coverage for those paths.</li>
<li>The fake-CLI test harness is cross-platform: it installs a batch shim on
Windows and a shell wrapper on Unix, and the fake reads its own configuration
so the same integration tests drive a real subprocess on every runner.</li>
<li>The count of platform-reason test skips is reduced, with the file-mode and
permission cases and the canary worktree round-trip now running on every
platform.</li>
</ul>
<h2 id="packaging">Packaging</h2>
<ul>
<li>Signed-image provenance verification. The MCP registry listing and the Docker
catalog entry are checked, offline, to resolve to the same signed container
image pinned to the release version. A new <code>bernstein skills package image-verify</code> command surfaces the verdict, and the release manifest check
fails a release that would publish a listing pointing at a different or
unsigned image. The registry and plugin manifests are version-synced with the
release.</li>
</ul>
<h2 id="upgrading">Upgrading</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx upgrade bernstein     <span style="color:#75715e"># or: uv tool upgrade bernstein</span>
</span></span></code></pre></div><p>No configuration migration is required. Every capability available in v3.4.1
is unchanged.</p>
]]></content:encoded></item><item><title>Ward - Pre-Agent Metadata Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/ward-pre-agent-metadata-scanner/</link><pubDate>Sun, 12 Jul 2026 06:08:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/ward-pre-agent-metadata-scanner/</guid><description>Version updated for https://github.com/Sonofg0tham/ward to version v0.2.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed ci(deps): bump actions/upload-artifact from 4 to 7 by @dependabot[bot] in https://github.com/Sonofg0tham/ward/pull/3 ci(deps): bump actions/download-artifact from 4 to 8 by @dependabot[bot] in https://github.com/Sonofg0tham/ward/pull/5 ci(deps): bump actions/setup-python from 5 to 6 by @dependabot[bot] in https://github.com/Sonofg0tham/ward/pull/1 ci(deps): bump marocchino/sticky-pull-request-comment from 2 to 3 by @dependabot[bot] in https://github.com/Sonofg0tham/ward/pull/7 ci(deps): bump softprops/action-gh-release from 2 to 3 by @dependabot[bot] in https://github.com/Sonofg0tham/ward/pull/8 ci(deps): bump actions/checkout from 4 to 7 by @dependabot[bot] in https://github.com/Sonofg0tham/ward/pull/9 New Contributors @dependabot[bot] made their first contribution in https://github.com/Sonofg0tham/ward/pull/3 Full Changelog: https://github.com/Sonofg0tham/ward/compare/v0.2.2...v0.2.3</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Sonofg0tham/ward">https://github.com/Sonofg0tham/ward</a></strong> to version <strong>v0.2.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ward-pre-agent-metadata-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(deps): bump actions/upload-artifact from 4 to 7 by @dependabot[bot] in <a href="https://github.com/Sonofg0tham/ward/pull/3">https://github.com/Sonofg0tham/ward/pull/3</a></li>
<li>ci(deps): bump actions/download-artifact from 4 to 8 by @dependabot[bot] in <a href="https://github.com/Sonofg0tham/ward/pull/5">https://github.com/Sonofg0tham/ward/pull/5</a></li>
<li>ci(deps): bump actions/setup-python from 5 to 6 by @dependabot[bot] in <a href="https://github.com/Sonofg0tham/ward/pull/1">https://github.com/Sonofg0tham/ward/pull/1</a></li>
<li>ci(deps): bump marocchino/sticky-pull-request-comment from 2 to 3 by @dependabot[bot] in <a href="https://github.com/Sonofg0tham/ward/pull/7">https://github.com/Sonofg0tham/ward/pull/7</a></li>
<li>ci(deps): bump softprops/action-gh-release from 2 to 3 by @dependabot[bot] in <a href="https://github.com/Sonofg0tham/ward/pull/8">https://github.com/Sonofg0tham/ward/pull/8</a></li>
<li>ci(deps): bump actions/checkout from 4 to 7 by @dependabot[bot] in <a href="https://github.com/Sonofg0tham/ward/pull/9">https://github.com/Sonofg0tham/ward/pull/9</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/Sonofg0tham/ward/pull/3">https://github.com/Sonofg0tham/ward/pull/3</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Sonofg0tham/ward/compare/v0.2.2...v0.2.3">https://github.com/Sonofg0tham/ward/compare/v0.2.2...v0.2.3</a></p>
]]></content:encoded></item><item><title>Build Apache Maven Dependency</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/build-apache-maven-dependency/</link><pubDate>Sun, 12 Jul 2026 06:07:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/build-apache-maven-dependency/</guid><description>Version updated for https://github.com/sualeh/build-maven-dependency to version v1.0.9.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed GitHub Action to Build a Maven Dependency v1.0.9 release at last commit abcce43ccf66f696fd5417516cf9449a29f32411
What’s Changed Bump softprops/action-gh-release from 2 to 3 by @dependabot[bot] in https://github.com/sualeh/build-maven-dependency/pull/1 Bump actions/checkout from 6 to 7 by @dependabot[bot] in https://github.com/sualeh/build-maven-dependency/pull/2 New Contributors @dependabot[bot] made their first contribution in https://github.com/sualeh/build-maven-dependency/pull/1 Full Changelog: https://github.com/sualeh/build-maven-dependency/compare/v1.0.8...v1.0.9</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sualeh/build-maven-dependency">https://github.com/sualeh/build-maven-dependency</a></strong> to version <strong>v1.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/build-apache-maven-dependency">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>GitHub Action to Build a Maven Dependency
v1.0.9 release at last commit abcce43ccf66f696fd5417516cf9449a29f32411</p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump softprops/action-gh-release from 2 to 3 by @dependabot[bot] in <a href="https://github.com/sualeh/build-maven-dependency/pull/1">https://github.com/sualeh/build-maven-dependency/pull/1</a></li>
<li>Bump actions/checkout from 6 to 7 by @dependabot[bot] in <a href="https://github.com/sualeh/build-maven-dependency/pull/2">https://github.com/sualeh/build-maven-dependency/pull/2</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/sualeh/build-maven-dependency/pull/1">https://github.com/sualeh/build-maven-dependency/pull/1</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sualeh/build-maven-dependency/compare/v1.0.8...v1.0.9">https://github.com/sualeh/build-maven-dependency/compare/v1.0.8...v1.0.9</a></p>
]]></content:encoded></item><item><title>Setup DepVault CLI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/setup-depvault-cli/</link><pubDate>Sun, 12 Jul 2026 06:07:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/setup-depvault-cli/</guid><description>Version updated for https://github.com/suxrobGM/depvault to version cli/v1.9.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Stored credentials (~/.depvault/credentials.json) are now encrypted at rest — DPAPI on Windows, an owner-only AES-GCM key file on POSIX — instead of plaintext. You must sign in again after upgrading: plaintext credential files are no longer migrated, and the server-side session cutover requires a fresh login regardless Fix long-lived sessions dropping to the auth-error panel on a second token expiry: token refresh is now attempted once per request (not once per process) and re-reads credentials from disk first, so a rotation performed by a concurrent request or another depvault process is picked up instead of tripping the server’s replay detection. CI-token 401s are returned as-is, since CI tokens aren’t refreshable login now flows straight into the vault unlock prompt, so push/pull work without a second command logout now revokes the refresh session server-side before clearing local credentials whoami shows the auth panel when the session has expired, instead of a generic failure Fix signing in with GitHub from a CLI login link leaving the CLI polling forever — the OAuth round-trip now carries the device code back (server-side fix; no CLI upgrade needed)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/suxrobGM/depvault">https://github.com/suxrobGM/depvault</a></strong> to version <strong>cli/v1.9.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-depvault-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Stored credentials (<code>~/.depvault/credentials.json</code>) are now encrypted at rest — DPAPI on Windows, an owner-only AES-GCM key file on POSIX — instead of plaintext. <strong>You must sign in again after upgrading</strong>: plaintext credential files are no longer migrated, and the server-side session cutover requires a fresh login regardless</li>
<li>Fix long-lived sessions dropping to the auth-error panel on a second token expiry: token refresh is now attempted once per request (not once per process) and re-reads credentials from disk first, so a rotation performed by a concurrent request or another <code>depvault</code> process is picked up instead of tripping the server&rsquo;s replay detection. CI-token 401s are returned as-is, since CI tokens aren&rsquo;t refreshable</li>
<li><code>login</code> now flows straight into the vault unlock prompt, so <code>push</code>/<code>pull</code> work without a second command</li>
<li><code>logout</code> now revokes the refresh session server-side before clearing local credentials</li>
<li><code>whoami</code> shows the auth panel when the session has expired, instead of a generic failure</li>
<li>Fix signing in with GitHub from a CLI login link leaving the CLI polling forever — the OAuth round-trip now carries the device code back (server-side fix; no CLI upgrade needed)</li>
</ul>
]]></content:encoded></item><item><title>MIU PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/miu-pr-review/</link><pubDate>Sun, 12 Jul 2026 06:06:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/miu-pr-review/</guid><description>Version updated for https://github.com/vanducng/miu-cr to version v0.85.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed miu-cr v0.85.3 AI code review for local changes and GitHub pull requests. Use it as a CLI, CI gate, or GitHub Action with your own LLM key.
Install curl -fsSL https://cr.miu.sh/install.sh | sh -s -- v0.85.3 brew install vanducng/tap/miucr go install github.com/vanducng/miu-cr/cmd/miucr@v0.85.3 GitHub Action:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vanducng/miu-cr">https://github.com/vanducng/miu-cr</a></strong> to version <strong>v0.85.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/miu-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="miu-cr-v0853">miu-cr v0.85.3</h2>
<p>AI code review for local changes and GitHub pull requests. Use it as a CLI, CI gate, or GitHub Action with your own LLM key.</p>
<h3 id="install">Install</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>curl -fsSL https://cr.miu.sh/install.sh | sh -s -- v0.85.3
</span></span><span style="display:flex;"><span>brew install vanducng/tap/miucr
</span></span><span style="display:flex;"><span>go install github.com/vanducng/miu-cr/cmd/miucr@v0.85.3
</span></span></code></pre></div><p>GitHub Action:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v6</span>
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">vanducng/miu-cr@v0.85.3</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span></code></pre></div><h3 id="common-commands">Common commands</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>miucr login --provider openai
</span></span><span style="display:flex;"><span>miucr review --staged
</span></span><span style="display:flex;"><span>miucr review --from main --to HEAD --gate high
</span></span><span style="display:flex;"><span>miucr review --pr owner/repo#123 --post
</span></span><span style="display:flex;"><span>miucr upgrade
</span></span></code></pre></div><p>Docs: <a href="https://cr.miu.sh">https://cr.miu.sh</a></p>
]]></content:encoded></item><item><title>MCP Test Harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/mcp-test-harness/</link><pubDate>Sun, 12 Jul 2026 06:06:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/mcp-test-harness/</guid><description>Version updated for https://github.com/vaquarkhan/mcp-test-harness to version v3.0.7.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Product website: integrations widget, features deck, visual gallery, README badge row. Website naming in user copy. All 18 PyPI packages and GHCR Docker at 3.0.7.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vaquarkhan/mcp-test-harness">https://github.com/vaquarkhan/mcp-test-harness</a></strong> to version <strong>v3.0.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcp-test-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Product website: integrations widget, features deck, visual gallery, README badge row. Website naming in user copy. All 18 PyPI packages and GHCR Docker at 3.0.7.</p>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/vibgrate-scan/</link><pubDate>Sun, 12 Jul 2026 06:05:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.711.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Vibgrate CLI 2026.711.2 Released 2026-07-11
This release of the vg command-line scanner introduces enhanced vulnerability detection and performance improvements. The documentation has also been updated for easier navigation to relevant resources.
What changed New vg scan now checks whether the vulnerable code in your dependencies is actually used, tagging findings as reachable, potentially reachable, not reached, or unknown. Improved The CLI’s public documentation now includes direct links to relevant vibgrate.com pages for easier access to full references. Performance Hosted library docs answers are now cached locally for a day, allowing for instant responses to repeat vg lib and AI-context lookups. Benchmarks Two-arm benchmark of this release against 2026.711.1, interleaved on one runner against the pinned corpus (157 metrics compared).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.711.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20267112">Vibgrate CLI 2026.711.2</h1>
<p><em>Released 2026-07-11</em></p>
<p>This release of the vg command-line scanner introduces enhanced vulnerability detection and performance improvements. The documentation has also been updated for easier navigation to relevant resources.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="new">New</h3>
<ul>
<li>vg scan now checks whether the vulnerable code in your dependencies is actually used, tagging findings as reachable, potentially reachable, not reached, or unknown.</li>
</ul>
<h3 id="improved">Improved</h3>
<ul>
<li>The CLI&rsquo;s public documentation now includes direct links to relevant vibgrate.com pages for easier access to full references.</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li>Hosted library docs answers are now cached locally for a day, allowing for instant responses to repeat vg lib and AI-context lookups.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.711.1, interleaved on one runner against the pinned corpus (157 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>18869 count</td>
          <td>18869 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>7530 count</td>
          <td>7530 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.97 ratio</td>
          <td>0.97 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>619.90 ms</td>
          <td>637.20 ms</td>
      </tr>
  </tbody>
</table>
<p>No regressions against the previous release.</p>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.711.2">https://vibgrate.com/changelog/cli/2026.711.2</a></p>
]]></content:encoded></item><item><title>VICE Security Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/vice-security-audit/</link><pubDate>Sun, 12 Jul 2026 06:05:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/12/vice-security-audit/</guid><description>Version updated for https://github.com/Webba-Creative-Technologies/vice to version v3.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Summary VICE 3.3.0 strengthens remote and local audits with stricter scope controls, safer probes, clearer evidence and more reliable reports.
This release keeps the existing CLI commands, runScan API, scan profiles and GitHub Action inputs compatible.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Webba-Creative-Technologies/vice">https://github.com/Webba-Creative-Technologies/vice</a></strong> to version <strong>v3.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vice-security-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="summary">Summary</h2>
<p>VICE 3.3.0 strengthens remote and local audits with stricter scope controls,
safer probes, clearer evidence and more reliable reports.</p>
<p>This release keeps the existing CLI commands, <code>runScan</code> API, scan profiles and
GitHub Action inputs compatible.</p>
<h2 id="security-and-scope">Security and scope</h2>
<ul>
<li>Strict URL, DNS, redirect, browser and raw socket scope enforcement</li>
<li>Per-scan isolation, cancellation, request budgets and bounded concurrency</li>
<li>Non-destructive remote probes for APIs, authentication, storage and login flows</li>
<li>Credentials kept on the original target and removed from reports and logs</li>
<li>Sensitive values redacted in JSON, SARIF, console and HTML reports</li>
</ul>
<h2 id="detection-quality">Detection quality</h2>
<ul>
<li>Evidence-based classification for Supabase, APIs, GraphQL, WebSockets, TLS and exposed services</li>
<li>Stable rule IDs, fingerprints, confidence levels and versioned scoring</li>
<li>Better distinction between confirmed findings, heuristics and public information</li>
<li>Reduced false positives for secrets, source maps, CORS, files, forms and public data</li>
<li>Deterministic client bundle collection for consistent CLI and platform results</li>
</ul>
<h2 id="reports-and-github-action">Reports and GitHub Action</h2>
<ul>
<li>Coverage, module errors, metrics and score reliability included in JSON reports</li>
<li>Per-rule score breakdown for easier result review</li>
<li>Live progress restored for interactive CLI scans</li>
<li>SARIF paths validated for GitHub Code Scanning</li>
<li>GitHub Action updated for CodeQL v4 and current Node-based actions</li>
<li>The moving <code>v3</code> tag now points to this release</li>
</ul>
<h2 id="validation">Validation</h2>
<ul>
<li>244 engine, reporter and CLI tests</li>
<li>GitHub Action self-audit completed successfully</li>
<li>npm audit reports no known vulnerabilities</li>
<li>Published package contains no tests, local reports or environment files</li>
</ul>
<h2 id="upgrade">Upgrade</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npm install -g vice-security@latest
</span></span></code></pre></div><p>GitHub Action users can keep the current major tag:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Webba-Creative-Technologies/vice@v3</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/ai-plugin-scanner/</link><pubDate>Sat, 11 Jul 2026 22:29:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.448.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/992e636d4bf312a3b4cdae1fc03a7ffc2eae478f with plugin-scanner 2.0.1049.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.447...v1.2.448</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.448</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>18</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/992e636d4bf312a3b4cdae1fc03a7ffc2eae478f">https://github.com/hashgraph-online/hol-guard/tree/992e636d4bf312a3b4cdae1fc03a7ffc2eae478f</a> with plugin-scanner 2.0.1049.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.447...v1.2.448">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.447...v1.2.448</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/hol-codex-plugin-scanner/</link><pubDate>Sat, 11 Jul 2026 22:28:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.448.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.448</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.448</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.448">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.448</a></p>
]]></content:encoded></item><item><title>Mirror to BitBucket GitHub Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/mirror-to-bitbucket-github-action/</link><pubDate>Sat, 11 Jul 2026 22:28:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/mirror-to-bitbucket-github-action/</guid><description>Version updated for https://github.com/heussd/mirror-to-bitbucket-github-action to version v3.
This action is used across all versions by 96 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/heussd/mirror-to-bitbucket-github-action/compare/v2...v3</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/heussd/mirror-to-bitbucket-github-action">https://github.com/heussd/mirror-to-bitbucket-github-action</a></strong> to version <strong>v3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>96</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mirror-to-bitbucket-github-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/heussd/mirror-to-bitbucket-github-action/compare/v2...v3">https://github.com/heussd/mirror-to-bitbucket-github-action/compare/v2...v3</a></p>
]]></content:encoded></item><item><title>Supply Chain Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/supply-chain-guard/</link><pubDate>Sat, 11 Jul 2026 22:27:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/supply-chain-guard/</guid><description>Version updated for https://github.com/homeofe/supply-chain-guard to version v5.12.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v5.12.0 (2026-07-11) Issue #54 hardening: oversized-file transparency + threat-intel indicator contract
Implements both hardening gaps tracked in issue #54 (follow-up to the merged PR #55 extraction/IOC hardening), plus the dependency maintenance merged this cycle (docker/login-action 4.4.0, vitest + @vitest/coverage-v8 4.1.10). This minor also carries PR #55’s archive-extraction and self-scan-suppression fix to npm (it landed after v5.11.1 was published).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/homeofe/supply-chain-guard">https://github.com/homeofe/supply-chain-guard</a></strong> to version <strong>v5.12.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/supply-chain-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="v5120-2026-07-11">v5.12.0 (2026-07-11)</h3>
<p><strong>Issue #54 hardening: oversized-file transparency + threat-intel indicator contract</strong></p>
<p>Implements both hardening gaps tracked in issue #54 (follow-up to the merged
PR #55 extraction/IOC hardening), plus the dependency maintenance merged this
cycle (docker/login-action 4.4.0, vitest + @vitest/coverage-v8 4.1.10). This
minor also carries PR #55&rsquo;s archive-extraction and self-scan-suppression fix
to npm (it landed after v5.11.1 was published).</p>
<ul>
<li>New rule <code>FILE_TOO_LARGE_SKIPPED</code> (info): the core, VSIX, npm, and PyPI
scanners no longer skip files above the 5 MB content-scan limit silently -
every skipped scannable file is surfaced with its path and size, because an
attacker can deliberately pad a payload past the limit to dodge scanning.
info severity: never affects exit codes; filterable via &ndash;min-severity or
&ndash;exclude FILE_TOO_LARGE_SKIPPED. The oversized body is never read.</li>
<li>Threat-intel indicator contract: feed values are LITERAL indicators, never
regexes. Domain values were previously compiled to RegExp with only dots
escaped, so a hostile or malformed remote feed value like &ldquo;(&rdquo; threw inside
the per-file loop - swallowed by the per-file catch, silently disabling all
downstream checks for every file while the scan exited green, and a valid
catastrophic pattern (&quot;(a+)+b&quot;) would be ReDoS-tested against full file
contents. Now: full metacharacter escaping (values match only themselves),
compiled once per unique value, with a substring fallback that can never
throw.</li>
<li>Type-aware quarantine at every feed ingestion point (<code>feed refresh</code>, the
legacy update API, and the cached-feed load at scan time): each entry must
match its type&rsquo;s shape (domain/ip/url/hash/package charsets, 2048-char cap).
Invalid entries are dropped deterministically; a rejected refresh never
overwrites the previous cache. This also stops a structurally-valid garbage
literal like a bare &ldquo;(&rdquo; from flooding reports with false matches.</li>
<li>npm/PyPI extracted-file walkers are now exported (scanExtractedNpmFiles /
scanExtractedFiles) so the size-limit behavior is regression-tested without
network; 16 new tests across all five scanner families and all three
ingestion paths.</li>
<li>An adversarial review gate BLOCKED the first candidate with 6 confirmed
findings, all fixed pre-tag: (1)+(2) the ip/url value shapes were
charset-only, so a degenerate flood value like ip &ldquo;.&rdquo; or url &ldquo;(&rdquo; passed the
quarantine and substring-matched a critical finding onto virtually every
scanned file - ip now requires IPv4/IPv6 structure, url an 8-char floor;
(3) the domain regex cache was unbounded (long-running MCP server + rotating
hostile feed = monotonic memory growth) - now cleared at 10k entries;
(4) severity is enum-checked and confidence range-checked (an unknown
severity string would have produced NaN scores downstream); (5) the
skills-scanner&rsquo;s agent-rules reader also surfaces oversized files now
(fifth family, full DoD parity); (6) the feed-reject error message bounds
the attacker-controlled type field, not just the value.</li>
</ul>
]]></content:encoded></item><item><title>Hosho Prompt Reviewer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/hosho-prompt-reviewer/</link><pubDate>Sat, 11 Jul 2026 22:27:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/hosho-prompt-reviewer/</guid><description>Version updated for https://github.com/HOSHO-AI/Hosho-prompt-optimization-public to version v1.41.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Taxonomy restructure — Provider-fit moves to Guidance, safety sub-factor retired Mirrors the API taxonomy change (API #175). The PR-comment renderer’s hardcoded taxonomy is load-bearing for the 4-macro score table, so it moves in lockstep:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/HOSHO-AI/Hosho-prompt-optimization-public">https://github.com/HOSHO-AI/Hosho-prompt-optimization-public</a></strong> to version <strong>v1.41.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hosho-prompt-reviewer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="taxonomy-restructure--provider-fit-moves-to-guidance-safety-sub-factor-retired">Taxonomy restructure — Provider-fit moves to Guidance, safety sub-factor retired</h2>
<p>Mirrors the API taxonomy change (API #175). The PR-comment renderer&rsquo;s hardcoded taxonomy is load-bearing for the 4-macro score table, so it moves in lockstep:</p>
<ul>
<li><strong>Provider-fit</strong> (<code>model-fit</code>) now buckets under the <strong>Guidance</strong> macro (was Structure) — its insights and macroScore are now consistent.</li>
<li>The <strong><code>safety</code></strong> sub-factor is retired; deterministic agent-security convention findings now tag under <strong>Inputs</strong> (Guidance macro).</li>
<li>Legacy v2-fallback mapping updated for coherence.</li>
</ul>
<p>Rebuilt <code>dist/</code> bundle. <code>@v1</code> now points here.</p>
]]></content:encoded></item><item><title>cibuild-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/cibuild-action/</link><pubDate>Sat, 11 Jul 2026 22:26:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/cibuild-action/</guid><description>Version updated for https://github.com/invarnhq/cibuild to version v2.3.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v2.3.6</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/invarnhq/cibuild">https://github.com/invarnhq/cibuild</a></strong> to version <strong>v2.3.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cibuild-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release v2.3.6</p>
]]></content:encoded></item><item><title>Dependency Support Policy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/dependency-support-policy/</link><pubDate>Sat, 11 Jul 2026 22:26:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/dependency-support-policy/</guid><description>Version updated for https://github.com/isaac-cf-wong/dependency-support-policy-action to version v0.1.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.1.1 - 2026-07-11 🐛 Bug Fixes Shorten action description for Marketplace listing (#18) - (1297dd8) Compute TestPyPI publish version fresh via hatch (#19) - (4f9ff16) Point the floating major tag at the release commit (#22) - (f6fc6d3) ⚙️ Miscellaneous Tasks (deps) Update dependency hatch to &amp;gt;=1.17.1 (#20) - (39b7c79) (deps) Update pre-commit hook rbubley/mirrors-prettier to v3.9.5 (#21) - (9a317cd) Contributing: Contributions are welcome! See the Contributing Guide.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/isaac-cf-wong/dependency-support-policy-action">https://github.com/isaac-cf-wong/dependency-support-policy-action</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/dependency-support-policy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="011---2026-07-11"><a href="https://github.com/isaac-cf-wong/dependency-support-policy-action/compare/v0.1.0..v0.1.1">0.1.1</a> - 2026-07-11</h2>
<h3 id="-bug-fixes">🐛 Bug Fixes</h3>
<ul>
<li>Shorten action description for Marketplace listing (#18) - (<a href="https://github.com/isaac-cf-wong/dependency-support-policy-action/commit/1297dd8d2cffde0b004eba5f2f5e892de3f58892">1297dd8</a>)</li>
<li>Compute TestPyPI publish version fresh via hatch (#19) - (<a href="https://github.com/isaac-cf-wong/dependency-support-policy-action/commit/4f9ff168decb2f779294ecad4b6d6e214d9305cc">4f9ff16</a>)</li>
<li>Point the floating major tag at the release commit (#22) - (<a href="https://github.com/isaac-cf-wong/dependency-support-policy-action/commit/f6fc6d354d6867021e58cdfbb8c22175ed11b3b3">f6fc6d3</a>)</li>
</ul>
<h3 id="-miscellaneous-tasks">⚙️ Miscellaneous Tasks</h3>
<ul>
<li><em>(deps)</em> Update dependency hatch to &gt;=1.17.1 (#20) - (<a href="https://github.com/isaac-cf-wong/dependency-support-policy-action/commit/39b7c797bc14093286ae0bdcf43c9f008df04d44">39b7c79</a>)</li>
<li><em>(deps)</em> Update pre-commit hook rbubley/mirrors-prettier to v3.9.5 (#21) - (<a href="https://github.com/isaac-cf-wong/dependency-support-policy-action/commit/9a317cda9b3b210f4ac055f3dcfc8409142096eb">9a317cd</a>)</li>
</ul>
<hr>
<p><strong>Contributing</strong>: Contributions are welcome! See the <a href="https://github.com/isaac-cf-wong/dependency-support-policy-action/blob/main/CONTRIBUTING.md">Contributing Guide</a>.</p>
<p><strong>Questions?</strong> Open an issue on <a href="https://github.com/isaac-cf-wong/dependency-support-policy-action/issues">GitHub</a>.</p>
]]></content:encoded></item><item><title>Actions Breakage Radar</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/actions-breakage-radar/</link><pubDate>Sat, 11 Jul 2026 22:25:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/actions-breakage-radar/</guid><description>Version updated for https://github.com/jackwalkerlabs/actions-breakage-radar to version v1.1.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Parser compatibility patch for valid GitHub Actions YAML forms.
Supports bare-dash step mappings where uses appears on the following line Supports quoted jobs, steps, runs-on, and uses keys Adds non-null repository and branch report-output coverage 34 tests pass; live 3-repository validation remains 12 workflows and 23 migration warnings with zero failures Use the stable major tag: jackwalkerlabs/actions-breakage-radar@v1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jackwalkerlabs/actions-breakage-radar">https://github.com/jackwalkerlabs/actions-breakage-radar</a></strong> to version <strong>v1.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/actions-breakage-radar">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Parser compatibility patch for valid GitHub Actions YAML forms.</p>
<ul>
<li>Supports bare-dash step mappings where uses appears on the following line</li>
<li>Supports quoted jobs, steps, runs-on, and uses keys</li>
<li>Adds non-null repository and branch report-output coverage</li>
<li>34 tests pass; live 3-repository validation remains 12 workflows and 23 migration warnings with zero failures</li>
</ul>
<p>Use the stable major tag: jackwalkerlabs/actions-breakage-radar@v1</p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/neurolink-ai/</link><pubDate>Sat, 11 Jul 2026 22:25:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v9.86.3.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 9.86.3 (2026-07-11) Bug Fixes (deps): declare js-yaml + fast-xml-parser as runtime dependencies (48f54d5)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v9.86.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="9863-2026-07-11"><a href="https://github.com/juspay/neurolink/compare/v9.86.2...v9.86.3">9.86.3</a> (2026-07-11)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(deps):</strong>  declare js-yaml + fast-xml-parser as runtime dependencies (<a href="https://github.com/juspay/neurolink/commit/48f54d5d4085a4e77764a2fcab9e5b2c5fa1403f">48f54d5</a>)</li>
</ul>
]]></content:encoded></item><item><title>L10n.dev AI Localization Automation</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/l10n.dev-ai-localization-automation/</link><pubDate>Sat, 11 Jul 2026 22:24:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/l10n.dev-ai-localization-automation/</guid><description>Version updated for https://github.com/l10n-dev/ai-l10n to version v1.10.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Added client option to identify integrations of the l10n.dev localization platform. SDK:
Added authOptions as an optional arg to the translate method of AITranslator class. Add client to identify client’s usage correctly Moved apiKey to the authOptions. Breaking changes Optional apiKey arg now in the authOptions CORE:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/l10n-dev/ai-l10n">https://github.com/l10n-dev/ai-l10n</a></strong> to version <strong>v1.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/l10n-dev-ai-localization-automation">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Added <code>client</code> option to identify integrations of the l10n.dev localization platform.</li>
</ul>
<p>SDK:</p>
<ul>
<li>Added <code>authOptions</code> as an optional arg to the <code>translate</code> method of <code>AITranslator</code> class.
<ul>
<li>Add <code>client</code> to identify client&rsquo;s usage correctly</li>
<li>Moved <code>apiKey</code> to the <code>authOptions</code>.</li>
</ul>
</li>
</ul>
<h3 id="breaking-changes">Breaking changes</h3>
<ul>
<li>Optional <code>apiKey</code> arg now in the <code>authOptions</code></li>
</ul>
<p>CORE:</p>
<ul>
<li>API documentation is improved</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/l10n-dev/ai-l10n/compare/v1.9.1...v1.10.0">https://github.com/l10n-dev/ai-l10n/compare/v1.9.1...v1.10.0</a></p>
]]></content:encoded></item><item><title>SkillCI Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/skillci-audit/</link><pubDate>Sat, 11 Jul 2026 22:23:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/skillci-audit/</guid><description>Version updated for https://github.com/LM20230311/skillci to version v0.4.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Phase 3 complete\n\n- Add strict Node behavior-trace assertions for commands, file reads, file writes, and network API attempts.\n- Fail behavior cases on undeclared observed commands or file activity.\n- Keep Docker network denial and constrained fixture isolation in place.\n- Publish npm automatically through GitHub OIDC trusted publishing.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/LM20230311/skillci">https://github.com/LM20230311/skillci</a></strong> to version <strong>v0.4.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skillci-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="phase-3-completenn--add-strict-node-behavior-trace-assertions-for-commands-file-reads-file-writes-and-network-api-attemptsn--fail-behavior-cases-on-undeclared-observed-commands-or-file-activityn--keep-docker-network-denial-and-constrained-fixture-isolation-in-placen--publish-npm-automatically-through-github-oidc-trusted-publishing">Phase 3 complete\n\n- Add strict Node behavior-trace assertions for commands, file reads, file writes, and network API attempts.\n- Fail behavior cases on undeclared observed commands or file activity.\n- Keep Docker network denial and constrained fixture isolation in place.\n- Publish npm automatically through GitHub OIDC trusted publishing.</h2>
]]></content:encoded></item><item><title>Selvedge Coverage Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/selvedge-coverage-check/</link><pubDate>Sat, 11 Jul 2026 22:23:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/selvedge-coverage-check/</guid><description>Version updated for https://github.com/masondelan/selvedge to version v0.3.9.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s changed docs(roadmap): capture the reason-vs-name keying convergence (cowork-os) docs: state the git-import identity boundary + plan the provenance/trust-tier follow-up docs(release): v0.3.9.1 — the dev.to feedback release fix: post-review hardening for the v0.3.9.1 features feat(semantic): optional fuzzy recall — prior_attempts survives renames feat(import): git-history backfill — pre-Selvedge reverts become first-class records feat(hook): PreToolUse enforcement hook — the prior_attempts check becomes deterministic feat(supersede): decision states + supersede flow — reverted is no longer a permanent ban gitignore: keep LLMO mention-share scoreboard local-only build(docker): add Dockerfile for the Docker MCP Catalog submission build(deps): bump actions/setup-python from 5 to 6 build(deps): bump actions/checkout from 4 to 7 chore(gitignore): keep docs/growth-master-plan.md local-only docs(readme): remove broken editor install badges docs: correct phase markers — HTTP + auth ships in v0.4.1, not v0.4.0 docs(architecture): make the Phase 3.2 heading paren-last so notion-sync parses it fix(notion-sync): bump LATEST_SHIPPED to 0.3.9 so the Roadmap mirror marks v0.3.9 phases Done docs(architecture): reconcile v0.3.9 phase plan — Agent Trace export shipped, dev-ergonomics deferred to v0.3.16 docs(manifest): note agent-trace export in the bundle/listing description docs: pin the Coverage Check action example to @v0.3.9 fix(action): trim Marketplace description under the 125-char limit Install: pip install selvedge==0.3.9.1 PyPI: https://pypi.org/project/selvedge/ Docs: https://github.com/masondelan/selvedge/blob/main/docs/getting-started.md</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/masondelan/selvedge">https://github.com/masondelan/selvedge</a></strong> to version <strong>v0.3.9.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/selvedge-coverage-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s changed</h2>
<ul>
<li>docs(roadmap): capture the reason-vs-name keying convergence (cowork-os)</li>
<li>docs: state the git-import identity boundary + plan the provenance/trust-tier follow-up</li>
<li>docs(release): v0.3.9.1 — the dev.to feedback release</li>
<li>fix: post-review hardening for the v0.3.9.1 features</li>
<li>feat(semantic): optional fuzzy recall — prior_attempts survives renames</li>
<li>feat(import): git-history backfill — pre-Selvedge reverts become first-class records</li>
<li>feat(hook): PreToolUse enforcement hook — the prior_attempts check becomes deterministic</li>
<li>feat(supersede): decision states + supersede flow — reverted is no longer a permanent ban</li>
<li>gitignore: keep LLMO mention-share scoreboard local-only</li>
<li>build(docker): add Dockerfile for the Docker MCP Catalog submission</li>
<li>build(deps): bump actions/setup-python from 5 to 6</li>
<li>build(deps): bump actions/checkout from 4 to 7</li>
<li>chore(gitignore): keep docs/growth-master-plan.md local-only</li>
<li>docs(readme): remove broken editor install badges</li>
<li>docs: correct phase markers — HTTP + auth ships in v0.4.1, not v0.4.0</li>
<li>docs(architecture): make the Phase 3.2 heading paren-last so notion-sync parses it</li>
<li>fix(notion-sync): bump LATEST_SHIPPED to 0.3.9 so the Roadmap mirror marks v0.3.9 phases Done</li>
<li>docs(architecture): reconcile v0.3.9 phase plan — Agent Trace export shipped, dev-ergonomics deferred to v0.3.16</li>
<li>docs(manifest): note agent-trace export in the bundle/listing description</li>
<li>docs: pin the Coverage Check action example to @v0.3.9</li>
<li>fix(action): trim Marketplace description under the 125-char limit</li>
</ul>
<hr>
<p><strong>Install:</strong> <code>pip install selvedge==0.3.9.1</code>
<strong>PyPI:</strong> <a href="https://pypi.org/project/selvedge/">https://pypi.org/project/selvedge/</a>
<strong>Docs:</strong> <a href="https://github.com/masondelan/selvedge/blob/main/docs/getting-started.md">https://github.com/masondelan/selvedge/blob/main/docs/getting-started.md</a></p>
]]></content:encoded></item><item><title>Star History Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/star-history-action/</link><pubDate>Sat, 11 Jul 2026 22:22:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/star-history-action/</guid><description>Version updated for https://github.com/narayann7/star-history-action to version v1.0.1.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Makes the star history chart render on GitHub and on package registries (npm, pub.dev), and stops external image URLs from 404ing.
Added PNG output. The renderer rasterizes a star-history.png alongside the SVGs, so the chart shows on registries that cannot render SVG (npm, pub.dev). readme-format input (picture or png). picture keeps the SVG &amp;lt;picture&amp;gt; block with GitHub dark/light support; png writes a plain-markdown image at an absolute raw.githubusercontent.com URL, the only form that renders on npm and pub.dev. Changed Stable filenames. Charts are written to fixed paths (star-history-&amp;lt;theme&amp;gt;.svg, star-history.png) and overwritten in place instead of timestamped names. A frozen README URL on a registry no longer 404s when a new chart is generated. This action’s own repository now demos with a static placeholder and no longer commits its live chart into git. Fixed PNG rasterization stripped the decorative feTurbulence/feDisplacementMap sketch filter, which crashed the raster engine (resvg). The SVG output keeps the filter; only the PNG drops it. Compatibility Repositories upgrading from 1.0.0 keep their old timestamped files, so any already published registry README that points at the old URL still resolves. The action stops producing timestamped names but does not delete existing ones. On the first run after upgrade, the chart is regenerated even when the star count is unchanged, so the new stable files and the PNG are created once. Full CHANGELOG: https://github.com/narayann7/star-history-action/blob/main/CHANGELOG.md</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/narayann7/star-history-action">https://github.com/narayann7/star-history-action</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/star-history-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Makes the star history chart render on GitHub and on package registries (npm, pub.dev), and stops external image URLs from 404ing.</p>
<h3 id="added">Added</h3>
<ul>
<li>PNG output. The renderer rasterizes a <code>star-history.png</code> alongside the SVGs, so the chart shows on registries that cannot render SVG (npm, pub.dev).</li>
<li><code>readme-format</code> input (<code>picture</code> or <code>png</code>). <code>picture</code> keeps the SVG <code>&lt;picture&gt;</code> block with GitHub dark/light support; <code>png</code> writes a plain-markdown image at an absolute <code>raw.githubusercontent.com</code> URL, the only form that renders on npm and pub.dev.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>Stable filenames. Charts are written to fixed paths (<code>star-history-&lt;theme&gt;.svg</code>, <code>star-history.png</code>) and overwritten in place instead of timestamped names. A frozen README URL on a registry no longer 404s when a new chart is generated.</li>
<li>This action&rsquo;s own repository now demos with a static placeholder and no longer commits its live chart into git.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>PNG rasterization stripped the decorative <code>feTurbulence</code>/<code>feDisplacementMap</code> sketch filter, which crashed the raster engine (resvg). The SVG output keeps the filter; only the PNG drops it.</li>
</ul>
<h3 id="compatibility">Compatibility</h3>
<ul>
<li>Repositories upgrading from 1.0.0 keep their old timestamped files, so any already published registry README that points at the old URL still resolves. The action stops producing timestamped names but does not delete existing ones.</li>
<li>On the first run after upgrade, the chart is regenerated even when the star count is unchanged, so the new stable files and the PNG are created once.</li>
</ul>
<p><strong>Full CHANGELOG:</strong> <a href="https://github.com/narayann7/star-history-action/blob/main/CHANGELOG.md">https://github.com/narayann7/star-history-action/blob/main/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>Setup Nimbus</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/setup-nimbus/</link><pubDate>Sat, 11 Jul 2026 22:22:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/setup-nimbus/</guid><description>Version updated for https://github.com/nimbus-solution/setup-nimbus to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Resolve latest via release redirect, not the rate-limited API (fcc9f53) Fix curl SIGPIPE (exit 23) when resolving the latest version (c54c8ac) Retry transient download failures on hosted runners (ec9659c) setup-nimbus v1.0.0 — install the Nimbus CLI in GitHub Actions (330632a)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nimbus-solution/setup-nimbus">https://github.com/nimbus-solution/setup-nimbus</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-nimbus">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Resolve latest via release redirect, not the rate-limited API (fcc9f53)</li>
<li>Fix curl SIGPIPE (exit 23) when resolving the latest version (c54c8ac)</li>
<li>Retry transient download failures on hosted runners (ec9659c)</li>
<li>setup-nimbus v1.0.0 — install the Nimbus CLI in GitHub Actions (330632a)</li>
</ul>
]]></content:encoded></item><item><title>Run AER Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/run-aer-tests/</link><pubDate>Sat, 11 Jul 2026 22:21:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/run-aer-tests/</guid><description>Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.13.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Version v1.2.13
Parse Text Arguments In TIMEVALUE Formula Function
Match Salesforce Errors For emptyRecycleBin, Savepoints, And convertLead
Renew Expired CI Licenses To Support Monthly Subscriptions
Fix EntityParticle And FieldDefinition Metadata</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/octoberswimmer/aer-dist">https://github.com/octoberswimmer/aer-dist</a></strong> to version <strong>v1.2.13</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-aer-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Version v1.2.13</p>
<ul>
<li>
<p>Parse Text Arguments In TIMEVALUE Formula Function</p>
</li>
<li>
<p>Match Salesforce Errors For emptyRecycleBin, Savepoints, And convertLead</p>
</li>
<li>
<p>Renew Expired CI Licenses To Support Monthly Subscriptions</p>
</li>
<li>
<p>Fix EntityParticle And FieldDefinition Metadata</p>
</li>
<li>
<p>Fix Platform Event Describes And Route Describe Properties Through Getter Logic</p>
</li>
<li>
<p>Throw FIELD_INTEGRITY_EXCEPTION For Lookup Ids Of Unsupported Types</p>
</li>
<li>
<p>Reject Floats For Integer And Deny samePackage In JSON Deserialization</p>
</li>
<li>
<p>Throw For String.format Number Patterns And Pad With Spaces On Empty Padding</p>
</li>
<li>
<p>Skip User-Mode Permission Checks In System-Mode Contexts For Keyword DML</p>
</li>
</ul>
]]></content:encoded></item><item><title>Agnostic Code Metrics</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/agnostic-code-metrics/</link><pubDate>Sat, 11 Jul 2026 22:20:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/agnostic-code-metrics/</guid><description>Version updated for https://github.com/rw-core/agnostic-code-metrics to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Rolling release; tracks the latest v1.x. Pin to v1.0.5 for immutability.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rw-core/agnostic-code-metrics">https://github.com/rw-core/agnostic-code-metrics</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agnostic-code-metrics">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Rolling release; tracks the latest v1.x. Pin to v1.0.5 for immutability.</p>
]]></content:encoded></item><item><title>sec-recon SBOM gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/sec-recon-sbom-gate/</link><pubDate>Sat, 11 Jul 2026 22:20:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/sec-recon-sbom-gate/</guid><description>Version updated for https://github.com/Shurtug4l/sec-recon-agent to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Publishes the sec-recon SBOM gate to the GitHub Marketplace.
No behavioural change to the gate since v0.1.0. This release trims the action.yml description under the Marketplace 125-character limit and folds in the dependency-lockfile security patches (aiohttp, cryptography, joserfc, pyjwt, python-multipart, starlette, pydantic-ai, js-yaml).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Shurtug4l/sec-recon-agent">https://github.com/Shurtug4l/sec-recon-agent</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sec-recon-sbom-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Publishes the <strong>sec-recon SBOM gate</strong> to the GitHub Marketplace.</p>
<p>No behavioural change to the gate since <code>v0.1.0</code>. This release trims the <code>action.yml</code> description under the Marketplace 125-character limit and folds in the dependency-lockfile security patches (<code>aiohttp</code>, <code>cryptography</code>, <code>joserfc</code>, <code>pyjwt</code>, <code>python-multipart</code>, <code>starlette</code>, <code>pydantic-ai</code>, <code>js-yaml</code>).</p>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Shurtug4l/sec-recon-agent@v0.1.1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">sbom-path</span>: <span style="color:#ae81ff">sbom.cdx.json     </span> <span style="color:#75715e"># CycloneDX / SPDX JSON or requirements.txt</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">act                 </span> <span style="color:#75715e"># act | attend | track-star | never</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">github-token</span>: <span style="color:#ae81ff">${{ github.token }}  </span> <span style="color:#75715e"># optional; omit = degraded, not silent</span>
</span></span></code></pre></div><p>Deterministic and LLM-free: OSV.dev advisories enriched with CISA KEV, FIRST EPSS and public-exploit signals, prioritised with SSVC, rendered to SARIF 2.1.0 and OpenVEX v0.2.0. The exit code is the CI contract.</p>
]]></content:encoded></item><item><title>Harnessie Verify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/harnessie-verify/</link><pubDate>Sat, 11 Jul 2026 22:19:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/harnessie-verify/</guid><description>Version updated for https://github.com/snapsynapse/harnessie-verify-action to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First release. Adopted via a recorded, human-arbitrated decision: AIDR-0007.
Treat a pull request’s description as claims, not evidence. This action runs your deterministic checks sandboxed (exit codes only), then a fresh-context verifier model that never sees the author’s narrative tests each remaining claim against the actual artifacts, and the job’s exit code gates the merge.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/snapsynapse/harnessie-verify-action">https://github.com/snapsynapse/harnessie-verify-action</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/harnessie-verify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release. Adopted via a recorded, human-arbitrated decision: <a href="https://github.com/snapsynapse/harnessie/blob/main/decisions/AIDR-0007-ship-harnessie-verify-as-a-github-action.md">AIDR-0007</a>.</p>
<p>Treat a pull request&rsquo;s description as claims, not evidence. This action runs your deterministic checks sandboxed (exit codes only), then a fresh-context verifier model that never sees the author&rsquo;s narrative tests each remaining claim against the actual artifacts, and the job&rsquo;s exit code gates the merge.</p>
<h2 id="what-ships-in-010">What ships in 0.1.0</h2>
<ul>
<li>Fail-closed exit contract: 0 verified, 1 failed, 2 cannot-verify, and cannot-verify fails the job by default because unverified is not passed (relaxable to advisory with <code>fail-on-cannot-verify: false</code>)</li>
<li><code>criteria: auto</code> derives claims verbatim from the PR body, provenance-stamped, with deliberately no extraction intelligence: an action that authors the claims it grades is self-dealing</li>
<li>PR diff staged into the workspace so change-surface claims (&ldquo;docs-only&rdquo;, &ldquo;additive&rdquo;) are checkable</li>
<li>Bring your own verifier model: any OpenAI-compatible endpoint, including one on your own infrastructure, so untrusted diffs never leave machines you control</li>
<li><code>pull_request_target</code> refused at runtime; the README documents the safe trigger pattern</li>
<li>OS sandbox inherited from the harness (bubblewrap, firejail, or docker on Linux runners; fail-closed when none is admitted)</li>
<li>Structured claim table to the job summary; model prose confined to the uploaded report artifact</li>
<li>Offline CI matrix proving the exit-code mapping with a mock provider</li>
</ul>
<h2 id="provenance">Provenance</h2>
<p>The tool behind this action refuted a claim in its own author&rsquo;s PR on its first real run; the description was corrected and only then did it verify. Pinned to harnessie 0.7.1 (<a href="https://pypi.org/project/harnessie/">PyPI</a>). Docs: <a href="https://harnessie.com/">https://harnessie.com/</a></p>
<p>A VERIFIED run requires your live verifier endpoint; see the README quickstart (one workflow file, under five minutes).</p>
]]></content:encoded></item><item><title>Pipr Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/pipr-review/</link><pubDate>Sat, 11 Jul 2026 22:19:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/pipr-review/</guid><description>Version updated for https://github.com/somus/pipr to version v0.3.8.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.3.8 (2026-07-11) Features config: configure main comment presentation (#56) (3c9de80) This PR was generated with Release Please. See documentation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somus/pipr">https://github.com/somus/pipr</a></strong> to version <strong>v0.3.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pipr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="038-2026-07-11"><a href="https://github.com/somus/pipr/compare/v0.3.7...v0.3.8">0.3.8</a> (2026-07-11)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>config:</strong> configure main comment presentation (<a href="https://github.com/somus/pipr/issues/56">#56</a>) (<a href="https://github.com/somus/pipr/commit/3c9de807d3095cba19ac102bc006703addc0b68e">3c9de80</a>)</li>
</ul>
<hr>
<p>This PR was generated with <a href="https://github.com/googleapis/release-please">Release Please</a>. See <a href="https://github.com/googleapis/release-please#release-please">documentation</a>.</p>
<!-- stage-review-badge-begin -->
]]></content:encoded></item><item><title>Normalize Major Version Tag</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/normalize-major-version-tag/</link><pubDate>Sat, 11 Jul 2026 22:18:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/normalize-major-version-tag/</guid><description>Version updated for https://github.com/stairwaytowonderland/normalize-majorver to version v1.0.9.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed chore(release): 1.0.9
1.0.9 (2026-07-11) 🐛 Bug Fixes add checkov comments to publish inputs; removed unnecessary inputs from main ci (9a5334d)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stairwaytowonderland/normalize-majorver">https://github.com/stairwaytowonderland/normalize-majorver</a></strong> to version <strong>v1.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/normalize-major-version-tag">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>chore(release): 1.0.9</p>
<h2 id="109-2026-07-11"><a href="https://github.com/stairwaytowonderland/normalize-majorver/compare/v1.0.8...v1.0.9">1.0.9</a> (2026-07-11)</h2>
<h3 id="-bug-fixes">🐛 Bug Fixes</h3>
<ul>
<li>add checkov comments to publish inputs; removed unnecessary inputs from main ci (<a href="https://github.com/stairwaytowonderland/normalize-majorver/commit/9a5334d7bbd733dee7454a42e8adff762016725b">9a5334d</a>)</li>
</ul>
]]></content:encoded></item><item><title>Graveyard Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/graveyard-check/</link><pubDate>Sat, 11 Jul 2026 22:17:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/graveyard-check/</guid><description>Version updated for https://github.com/TahaKotwal12/graveyard-check to version v0.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First public release of graveyard-check — a CLI that scans your npm lockfile, flags dependencies that are effectively abandoned, and recommends verified community- maintained successors.
What it does graveyard-check scan — scans your package-lock.json, flags likely-abandoned or at-risk dependencies with evidence (last release/commit age, npm deprecation flag, issue response rate), and suggests a maintained successor where one exists graveyard-check check &amp;lt;package&amp;gt; — single-package lookup, no lockfile required --json output and a GitHub Action wrapper for CI integration Seed dataset Ships with 9 researched successor records covering well-known npm abandonment cases: request, node-sass, moment, request-promise, istanbul, gulp-util, colors, faker, and tslint. Every record is backed by verified evidence, not guesses — see data/successors/SCHEMA.md.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TahaKotwal12/graveyard-check">https://github.com/TahaKotwal12/graveyard-check</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/graveyard-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release of graveyard-check — a CLI that scans your npm lockfile, flags
dependencies that are effectively abandoned, and recommends verified community-
maintained successors.</p>
<h2 id="what-it-does">What it does</h2>
<ul>
<li><code>graveyard-check scan</code> — scans your package-lock.json, flags likely-abandoned or
at-risk dependencies with evidence (last release/commit age, npm deprecation flag,
issue response rate), and suggests a maintained successor where one exists</li>
<li><code>graveyard-check check &lt;package&gt;</code> — single-package lookup, no lockfile required</li>
<li><code>--json</code> output and a GitHub Action wrapper for CI integration</li>
</ul>
<h2 id="seed-dataset">Seed dataset</h2>
<p>Ships with 9 researched successor records covering well-known npm abandonment cases:
request, node-sass, moment, request-promise, istanbul, gulp-util, colors, faker,
and tslint. Every record is backed by verified evidence, not guesses — see
<code>data/successors/SCHEMA.md</code>.</p>
<p>Notable finding from building this dataset: <code>npm install faker</code> still installs
<code>6.6.6</code> — the January 2022 sabotage stub — four and a half years later.</p>
<h2 id="contributing">Contributing</h2>
<p>The dataset grows through community PRs. See <code>CONTRIBUTING.md</code> for how to submit
a successor record — the bar for evidence is high on purpose, since this data is
the whole point of the tool.</p>
<h2 id="install">Install</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx graveyard-check scan
</span></span></code></pre></div><h2 id="whats-not-here-yet">What&rsquo;s not here yet</h2>
<ul>
<li>npm/pnpm/yarn lockfile support only covers <code>package-lock.json</code> for now —
pnpm-lock.yaml and yarn.lock are planned</li>
<li>Single ecosystem (npm) — PyPI/Go/crates are on the roadmap</li>
<li>Fork-health analysis (auto-ranking forks of a dead repo) is not yet automated</li>
</ul>
]]></content:encoded></item><item><title>Install bashunit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/install-bashunit/</link><pubDate>Sat, 11 Jul 2026 22:17:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/install-bashunit/</guid><description>Version updated for https://github.com/TypedDevs/bashunit to version 0.41.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ✨ Improvements --retry &amp;lt;n&amp;gt; / BASHUNIT_RETRY re-runs a failed test up to N times; passes if any attempt passes, annotates retried tests, and works with --parallel and --stop-on-failure (#737) --random-order with --seed &amp;lt;n&amp;gt; / BASHUNIT_SEED randomizes test file and function order to surface inter-test coupling; prints the seed for reproducible replay and works with --parallel (#738) --shard &amp;lt;index&amp;gt;/&amp;lt;total&amp;gt; runs a deterministic, non-overlapping subset of the test files to split a suite across parallel CI runners; composes with --parallel (#739) --report-tap &amp;lt;file&amp;gt; writes a TAP v13 report to a file (complements the streaming --output tap) (#740) --report-json &amp;lt;file&amp;gt; writes results as JSON (summary counts + per-test records); no jq dependency (#741) assert_file_permissions &amp;lt;mode&amp;gt; &amp;lt;file&amp;gt; asserts a file’s octal permission mode; portable across GNU/BSD stat (#742) assert_array_length &amp;lt;n&amp;gt; &amp;lt;array&amp;gt; asserts an array has exactly n elements (#743) assert_within_delta &amp;lt;expected&amp;gt; &amp;lt;actual&amp;gt; &amp;lt;delta&amp;gt; asserts a number is within a tolerance; supports floats (#744) 🐛 Bug Fixes watch subcommand failed with bashunit::watch::run: command not found in the released binary because src/watch.sh was missing from the build; it is now bundled (#735) 🛠️ Changes Faster test execution by removing subprocess forks from hot paths (no behaviour change) 👥 Contributors @Chemaclass Checksum SHA256: 146c9b1f5462633d40c377ab0548bbd1a720ce365f49ef6942621192b4d15f79</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TypedDevs/bashunit">https://github.com/TypedDevs/bashunit</a></strong> to version <strong>0.41.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-bashunit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-improvements">✨ Improvements</h2>
<ul>
<li><code>--retry &lt;n&gt;</code> / <code>BASHUNIT_RETRY</code> re-runs a failed test up to N times; passes if any attempt passes, annotates retried tests, and works with <code>--parallel</code> and <code>--stop-on-failure</code> (#737)</li>
<li><code>--random-order</code> with <code>--seed &lt;n&gt;</code> / <code>BASHUNIT_SEED</code> randomizes test file and function order to surface inter-test coupling; prints the seed for reproducible replay and works with <code>--parallel</code> (#738)</li>
<li><code>--shard &lt;index&gt;/&lt;total&gt;</code> runs a deterministic, non-overlapping subset of the test files to split a suite across parallel CI runners; composes with <code>--parallel</code> (#739)</li>
<li><code>--report-tap &lt;file&gt;</code> writes a TAP v13 report to a file (complements the streaming <code>--output tap</code>) (#740)</li>
<li><code>--report-json &lt;file&gt;</code> writes results as JSON (summary counts + per-test records); no <code>jq</code> dependency (#741)</li>
<li><code>assert_file_permissions &lt;mode&gt; &lt;file&gt;</code> asserts a file&rsquo;s octal permission mode; portable across GNU/BSD <code>stat</code> (#742)</li>
<li><code>assert_array_length &lt;n&gt; &lt;array&gt;</code> asserts an array has exactly <code>n</code> elements (#743)</li>
<li><code>assert_within_delta &lt;expected&gt; &lt;actual&gt; &lt;delta&gt;</code> asserts a number is within a tolerance; supports floats (#744)</li>
</ul>
<h2 id="-bug-fixes">🐛 Bug Fixes</h2>
<ul>
<li><code>watch</code> subcommand failed with <code>bashunit::watch::run: command not found</code> in the released binary because <code>src/watch.sh</code> was missing from the build; it is now bundled (#735)</li>
</ul>
<h2 id="-changes">🛠️ Changes</h2>
<ul>
<li>Faster test execution by removing subprocess forks from hot paths (no behaviour change)</li>
</ul>
<h2 id="-contributors">👥 Contributors</h2>
<ul>
<li>@Chemaclass</li>
</ul>
<h2 id="checksum">Checksum</h2>
<p>SHA256: <code>146c9b1f5462633d40c377ab0548bbd1a720ce365f49ef6942621192b4d15f79</code></p>
<p><strong>Full Changelog:</strong> <a href="https://github.com/TypedDevs/bashunit/compare/0.40.0...0.41.0">0.40.0&hellip;0.41.0</a></p>
]]></content:encoded></item><item><title>MCP Test Harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/mcp-test-harness/</link><pubDate>Sat, 11 Jul 2026 22:16:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/mcp-test-harness/</guid><description>Version updated for https://github.com/vaquarkhan/mcp-test-harness to version v3.0.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed GitHub Pages PyPI stats bar fix, SPONSORS.md, all 18 PyPI packages and GHCR Docker at 3.0.6.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vaquarkhan/mcp-test-harness">https://github.com/vaquarkhan/mcp-test-harness</a></strong> to version <strong>v3.0.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcp-test-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>GitHub Pages PyPI stats bar fix, SPONSORS.md, all 18 PyPI packages and GHCR Docker at 3.0.6.</p>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/vibgrate-scan/</link><pubDate>Sat, 11 Jul 2026 22:16:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.711.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Vibgrate CLI 2026.711.1 Released 2026-07-11
This release of the Vibgrate CLI includes the addition of documentation related to the scoring methodology. Users can now access the public scoring specification, the risk and drift scoring whitepaper, and shared legal notes directly from the repository.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.711.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20267111">Vibgrate CLI 2026.711.1</h1>
<p><em>Released 2026-07-11</em></p>
<p>This release of the Vibgrate CLI includes the addition of documentation related to the scoring methodology. Users can now access the public scoring specification, the risk and drift scoring whitepaper, and shared legal notes directly from the repository.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="new">New</h3>
<ul>
<li>Published the scoring methodology documentation in the repository, including the public scoring specification, risk and drift scoring whitepaper, and shared legal notes.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.710.1, interleaved on one runner against the pinned corpus (157 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>18816 count</td>
          <td>18816 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>7480 count</td>
          <td>7480 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.97 ratio</td>
          <td>0.97 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>625.10 ms</td>
          <td>631.60 ms</td>
      </tr>
  </tbody>
</table>
<p>No regressions against the previous release.</p>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.711.1">https://vibgrate.com/changelog/cli/2026.711.1</a></p>
]]></content:encoded></item><item><title>Premature Contribution Firewall dry-run</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/premature-contribution-firewall-dry-run/</link><pubDate>Sat, 11 Jul 2026 22:15:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/premature-contribution-firewall-dry-run/</guid><description>Version updated for https://github.com/VrtxOmega/premature-contribution-firewall to version v0.1.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed PCF v0.1.3 adds impact-first serious candidate scouting and hardens the authority boundaries that keep automation advisory.
Highlights Added broad, read-only serious candidate scouting with explicit collection-integrity and open-PR-overlap gates. Expanded the adversarial residue corpus from 15 to 29 cases covering Unicode/control-text evasion, overlap ownership, repository-context vacuum, lane-gate omission, repro laundering, malformed MCP frames, and malformed batch inputs. Made repository context, lane persistence, repro evidence, and MCP framing fail closed when evidence is missing or malformed. Published through GitHub OIDC trusted publishing with npm provenance; no reusable npm token was required. Verification Tests: 242/242 Deterministic benchmark: 77/77 Adversarial red test: 29/29 Maintainer demo: PASS, replay stable, 0 regressions MCP smoke: PASS npm package dry run: PASS, 75 files Clean registry install: PASS for pcf and pcf-mcp Installed MCP surface: 25 tools, serious scout present, GitHub writes disabled Main verification: https://github.com/VrtxOmega/premature-contribution-firewall/actions/runs/29156257898</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/VrtxOmega/premature-contribution-firewall">https://github.com/VrtxOmega/premature-contribution-firewall</a></strong> to version <strong>v0.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/premature-contribution-firewall-dry-run">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>PCF v0.1.3 adds impact-first serious candidate scouting and hardens the authority boundaries that keep automation advisory.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Added broad, read-only serious candidate scouting with explicit collection-integrity and open-PR-overlap gates.</li>
<li>Expanded the adversarial residue corpus from 15 to 29 cases covering Unicode/control-text evasion, overlap ownership, repository-context vacuum, lane-gate omission, repro laundering, malformed MCP frames, and malformed batch inputs.</li>
<li>Made repository context, lane persistence, repro evidence, and MCP framing fail closed when evidence is missing or malformed.</li>
<li>Published through GitHub OIDC trusted publishing with npm provenance; no reusable npm token was required.</li>
</ul>
<h2 id="verification">Verification</h2>
<ul>
<li>Tests: 242/242</li>
<li>Deterministic benchmark: 77/77</li>
<li>Adversarial red test: 29/29</li>
<li>Maintainer demo: PASS, replay stable, 0 regressions</li>
<li>MCP smoke: PASS</li>
<li>npm package dry run: PASS, 75 files</li>
<li>Clean registry install: PASS for <code>pcf</code> and <code>pcf-mcp</code></li>
<li>Installed MCP surface: 25 tools, serious scout present, GitHub writes disabled</li>
</ul>
<p>Main verification: <a href="https://github.com/VrtxOmega/premature-contribution-firewall/actions/runs/29156257898">https://github.com/VrtxOmega/premature-contribution-firewall/actions/runs/29156257898</a></p>
<p>Trusted publish: <a href="https://github.com/VrtxOmega/premature-contribution-firewall/actions/runs/29156361509">https://github.com/VrtxOmega/premature-contribution-firewall/actions/runs/29156361509</a></p>
<p>npm: <a href="https://www.npmjs.com/package/premature-contribution-firewall/v/0.1.3">https://www.npmjs.com/package/premature-contribution-firewall/v/0.1.3</a></p>
<h2 id="try-it">Try It</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx -y -p premature-contribution-firewall@0.1.3 pcf --help
</span></span><span style="display:flex;"><span>npx -y -p premature-contribution-firewall@0.1.3 pcf-mcp
</span></span></code></pre></div><p>PCF remains advisory. Heuristic results do not prove correctness, mergeability, authorship, or maintainer endorsement, and the MCP server exposes no public GitHub write tools.</p>
]]></content:encoded></item><item><title>Diviqra Guard LLM Prompt Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/diviqra-guard-llm-prompt-scanner/</link><pubDate>Sat, 11 Jul 2026 14:23:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/diviqra-guard-llm-prompt-scanner/</guid><description>Version updated for https://github.com/diviqra-builds/guard-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Diviqra Guard — GitHub Action v1.0.0 Scan LLM prompts for injection attacks before deployment.
Usage - name: Guard Prompt Scan uses: diviqra-builds/guard-action@v1 with: api_key: ${{ secrets.GUARD_API_KEY }} scan_path: ./prompts/ fail_on: block What’s new Scans .txt/.json/.yaml/.yml/.md prompt files Detects prompt injection, jailbreaks, PII leakage Hindi/Hinglish/Tamil/Telugu/Kannada support Colored summary table in Actions log Configurable fail threshold (block/warn/never) LangChain, OpenAI, FastAPI integrations included Get free API key: https://guard.diviqra.com/register</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/diviqra-builds/guard-action">https://github.com/diviqra-builds/guard-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/diviqra-guard-llm-prompt-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="diviqra-guard--github-action-v100">Diviqra Guard — GitHub Action v1.0.0</h2>
<p>Scan LLM prompts for injection attacks before deployment.</p>
<h3 id="usage">Usage</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">name</span>: <span style="color:#ae81ff">Guard Prompt Scan</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">diviqra-builds/guard-action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">api_key</span>: <span style="color:#ae81ff">${{ secrets.GUARD_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">scan_path</span>: <span style="color:#ae81ff">./prompts/</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail_on</span>: <span style="color:#ae81ff">block</span>
</span></span></code></pre></div><h3 id="whats-new">What&rsquo;s new</h3>
<ul>
<li>Scans .txt/.json/.yaml/.yml/.md prompt files</li>
<li>Detects prompt injection, jailbreaks, PII leakage</li>
<li>Hindi/Hinglish/Tamil/Telugu/Kannada support</li>
<li>Colored summary table in Actions log</li>
<li>Configurable fail threshold (block/warn/never)</li>
<li>LangChain, OpenAI, FastAPI integrations included</li>
</ul>
<p>Get free API key: <a href="https://guard.diviqra.com/register">https://guard.diviqra.com/register</a></p>
]]></content:encoded></item><item><title>DoesQA Trigger</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/doesqa-trigger/</link><pubDate>Sat, 11 Jul 2026 14:22:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/doesqa-trigger/</guid><description>Version updated for https://github.com/Does-QA/action to version v1.1.35.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Security patch: fixed 1 → 1 vulnerabilities via npm audit fix.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Does-QA/action">https://github.com/Does-QA/action</a></strong> to version <strong>v1.1.35</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/doesqa-trigger">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Security patch: fixed 1 → 1 vulnerabilities via <code>npm audit fix</code>.</p>
]]></content:encoded></item><item><title>trimja action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/trimja-action/</link><pubDate>Sat, 11 Jul 2026 14:22:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/trimja-action/</guid><description>Version updated for https://github.com/elliotgoodrich/trimja-action to version v1.8.0.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump undici from 6.26.0 to 6.27.0 by @dependabot[bot] in https://github.com/elliotgoodrich/trimja-action/pull/32 Improve logging by @elliotgoodrich in https://github.com/elliotgoodrich/trimja-action/pull/33 New Contributors @dependabot[bot] made their first contribution in https://github.com/elliotgoodrich/trimja-action/pull/32 Full Changelog: https://github.com/elliotgoodrich/trimja-action/compare/v1...v1.8.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/elliotgoodrich/trimja-action">https://github.com/elliotgoodrich/trimja-action</a></strong> to version <strong>v1.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/trimja-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump undici from 6.26.0 to 6.27.0 by @dependabot[bot] in <a href="https://github.com/elliotgoodrich/trimja-action/pull/32">https://github.com/elliotgoodrich/trimja-action/pull/32</a></li>
<li>Improve logging by @elliotgoodrich in <a href="https://github.com/elliotgoodrich/trimja-action/pull/33">https://github.com/elliotgoodrich/trimja-action/pull/33</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/elliotgoodrich/trimja-action/pull/32">https://github.com/elliotgoodrich/trimja-action/pull/32</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/elliotgoodrich/trimja-action/compare/v1...v1.8.0">https://github.com/elliotgoodrich/trimja-action/compare/v1...v1.8.0</a></p>
]]></content:encoded></item><item><title>Setup Malbolge</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/setup-malbolge/</link><pubDate>Sat, 11 Jul 2026 14:21:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/setup-malbolge/</guid><description>Version updated for https://github.com/fabasoad/setup-malbolge-action to version v0.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps): bump actions/checkout from 4 to 5 by @dependabot[bot] in https://github.com/fabasoad/setup-malbolge-action/pull/16 fix: issue found by markdownlint by @fabasoad in https://github.com/fabasoad/setup-malbolge-action/pull/17 Update license copyright year to 2026 by @github-actions[bot] in https://github.com/fabasoad/setup-malbolge-action/pull/18 chore(deps): bump gitleaks from 8.30.0 to 8.30.1 by @fabasoad in https://github.com/fabasoad/setup-malbolge-action/pull/19 Full Changelog: https://github.com/fabasoad/setup-malbolge-action/compare/v0.2.0...v0.2.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/fabasoad/setup-malbolge-action">https://github.com/fabasoad/setup-malbolge-action</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-malbolge">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): bump actions/checkout from 4 to 5 by @dependabot[bot] in <a href="https://github.com/fabasoad/setup-malbolge-action/pull/16">https://github.com/fabasoad/setup-malbolge-action/pull/16</a></li>
<li>fix: issue found by markdownlint by @fabasoad in <a href="https://github.com/fabasoad/setup-malbolge-action/pull/17">https://github.com/fabasoad/setup-malbolge-action/pull/17</a></li>
<li>Update license copyright year to 2026 by @github-actions[bot] in <a href="https://github.com/fabasoad/setup-malbolge-action/pull/18">https://github.com/fabasoad/setup-malbolge-action/pull/18</a></li>
<li>chore(deps): bump gitleaks from 8.30.0 to 8.30.1 by @fabasoad in <a href="https://github.com/fabasoad/setup-malbolge-action/pull/19">https://github.com/fabasoad/setup-malbolge-action/pull/19</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/fabasoad/setup-malbolge-action/compare/v0.2.0...v0.2.1">https://github.com/fabasoad/setup-malbolge-action/compare/v0.2.0...v0.2.1</a></p>
]]></content:encoded></item><item><title>GitHub Action for Python based Firebase projects</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/github-action-for-python-based-firebase-projects/</link><pubDate>Sat, 11 Jul 2026 14:21:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/github-action-for-python-based-firebase-projects/</guid><description>Version updated for https://github.com/gannonk08/firebase-action-python to version v15.23.0.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Bump firebase-tools to v15.23.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/gannonk08/firebase-action-python">https://github.com/gannonk08/firebase-action-python</a></strong> to version <strong>v15.23.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-action-for-python-based-firebase-projects">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Bump <code>firebase-tools</code> to v15.23.0</p>
]]></content:encoded></item><item><title>Vizb Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/vizb-action/</link><pubDate>Sat, 11 Jul 2026 14:20:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/vizb-action/</guid><description>Version updated for https://github.com/goptics/vizb to version v0.15.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat(line): add –smooth flag for 2D line charts by @hfl0506 in https://github.com/goptics/vizb/pull/187 feat(stats): add multi-select descriptive column picker by @hfl0506 in https://github.com/goptics/vizb/pull/191 feat(bar): add –horizontal flag for 2D grouped bar charts by @fahimfaisaal in https://github.com/goptics/vizb/pull/190 feat(bar/line): add –stack for 2d charts by @hfl0506 in https://github.com/goptics/vizb/pull/194 fix: clear grouped 3D z-axis name under option merge by @ahfoysal in https://github.com/goptics/vizb/pull/192 feat(ci): untrack vizb-ui.gen.go and generate embed in CI by @fahimfaisaal in https://github.com/goptics/vizb/pull/197 feat: add –theme color palette support by @ahfoysal in https://github.com/goptics/vizb/pull/195 New Contributors @hfl0506 made their first contribution in https://github.com/goptics/vizb/pull/187 @ahfoysal made their first contribution in https://github.com/goptics/vizb/pull/192 Full Changelog: https://github.com/goptics/vizb/compare/v0.14.1...v0.15.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/goptics/vizb">https://github.com/goptics/vizb</a></strong> to version <strong>v0.15.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vizb-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(line): add &ndash;smooth flag for 2D line charts by @hfl0506 in <a href="https://github.com/goptics/vizb/pull/187">https://github.com/goptics/vizb/pull/187</a></li>
<li>feat(stats): add multi-select descriptive column picker by @hfl0506 in <a href="https://github.com/goptics/vizb/pull/191">https://github.com/goptics/vizb/pull/191</a></li>
<li>feat(bar): add &ndash;horizontal flag for 2D grouped bar charts by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/190">https://github.com/goptics/vizb/pull/190</a></li>
<li>feat(bar/line): add &ndash;stack for 2d charts by @hfl0506 in <a href="https://github.com/goptics/vizb/pull/194">https://github.com/goptics/vizb/pull/194</a></li>
<li>fix: clear grouped 3D z-axis name under option merge by @ahfoysal in <a href="https://github.com/goptics/vizb/pull/192">https://github.com/goptics/vizb/pull/192</a></li>
<li>feat(ci): untrack vizb-ui.gen.go and generate embed in CI by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/197">https://github.com/goptics/vizb/pull/197</a></li>
<li>feat: add &ndash;theme color palette support by @ahfoysal in <a href="https://github.com/goptics/vizb/pull/195">https://github.com/goptics/vizb/pull/195</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@hfl0506 made their first contribution in <a href="https://github.com/goptics/vizb/pull/187">https://github.com/goptics/vizb/pull/187</a></li>
<li>@ahfoysal made their first contribution in <a href="https://github.com/goptics/vizb/pull/192">https://github.com/goptics/vizb/pull/192</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/goptics/vizb/compare/v0.14.1...v0.15.0">https://github.com/goptics/vizb/compare/v0.14.1...v0.15.0</a></p>
]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/ai-plugin-scanner/</link><pubDate>Sat, 11 Jul 2026 14:20:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.437.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/3049ba4a2fd13a42906f6745178ece5f65f4beb1 with plugin-scanner 2.0.1038.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.436...v1.2.437</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.437</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>18</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/3049ba4a2fd13a42906f6745178ece5f65f4beb1">https://github.com/hashgraph-online/hol-guard/tree/3049ba4a2fd13a42906f6745178ece5f65f4beb1</a> with plugin-scanner 2.0.1038.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.436...v1.2.437">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.436...v1.2.437</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/hol-codex-plugin-scanner/</link><pubDate>Sat, 11 Jul 2026 14:19:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.437.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.437</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.437</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.437">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.437</a></p>
]]></content:encoded></item><item><title>helmfile-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/helmfile-action/</link><pubDate>Sat, 11 Jul 2026 14:18:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/helmfile-action/</guid><description>Version updated for https://github.com/helmfile/helmfile-action to version v2.4.7.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed build(deps-dev): bump @types/node from 26.0.0 to 26.0.1 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/727 build(deps-dev): bump prettier from 3.8.4 to 3.9.1 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/728 build(deps-dev): bump eslint-plugin-jest from 29.15.2 to 29.15.3 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/729 build(deps-dev): bump eslint-plugin-jest from 29.15.3 to 29.15.4 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/733 build(deps-dev): bump @vercel/ncc from 0.44.0 to 0.44.1 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/734 build(deps-dev): bump @types/node from 26.0.1 to 26.1.0 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/735 build(deps-dev): bump prettier from 3.9.1 to 3.9.4 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/731 build(deps-dev): bump @typescript-eslint/parser from 8.62.0 to 8.62.1 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/730 build(deps-dev): bump @typescript-eslint/eslint-plugin from 8.62.0 to 8.62.1 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/732 build(deps-dev): bump @typescript-eslint/parser from 8.62.1 to 8.63.0 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/736 build(deps-dev): bump eslint-plugin-github from 6.0.0 to 6.1.0 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/738 build(deps-dev): bump @types/node from 26.1.0 to 26.1.1 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/739 build(deps-dev): bump typescript from 6.0.3 to 7.0.2 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/740 build(deps-dev): bump @typescript-eslint/eslint-plugin from 8.62.1 to 8.63.0 by @dependabot[bot] in https://github.com/helmfile/helmfile-action/pull/737 Full Changelog: https://github.com/helmfile/helmfile-action/compare/v2.4.6...v2.4.7</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/helmfile/helmfile-action">https://github.com/helmfile/helmfile-action</a></strong> to version <strong>v2.4.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/helmfile-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>build(deps-dev): bump @types/node from 26.0.0 to 26.0.1 by @dependabot[bot] in <a href="https://github.com/helmfile/helmfile-action/pull/727">https://github.com/helmfile/helmfile-action/pull/727</a></li>
<li>build(deps-dev): bump prettier from 3.8.4 to 3.9.1 by @dependabot[bot] in <a href="https://github.com/helmfile/helmfile-action/pull/728">https://github.com/helmfile/helmfile-action/pull/728</a></li>
<li>build(deps-dev): bump eslint-plugin-jest from 29.15.2 to 29.15.3 by @dependabot[bot] in <a href="https://github.com/helmfile/helmfile-action/pull/729">https://github.com/helmfile/helmfile-action/pull/729</a></li>
<li>build(deps-dev): bump eslint-plugin-jest from 29.15.3 to 29.15.4 by @dependabot[bot] in <a href="https://github.com/helmfile/helmfile-action/pull/733">https://github.com/helmfile/helmfile-action/pull/733</a></li>
<li>build(deps-dev): bump @vercel/ncc from 0.44.0 to 0.44.1 by @dependabot[bot] in <a href="https://github.com/helmfile/helmfile-action/pull/734">https://github.com/helmfile/helmfile-action/pull/734</a></li>
<li>build(deps-dev): bump @types/node from 26.0.1 to 26.1.0 by @dependabot[bot] in <a href="https://github.com/helmfile/helmfile-action/pull/735">https://github.com/helmfile/helmfile-action/pull/735</a></li>
<li>build(deps-dev): bump prettier from 3.9.1 to 3.9.4 by @dependabot[bot] in <a href="https://github.com/helmfile/helmfile-action/pull/731">https://github.com/helmfile/helmfile-action/pull/731</a></li>
<li>build(deps-dev): bump @typescript-eslint/parser from 8.62.0 to 8.62.1 by @dependabot[bot] in <a href="https://github.com/helmfile/helmfile-action/pull/730">https://github.com/helmfile/helmfile-action/pull/730</a></li>
<li>build(deps-dev): bump @typescript-eslint/eslint-plugin from 8.62.0 to 8.62.1 by @dependabot[bot] in <a href="https://github.com/helmfile/helmfile-action/pull/732">https://github.com/helmfile/helmfile-action/pull/732</a></li>
<li>build(deps-dev): bump @typescript-eslint/parser from 8.62.1 to 8.63.0 by @dependabot[bot] in <a href="https://github.com/helmfile/helmfile-action/pull/736">https://github.com/helmfile/helmfile-action/pull/736</a></li>
<li>build(deps-dev): bump eslint-plugin-github from 6.0.0 to 6.1.0 by @dependabot[bot] in <a href="https://github.com/helmfile/helmfile-action/pull/738">https://github.com/helmfile/helmfile-action/pull/738</a></li>
<li>build(deps-dev): bump @types/node from 26.1.0 to 26.1.1 by @dependabot[bot] in <a href="https://github.com/helmfile/helmfile-action/pull/739">https://github.com/helmfile/helmfile-action/pull/739</a></li>
<li>build(deps-dev): bump typescript from 6.0.3 to 7.0.2 by @dependabot[bot] in <a href="https://github.com/helmfile/helmfile-action/pull/740">https://github.com/helmfile/helmfile-action/pull/740</a></li>
<li>build(deps-dev): bump @typescript-eslint/eslint-plugin from 8.62.1 to 8.63.0 by @dependabot[bot] in <a href="https://github.com/helmfile/helmfile-action/pull/737">https://github.com/helmfile/helmfile-action/pull/737</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/helmfile/helmfile-action/compare/v2.4.6...v2.4.7">https://github.com/helmfile/helmfile-action/compare/v2.4.6...v2.4.7</a></p>
]]></content:encoded></item><item><title>Hyperlocalise CI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/hyperlocalise-ci/</link><pubDate>Sat, 11 Jul 2026 14:18:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/hyperlocalise-ci/</guid><description>Version updated for https://github.com/hyperlocalise/hyperlocalise to version v1.8.24.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat(web): localize app shell UI with react-intl by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1360 fix(web): show skeleton while side-by-side translations load by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1361 feat(cat): add Find context to side-by-side intelligence panel by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1364 chore(web): sync Hyperlocalise translations by @hyperlocalise[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1363 feat(web): support image upload, agent localize, sync, and CAT by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1365 feat(web): add app shell plan footer by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1362 feat(web): stream inbox agent tool calls and text by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1366 ⚡ Bolt: optimize PHP array parser and marshaler by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1369 test(web): cover image localization guards by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1368 feat(cat): treat-as-image and upload for external TMS URL strings by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1367 feat(web): fail db:migrate on duplicate migration numbers by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1372 fix(crowdin): add missing concepts field to Glossary model by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1373 fix(web): critical regressions in image jobs, inbox agent parts, and side-by-side CAT by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1370 fix(inbox): strip markdown from conversation list previews by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1374 fix(inbox): prevent stream crash from undefined tool code blocks by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1375 fix(inbox): simplify tool call UI and scroll button contrast by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1376 feat(app-shell): persistent MobX chat dock with conversation tabs by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1377 feat: use gpt-5.6-luna instead of gpt-5.4-mini by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1378 fix(web): refine floating chat dock by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1379 fix(web): improve CAT loading and file menu actions by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1380 fix(markdown): preserve link delimiters during translation by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1382 fix(billing): track Translation jobs and Agent runs meters correctly by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1383 chore(web): sync Hyperlocalise translations by @hyperlocalise[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1384 Full Changelog: https://github.com/hyperlocalise/hyperlocalise/compare/v1...v1.8.24</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hyperlocalise/hyperlocalise">https://github.com/hyperlocalise/hyperlocalise</a></strong> to version <strong>v1.8.24</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hyperlocalise-ci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(web): localize app shell UI with react-intl by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1360">https://github.com/hyperlocalise/hyperlocalise/pull/1360</a></li>
<li>fix(web): show skeleton while side-by-side translations load by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1361">https://github.com/hyperlocalise/hyperlocalise/pull/1361</a></li>
<li>feat(cat): add Find context to side-by-side intelligence panel by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1364">https://github.com/hyperlocalise/hyperlocalise/pull/1364</a></li>
<li>chore(web): sync Hyperlocalise translations by @hyperlocalise[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1363">https://github.com/hyperlocalise/hyperlocalise/pull/1363</a></li>
<li>feat(web): support image upload, agent localize, sync, and CAT by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1365">https://github.com/hyperlocalise/hyperlocalise/pull/1365</a></li>
<li>feat(web): add app shell plan footer by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1362">https://github.com/hyperlocalise/hyperlocalise/pull/1362</a></li>
<li>feat(web): stream inbox agent tool calls and text by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1366">https://github.com/hyperlocalise/hyperlocalise/pull/1366</a></li>
<li>⚡ Bolt: optimize PHP array parser and marshaler by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1369">https://github.com/hyperlocalise/hyperlocalise/pull/1369</a></li>
<li>test(web): cover image localization guards by @cursor[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1368">https://github.com/hyperlocalise/hyperlocalise/pull/1368</a></li>
<li>feat(cat): treat-as-image and upload for external TMS URL strings by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1367">https://github.com/hyperlocalise/hyperlocalise/pull/1367</a></li>
<li>feat(web): fail db:migrate on duplicate migration numbers by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1372">https://github.com/hyperlocalise/hyperlocalise/pull/1372</a></li>
<li>fix(crowdin): add missing concepts field to Glossary model by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1373">https://github.com/hyperlocalise/hyperlocalise/pull/1373</a></li>
<li>fix(web): critical regressions in image jobs, inbox agent parts, and side-by-side CAT by @cursor[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1370">https://github.com/hyperlocalise/hyperlocalise/pull/1370</a></li>
<li>fix(inbox): strip markdown from conversation list previews by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1374">https://github.com/hyperlocalise/hyperlocalise/pull/1374</a></li>
<li>fix(inbox): prevent stream crash from undefined tool code blocks by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1375">https://github.com/hyperlocalise/hyperlocalise/pull/1375</a></li>
<li>fix(inbox): simplify tool call UI and scroll button contrast by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1376">https://github.com/hyperlocalise/hyperlocalise/pull/1376</a></li>
<li>feat(app-shell): persistent MobX chat dock with conversation tabs by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1377">https://github.com/hyperlocalise/hyperlocalise/pull/1377</a></li>
<li>feat: use gpt-5.6-luna instead of gpt-5.4-mini by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1378">https://github.com/hyperlocalise/hyperlocalise/pull/1378</a></li>
<li>fix(web): refine floating chat dock by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1379">https://github.com/hyperlocalise/hyperlocalise/pull/1379</a></li>
<li>fix(web): improve CAT loading and file menu actions by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1380">https://github.com/hyperlocalise/hyperlocalise/pull/1380</a></li>
<li>fix(markdown): preserve link delimiters during translation by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1382">https://github.com/hyperlocalise/hyperlocalise/pull/1382</a></li>
<li>fix(billing): track Translation jobs and Agent runs meters correctly by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1383">https://github.com/hyperlocalise/hyperlocalise/pull/1383</a></li>
<li>chore(web): sync Hyperlocalise translations by @hyperlocalise[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1384">https://github.com/hyperlocalise/hyperlocalise/pull/1384</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hyperlocalise/hyperlocalise/compare/v1...v1.8.24">https://github.com/hyperlocalise/hyperlocalise/compare/v1...v1.8.24</a></p>
]]></content:encoded></item><item><title>Jentic API Scorecard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/jentic-api-scorecard/</link><pubDate>Sat, 11 Jul 2026 14:17:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/jentic-api-scorecard/</guid><description>Version updated for https://github.com/jentic/jentic-api-scorecard to version v1.10.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.10.0 (2026-07-11) Bug Fixes extract-docs: rewrite improve-skill cross-link on extraction (97bb1d6) extract-docs: rewrite requirements anchor in improve-skill (1f02432) score: make engine tokenUsage opt-in via –report-token-usage (c542268), closes #284 scripts: derive benchmark metrics from raw scorecards (b623161), closes #284 scripts: exercise proxy self-check + real plumbing in dry-run (a84aa55), closes #284 scripts: match raw scorecards by content, not exact name (c9c15c4), closes #284 skill: guard jentic-api-improve against shipping regressions (b301395), closes #284 skills: make token-usage.json opt-in on explicit request (d0382ea), closes #284 Features cli: add hidden –report-token-usage flag (dfad477), closes #284 scripts: add benchmark results data-file sample fixture (0b1a3be), closes #284 scripts: add improve-benchmark matrix driver + dry-run (ffd3750), closes #284 scripts: add token-counting proxy for engine LLM spend (d7c3890), closes #284 scripts: benchmark 6 default specs, –specs, output dir (1a42db1), closes #284 scripts: capture + render score before/after + iters (c210984), closes #284 scripts: implement real benchmark measurement run (be3ded4), closes #284 scripts: render benchmark doc from results data file (cc3ed72), closes #284 scripts: request engine token usage in benchmark prompt (4aaceb5), closes #284 scripts: sample benchmark cells N times, report median + range (d480d69), closes #284 skills: emit benchmark-summary.json with run outcome (7ae3dae), closes #284 skills: emit token-usage.json from engine tokenUsage (2424387), closes #284 Performance Improvements scripts: run benchmark samples concurrently, isolated per cwd (30df98d), closes #284</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jentic/jentic-api-scorecard">https://github.com/jentic/jentic-api-scorecard</a></strong> to version <strong>v1.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jentic-api-scorecard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="1100-2026-07-11"><a href="https://github.com/jentic/jentic-api-scorecard/compare/v1.9.3...v1.10.0">1.10.0</a> (2026-07-11)</h1>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>extract-docs:</strong> rewrite improve-skill cross-link on extraction (<a href="https://github.com/jentic/jentic-api-scorecard/commit/97bb1d6af91e2344f6a219f79583d5c819b924a3">97bb1d6</a>)</li>
<li><strong>extract-docs:</strong> rewrite requirements anchor in improve-skill (<a href="https://github.com/jentic/jentic-api-scorecard/commit/1f0243261b4c568a621b5d0ae2be02d819cbd877">1f02432</a>)</li>
<li><strong>score:</strong> make engine tokenUsage opt-in via &ndash;report-token-usage (<a href="https://github.com/jentic/jentic-api-scorecard/commit/c542268b317570bf412dcbdf3cc6534d8d2515dc">c542268</a>), closes <a href="https://github.com/jentic/jentic-api-scorecard/issues/284">#284</a></li>
<li><strong>scripts:</strong> derive benchmark metrics from raw scorecards (<a href="https://github.com/jentic/jentic-api-scorecard/commit/b623161da21e80e7509af09327d9002a36e9d7b6">b623161</a>), closes <a href="https://github.com/jentic/jentic-api-scorecard/issues/284">#284</a></li>
<li><strong>scripts:</strong> exercise proxy self-check + real plumbing in dry-run (<a href="https://github.com/jentic/jentic-api-scorecard/commit/a84aa55c5349e6a75e47c3aeba703c8bd883ce74">a84aa55</a>), closes <a href="https://github.com/jentic/jentic-api-scorecard/issues/284">#284</a></li>
<li><strong>scripts:</strong> match raw scorecards by content, not exact name (<a href="https://github.com/jentic/jentic-api-scorecard/commit/c9c15c4735b47faca68a0ee591516786cc924a6a">c9c15c4</a>), closes <a href="https://github.com/jentic/jentic-api-scorecard/issues/284">#284</a></li>
<li><strong>skill:</strong> guard jentic-api-improve against shipping regressions (<a href="https://github.com/jentic/jentic-api-scorecard/commit/b301395af9285efdc65a7fc5ec730e5ab60d87d0">b301395</a>), closes <a href="https://github.com/jentic/jentic-api-scorecard/issues/284">#284</a></li>
<li><strong>skills:</strong> make token-usage.json opt-in on explicit request (<a href="https://github.com/jentic/jentic-api-scorecard/commit/d0382eaf874adb0a92905d77ec2a74cd37a1bed2">d0382ea</a>), closes <a href="https://github.com/jentic/jentic-api-scorecard/issues/284">#284</a></li>
</ul>
<h3 id="features">Features</h3>
<ul>
<li><strong>cli:</strong> add hidden &ndash;report-token-usage flag (<a href="https://github.com/jentic/jentic-api-scorecard/commit/dfad477bbc45846fa4da432f0871bfc83bc5fb6a">dfad477</a>), closes <a href="https://github.com/jentic/jentic-api-scorecard/issues/284">#284</a></li>
<li><strong>scripts:</strong> add benchmark results data-file sample fixture (<a href="https://github.com/jentic/jentic-api-scorecard/commit/0b1a3be4dc0be4ae205fe799fa71a2f99ec1f5d4">0b1a3be</a>), closes <a href="https://github.com/jentic/jentic-api-scorecard/issues/284">#284</a></li>
<li><strong>scripts:</strong> add improve-benchmark matrix driver + dry-run (<a href="https://github.com/jentic/jentic-api-scorecard/commit/ffd3750cefa614e176718cc0fcc8cf44dc7b4248">ffd3750</a>), closes <a href="https://github.com/jentic/jentic-api-scorecard/issues/284">#284</a></li>
<li><strong>scripts:</strong> add token-counting proxy for engine LLM spend (<a href="https://github.com/jentic/jentic-api-scorecard/commit/d7c389095e3ee624ec00d61db8a9b6531c4f2b6e">d7c3890</a>), closes <a href="https://github.com/jentic/jentic-api-scorecard/issues/284">#284</a></li>
<li><strong>scripts:</strong> benchmark 6 default specs, &ndash;specs, output dir (<a href="https://github.com/jentic/jentic-api-scorecard/commit/1a42db1b0db8beb35a8ec5ead12195490cbff1c9">1a42db1</a>), closes <a href="https://github.com/jentic/jentic-api-scorecard/issues/284">#284</a></li>
<li><strong>scripts:</strong> capture + render score before/after + iters (<a href="https://github.com/jentic/jentic-api-scorecard/commit/c210984c3d8f601a111ccfd3d307084113e744f1">c210984</a>), closes <a href="https://github.com/jentic/jentic-api-scorecard/issues/284">#284</a></li>
<li><strong>scripts:</strong> implement real benchmark measurement run (<a href="https://github.com/jentic/jentic-api-scorecard/commit/be3ded40a67dd4b95e2d94ab7115e8d8f6f83be3">be3ded4</a>), closes <a href="https://github.com/jentic/jentic-api-scorecard/issues/284">#284</a></li>
<li><strong>scripts:</strong> render benchmark doc from results data file (<a href="https://github.com/jentic/jentic-api-scorecard/commit/cc3ed72dc4f3656c50bcd4971190494c456e44e7">cc3ed72</a>), closes <a href="https://github.com/jentic/jentic-api-scorecard/issues/284">#284</a></li>
<li><strong>scripts:</strong> request engine token usage in benchmark prompt (<a href="https://github.com/jentic/jentic-api-scorecard/commit/4aaceb5d4b6e5694b266612cc5d67518251ee43d">4aaceb5</a>), closes <a href="https://github.com/jentic/jentic-api-scorecard/issues/284">#284</a></li>
<li><strong>scripts:</strong> sample benchmark cells N times, report median + range (<a href="https://github.com/jentic/jentic-api-scorecard/commit/d480d69d8831787219794db8f9a7456b8532668f">d480d69</a>), closes <a href="https://github.com/jentic/jentic-api-scorecard/issues/284">#284</a></li>
<li><strong>skills:</strong> emit benchmark-summary.json with run outcome (<a href="https://github.com/jentic/jentic-api-scorecard/commit/7ae3dae2603662a245c5d66470d25e50b4b5953a">7ae3dae</a>), closes <a href="https://github.com/jentic/jentic-api-scorecard/issues/284">#284</a></li>
<li><strong>skills:</strong> emit token-usage.json from engine tokenUsage (<a href="https://github.com/jentic/jentic-api-scorecard/commit/2424387fc47ebeaef44a07e16b8ebde57426d602">2424387</a>), closes <a href="https://github.com/jentic/jentic-api-scorecard/issues/284">#284</a></li>
</ul>
<h3 id="performance-improvements">Performance Improvements</h3>
<ul>
<li><strong>scripts:</strong> run benchmark samples concurrently, isolated per cwd (<a href="https://github.com/jentic/jentic-api-scorecard/commit/30df98d0d0a4e059d2c3de1521fcbd3994a0bcc6">30df98d</a>), closes <a href="https://github.com/jentic/jentic-api-scorecard/issues/284">#284</a></li>
</ul>
]]></content:encoded></item><item><title>E2E Self-Heal</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/e2e-self-heal/</link><pubDate>Sat, 11 Jul 2026 14:17:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/e2e-self-heal/</guid><description>Version updated for https://github.com/Lee-Dongwook/E2E-Self-Heal to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changed Diff parsing rewritten on a tree-sitter AST: the JSX/TSX diff analyzer now walks the parsed syntax tree instead of matching regexes, producing more accurate and robust before/after DOM node extraction. Added tree-sitter dependencies and expanded diff-analyzer test coverage. (#8) Full Changelog: https://github.com/Lee-Dongwook/E2E-Self-Heal/compare/v0.2.2...v0.3.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Lee-Dongwook/E2E-Self-Heal">https://github.com/Lee-Dongwook/E2E-Self-Heal</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/e2e-self-heal">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changed">Changed</h2>
<ul>
<li>Diff parsing rewritten on a <strong>tree-sitter AST</strong>: the JSX/TSX diff analyzer now walks the parsed syntax tree instead of matching regexes, producing more accurate and robust before/after DOM node extraction. Added tree-sitter dependencies and expanded diff-analyzer test coverage. (#8)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Lee-Dongwook/E2E-Self-Heal/compare/v0.2.2...v0.3.0">https://github.com/Lee-Dongwook/E2E-Self-Heal/compare/v0.2.2...v0.3.0</a></p>
]]></content:encoded></item><item><title>SkillCI Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/skillci-audit/</link><pubDate>Sat, 11 Jul 2026 14:16:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/skillci-audit/</guid><description>Version updated for https://github.com/LM20230311/skillci to version v0.3.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Highlights Publish the skillci CLI to npm for local development and non-GitHub CI usage. Add npm installation, one-off npx usage, and npm badges to both README languages. Install npm install --save-dev skillci npx skillci audit .github/skills Use LM20230311/skillci@v0.3.2 for GitHub Actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/LM20230311/skillci">https://github.com/LM20230311/skillci</a></strong> to version <strong>v0.3.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skillci-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Publish the <code>skillci</code> CLI to npm for local development and non-GitHub CI usage.</li>
<li>Add npm installation, one-off <code>npx</code> usage, and npm badges to both README languages.</li>
</ul>
<h2 id="install">Install</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npm install --save-dev skillci
</span></span><span style="display:flex;"><span>npx skillci audit .github/skills
</span></span></code></pre></div><p>Use <code>LM20230311/skillci@v0.3.2</code> for GitHub Actions.</p>
]]></content:encoded></item><item><title>EIS — Upload Signals</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/eis-upload-signals/</link><pubDate>Sat, 11 Jul 2026 14:16:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/eis-upload-signals/</guid><description>Version updated for https://github.com/machuz/eis to version v2.31.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog 744153cfade21c2ddbd0075fd9ae832ad6a8fb32 feat(cli): add anchors — surviving exemplar code per module (Build2 ①) (#359) 8063822db503221bd5ab410f7111800cb306422b feat(cli): add get-write-context — structured write context (MCP core) (#358) 2f549cf7ea29012ce21ff8af74e7368871d15974 feat(cli): add graveyard — where past attempts died (Build2 ②) (#361) f606b97d2751cda0237baebd82faf235294a6ba5 feat(cli): add precheck-hook — Claude Code PreToolUse debt injector (#357) 5072795f679b0af30de226f1f37e00a0d895c5ef feat(cli): add write-index — per-module index for AI coding agents (#356) 25c73e72fbb4366732a4254cff61545411be3c6c feat(cli): structural-debt Tier-1 meter (SDR, AI-agnostic) (#354) 4da4a8507f2b046b5b1236da5fe95d33512a6d9a feat(graveyard): drop non-code files (docs/config/images) from the death walk (#363) 19c93511030a250140bde0d9662fd0b2d0ef2c5f feat(mcp): add eis mcp — MCP stdio server exposing get_write_context (#364) 2fd32d6e069c9cfa283b8f3f2d7553d09e6dd21c feat(structural-debt): lean pipeline path (skip science debt never reads) (#355) 08032192b0c8fb08cc9ab5fd1b1536ae40a8a9f8 feat(timeline): expose per-period module survival-by-author; pin analysis instant (#366) c9b680d3ef1960d4f4c7f62f0988ed9c4fb4864d feat(write-index): wire anchors + graveyard into the per-module index (#365) fa697e1074f7558cc4640d6ffd918ebb1ff500bd fix(anchors): calibrate exemplar quality (core source + real-logic digests) (#360) 090079032c0b51fcb5bc009c924807cddf7a73b7 test(metric): adversarial fixtures for the contest detector (verify, don’t assume) (#362)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/machuz/eis">https://github.com/machuz/eis</a></strong> to version <strong>v2.31.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/eis-upload-signals">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>744153cfade21c2ddbd0075fd9ae832ad6a8fb32 feat(cli): add anchors — surviving exemplar code per module (Build2 ①) (#359)</li>
<li>8063822db503221bd5ab410f7111800cb306422b feat(cli): add get-write-context — structured write context (MCP core) (#358)</li>
<li>2f549cf7ea29012ce21ff8af74e7368871d15974 feat(cli): add graveyard — where past attempts died (Build2 ②) (#361)</li>
<li>f606b97d2751cda0237baebd82faf235294a6ba5 feat(cli): add precheck-hook — Claude Code PreToolUse debt injector (#357)</li>
<li>5072795f679b0af30de226f1f37e00a0d895c5ef feat(cli): add write-index — per-module index for AI coding agents (#356)</li>
<li>25c73e72fbb4366732a4254cff61545411be3c6c feat(cli): structural-debt Tier-1 meter (SDR, AI-agnostic) (#354)</li>
<li>4da4a8507f2b046b5b1236da5fe95d33512a6d9a feat(graveyard): drop non-code files (docs/config/images) from the death walk (#363)</li>
<li>19c93511030a250140bde0d9662fd0b2d0ef2c5f feat(mcp): add eis mcp — MCP stdio server exposing get_write_context (#364)</li>
<li>2fd32d6e069c9cfa283b8f3f2d7553d09e6dd21c feat(structural-debt): lean pipeline path (skip science debt never reads) (#355)</li>
<li>08032192b0c8fb08cc9ab5fd1b1536ae40a8a9f8 feat(timeline): expose per-period module survival-by-author; pin analysis instant (#366)</li>
<li>c9b680d3ef1960d4f4c7f62f0988ed9c4fb4864d feat(write-index): wire anchors + graveyard into the per-module index (#365)</li>
<li>fa697e1074f7558cc4640d6ffd918ebb1ff500bd fix(anchors): calibrate exemplar quality (core source + real-logic digests) (#360)</li>
<li>090079032c0b51fcb5bc009c924807cddf7a73b7 test(metric): adversarial fixtures for the contest detector (verify, don&rsquo;t assume) (#362)</li>
</ul>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/go-proxy-cache-updater/</link><pubDate>Sat, 11 Jul 2026 14:15:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.19.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.1.19 (2026-07-11)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.19</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1119-2026-07-11"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.18...v1.1.19">1.1.19</a> (2026-07-11)</h2>
]]></content:encoded></item><item><title>Changelog Bot Runner Nyaomaru</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/changelog-bot-runner-nyaomaru/</link><pubDate>Sat, 11 Jul 2026 14:15:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/changelog-bot-runner-nyaomaru/</guid><description>Version updated for https://github.com/nyaomaru/changelog-bot to version v0.6.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed docs(changelog): 0.6.4 by @github-actions[bot] in https://github.com/nyaomaru/changelog-bot/pull/157 fix: document exit codes and typed config errors by @nyaomaru in https://github.com/nyaomaru/changelog-bot/pull/158 refactor: clarify category tuning rules by @nyaomaru in https://github.com/nyaomaru/changelog-bot/pull/159 refactor: clarify release section rendering by @nyaomaru in https://github.com/nyaomaru/changelog-bot/pull/160 Release: 0.6.5 by @github-actions[bot] in https://github.com/nyaomaru/changelog-bot/pull/161 Full Changelog: https://github.com/nyaomaru/changelog-bot/compare/v0...v0.6.5</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nyaomaru/changelog-bot">https://github.com/nyaomaru/changelog-bot</a></strong> to version <strong>v0.6.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/changelog-bot-runner-nyaomaru">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs(changelog): 0.6.4 by @github-actions[bot] in <a href="https://github.com/nyaomaru/changelog-bot/pull/157">https://github.com/nyaomaru/changelog-bot/pull/157</a></li>
<li>fix: document exit codes and typed config errors by @nyaomaru in <a href="https://github.com/nyaomaru/changelog-bot/pull/158">https://github.com/nyaomaru/changelog-bot/pull/158</a></li>
<li>refactor: clarify category tuning rules by @nyaomaru in <a href="https://github.com/nyaomaru/changelog-bot/pull/159">https://github.com/nyaomaru/changelog-bot/pull/159</a></li>
<li>refactor: clarify release section rendering by @nyaomaru in <a href="https://github.com/nyaomaru/changelog-bot/pull/160">https://github.com/nyaomaru/changelog-bot/pull/160</a></li>
<li>Release: 0.6.5 by @github-actions[bot] in <a href="https://github.com/nyaomaru/changelog-bot/pull/161">https://github.com/nyaomaru/changelog-bot/pull/161</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nyaomaru/changelog-bot/compare/v0...v0.6.5">https://github.com/nyaomaru/changelog-bot/compare/v0...v0.6.5</a></p>
]]></content:encoded></item><item><title>Setup OCX</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/setup-ocx/</link><pubDate>Sat, 11 Jul 2026 14:14:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/setup-ocx/</guid><description>Version updated for https://github.com/ocx-sh/setup-ocx to version v1.3.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.3.0 — 2026-07-11 Added Support tar.gz archives with tar.xz fallback by @michael-herwig (ae06166) Release V1.3.0 by @michael-herwig (dbb4743)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ocx-sh/setup-ocx">https://github.com/ocx-sh/setup-ocx</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-ocx">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="130--2026-07-11"><a href="https://github.com/ocx-sh/setup-ocx/releases/tag/v1.3.0">1.3.0</a> — 2026-07-11</h2>
<h3 id="added">Added</h3>
<ul>
<li>Support tar.gz archives with tar.xz fallback by @michael-herwig (<a href="https://github.com/ocx-sh/setup-ocx/commit/ae06166db67732f6633e63b28dd96d26a82def10">ae06166</a>)</li>
</ul>
<h3 id="release">Release</h3>
<ul>
<li>V1.3.0 by @michael-herwig (<a href="https://github.com/ocx-sh/setup-ocx/commit/dbb4743307c8c867e5e34d9a8658f08dfdeb962b">dbb4743</a>)</li>
</ul>
]]></content:encoded></item><item><title>spec.md check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/spec.md-check/</link><pubDate>Sat, 11 Jul 2026 14:13:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/spec.md-check/</guid><description>Version updated for https://github.com/rosenjcb/spec.md to version v0.3.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed @rosenjcb/spec-md v0.3.4 Patch Changes Fix Claude Code plugin command names: files are action-only (update.md, check.md, coverage.md, new.md) so invocations are /spec-md:update, /spec-md:check, /spec-md:coverage, /spec-md:new. Previous spec:update.md / spec-update.md stems double-prefixed under plugin spec-md. Docs and a regression test lock the mapping. Install npm install --save-dev @rosenjcb/spec-md@0.3.4 npx @rosenjcb/spec-md check - uses: rosenjcb/spec.md@v0.3.4 GitHub Action Marketplace: automated releases do not check “Publish to Marketplace”. On the first release, open the release in GitHub and enable marketplace publishing manually. See RELEASING.md.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rosenjcb/spec.md">https://github.com/rosenjcb/spec.md</a></strong> to version <strong>v0.3.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spec-md-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="rosenjcbspec-md-v034">@rosenjcb/spec-md v0.3.4</h2>
<h3 id="patch-changes">Patch Changes</h3>
<ul>
<li>Fix Claude Code plugin command names: files are action-only (<code>update.md</code>, <code>check.md</code>, <code>coverage.md</code>, <code>new.md</code>) so invocations are <code>/spec-md:update</code>, <code>/spec-md:check</code>, <code>/spec-md:coverage</code>, <code>/spec-md:new</code>. Previous <code>spec:update.md</code> / <code>spec-update.md</code> stems double-prefixed under plugin <code>spec-md</code>. Docs and a regression test lock the mapping.</li>
</ul>
<h3 id="install">Install</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npm install --save-dev @rosenjcb/spec-md@0.3.4
</span></span><span style="display:flex;"><span>npx @rosenjcb/spec-md check
</span></span></code></pre></div><div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">rosenjcb/spec.md@v0.3.4</span>
</span></span></code></pre></div><blockquote>
<p><strong>GitHub Action Marketplace:</strong> automated releases do not check &ldquo;Publish to Marketplace&rdquo;.
On the first release, open the release in GitHub and enable marketplace publishing manually.
See <a href="https://github.com/rosenjcb/spec.md/blob/main/RELEASING.md">RELEASING.md</a>.</p>
</blockquote>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Fix Claude plugin invocations to <code>/spec-md:&lt;action&gt;</code> by @rosenjcb in <a href="https://github.com/rosenjcb/spec.md/pull/10">https://github.com/rosenjcb/spec.md/pull/10</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/rosenjcb/spec.md/compare/v0.3.3...v0.3.4">https://github.com/rosenjcb/spec.md/compare/v0.3.3...v0.3.4</a></p>
]]></content:encoded></item><item><title>Auto-download resume from overleaf</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/auto-download-resume-from-overleaf/</link><pubDate>Sat, 11 Jul 2026 14:12:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/auto-download-resume-from-overleaf/</guid><description>Version updated for https://github.com/Sbrjt/overleaf-resume-syncer to version v2.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Added google drive upload integration by @sahitya1903 in https://github.com/Sbrjt/overleaf-resume-syncer/pull/2 Full Changelog: https://github.com/Sbrjt/overleaf-resume-syncer/compare/v1...v2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Sbrjt/overleaf-resume-syncer">https://github.com/Sbrjt/overleaf-resume-syncer</a></strong> to version <strong>v2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/auto-download-resume-from-overleaf">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Added google drive upload integration by @sahitya1903 in <a href="https://github.com/Sbrjt/overleaf-resume-syncer/pull/2">https://github.com/Sbrjt/overleaf-resume-syncer/pull/2</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Sbrjt/overleaf-resume-syncer/compare/v1...v2">https://github.com/Sbrjt/overleaf-resume-syncer/compare/v1...v2</a></p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/bernstein-multi-agent-orchestration/</link><pubDate>Sat, 11 Jul 2026 14:12:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.3.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v3.3.0 Released 2026-07-11.
An operator-capability release. The dashboard gains authentication with scoped tokens whose every decision lands a governance receipt, a new agy adapter joins the matrix with a nightly conformance canary sealing its probe results, and the run review board projects the run journal into a web view backed by sealed evidence bundles. Groundwork lands for Windows parity and for installing bernstein as an agent skill or plugin.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v330">v3.3.0</h1>
<p>Released 2026-07-11.</p>
<p>An operator-capability release. The dashboard gains authentication with
scoped tokens whose every decision lands a governance receipt, a new agy
adapter joins the matrix with a nightly conformance canary sealing its
probe results, and the run review board projects the run journal into a
web view backed by sealed evidence bundles. Groundwork lands for Windows
parity and for installing bernstein as an agent skill or plugin.</p>
<h2 id="dashboard-authentication-and-scoped-tokens-2366">Dashboard authentication and scoped tokens (#2366)</h2>
<p>The dashboard is no longer an all-or-nothing surface. Operators issue
scoped credentials, and every authentication decision is a receipt:</p>
<ul>
<li>Password login and scoped bearer tokens coexist; tokens carry either a
read-only or an operator scope, and route access is enforced per scope.</li>
<li>Token grants and revocations are signed journal rows; a tampered grant
fails signature verification and is treated as no grant at all.</li>
<li>Every allow or deny decision is recorded as a governance journal
receipt, so an access review can reconstruct exactly who reached which
surface and under which credential.</li>
<li><code>bernstein dashboard-token</code> issues, lists, and revokes tokens from the
CLI; revocation is itself a signed journal row, never a silent delete.</li>
</ul>
<h2 id="agy-adapter-and-adapter-conformance-canary-2368">agy adapter and adapter conformance canary (#2368)</h2>
<p>agy joins the adapter matrix, and adapter contracts are now exercised
nightly instead of waiting for a user&rsquo;s broken run:</p>
<ul>
<li>The agy adapter maps goals onto the agy CLI with the same contract
surface as every other adapter, including golden transcripts and a
contract fixture.</li>
<li>A nightly canary probes every primary adapter against whatever upstream
version is installed; each probe result is a sealed, content-addressed
receipt mirrored into the audit chain.</li>
<li>A last-green table names the newest upstream version each adapter
passed with, and every row carries the hash of the receipt that
attested it. <code>bernstein doctor</code> reads the same projection and advises
when the installed version is newer than the last attested one.</li>
<li>Issue automation is threshold-gated and deduplicated: one upstream
flake never opens an issue, and the same failure fingerprint never
opens two.</li>
</ul>
<h2 id="run-review-board-core-2365">Run review board core (#2365)</h2>
<p>Finished runs can now be reviewed on a board instead of by reading raw
journals:</p>
<ul>
<li>The board is a deterministic projection of the run journal: the same
journal always produces the same board state, byte for byte, with no
hand-maintained status anywhere.</li>
<li>A web view lists runs with their outcomes, decisions, and artefacts,
consuming sealed evidence bundles so what the reviewer sees is what the
journal attests.</li>
<li>Further review-board phases (annotations, sign-off flows) are tracked
separately.</li>
</ul>
<h2 id="windows-parity-groundwork-2367">Windows parity groundwork (#2367)</h2>
<p>The platform layer gains the pieces Windows needs, validated so far on
the existing test matrix:</p>
<ul>
<li>Process cleanup emits reap receipts into the audit chain, so a killed
worker tree is reconstructable after the fact on every platform.</li>
<li>Job Object process management groups worker processes on Windows the
way process groups do on POSIX, closing the orphaned-child gap.</li>
<li>Worktree isolation is junction-aware, so per-task isolation survives
filesystems where symlinks require elevation.</li>
<li>Full validation on Windows runners is tracked separately.</li>
</ul>
<h2 id="agent-skill-and-plugin-packaging-groundwork-2369">Agent skill and plugin packaging groundwork (#2369)</h2>
<p>Installing bernstein as an agent skill or plugin gets its packaging
foundation:</p>
<ul>
<li><code>bernstein skills package</code> builds a skill/plugin bundle from the
packaged templates, with a manifest generated from the package version
so the bundle can never drift from the release.</li>
<li>Each install produces a lineage receipt, so an installed bundle can be
traced back to the exact release artefact it came from.</li>
<li>Remaining distribution surfaces are tracked separately.</li>
</ul>
<h2 id="housekeeping">Housekeeping</h2>
<ul>
<li>Resolved all open scanner alerts: applied suggested idiom cleanups,
moved dashboard password comparison onto a computationally expensive
key derivation, and annotated two exception-name-only log lines as
scanner false positives.</li>
<li>Dependency updates.</li>
</ul>
]]></content:encoded></item><item><title>The Slack GitHub Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/the-slack-github-action/</link><pubDate>Sat, 11 Jul 2026 14:11:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/the-slack-github-action/</guid><description>Version updated for https://github.com/slackapi/slack-github-action to version v3.0.5.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 26,705 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Patch Changes 96fddbe: fix: revert multiline yaml parsing indentation change</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/slackapi/slack-github-action">https://github.com/slackapi/slack-github-action</a></strong> to version <strong>v3.0.5</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>26,705</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/the-slack-github-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="patch-changes">Patch Changes</h3>
<ul>
<li>96fddbe: fix: revert multiline yaml parsing indentation change</li>
</ul>
]]></content:encoded></item><item><title>Pipr Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/pipr-review/</link><pubDate>Sat, 11 Jul 2026 14:11:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/pipr-review/</guid><description>Version updated for https://github.com/somus/pipr to version v0.3.7.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.3.7 (2026-07-11) Features runtime: add collapsible review stats (#53) (5bb8fa3) This PR was generated with Release Please. See documentation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somus/pipr">https://github.com/somus/pipr</a></strong> to version <strong>v0.3.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pipr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="037-2026-07-11"><a href="https://github.com/somus/pipr/compare/v0.3.6...v0.3.7">0.3.7</a> (2026-07-11)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>runtime:</strong> add collapsible review stats (<a href="https://github.com/somus/pipr/issues/53">#53</a>) (<a href="https://github.com/somus/pipr/commit/5bb8fa371f063cf07732abe522ef391accce1dbd">5bb8fa3</a>)</li>
</ul>
<hr>
<p>This PR was generated with <a href="https://github.com/googleapis/release-please">Release Please</a>. See <a href="https://github.com/googleapis/release-please#release-please">documentation</a>.</p>
<!-- stage-review-badge-begin -->
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/ssg-static-site-generator/</link><pubDate>Sat, 11 Jul 2026 14:10:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Installation Quick Install (Linux/macOS) curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash Package Managers Homebrew: brew install spagu/tap/ssg Snap: snap install ssg Debian/Ubuntu: Download .deb file below Fedora/RHEL: Download .rpm file below Checksums See checksums.sha256 for file verification.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs(readme): fix GitHub Pages Jekyll build (Liquid syntax in engines table) by @spagu in <a href="https://github.com/spagu/ssg/pull/21">https://github.com/spagu/ssg/pull/21</a></li>
<li>feat(1.8.2): SEO injection opt-in (&ndash;seo) + greatly expanded README by @spagu in <a href="https://github.com/spagu/ssg/pull/22">https://github.com/spagu/ssg/pull/22</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.8.1...v1.8.2">https://github.com/spagu/ssg/compare/v1.8.1...v1.8.2</a></p>
]]></content:encoded></item><item><title>xilo-nix-cache</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/xilo-nix-cache/</link><pubDate>Sat, 11 Jul 2026 14:10:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/xilo-nix-cache/</guid><description>Version updated for https://github.com/stubbedev/xilo to version v0.2.5.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/stubbedev/xilo/compare/v0...v0.2.5</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stubbedev/xilo">https://github.com/stubbedev/xilo</a></strong> to version <strong>v0.2.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/xilo-nix-cache">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/stubbedev/xilo/compare/v0...v0.2.5">https://github.com/stubbedev/xilo/compare/v0...v0.2.5</a></p>
]]></content:encoded></item><item><title>Pi Review Agent</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/pi-review-agent/</link><pubDate>Sat, 11 Jul 2026 14:09:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/pi-review-agent/</guid><description>Version updated for https://github.com/sun-praise/pi-review-agent to version v1.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s new Repository style-guide support: pi-review-agent can now load a repo-level style-guide and inject it into reviewer prompts. Auto-detected paths: STYLE_GUIDE.md, .github/STYLE_GUIDE.md, docs/style-guide.md, .github/style-guide.md. New built-in style persona dedicated to style-guide enforcement. quality persona now receives the style-guide by default. Custom personas can opt in via use-style-guide: true in .github/reviewers/*.yaml. Explicit override via --style-guide CLI flag or style-guide action input. Usage - uses: sun-praise/pi-review-agent@v1 with: team: &amp;#34;quality:1,style:1,security:1&amp;#34; style-guide: &amp;#34;./docs/STYLE_GUIDE.md&amp;#34; litellm-url: ${{ secrets.LITELLM_URL }} litellm-api-key: ${{ secrets.LITELLM_API_KEY }} Refer to README.md for full documentation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sun-praise/pi-review-agent">https://github.com/sun-praise/pi-review-agent</a></strong> to version <strong>v1.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pi-review-agent">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new">What&rsquo;s new</h2>
<ul>
<li><strong>Repository style-guide support</strong>: <code>pi-review-agent</code> can now load a repo-level style-guide and inject it into reviewer prompts.
<ul>
<li>Auto-detected paths: <code>STYLE_GUIDE.md</code>, <code>.github/STYLE_GUIDE.md</code>, <code>docs/style-guide.md</code>, <code>.github/style-guide.md</code>.</li>
<li>New built-in <code>style</code> persona dedicated to style-guide enforcement.</li>
<li><code>quality</code> persona now receives the style-guide by default.</li>
<li>Custom personas can opt in via <code>use-style-guide: true</code> in <code>.github/reviewers/*.yaml</code>.</li>
<li>Explicit override via <code>--style-guide</code> CLI flag or <code>style-guide</code> action input.</li>
</ul>
</li>
</ul>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sun-praise/pi-review-agent@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">team</span>: <span style="color:#e6db74">&#34;quality:1,style:1,security:1&#34;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">style-guide</span>: <span style="color:#e6db74">&#34;./docs/STYLE_GUIDE.md&#34;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">litellm-url</span>: <span style="color:#ae81ff">${{ secrets.LITELLM_URL }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">litellm-api-key</span>: <span style="color:#ae81ff">${{ secrets.LITELLM_API_KEY }}</span>
</span></span></code></pre></div><p>Refer to <code>README.md</code> for full documentation.</p>
]]></content:encoded></item><item><title>Ansible Molecule</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/ansible-molecule/</link><pubDate>Sat, 11 Jul 2026 06:19:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/ansible-molecule/</guid><description>Version updated for https://github.com/gofrolist/molecule-action to version v2.9.2.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.9.2 (2026-07-11) This release is published under the MIT License.
Bug Fixes deps: Bump astral-sh/uv from 0.11.27 to 0.11.28 (83bf83d) Detailed Changes: v2.9.1…v2.9.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/gofrolist/molecule-action">https://github.com/gofrolist/molecule-action</a></strong> to version <strong>v2.9.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ansible-molecule">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v292-2026-07-11">v2.9.2 (2026-07-11)</h2>
<p><em>This release is published under the MIT License.</em></p>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>deps</strong>: Bump astral-sh/uv from 0.11.27 to 0.11.28 (<a href="https://github.com/gofrolist/molecule-action/commit/83bf83d999fb1fc4f1be89d1f9b96fcae3be5e14"><code>83bf83d</code></a>)</li>
</ul>
<hr>
<p><strong>Detailed Changes</strong>: <a href="https://github.com/gofrolist/molecule-action/compare/v2.9.1...v2.9.2">v2.9.1&hellip;v2.9.2</a></p>
]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/ai-plugin-scanner/</link><pubDate>Sat, 11 Jul 2026 06:19:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.431.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/533303a1e5604620ca7e806d750472a99379d081 with plugin-scanner 2.0.1031.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.430...v1.2.431</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.431</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>18</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/533303a1e5604620ca7e806d750472a99379d081">https://github.com/hashgraph-online/hol-guard/tree/533303a1e5604620ca7e806d750472a99379d081</a> with plugin-scanner 2.0.1031.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.430...v1.2.431">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.430...v1.2.431</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/hol-codex-plugin-scanner/</link><pubDate>Sat, 11 Jul 2026 06:18:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.431.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.431</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.431</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.431">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.431</a></p>
]]></content:encoded></item><item><title>action-lambda-publish</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/action-lambda-publish/</link><pubDate>Sat, 11 Jul 2026 06:18:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/action-lambda-publish/</guid><description>Version updated for https://github.com/heronlabs/action-lambda-publish to version v4.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [skip ci] bump v4.0.2 (b2b33b4) chore(deps): bump heronlabs/action-tag-release-build (#25) (9bc047e) [skip ci] bump v4.0.1 (a3343a0) chore: migrate supera.json to 2.x + doc fix (#26) (22a5ee0) [skip ci] bump v4.0.0 (401b931) chore: polish metadata, docs, gitignore, and SHA-to-tag refs (bd10446) [skip ci] bump v3.0.14 (2a7a37c) chore: add CODEOWNERS file to define repository ownership (82d7d6e) [skip ci] bump v3.0.13 (02e3934) Merge pull request #21 from heronlabs/chore-dependabot-daily (3bd72a6)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/heronlabs/action-lambda-publish">https://github.com/heronlabs/action-lambda-publish</a></strong> to version <strong>v4.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/action-lambda-publish">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>[skip ci] bump v4.0.2 (b2b33b4)</li>
<li>chore(deps): bump heronlabs/action-tag-release-build (#25) (9bc047e)</li>
<li>[skip ci] bump v4.0.1 (a3343a0)</li>
<li>chore: migrate supera.json to 2.x + doc fix (#26) (22a5ee0)</li>
<li>[skip ci] bump v4.0.0 (401b931)</li>
<li>chore: polish metadata, docs, gitignore, and SHA-to-tag refs (bd10446)</li>
<li>[skip ci] bump v3.0.14 (2a7a37c)</li>
<li>chore: add CODEOWNERS file to define repository ownership (82d7d6e)</li>
<li>[skip ci] bump v3.0.13 (02e3934)</li>
<li>Merge pull request #21 from heronlabs/chore-dependabot-daily (3bd72a6)</li>
</ul>
]]></content:encoded></item><item><title>hide-comment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/hide-comment/</link><pubDate>Sat, 11 Jul 2026 06:17:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/hide-comment/</guid><description>Version updated for https://github.com/int128/hide-comment-action to version v1.65.0.
This action is used across all versions by 228 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed uses: int128/hide-comment-action@7938621b1746abfe9727d44c8f6c47d5485192ca # v1.65.0 What’s Changed Remove unused js-yaml dependency by @int128-actions-tanpopo[bot] in https://github.com/int128/hide-comment-action/pull/1650 chore(deps): update dependency @vercel/ncc to v0.44.1 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1652 Full Changelog: https://github.com/int128/hide-comment-action/compare/v1.64.0...v1.65.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/int128/hide-comment-action">https://github.com/int128/hide-comment-action</a></strong> to version <strong>v1.65.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>228</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hide-comment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">uses</span>: <span style="color:#ae81ff">int128/hide-comment-action@7938621b1746abfe9727d44c8f6c47d5485192ca</span> <span style="color:#75715e"># v1.65.0</span>
</span></span></code></pre></div><h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Remove unused js-yaml dependency by @int128-actions-tanpopo[bot] in <a href="https://github.com/int128/hide-comment-action/pull/1650">https://github.com/int128/hide-comment-action/pull/1650</a></li>
<li>chore(deps): update dependency @vercel/ncc to v0.44.1 by @renovate[bot] in <a href="https://github.com/int128/hide-comment-action/pull/1652">https://github.com/int128/hide-comment-action/pull/1652</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/int128/hide-comment-action/compare/v1.64.0...v1.65.0">https://github.com/int128/hide-comment-action/compare/v1.64.0...v1.65.0</a></p>
]]></content:encoded></item><item><title>stackit-cli tools installer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/stackit-cli-tools-installer/</link><pubDate>Sat, 11 Jul 2026 06:17:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/stackit-cli-tools-installer/</guid><description>Version updated for https://github.com/jkroepke/setup-stackit-cli to version v1.2.87.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed 🛠️ Dependencies chore(deps): lock file maintenance by @renovate[bot] in https://github.com/jkroepke/setup-stackit-cli/pull/284 Full Changelog: https://github.com/jkroepke/setup-stackit-cli/compare/v1.2.86...v1.2.87</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jkroepke/setup-stackit-cli">https://github.com/jkroepke/setup-stackit-cli</a></strong> to version <strong>v1.2.87</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/stackit-cli-tools-installer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at v1.2.87 -->
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="-dependencies">🛠️ Dependencies</h3>
<ul>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/jkroepke/setup-stackit-cli/pull/284">https://github.com/jkroepke/setup-stackit-cli/pull/284</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jkroepke/setup-stackit-cli/compare/v1.2.86...v1.2.87">https://github.com/jkroepke/setup-stackit-cli/compare/v1.2.86...v1.2.87</a></p>
]]></content:encoded></item><item><title>probelock gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/probelock-gate/</link><pubDate>Sat, 11 Jul 2026 06:16:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/probelock-gate/</guid><description>Version updated for https://github.com/kelkalot/probelock to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Refine release workflow to match only version tags by @kelkalot in https://github.com/kelkalot/probelock/pull/7 Release 1.0.0: stability, doctor, robustness by @kelkalot in https://github.com/kelkalot/probelock/pull/8 Full Changelog: https://github.com/kelkalot/probelock/compare/v0...v1.0.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kelkalot/probelock">https://github.com/kelkalot/probelock</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/probelock-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Refine release workflow to match only version tags by @kelkalot in <a href="https://github.com/kelkalot/probelock/pull/7">https://github.com/kelkalot/probelock/pull/7</a></li>
<li>Release 1.0.0: stability, doctor, robustness by @kelkalot in <a href="https://github.com/kelkalot/probelock/pull/8">https://github.com/kelkalot/probelock/pull/8</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/kelkalot/probelock/compare/v0...v1.0.0">https://github.com/kelkalot/probelock/compare/v0...v1.0.0</a></p>
]]></content:encoded></item><item><title>aria-reach — ARIA anti-pattern scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/aria-reach-aria-anti-pattern-scan/</link><pubDate>Sat, 11 Jul 2026 06:16:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/aria-reach-aria-anti-pattern-scan/</guid><description>Version updated for https://github.com/manichandra/aria-reach to version v0.1.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed projection-aware listbox rule; cross-ecosystem scan harness</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/manichandra/aria-reach">https://github.com/manichandra/aria-reach</a></strong> to version <strong>v0.1.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aria-reach-aria-anti-pattern-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>projection-aware listbox rule; cross-ecosystem scan harness</p>
]]></content:encoded></item><item><title>Setup Marmot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/setup-marmot/</link><pubDate>Sat, 11 Jul 2026 06:15:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/setup-marmot/</guid><description>Version updated for https://github.com/marmotdata/setup-marmot to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/marmotdata/setup-marmot/commits/v0.1.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/marmotdata/setup-marmot">https://github.com/marmotdata/setup-marmot</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-marmot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/marmotdata/setup-marmot/commits/v0.1.0">https://github.com/marmotdata/setup-marmot/commits/v0.1.0</a></p>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/totem-shield/</link><pubDate>Sat, 11 Jul 2026 06:14:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.92.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Cohort-link bump (no direct package changes). See .changeset/config.json for the fixed-cohort definition.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.92.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>Agent Behavior Safety Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/agent-behavior-safety-gate/</link><pubDate>Sat, 11 Jul 2026 06:14:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/agent-behavior-safety-gate/</guid><description>Version updated for https://github.com/NavidBroumandfar/agent-behavior-evals-lab to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Real-agent fleet calibration (320 records, 3-judge panel), verifier red-team hardening, refusal-under-temptation corpus (local_public_v3), measured eval-awareness reports, laundered-refusal demo record shipped in the offline gate demo. Full details in README and reports/comparisons/.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NavidBroumandfar/agent-behavior-evals-lab">https://github.com/NavidBroumandfar/agent-behavior-evals-lab</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-behavior-safety-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Real-agent fleet calibration (320 records, 3-judge panel), verifier red-team hardening, refusal-under-temptation corpus (local_public_v3), measured eval-awareness reports, laundered-refusal demo record shipped in the offline gate demo. Full details in README and reports/comparisons/.</p>
]]></content:encoded></item><item><title>Nox Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/nox-security-scanner/</link><pubDate>Sat, 11 Jul 2026 06:13:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/nox-security-scanner/</guid><description>Version updated for https://github.com/Nox-HQ/nox to version v1.8.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Nox v1.8.0 (2026-07-10T20:09:28Z) Language-agnostic security scanner with first-class AI application security.
Installation macOS/Linux (Homebrew) brew tap felixgeelhaar/tap brew install nox Direct Download Download the appropriate archive for your platform from the assets below.
What’s Changed Changelog Features 447c45f37e18f308f1ca17822f8ebdd195da2746 feat(server): return structured content from read/report tools (#230) Others 8d3112f55e43db84eecca7e93e7e92b10ac1aa30 chore(deps): bump go.klarlabs.de/mcp to v1.21.0 (#227) 9baa04fcda33d5fd30e84cf8600998565dd598a4 chore(deps): bump go.klarlabs.de/mcp to v1.22.0 (#229) d75e6e26ce0a297c164491dd4a27bfc757b6e1e4 chore(deps): bump golang.org/x/net from 0.54.0 to 0.55.0 in /plugins/nox-plugin-grc (#228) Full Changelog: https://github.com/nox-hq/nox/compare/v1.7.1...v1.8.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Nox-HQ/nox">https://github.com/Nox-HQ/nox</a></strong> to version <strong>v1.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nox-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="nox-v180-2026-07-10t200928z">Nox v1.8.0 (2026-07-10T20:09:28Z)</h2>
<p>Language-agnostic security scanner with first-class AI application security.</p>
<h3 id="installation">Installation</h3>
<h4 id="macoslinux-homebrew">macOS/Linux (Homebrew)</h4>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>brew tap felixgeelhaar/tap
</span></span><span style="display:flex;"><span>brew install nox
</span></span></code></pre></div><h4 id="direct-download">Direct Download</h4>
<p>Download the appropriate archive for your platform from the assets below.</p>
<h3 id="whats-changed-1">What&rsquo;s Changed</h3>
<h2 id="changelog">Changelog</h2>
<h3 id="features">Features</h3>
<ul>
<li>447c45f37e18f308f1ca17822f8ebdd195da2746 feat(server): return structured content from read/report tools (#230)</li>
</ul>
<h3 id="others">Others</h3>
<ul>
<li>8d3112f55e43db84eecca7e93e7e92b10ac1aa30 chore(deps): bump go.klarlabs.de/mcp to v1.21.0 (#227)</li>
<li>9baa04fcda33d5fd30e84cf8600998565dd598a4 chore(deps): bump go.klarlabs.de/mcp to v1.22.0 (#229)</li>
<li>d75e6e26ce0a297c164491dd4a27bfc757b6e1e4 chore(deps): bump golang.org/x/net from 0.54.0 to 0.55.0 in /plugins/nox-plugin-grc (#228)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nox-hq/nox/compare/v1.7.1...v1.8.0">https://github.com/nox-hq/nox/compare/v1.7.1...v1.8.0</a></p>
]]></content:encoded></item><item><title>start-aws-gha-runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/start-aws-gha-runner/</link><pubDate>Sat, 11 Jul 2026 06:13:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/start-aws-gha-runner/</guid><description>Version updated for https://github.com/omsf/start-aws-gha-runner to version v1.3.0.
This action is used across all versions by 10 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: support spot runners by @jandom in https://github.com/omsf/start-aws-gha-runner/pull/7 New Contributors @jandom made their first contribution in https://github.com/omsf/start-aws-gha-runner/pull/7 Full Changelog: https://github.com/omsf/start-aws-gha-runner/compare/v1.2.0...v1.3.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/omsf/start-aws-gha-runner">https://github.com/omsf/start-aws-gha-runner</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/start-aws-gha-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: support spot runners by @jandom in <a href="https://github.com/omsf/start-aws-gha-runner/pull/7">https://github.com/omsf/start-aws-gha-runner/pull/7</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@jandom made their first contribution in <a href="https://github.com/omsf/start-aws-gha-runner/pull/7">https://github.com/omsf/start-aws-gha-runner/pull/7</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/omsf/start-aws-gha-runner/compare/v1.2.0...v1.3.0">https://github.com/omsf/start-aws-gha-runner/compare/v1.2.0...v1.3.0</a></p>
]]></content:encoded></item><item><title>Rosentic - Cross-Branch Compatibility Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/rosentic-cross-branch-compatibility-check/</link><pubDate>Sat, 11 Jul 2026 06:12:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/rosentic-cross-branch-compatibility-check/</guid><description>Version updated for https://github.com/Rosentic/rosentic-action to version v1.8.0.
This action is used across all versions by 5 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Catches when AI-agent branches break each other’s contracts before merge. 13 languages, AST-level, runs on your CI runners. The engine goes to the code; the code never goes to the engine unless you send it.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Rosentic/rosentic-action">https://github.com/Rosentic/rosentic-action</a></strong> to version <strong>v1.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rosentic-cross-branch-compatibility-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Catches when AI-agent branches break each other&rsquo;s contracts before merge. <strong>13 languages</strong>, AST-level, runs on your CI runners. The engine goes to the code; the code never goes to the engine unless you send it.</p>
<h3 id="whats-new-since-170">What&rsquo;s new since 1.7.0</h3>
<ul>
<li><strong>Dart is the 13th language</strong> - L1 signature analysis (free functions and class methods; named, optional-positional, and required parameters).</li>
<li><strong>Reachability</strong> - every UNSAFE finding now says whether the broken contract is actually reachable from an entrypoint or export (or test-only / unreachable / unknown), with the shortest path. <code>unreachable</code> requires closed-world proof; uncertainty degrades to unknown, never suppresses.</li>
<li><strong>Enforced merge gate</strong> - policy-driven exit codes in CI. The gate fetches your effective policy at scan time; advisory fails open, blocking fails closed, never silent.</li>
<li><strong>Agent-facing next steps</strong> - when the gate blocks, the output and the PR comment tell a coding agent exactly how to fetch the SHA-keyed verdict JSON and how to load the Rosentic MCP tools, so an agent can act on a block without a human.</li>
<li><strong>Tamper-evident audit trail</strong> - hash-chained, append-only ledger of every gate verdict, replayable, JSON/CSV export. <code>verify-chain</code> recomputes from genesis.</li>
<li><strong>Govern</strong> - versioned per-repo/org policy (gate mode, severity, per-layer enforce/advisory); overrides require who + reason and land in the ledger.</li>
<li><strong>Agent attribution</strong> - which agent authored each branch, multi-signal (branch + commit identity + trailers + <code>.rosentic/agents.yml</code>), with confidence tiers.</li>
<li><strong>MCP server</strong> - six in-loop tools (check before the write, check before the push) for Cursor / Windsurf / Claude Code / Codex and more. Offline-capable. <code>pip install rosentic-mcp</code>.</li>
<li><strong>Anonymized telemetry contract</strong> - branch names and commit SHAs are hashed on your runner; raw names/SHAs never leave in no-key mode.</li>
<li><strong>Cross-repo drift (experimental)</strong> - detects the same contract drifting across your repos (proto lane). Standalone; not yet in the default scan.</li>
</ul>
<p>No workflow changes required. <code>@v1</code> users get everything automatically.</p>
]]></content:encoded></item><item><title>MCPShield MCP Config Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/mcpshield-mcp-config-scan/</link><pubDate>Sat, 11 Jul 2026 06:11:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/mcpshield-mcp-config-scan/</guid><description>Version updated for https://github.com/RunTimeAdmin/mcpshield-action to version v1.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixes discover_files no longer crashes when an absolute path or glob is passed to --paths (pathlib rejects non-relative glob patterns). Standard CI usage passes repo-relative paths and was unaffected.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RunTimeAdmin/mcpshield-action">https://github.com/RunTimeAdmin/mcpshield-action</a></strong> to version <strong>v1.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcpshield-mcp-config-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="fixes">Fixes</h2>
<ul>
<li><code>discover_files</code> no longer crashes when an <strong>absolute path or glob</strong> is passed to <code>--paths</code> (pathlib rejects non-relative glob patterns). Standard CI usage passes repo-relative paths and was unaffected.</li>
</ul>
]]></content:encoded></item><item><title>Sentinel Git Secrets Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/sentinel-git-secrets-scanner/</link><pubDate>Sat, 11 Jul 2026 06:11:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/sentinel-git-secrets-scanner/</guid><description>Version updated for https://github.com/sentinel-cli/sentinel to version v2.0.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/sentinel-cli/sentinel/compare/v2.0.5...v2.0.6</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sentinel-cli/sentinel">https://github.com/sentinel-cli/sentinel</a></strong> to version <strong>v2.0.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sentinel-git-secrets-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sentinel-cli/sentinel/compare/v2.0.5...v2.0.6">https://github.com/sentinel-cli/sentinel/compare/v2.0.5...v2.0.6</a></p>
]]></content:encoded></item><item><title>The Slack GitHub Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/the-slack-github-action/</link><pubDate>Sat, 11 Jul 2026 06:10:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/the-slack-github-action/</guid><description>Version updated for https://github.com/slackapi/slack-github-action to version v3.0.4.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 26,704 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Patch Changes fa03fe4: refactor: send webhooks with the @slack/webhook package</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/slackapi/slack-github-action">https://github.com/slackapi/slack-github-action</a></strong> to version <strong>v3.0.4</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>26,704</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/the-slack-github-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="patch-changes">Patch Changes</h3>
<ul>
<li>fa03fe4: refactor: send webhooks with the <a href="https://docs.slack.dev/tools/node-slack-sdk/webhook"><code>@slack/webhook</code></a> package</li>
</ul>
]]></content:encoded></item><item><title>Skill Provenance Validate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/skill-provenance-validate/</link><pubDate>Sat, 11 Jul 2026 06:09:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/skill-provenance-validate/</guid><description>Version updated for https://github.com/snapsynapse/skill-provenance to version v5.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 5.0.0 - 2026-07-10 Security hardening release for Skill Provenance manifest validation and its GitHub Actions wrapper.
Security fixes Prevented bundle-path shell injection by transporting caller-controlled action input through an environment variable instead of interpolating it into Bash source. Made verify mode fail closed on missing, malformed, or duplicate manifest hash fields. Added explicit hash: null as the only intentional hash-verification opt-out. Made update mode repair missing or malformed hashes while preserving explicit null opt-outs. Kept inventory presence checks active for files whose hashes are explicitly opted out. Tests and evals Added executable CI regressions for action input transport and validator hash states. Added adversarial quote, separator, command-substitution, newline, and spaced-path action coverage. Added core evals for fail-closed verification, explicit null semantics, and update repair. Added a supplemental eval for GitHub Action shell safety. Expanded coverage from 46 to 50 scenarios: 33 core and 17 supplemental. Breaking change Manifest entries may no longer omit the hash field. Use a complete lowercase sha256: value or explicit hash: null. This intentional contract tightening requires the 5.0.0 major version.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/snapsynapse/skill-provenance">https://github.com/snapsynapse/skill-provenance</a></strong> to version <strong>v5.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skill-provenance-validate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="500---2026-07-10">5.0.0 - 2026-07-10</h2>
<p>Security hardening release for Skill Provenance manifest validation and its GitHub Actions wrapper.</p>
<h3 id="security-fixes">Security fixes</h3>
<ul>
<li>Prevented <code>bundle-path</code> shell injection by transporting caller-controlled action input through an environment variable instead of interpolating it into Bash source.</li>
<li>Made verify mode fail closed on missing, malformed, or duplicate manifest hash fields.</li>
<li>Added explicit <code>hash: null</code> as the only intentional hash-verification opt-out.</li>
<li>Made update mode repair missing or malformed hashes while preserving explicit null opt-outs.</li>
<li>Kept inventory presence checks active for files whose hashes are explicitly opted out.</li>
</ul>
<h3 id="tests-and-evals">Tests and evals</h3>
<ul>
<li>Added executable CI regressions for action input transport and validator hash states.</li>
<li>Added adversarial quote, separator, command-substitution, newline, and spaced-path action coverage.</li>
<li>Added core evals for fail-closed verification, explicit null semantics, and update repair.</li>
<li>Added a supplemental eval for GitHub Action shell safety.</li>
<li>Expanded coverage from 46 to 50 scenarios: 33 core and 17 supplemental.</li>
</ul>
<h3 id="breaking-change">Breaking change</h3>
<p>Manifest entries may no longer omit the <code>hash</code> field. Use a complete lowercase <code>sha256:</code> value or explicit <code>hash: null</code>. This intentional contract tightening requires the 5.0.0 major version.</p>
<h3 id="verification">Verification</h3>
<ul>
<li>Merged GitHub CI: pass</li>
<li>Canonical bundle hash verification: pass, 7 checked and 0 errors</li>
<li>Validator hash-state regression suite: pass</li>
<li>Action input adversarial regression: pass</li>
<li>Strict and ClawHub package builds: pass</li>
<li>Strict derived-bundle validation: pass</li>
<li>Release-surface, GuideCheck sidecar, and <code>.skill</code> freshness checks: pass</li>
<li>Bash syntax, JSON counts, skill validation, and <code>git diff --check</code>: pass</li>
<li>Adversarial result: no command execution and no legitimate spaced-path false positive observed</li>
</ul>
<h3 id="deferred-residuals">Deferred residuals</h3>
<p>The next hardening tranche should define and test policies for absolute or parent-traversal manifest paths, symlinks, duplicate path entries, and the exact zero-dependency YAML subset supported by the parser.</p>
<h3 id="asset-digest">Asset digest</h3>
<ul>
<li><code>skill-provenance.skill</code> SHA-256: <code>c20dea21230ffcd7e799187c4e65d44c21ec4a602f04305dd36ff2a904cd4144</code></li>
</ul>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/ssg-static-site-generator/</link><pubDate>Sat, 11 Jul 2026 06:09:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.8.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Installation Quick Install (Linux/macOS) curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash Package Managers Homebrew: brew install spagu/tap/ssg Snap: snap install ssg Debian/Ubuntu: Download .deb file below Fedora/RHEL: Download .rpm file below Checksums See checksums.sha256 for file verification.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>v1.8.0 — Blog Essentials, SEO/Assets/Authoring, Platform + audit hardening by @spagu in <a href="https://github.com/spagu/ssg/pull/19">https://github.com/spagu/ssg/pull/19</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.7.15...v1.8.0">https://github.com/spagu/ssg/compare/v1.7.15...v1.8.0</a></p>
]]></content:encoded></item><item><title>nix init</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/nix-init/</link><pubDate>Sat, 11 Jul 2026 06:08:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/nix-init/</guid><description>Version updated for https://github.com/spotdemo4/nix-init to version v1.57.0.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed feat: Update cachix/install-nix-action action to v31.10.7 (#159) (97318f9a6c3ec7b40483d6b25bf8d308a213eb20) bump: v1.56.0 -&amp;gt; v1.57.0 (a381c8e0765c98cb84fdc4a392eefd6c4db309a5) chore(deps): update github actions to v1.56.0 (#158) (88f6dbaed49ea12307fa5ea2c1b5a81dfa70a932)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spotdemo4/nix-init">https://github.com/spotdemo4/nix-init</a></strong> to version <strong>v1.57.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nix-init">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update cachix/install-nix-action action to v31.10.7 (#159) (97318f9a6c3ec7b40483d6b25bf8d308a213eb20)</li>
<li>bump: v1.56.0 -&gt; v1.57.0 (a381c8e0765c98cb84fdc4a392eefd6c4db309a5)</li>
<li>chore(deps): update github actions to v1.56.0 (#158) (88f6dbaed49ea12307fa5ea2c1b5a81dfa70a932)</li>
</ul>
]]></content:encoded></item><item><title>Azure Static Web Apps Deploy (small)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/azure-static-web-apps-deploy-small/</link><pubDate>Sat, 11 Jul 2026 06:08:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/azure-static-web-apps-deploy-small/</guid><description>Version updated for https://github.com/svrooij/azure-static-web-app-deploy-action to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Azure Static Web Apps Deploy (small) Features:
Deploy to Azure Static Web App 📦without a massive docker container 🐋 Support for federated credentials 🔑 and the less secure API token What’s Changed Remove extra colon by @arlobelshee in https://github.com/svrooij/azure-static-web-app-deploy-action/pull/2 Adjust README and update workflow to use azure/login@v3 by @svrooij in https://github.com/svrooij/azure-static-web-app-deploy-action/pull/3 Fix: failed SWA CLI deployment not propagating as action failure by @svrooij with @Copilot in https://github.com/svrooij/azure-static-web-app-deploy-action/pull/5 New Contributors @arlobelshee made their first contribution in https://github.com/svrooij/azure-static-web-app-deploy-action/pull/2 Full Changelog: https://github.com/svrooij/azure-static-web-app-deploy-action/compare/v1.0.0...v1.2.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/svrooij/azure-static-web-app-deploy-action">https://github.com/svrooij/azure-static-web-app-deploy-action</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/azure-static-web-apps-deploy-small">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="azure-static-web-apps-deploy-small">Azure Static Web Apps Deploy (small)</h2>
<p>Features:</p>
<ul>
<li>Deploy to Azure Static Web App 📦without a massive docker container 🐋</li>
<li>Support for federated credentials 🔑 and the less secure <code>API token</code></li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Remove extra colon by @arlobelshee in <a href="https://github.com/svrooij/azure-static-web-app-deploy-action/pull/2">https://github.com/svrooij/azure-static-web-app-deploy-action/pull/2</a></li>
<li>Adjust README and update workflow to use azure/login@v3 by @svrooij in <a href="https://github.com/svrooij/azure-static-web-app-deploy-action/pull/3">https://github.com/svrooij/azure-static-web-app-deploy-action/pull/3</a></li>
<li>Fix: failed SWA CLI deployment not propagating as action failure by @svrooij with @Copilot in <a href="https://github.com/svrooij/azure-static-web-app-deploy-action/pull/5">https://github.com/svrooij/azure-static-web-app-deploy-action/pull/5</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@arlobelshee made their first contribution in <a href="https://github.com/svrooij/azure-static-web-app-deploy-action/pull/2">https://github.com/svrooij/azure-static-web-app-deploy-action/pull/2</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/svrooij/azure-static-web-app-deploy-action/compare/v1.0.0...v1.2.0">https://github.com/svrooij/azure-static-web-app-deploy-action/compare/v1.0.0...v1.2.0</a></p>
]]></content:encoded></item><item><title>agentslint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/agentslint/</link><pubDate>Sat, 11 Jul 2026 06:07:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/agentslint/</guid><description>Version updated for https://github.com/toshi0607/agentslint to version v0.0.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First public release of agentslint — a CI linter for AI coding agent config files (AGENTS.md, CLAUDE.md, .claude/).
Highlights 6 rules: broken file references (AL001), stale commands (AL002), token budget (AL003), skill frontmatter (AL004), settings schema with 125 known keys (AL005), secret patterns (AL006) 4 output formats: pretty, JSON, SARIF (GitHub code scanning), GitHub annotations GitHub Action with PR inline annotations, job summary, and optional SARIF output --help / --version, zero-config npx @toshi0607/agentslint Tested on Ubuntu / macOS / Windows (47 tests) Usage - uses: actions/checkout@v4 - uses: toshi0607/agentslint@v0.0.2 See the README for CLI usage, configuration, and the code scanning setup.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/toshi0607/agentslint">https://github.com/toshi0607/agentslint</a></strong> to version <strong>v0.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentslint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release of <strong>agentslint</strong> — a CI linter for AI coding agent config files (<code>AGENTS.md</code>, <code>CLAUDE.md</code>, <code>.claude/</code>).</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>6 rules</strong>: broken file references (AL001), stale commands (AL002), token budget (AL003), skill frontmatter (AL004), settings schema with 125 known keys (AL005), secret patterns (AL006)</li>
<li><strong>4 output formats</strong>: pretty, JSON, SARIF (GitHub code scanning), GitHub annotations</li>
<li><strong>GitHub Action</strong> with PR inline annotations, job summary, and optional SARIF output</li>
<li><code>--help</code> / <code>--version</code>, zero-config <code>npx @toshi0607/agentslint</code></li>
<li>Tested on Ubuntu / macOS / Windows (47 tests)</li>
</ul>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">toshi0607/agentslint@v0.0.2</span>
</span></span></code></pre></div><p>See the <a href="https://github.com/toshi0607/agentslint#readme">README</a> for CLI usage, configuration, and the code scanning setup.</p>
]]></content:encoded></item><item><title>Magic Review OPENAI Code Review Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/magic-review-openai-code-review-action/</link><pubDate>Sat, 11 Jul 2026 06:07:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/magic-review-openai-code-review-action/</guid><description>Version updated for https://github.com/yuri-val/ai-codereviewer to version v4.
This action is used across all versions by 4 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s new since v3 Default model is now gpt-5.6-luna (was gpt-4o). Any model can still be set via the OPENAI_API_MODEL input. Prompts overhauled for the GPT-5.6 family: strict JSON output contract (response_format: json_object), severity levels (critical/major), line-number-anchored comments with GitHub suggestion blocks. Hardened review pipeline: concurrent per-file reviews, full-file context fetching, retry with exponential backoff on rate limits/5xx, adaptive completion-token budgets for reasoning models, comment batching with 422/403 fallback. OpenAI SDK upgraded to 4.104, Octokit to 21.x, action runtime on node20. Usage - uses: yuri-val/ai-codereviewer@v4 with: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }} OPENAI_API_MODEL: &amp;#34;gpt-5.6-luna&amp;#34; exclude: &amp;#34;**/*.lock,dist/**,**/*.json,**/*.md&amp;#34;</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yuri-val/ai-codereviewer">https://github.com/yuri-val/ai-codereviewer</a></strong> to version <strong>v4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/magic-review-openai-code-review-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new-since-v3">What&rsquo;s new since v3</h2>
<ul>
<li><strong>Default model is now <code>gpt-5.6-luna</code></strong> (was <code>gpt-4o</code>). Any model can still be set via the <code>OPENAI_API_MODEL</code> input.</li>
<li><strong>Prompts overhauled for the GPT-5.6 family</strong>: strict JSON output contract (<code>response_format: json_object</code>), severity levels (critical/major), line-number-anchored comments with GitHub <code>suggestion</code> blocks.</li>
<li><strong>Hardened review pipeline</strong>: concurrent per-file reviews, full-file context fetching, retry with exponential backoff on rate limits/5xx, adaptive completion-token budgets for reasoning models, comment batching with 422/403 fallback.</li>
<li><strong>OpenAI SDK upgraded to 4.104</strong>, Octokit to 21.x, action runtime on node20.</li>
</ul>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">yuri-val/ai-codereviewer@v4</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">GITHUB_TOKEN</span>: <span style="color:#ae81ff">${{ secrets.GITHUB_TOKEN }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">OPENAI_API_KEY</span>: <span style="color:#ae81ff">${{ secrets.OPENAI_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">OPENAI_API_MODEL</span>: <span style="color:#e6db74">&#34;gpt-5.6-luna&#34;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">exclude</span>: <span style="color:#e6db74">&#34;**/*.lock,dist/**,**/*.json,**/*.md&#34;</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Auto PR dev to main/master</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/auto-pr-dev-to-main/master/</link><pubDate>Sat, 11 Jul 2026 06:06:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/auto-pr-dev-to-main/master/</guid><description>Version updated for https://github.com/yuri-val/auto-pr-action to version v1.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changes in this Release:
feat: default to gpt-5.6-luna and tune prompt for GPT-5.6
Switch the default model from gpt-5.4-mini to gpt-5.6-luna
Rewrite the system prompt per the GPT-5.6 prompting guide: lean instructions, real newlines (previously literal \n sequences), clear output contract (summary + emoji sections, no title/preamble)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yuri-val/auto-pr-action">https://github.com/yuri-val/auto-pr-action</a></strong> to version <strong>v1.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/auto-pr-dev-to-main-master">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Changes in this Release:</p>
<ul>
<li>
<p>feat: default to gpt-5.6-luna and tune prompt for GPT-5.6</p>
</li>
<li>
<p>Switch the default model from gpt-5.4-mini to gpt-5.6-luna</p>
</li>
<li>
<p>Rewrite the system prompt per the GPT-5.6 prompting guide: lean
instructions, real newlines (previously literal \n sequences), clear
output contract (summary + emoji sections, no title/preamble)</p>
</li>
<li>
<p>Set reasoning_effort &ldquo;low&rdquo; and raise max_completion_tokens to 4096 so
reasoning tokens don&rsquo;t starve the visible answer on large releases</p>
</li>
<li>
<p>Expose pr_number as a composite action output via outputs.value
(previously declared but never propagated)</p>
</li>
</ul>
<p>Co-Authored-By: Claude Fable 5 <a href="mailto:noreply@anthropic.com">noreply@anthropic.com</a></p>
<ul>
<li>fix: bound the model payload so large releases don&rsquo;t 400</li>
</ul>
<p>A big release (the dev→master diff after a 256-commit feature branch merge)
produced a ~2.3MB diff. Capped at 1MB it was still ~300k+ tokens of dense
code+Cyrillic, overflowing the model&rsquo;s context window → OpenAI returned
HTTP 400 (context_length_exceeded), which the action reported only as the
opaque &ldquo;OpenAI API request failed&rdquo;.</p>
<p>Changes:</p>
<ul>
<li>Build a compact, high-signal payload: commit log + per-file diffstat first,
then the unified diff. The log/stat (~50KB here) always survive truncation.</li>
<li>Lower the cap to a context-safe default (max_diff_bytes input, 200000) and
truncate UTF-8-safely (head -c | iconv -f UTF-8 -t UTF-8 -c) so a multibyte
char split mid-sequence can&rsquo;t yield invalid UTF-8 (another 400 cause).</li>
<li>Drop the explicit temperature: 0.7 — the gpt-5 family only accepts the
default, so a non-default value is itself a 400 risk; the default is fine
for description generation.</li>
<li>Capture the HTTP status + API error body (no more &ndash;fail-with-body swallow)
so failures like context_length_exceeded are visible in the logs.</li>
</ul>
<p>Co-Authored-By: Claude Opus 4.8 (1M context) <a href="mailto:noreply@anthropic.com">noreply@anthropic.com</a></p>
]]></content:encoded></item><item><title>Auto-generate PR Description</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/auto-generate-pr-description/</link><pubDate>Sat, 11 Jul 2026 06:06:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/11/auto-generate-pr-description/</guid><description>Version updated for https://github.com/yuri-val/auto-pr-description-action to version v1.6.0.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changes in this Release:
feat: default to gpt-5.6-luna, tune prompt and token budget
Switch the default model from gpt-5.4-mini to gpt-5.6-luna
Rewrite the prompt per the GPT-5.6 prompting guide: lean system prompt with a clear output contract, diff moved to the user message</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yuri-val/auto-pr-description-action">https://github.com/yuri-val/auto-pr-description-action</a></strong> to version <strong>v1.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/auto-generate-pr-description">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Changes in this Release:</p>
<ul>
<li>
<p>feat: default to gpt-5.6-luna, tune prompt and token budget</p>
</li>
<li>
<p>Switch the default model from gpt-5.4-mini to gpt-5.6-luna</p>
</li>
<li>
<p>Rewrite the prompt per the GPT-5.6 prompting guide: lean system
prompt with a clear output contract, diff moved to the user message</p>
</li>
<li>
<p>Set reasoning_effort &ldquo;low&rdquo; for gpt-5.x models; keep temperature only
for non-reasoning models (gpt-5.x rejects custom temperature)</p>
</li>
<li>
<p>Raise max_completion_tokens 1024 -&gt; 4096 (reasoning tokens headroom)
and the diff cap 30k -&gt; 100k chars (400k-token context window)</p>
</li>
<li>
<p>Rebuild dist</p>
</li>
</ul>
<p>Co-Authored-By: Claude Fable 5 <a href="mailto:noreply@anthropic.com">noreply@anthropic.com</a></p>
<ul>
<li>📝 Refactor request body construction for OpenAI API call in PR description generation</li>
</ul>
]]></content:encoded></item><item><title>Agentic Workflow Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/agentic-workflow-guard/</link><pubDate>Fri, 10 Jul 2026 22:53:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/agentic-workflow-guard/</guid><description>Version updated for https://github.com/jinyounghub/agentic-workflow-guard to version v0.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v0.2.0 Public OSS release focused on real-world adoption: noise control, data-flow precision, catalog verification, and contributor onboarding.
Added Config file support with rule disable, severity override, path excludes, and narrow suppressions. Baseline support for accepted existing findings. Finding fingerprints and active/suppressed/baselined report state. Improved GitHub expression handling and one-step env data-flow detection for AI output references. Verified AI action catalog metadata and documentation. Contributor onboarding docs and beginner-friendly synthetic fixtures. Verification npm run lint npm test npm run build npm audit –audit-level=moderate npm pack –dry-run workflow self-scan fixture scans SARIF JSON parse check</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jinyounghub/agentic-workflow-guard">https://github.com/jinyounghub/agentic-workflow-guard</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentic-workflow-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v020">v0.2.0</h2>
<p>Public OSS release focused on real-world adoption: noise control, data-flow precision, catalog verification, and contributor onboarding.</p>
<h3 id="added">Added</h3>
<ul>
<li>Config file support with rule disable, severity override, path excludes, and narrow suppressions.</li>
<li>Baseline support for accepted existing findings.</li>
<li>Finding fingerprints and active/suppressed/baselined report state.</li>
<li>Improved GitHub expression handling and one-step env data-flow detection for AI output references.</li>
<li>Verified AI action catalog metadata and documentation.</li>
<li>Contributor onboarding docs and beginner-friendly synthetic fixtures.</li>
</ul>
<h3 id="verification">Verification</h3>
<ul>
<li>npm run lint</li>
<li>npm test</li>
<li>npm run build</li>
<li>npm audit &ndash;audit-level=moderate</li>
<li>npm pack &ndash;dry-run</li>
<li>workflow self-scan</li>
<li>fixture scans</li>
<li>SARIF JSON parse check</li>
</ul>
]]></content:encoded></item><item><title>sops tools installer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/sops-tools-installer/</link><pubDate>Fri, 10 Jul 2026 22:53:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/sops-tools-installer/</guid><description>Version updated for https://github.com/jkroepke/setup-sops to version v1.5.51.
This action is used across all versions by 4 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed 🛠️ Dependencies chore(deps): lock file maintenance by @renovate[bot] in https://github.com/jkroepke/setup-sops/pull/246 Full Changelog: https://github.com/jkroepke/setup-sops/compare/v1.5.50...v1.5.51</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jkroepke/setup-sops">https://github.com/jkroepke/setup-sops</a></strong> to version <strong>v1.5.51</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sops-tools-installer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at v1.5.51 -->
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="-dependencies">🛠️ Dependencies</h3>
<ul>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/jkroepke/setup-sops/pull/246">https://github.com/jkroepke/setup-sops/pull/246</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jkroepke/setup-sops/compare/v1.5.50...v1.5.51">https://github.com/jkroepke/setup-sops/compare/v1.5.50...v1.5.51</a></p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/neurolink-ai/</link><pubDate>Fri, 10 Jul 2026 22:52:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v9.86.2.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 9.86.2 (2026-07-10) Bug Fixes (anthropic): prompt-cache breakpoints + accounting parity for the direct-Anthropic path (66df1ae)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v9.86.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="9862-2026-07-10"><a href="https://github.com/juspay/neurolink/compare/v9.86.1...v9.86.2">9.86.2</a> (2026-07-10)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(anthropic):</strong>  prompt-cache breakpoints + accounting parity for the direct-Anthropic path (<a href="https://github.com/juspay/neurolink/commit/66df1ae537e5515434120b311c4af37d44c8b0a5">66df1ae</a>)</li>
</ul>
]]></content:encoded></item><item><title>Krystal Quorum Multi-AI Plan Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/krystal-quorum-multi-ai-plan-review/</link><pubDate>Fri, 10 Jul 2026 22:52:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/krystal-quorum-multi-ai-plan-review/</guid><description>Version updated for https://github.com/KrystalUnity/krystal-quorum to version v0.7.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Krystal Quorum v0.7.0 adds an agent-native two-gate workflow: review the implementation plan before coding, then verify the resulting diff against the approved commitments.
What’s new Automatic two-gate policy packs for Claude Code, Codex, GitHub Copilot, Hermes, OpenClaw/Claw, and OpenCode. Bound plan approvals and verified implementation-diff review. Deterministic commitment extraction, evidence reconciliation, and persisted review receipts. A standalone krystal-quorum diff gate for local workflows and CI. Expanded CI coverage across Ubuntu and Windows on Python 3.11/3.12, plus macOS on Python 3.12. Internal SDD workspace artifacts are excluded from the public package and repository. Install pip install --upgrade krystal-quorum krystal-quorum demo PyPI: https://pypi.org/project/krystal-quorum/0.7.0/</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/KrystalUnity/krystal-quorum">https://github.com/KrystalUnity/krystal-quorum</a></strong> to version <strong>v0.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/krystal-quorum-multi-ai-plan-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Krystal Quorum v0.7.0 adds an agent-native two-gate workflow: review the implementation plan before coding, then verify the resulting diff against the approved commitments.</p>
<h2 id="whats-new">What&rsquo;s new</h2>
<ul>
<li>Automatic two-gate policy packs for Claude Code, Codex, GitHub Copilot, Hermes, OpenClaw/Claw, and OpenCode.</li>
<li>Bound plan approvals and verified implementation-diff review.</li>
<li>Deterministic commitment extraction, evidence reconciliation, and persisted review receipts.</li>
<li>A standalone <code>krystal-quorum diff</code> gate for local workflows and CI.</li>
<li>Expanded CI coverage across Ubuntu and Windows on Python 3.11/3.12, plus macOS on Python 3.12.</li>
<li>Internal SDD workspace artifacts are excluded from the public package and repository.</li>
</ul>
<h2 id="install">Install</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install --upgrade krystal-quorum
</span></span><span style="display:flex;"><span>krystal-quorum demo
</span></span></code></pre></div><p>PyPI: <a href="https://pypi.org/project/krystal-quorum/0.7.0/">https://pypi.org/project/krystal-quorum/0.7.0/</a></p>
]]></content:encoded></item><item><title>Apex Backtest Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/apex-backtest-check/</link><pubDate>Fri, 10 Jul 2026 22:51:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/apex-backtest-check/</guid><description>Version updated for https://github.com/mickeyappol-create/apex-backtest-check to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First report-only release. Uses GitHub Actions OIDC with audience https://api.smartapex.uk, calls bounded DATA ONLY diagnostics, and writes receipt-backed results without exposing returns in logs or summaries.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mickeyappol-create/apex-backtest-check">https://github.com/mickeyappol-create/apex-backtest-check</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/apex-backtest-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First report-only release. Uses GitHub Actions OIDC with audience <a href="https://api.smartapex.uk">https://api.smartapex.uk</a>, calls bounded DATA ONLY diagnostics, and writes receipt-backed results without exposing returns in logs or summaries.</p>
]]></content:encoded></item><item><title>helm-scribe</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/helm-scribe/</link><pubDate>Fri, 10 Jul 2026 22:51:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/helm-scribe/</guid><description>Version updated for https://github.com/Miosp/helm-scribe to version v0.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Add Kubernetes type annotations by @Miosp in https://github.com/Miosp/helm-scribe/pull/5 Add Github Action by @Miosp in https://github.com/Miosp/helm-scribe/pull/6 Add a partial and strict schema option for k8s types by @Miosp in https://github.com/Miosp/helm-scribe/pull/7 Structural refactor and bug fixes by @Miosp in https://github.com/Miosp/helm-scribe/pull/8 Full Changelog: https://github.com/Miosp/helm-scribe/compare/v0.1.0...v0.2.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Miosp/helm-scribe">https://github.com/Miosp/helm-scribe</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/helm-scribe">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add Kubernetes type annotations by @Miosp in <a href="https://github.com/Miosp/helm-scribe/pull/5">https://github.com/Miosp/helm-scribe/pull/5</a></li>
<li>Add Github Action by @Miosp in <a href="https://github.com/Miosp/helm-scribe/pull/6">https://github.com/Miosp/helm-scribe/pull/6</a></li>
<li>Add a partial and strict schema option for k8s types by @Miosp in <a href="https://github.com/Miosp/helm-scribe/pull/7">https://github.com/Miosp/helm-scribe/pull/7</a></li>
<li>Structural refactor and bug fixes by @Miosp in <a href="https://github.com/Miosp/helm-scribe/pull/8">https://github.com/Miosp/helm-scribe/pull/8</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Miosp/helm-scribe/compare/v0.1.0...v0.2.0">https://github.com/Miosp/helm-scribe/compare/v0.1.0...v0.2.0</a></p>
]]></content:encoded></item><item><title>Agent Security Harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/agent-security-harness/</link><pubDate>Fri, 10 Jul 2026 22:50:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/agent-security-harness/</guid><description>Version updated for https://github.com/msaleme/red-team-blue-team-agent-fabric to version v4.9.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Corrects a CVE misattribution. The MCP tool-poisoning suite was incorrectly anchored to CVE-2026-25253, which is an unrelated OpenClaw WebSocket vulnerability. Re-anchored to the Invariant Labs Tool Poisoning research (2025) and ClawHub RFC #99; fabricated statistics removed; module renamed cve_2026_25253_harness to mcp_tool_poisoning_harness (CLI id mcp-tool-poisoning). Test IDs CVE-001..CVE-010 unchanged; CVE-009/010 still map to the real CVE-2026-35625/35629. 540 tests.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/msaleme/red-team-blue-team-agent-fabric">https://github.com/msaleme/red-team-blue-team-agent-fabric</a></strong> to version <strong>v4.9.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-security-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Corrects a CVE misattribution. The MCP tool-poisoning suite was incorrectly anchored to CVE-2026-25253, which is an unrelated OpenClaw WebSocket vulnerability. Re-anchored to the Invariant Labs Tool Poisoning research (2025) and ClawHub RFC #99; fabricated statistics removed; module renamed cve_2026_25253_harness to mcp_tool_poisoning_harness (CLI id mcp-tool-poisoning). Test IDs CVE-001..CVE-010 unchanged; CVE-009/010 still map to the real CVE-2026-35625/35629. 540 tests.</p>
]]></content:encoded></item><item><title>AI Agent Discipline Linter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/ai-agent-discipline-linter/</link><pubDate>Fri, 10 Jul 2026 22:49:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/ai-agent-discipline-linter/</guid><description>Version updated for https://github.com/naimkatiman/continuous-improvement to version v3.21.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix(hooks): keep lifecycle hooks working without Bash by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/284 feat(simplicity-review): diff-scoped over-engineering review skill (Law 4) by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/285 feat(production-readiness-review): add simplicity dimension delegating to simplicity-review by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/286 chore(release): cut v3.21.0 by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/287 Full Changelog: https://github.com/naimkatiman/continuous-improvement/compare/v3...v3.21.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/naimkatiman/continuous-improvement">https://github.com/naimkatiman/continuous-improvement</a></strong> to version <strong>v3.21.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-agent-discipline-linter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(hooks): keep lifecycle hooks working without Bash by @naimkatiman in <a href="https://github.com/naimkatiman/continuous-improvement/pull/284">https://github.com/naimkatiman/continuous-improvement/pull/284</a></li>
<li>feat(simplicity-review): diff-scoped over-engineering review skill (Law 4) by @naimkatiman in <a href="https://github.com/naimkatiman/continuous-improvement/pull/285">https://github.com/naimkatiman/continuous-improvement/pull/285</a></li>
<li>feat(production-readiness-review): add simplicity dimension delegating to simplicity-review by @naimkatiman in <a href="https://github.com/naimkatiman/continuous-improvement/pull/286">https://github.com/naimkatiman/continuous-improvement/pull/286</a></li>
<li>chore(release): cut v3.21.0 by @naimkatiman in <a href="https://github.com/naimkatiman/continuous-improvement/pull/287">https://github.com/naimkatiman/continuous-improvement/pull/287</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/naimkatiman/continuous-improvement/compare/v3...v3.21.0">https://github.com/naimkatiman/continuous-improvement/compare/v3...v3.21.0</a></p>
]]></content:encoded></item><item><title>Firefly Numerical Parity Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/firefly-numerical-parity-check/</link><pubDate>Fri, 10 Jul 2026 22:49:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/firefly-numerical-parity-check/</guid><description>Version updated for https://github.com/neelvad/firefly to version v0.6.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/neelvad/firefly/compare/v0...v0.6.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/neelvad/firefly">https://github.com/neelvad/firefly</a></strong> to version <strong>v0.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/firefly-numerical-parity-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/neelvad/firefly/compare/v0...v0.6.0">https://github.com/neelvad/firefly/compare/v0...v0.6.0</a></p>
]]></content:encoded></item><item><title>rust-audit-check-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/rust-audit-check-action/</link><pubDate>Fri, 10 Jul 2026 22:48:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/rust-audit-check-action/</guid><description>Version updated for https://github.com/pirafrank/audit-check-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First release with stable functionality.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pirafrank/audit-check-action">https://github.com/pirafrank/audit-check-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rust-audit-check-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release with stable functionality.</p>
]]></content:encoded></item><item><title>Prowler Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/prowler-security-scan/</link><pubDate>Fri, 10 Jul 2026 22:48:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/prowler-security-scan/</guid><description>Version updated for https://github.com/prowler-cloud/prowler to version 5.33.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed UI 🔄 Changed RBAC role forms now explain Unlimited Visibility inside the Visibility section and keep the setting visible while group selection is hidden (#11890) 🐞 Fixed CIS Level 1 and Level 2 compliance filters now match profiles prefixed with a license tier (e.g. “E3 Level 1”), so M365 CIS requirements are no longer hidden (#11924) Jira dispatch polling now reports failed issue creation tasks instead of treating partial failures as successful (#11925) API 🐞 Fixed Session tokens are rejected after account password updates (#11914) Jira dispatch task results now surface user-facing Jira failure messages (#11925) AWS Attack Paths privilege escalation queries no longer fail on Neo4j with Aggregation column contains implicit grouping expressions (#11939) 🔐 Security OpenAI-compatible Lighthouse provider base URLs are restricted before connection checks (#11940) LIGHTHOUSE_AI_OPENAI_COMPATIBLE_ALLOWED_HOSTS environment variable to allow internal hosts as OpenAI-compatible Lighthouse AI base URLs (#11942) SDK 🐞 Fixed ECS task definition resource limits now select the latest task definitions by registration date instead of relying on ARN ordering (#11891) dlm_ebs_snapshot_lifecycle_policy_exists no longer initializes the full EC2 inventory just to detect EBS snapshots, avoiding slow scans when checking DLM lifecycle policies (#11900) dms_instance_no_public_access no longer initializes the full EC2 service when there are no DMS replication instances (#11902) organizations_scp_check_deny_regions no longer reports false FAIL for AWS Organizations that restrict regions with Allow-based SCPs; the Allow path now checks the statement Effect instead of an always-false comparison that made it unreachable (#11915) Jira issue creation failures now preserve safe structured response details from Jira (#11925) Azure Function App optional permission failures now log as warnings, and Function App environment variable fields use the correct spelling internally (#11926)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/prowler-cloud/prowler">https://github.com/prowler-cloud/prowler</a></strong> to version <strong>5.33.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/prowler-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="ui">UI</h2>
<h3 id="-changed">🔄 Changed</h3>
<ul>
<li>RBAC role forms now explain Unlimited Visibility inside the Visibility section and keep the setting visible while group selection is hidden <a href="https://github.com/prowler-cloud/prowler/pull/11890">(#11890)</a></li>
</ul>
<h3 id="-fixed">🐞 Fixed</h3>
<ul>
<li>CIS Level 1 and Level 2 compliance filters now match profiles prefixed with a license tier (e.g. &ldquo;E3 Level 1&rdquo;), so M365 CIS requirements are no longer hidden <a href="https://github.com/prowler-cloud/prowler/pull/11924">(#11924)</a></li>
<li>Jira dispatch polling now reports failed issue creation tasks instead of treating partial failures as successful <a href="https://github.com/prowler-cloud/prowler/pull/11925">(#11925)</a></li>
</ul>
<h2 id="api">API</h2>
<h3 id="-fixed-1">🐞 Fixed</h3>
<ul>
<li>Session tokens are rejected after account password updates <a href="https://github.com/prowler-cloud/prowler/pull/11914">(#11914)</a></li>
<li>Jira dispatch task results now surface user-facing Jira failure messages <a href="https://github.com/prowler-cloud/prowler/pull/11925">(#11925)</a></li>
<li>AWS Attack Paths privilege escalation queries no longer fail on Neo4j with <code>Aggregation column contains implicit grouping expressions</code> <a href="https://github.com/prowler-cloud/prowler/pull/11939">(#11939)</a></li>
</ul>
<h3 id="-security">🔐 Security</h3>
<ul>
<li>OpenAI-compatible Lighthouse provider base URLs are restricted before connection checks <a href="https://github.com/prowler-cloud/prowler/pull/11940">(#11940)</a></li>
<li><code>LIGHTHOUSE_AI_OPENAI_COMPATIBLE_ALLOWED_HOSTS</code> environment variable to allow internal hosts as OpenAI-compatible Lighthouse AI base URLs <a href="https://github.com/prowler-cloud/prowler/pull/11942">(#11942)</a></li>
</ul>
<h2 id="sdk">SDK</h2>
<h3 id="-fixed-2">🐞 Fixed</h3>
<ul>
<li>ECS task definition resource limits now select the latest task definitions by registration date instead of relying on ARN ordering <a href="https://github.com/prowler-cloud/prowler/pull/11891">(#11891)</a></li>
<li><code>dlm_ebs_snapshot_lifecycle_policy_exists</code> no longer initializes the full EC2 inventory just to detect EBS snapshots, avoiding slow scans when checking DLM lifecycle policies <a href="https://github.com/prowler-cloud/prowler/pull/11900">(#11900)</a></li>
<li><code>dms_instance_no_public_access</code> no longer initializes the full EC2 service when there are no DMS replication instances <a href="https://github.com/prowler-cloud/prowler/pull/11902">(#11902)</a></li>
<li><code>organizations_scp_check_deny_regions</code> no longer reports false <code>FAIL</code> for AWS Organizations that restrict regions with Allow-based SCPs; the Allow path now checks the statement <code>Effect</code> instead of an always-false comparison that made it unreachable <a href="https://github.com/prowler-cloud/prowler/pull/11915">(#11915)</a></li>
<li>Jira issue creation failures now preserve safe structured response details from Jira <a href="https://github.com/prowler-cloud/prowler/pull/11925">(#11925)</a></li>
<li>Azure Function App optional permission failures now log as warnings, and Function App environment variable fields use the correct spelling internally <a href="https://github.com/prowler-cloud/prowler/pull/11926">(#11926)</a></li>
</ul>
]]></content:encoded></item><item><title>Remyx Outrider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/remyx-outrider/</link><pubDate>Fri, 10 Jul 2026 22:47:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/remyx-outrider/</guid><description>Version updated for https://github.com/remyxai/outrider to version v1.7.15.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Closes REMYX-195 with a mode-aware pre-PR fidelity gate and lands the lead-content input for spec-driven dispatches beyond arXiv paper implementations.
Mode-aware fidelity gate The pre-PR fidelity gate now routes by the coding session’s cited implementation mode instead of applying one strict method-vs-diff comparison to every output:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remyxai/outrider">https://github.com/remyxai/outrider</a></strong> to version <strong>v1.7.15</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/remyx-outrider">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Closes REMYX-195 with a mode-aware pre-PR fidelity gate and lands the <code>lead-content</code> input for spec-driven dispatches beyond arXiv paper implementations.</p>
<h2 id="mode-aware-fidelity-gate">Mode-aware fidelity gate</h2>
<p>The pre-PR fidelity gate now routes by the coding session&rsquo;s cited implementation mode instead of applying one strict method-vs-diff comparison to every output:</p>
<ul>
<li><strong>Mode 1 (direct port)</strong> — existing strict reference-vs-diff, plus <code>self_review['scoped_out']</code> items are cross-referenced against the Coverage matrix so deliberately-cut components don&rsquo;t fabrication-flag.</li>
<li><strong>Mode 2 (adapted port)</strong> — audit prompt is augmented with <code>self_review['substitutions']</code> so Claude treats named auxiliary swaps as defensible deviations, not needs-judgment. Core-mechanism deltas still strict.</li>
<li><strong>Mode 3 (inspired experiment)</strong> — method-vs-diff comparison replaced with an insight-preservation check that validates the paper&rsquo;s <code>reframed_insight</code> is embodied in the diff, the module docstring cites the paper honestly as inspired-not-ported, and the code path actually implements the insight.</li>
</ul>
<p>New self-review schema fields:</p>
<ul>
<li><code>mode_cited</code> — free-text; classified to mode-1/2/3</li>
<li><code>substitutions</code> — Mode 2 only; auxiliary swaps</li>
<li><code>reframed_insight</code> — Mode 3 only; the paper&rsquo;s insight being drawn on</li>
</ul>
<p>Pre-v1.7.14 self-reviews without <code>mode_cited</code> default to Mode 1 semantics — backward-compatible.</p>
<h2 id="lead-content-input">lead-content input</h2>
<p>New optional workflow input <code>lead-content</code> that replaces the paper&rsquo;s <code>suggested_experiment</code> slot in SPEC.md with caller-provided verbatim content. Both preflight and the coding session reason against the lead&rsquo;s scoped framing instead of the paper&rsquo;s full contribution — which is what the caller wants when converting a prior Outrider Issue (or an internal design doc, RFC, engineering brief) to a Draft PR.</p>
<p>Turns Outrider from arXiv-paper-implementation into any-spec-to-PR — and the mode-aware fidelity gate now handles the Mode-3 outputs that spec-driven dispatches naturally produce.</p>
<h2 id="readme">README</h2>
<ul>
<li>Opening rewritten around the 10× validation pain-point + a concrete deployment claim (schedule or dispatch as GitHub Action)</li>
<li>Cost section folded into a new &ldquo;Model backends&rdquo; table with Opus-vs-GLM comparison and a routing heuristic</li>
<li>Manual install workflow YAML fixed: obsolete <code>pin-method</code> input → correct <code>pin-arxiv</code> + <code>search-method</code> + <code>publish</code> inputs</li>
<li>Examples rewritten with explicit Match: / Shape: labels; ~40% shorter each</li>
</ul>
<h2 id="tests">Tests</h2>
<p>871 passing (11 new fidelity mode-routing tests).</p>
]]></content:encoded></item><item><title>Hey Sysmon</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/hey-sysmon/</link><pubDate>Fri, 10 Jul 2026 22:47:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/hey-sysmon/</guid><description>Version updated for https://github.com/rezen/action-hey-sysmon to version v0.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Edit action description (42e29a5) Fix ci job for blocked 1.1.1.1 (5c4734d) Update CI job for generating test telemetry (a8b71f0) Add windows firewall options (801ed7c) Add IP lookups when api keys are provided (fb2211c) Fix ci tests (c8e538f) Add parsing of sysmon logs (91b4673) Bump nodejs version (1e0c563) Work on error GITHUB_ACTION_PATH is not set (17e6609) Fix CI: add lockfile, commit dist bundle, move to Node 24 (5eb8ada)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rezen/action-hey-sysmon">https://github.com/rezen/action-hey-sysmon</a></strong> to version <strong>v0.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hey-sysmon">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Edit action description (42e29a5)</li>
<li>Fix ci job for blocked 1.1.1.1 (5c4734d)</li>
<li>Update CI job for generating test telemetry (a8b71f0)</li>
<li>Add windows firewall options (801ed7c)</li>
<li>Add IP lookups when api keys are provided (fb2211c)</li>
<li>Fix ci tests (c8e538f)</li>
<li>Add parsing of sysmon logs (91b4673)</li>
<li>Bump nodejs version (1e0c563)</li>
<li>Work on error GITHUB_ACTION_PATH is not set (17e6609)</li>
<li>Fix CI: add lockfile, commit dist bundle, move to Node 24 (5eb8ada)</li>
</ul>
]]></content:encoded></item><item><title>codemetrics complexity gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/codemetrics-complexity-gate/</link><pubDate>Fri, 10 Jul 2026 22:46:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/codemetrics-complexity-gate/</guid><description>Version updated for https://github.com/richardwooding/codemetrics to version v0.12.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog Features c64006d90f94e7b0fbc6f2141e236249f7fa1d5a: feat: add OpenGraph/Twitter preview image and meta tags (@richardwooding) 3218fa7d1ee90ebd0eefa0e9957b04b6a2aa4b8a: feat: install Google Tag Manager (@richardwooding) Others 313ec8bf15620f34e7b22aad4928ea8d48141fdc: chore(site): sync gloam assets to c2daafe2a5a046e61f2cce23a514fb9114b20e0e (#23) (@github-actions[bot]) a5b6a6302e89eaa3a61b543bae40cf8275eda960: docs(readme): use labeled Markdown link for website (#21) (@richardwooding) b9743bec9e6c7c739608dfba53955d00666a6e30: refactor(site): adopt the gloam design system (#19) (@richardwooding)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/richardwooding/codemetrics">https://github.com/richardwooding/codemetrics</a></strong> to version <strong>v0.12.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/codemetrics-complexity-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<h3 id="features">Features</h3>
<ul>
<li>c64006d90f94e7b0fbc6f2141e236249f7fa1d5a: feat: add OpenGraph/Twitter preview image and meta tags (@richardwooding)</li>
<li>3218fa7d1ee90ebd0eefa0e9957b04b6a2aa4b8a: feat: install Google Tag Manager (@richardwooding)</li>
</ul>
<h3 id="others">Others</h3>
<ul>
<li>313ec8bf15620f34e7b22aad4928ea8d48141fdc: chore(site): sync gloam assets to c2daafe2a5a046e61f2cce23a514fb9114b20e0e (#23) (@github-actions[bot])</li>
<li>a5b6a6302e89eaa3a61b543bae40cf8275eda960: docs(readme): use labeled Markdown link for website (#21) (@richardwooding)</li>
<li>b9743bec9e6c7c739608dfba53955d00666a6e30: refactor(site): adopt the gloam design system (#19) (@richardwooding)</li>
</ul>
]]></content:encoded></item><item><title>file-search-on review gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/file-search-on-review-gate/</link><pubDate>Fri, 10 Jul 2026 22:45:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/file-search-on-review-gate/</guid><description>Version updated for https://github.com/richardwooding/file-search-on to version v0.119.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog Others f163b11e6aa561a3e52c1c48151098ca17c50358 chore(deps): Bump the minor-and-patch group across 1 directory with 6 updates (#559)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/richardwooding/file-search-on">https://github.com/richardwooding/file-search-on</a></strong> to version <strong>v0.119.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/file-search-on-review-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<h3 id="others">Others</h3>
<ul>
<li>f163b11e6aa561a3e52c1c48151098ca17c50358 chore(deps): Bump the minor-and-patch group across 1 directory with 6 updates (#559)</li>
</ul>
]]></content:encoded></item><item><title>MCPShield MCP Config Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/mcpshield-mcp-config-scan/</link><pubDate>Fri, 10 Jul 2026 22:45:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/mcpshield-mcp-config-scan/</guid><description>Version updated for https://github.com/RunTimeAdmin/mcpshield-action to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s new Hardcoded-secret detection: flags embedded credentials in MCP config commands (AWS / GitHub / Slack / OpenAI / Anthropic / Google keys, private-key blocks, inline DB connection-string passwords), scored +30 as a typed finding. Only the credential type is surfaced, never the value. Parity with the MCPShield 0.4 engine. - uses: RunTimeAdmin/mcpshield-action@v1 with: fail-on: high</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RunTimeAdmin/mcpshield-action">https://github.com/RunTimeAdmin/mcpshield-action</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcpshield-mcp-config-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new">What&rsquo;s new</h2>
<ul>
<li><strong>Hardcoded-secret detection</strong>: flags embedded credentials in MCP config commands (AWS / GitHub / Slack / OpenAI / Anthropic / Google keys, private-key blocks, inline DB connection-string passwords), scored +30 as a typed finding. Only the credential <em>type</em> is surfaced, never the value. Parity with the MCPShield 0.4 engine.</li>
</ul>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">RunTimeAdmin/mcpshield-action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>SCP File or Directory Transfer to Remote</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/scp-file-or-directory-transfer-to-remote/</link><pubDate>Fri, 10 Jul 2026 22:44:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/scp-file-or-directory-transfer-to-remote/</guid><description>Version updated for https://github.com/shoops/scp-action to version v-1.0.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Merged action version updates from upstream</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/shoops/scp-action">https://github.com/shoops/scp-action</a></strong> to version <strong>v-1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/scp-file-or-directory-transfer-to-remote">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Merged action version updates from upstream</p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/bernstein-multi-agent-orchestration/</link><pubDate>Fri, 10 Jul 2026 22:44:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.2.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v3.2.0 Released 2026-07-10.
A resumability and availability release. Interrupted runs continue from a verified ledger instead of starting over, provider outages reroute along declared fallback chains with a receipt for every decision, and certified local endpoints join the worker pool behind a certification gate.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v320">v3.2.0</h1>
<p>Released 2026-07-10.</p>
<p>A resumability and availability release. Interrupted runs continue from a
verified ledger instead of starting over, provider outages reroute along
declared fallback chains with a receipt for every decision, and certified
local endpoints join the worker pool behind a certification gate.</p>
<h2 id="durable-work-ledger-2358">Durable work ledger (#2358)</h2>
<p>An interrupted orchestration run no longer discards finished work. The
scheduler records every task transition in a Merkle-chained work ledger:</p>
<ul>
<li>Every state transition of the task graph appends a redacted,
content-addressed ledger entry whose hash links its predecessor, using the
same canonical-JSON contract as the per-step replay journal.</li>
<li><code>bernstein ledger resume</code> rebuilds scheduler state purely by replaying the
chain and re-dispatches only tasks without a completion entry. Completed
work is never re-run.</li>
<li>The ledger is machine-portable: clone the repository on another machine and
resume there with zero lost completed work. Tampering or divergence
surfaces as a hash mismatch at an exact position, never as a silent merge.</li>
<li><code>bernstein resume &lt;task-id&gt;</code> picks up a single paused, killed, or crashed
task from its last checkpoint and points at the ledger when the id matches
a portable run.</li>
</ul>
<h2 id="checkpointed-retries-2359">Checkpointed retries (#2359)</h2>
<p>A failed task retry no longer has to start cold. When the native agent
session recorded a checkpoint, the retry engine resumes it warm:</p>
<ul>
<li>Warm resume replays the recorded session checkpoint with a templated
corrective instruction, so in-context progress is preserved.</li>
<li>Fork branches a fresh session off the checkpoint and leaves the original
session intact. Cold restart stays the always-safe fallback.</li>
<li>Every decision (warm, fork, or the downgrade reason that forced cold) is
anchored in the journal and mirrored to the audit chain, so a retry replays
identically and the decision trail survives the worktree.</li>
</ul>
<h2 id="provider-availability-policy-2355">Provider availability policy (#2355)</h2>
<p>Provider outages reroute instead of failing the spawn. Roles declare a
fallback chain, and failover is a deterministic, receipted decision:</p>
<ul>
<li>Per-role fallback chains list providers in preference order; health probes
are cached with an explicit TTL so dispatch bursts do not re-probe.</li>
<li>Chain resolution is deterministic: the same policy and probe results always
produce the same decision hash, and every failover lands a journal receipt
mirrored to the audit chain.</li>
<li><code>bernstein doctor --failover-drill</code> exercises every declared chain against
simulated outages and reports the route each role would take, before a real
outage forces the question.</li>
</ul>
<h2 id="local-model-worker-tier-2356">Local-model worker tier (#2356)</h2>
<p>OpenAI-compatible local endpoints can now serve worker roles behind a
certification gate:</p>
<ul>
<li><code>bernstein doctor --endpoint</code> runs the conformance suite against an
endpoint and produces a signed certification receipt; certified endpoint
profiles are the only ones the config gate accepts for role assignments.</li>
<li>Certification receipts are anchored to the audit chain, so an assignment
can always be traced back to the exact probe run that admitted the
endpoint.</li>
<li>Three verified local configurations are documented in the local-endpoints
reference, each reproduced from its certification receipt.</li>
</ul>
<h2 id="cross-adapter-coordination-2357">Cross-adapter coordination (#2357)</h2>
<p>Workers on different adapters now coordinate through a signed task mailbox
instead of ad-hoc files:</p>
<ul>
<li>Every mailbox message is HMAC-chained and Ed25519-signed; the response to a
post is the signed journal entry itself.</li>
<li>The claim API is dependency-gated: a task cannot be claimed until the tasks
it depends on have verified completions, and every claim emits a claim
receipt into the audit chain.</li>
<li>Delivery is replay-identical: replaying the same journal reproduces the
same message order and the same claim outcomes, byte for byte.</li>
</ul>
<h2 id="housekeeping">Housekeeping</h2>
<ul>
<li>Resolved all open scanner alerts in the new feature code: applied the
suggested idiom cleanups, restricted the endpoint conformance transport to
http/https handlers only, and added containment checks for filenames
derived from session and approval ids.</li>
<li>Dependency updates, including a pip lockfile bump past CVE-2026-8643.</li>
</ul>
]]></content:encoded></item><item><title>Normalize Major Version Tag</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/normalize-major-version-tag/</link><pubDate>Fri, 10 Jul 2026 22:43:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/normalize-major-version-tag/</guid><description>Version updated for https://github.com/stairwaytowonderland/normalize-majorver to version v1.0.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed chore(release): 1.0.4
1.0.4 (2026-07-10) 📚 Documentation README: update overview (322b533)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stairwaytowonderland/normalize-majorver">https://github.com/stairwaytowonderland/normalize-majorver</a></strong> to version <strong>v1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/normalize-major-version-tag">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>chore(release): 1.0.4</p>
<h2 id="104-2026-07-10"><a href="https://github.com/stairwaytowonderland/normalize-majorver/compare/v1.0.3...v1.0.4">1.0.4</a> (2026-07-10)</h2>
<h3 id="-documentation">📚 Documentation</h3>
<ul>
<li><strong>README:</strong> update overview (<a href="https://github.com/stairwaytowonderland/normalize-majorver/commit/322b5334a2d959428979cbebe40cfcc89f72874a">322b533</a>)</li>
</ul>
]]></content:encoded></item><item><title>Azure Static Web Apps Deploy (small)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/azure-static-web-apps-deploy-small/</link><pubDate>Fri, 10 Jul 2026 22:43:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/azure-static-web-apps-deploy-small/</guid><description>Version updated for https://github.com/svrooij/azure-static-web-app-deploy-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Azure Static Web Apps Deploy (small) Features:
Deploy to Azure Static Web App 📦without a massive docker container 🐋 Support for federated credentials 🔑 and the less secure API token What’s Changed Remove extra colon by @arlobelshee in https://github.com/svrooij/azure-static-web-app-deploy-action/pull/2 Adjust README and update workflow to use azure/login@v3 by @svrooij in https://github.com/svrooij/azure-static-web-app-deploy-action/pull/3 New Contributors @arlobelshee made their first contribution in https://github.com/svrooij/azure-static-web-app-deploy-action/pull/2 Full Changelog: https://github.com/svrooij/azure-static-web-app-deploy-action/compare/v1.0.0...v1.1.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/svrooij/azure-static-web-app-deploy-action">https://github.com/svrooij/azure-static-web-app-deploy-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/azure-static-web-apps-deploy-small">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="azure-static-web-apps-deploy-small">Azure Static Web Apps Deploy (small)</h2>
<p>Features:</p>
<ul>
<li>Deploy to Azure Static Web App 📦without a massive docker container 🐋</li>
<li>Support for federated credentials 🔑 and the less secure <code>API token</code></li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Remove extra colon by @arlobelshee in <a href="https://github.com/svrooij/azure-static-web-app-deploy-action/pull/2">https://github.com/svrooij/azure-static-web-app-deploy-action/pull/2</a></li>
<li>Adjust README and update workflow to use azure/login@v3 by @svrooij in <a href="https://github.com/svrooij/azure-static-web-app-deploy-action/pull/3">https://github.com/svrooij/azure-static-web-app-deploy-action/pull/3</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@arlobelshee made their first contribution in <a href="https://github.com/svrooij/azure-static-web-app-deploy-action/pull/2">https://github.com/svrooij/azure-static-web-app-deploy-action/pull/2</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/svrooij/azure-static-web-app-deploy-action/compare/v1.0.0...v1.1.0">https://github.com/svrooij/azure-static-web-app-deploy-action/compare/v1.0.0...v1.1.0</a></p>
]]></content:encoded></item><item><title>ArchGuard - Architectural Drift Detector</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/archguard-architectural-drift-detector/</link><pubDate>Fri, 10 Jul 2026 22:42:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/archguard-architectural-drift-detector/</guid><description>Version updated for https://github.com/Tgenz1213/ArchGuard to version v1.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog 80cfe34913c47307c4b563275df0d306edf7e74b perf: optimize vector indexing and provider concurrency (#23)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tgenz1213/ArchGuard">https://github.com/Tgenz1213/ArchGuard</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/archguard-architectural-drift-detector">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>80cfe34913c47307c4b563275df0d306edf7e74b perf: optimize vector indexing and provider concurrency (#23)</li>
</ul>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/vibgrate-scan/</link><pubDate>Fri, 10 Jul 2026 22:41:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.710.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Vibgrate CLI 2026.710.1 Released 2026-07-10
Routine maintenance update for the CLI.
What changed Changed Maintenance release with internal improvements and dependency updates. Benchmarks Two-arm benchmark of this release against 2026.709.2, interleaved on one runner against the pinned corpus (157 metrics compared).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.710.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20267101">Vibgrate CLI 2026.710.1</h1>
<p><em>Released 2026-07-10</em></p>
<p>Routine maintenance update for the CLI.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>Maintenance release with internal improvements and dependency updates.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.709.2, interleaved on one runner against the pinned corpus (157 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>18816 count</td>
          <td>18816 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>7480 count</td>
          <td>7480 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.97 ratio</td>
          <td>0.97 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>611.90 ms</td>
          <td>619.90 ms</td>
      </tr>
  </tbody>
</table>
<p>No regressions against the previous release.</p>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.710.1">https://vibgrate.com/changelog/cli/2026.710.1</a></p>
]]></content:encoded></item><item><title>SignalBrain receipt gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/signalbrain-receipt-gate/</link><pubDate>Fri, 10 Jul 2026 22:41:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/signalbrain-receipt-gate/</guid><description>Version updated for https://github.com/whitestone1121-web/signalbrain to version v0.1.5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ﻿## SignalBrain 0.1.5
Patch release aligning the public package with the current public repo and outreach story.
Highlights Adds the public field audit: 560 agent PRs, 8 agents, reproducible harness, and ledger. Generalizes sb report so calibration curves can be generated from any ledger. Fixes measure parsing around shell command substitutions/env-prefix detection. Improves Windows test portability and public package CI coverage. Adds the free compute harness and autonomous agent review beacon. Validation Public CI passed on Linux, macOS, Windows, Python 3.11-3.14. PyPI trusted publishing completed successfully. Fresh install smoke passed for signalbrain==0.1.5.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/whitestone1121-web/signalbrain">https://github.com/whitestone1121-web/signalbrain</a></strong> to version <strong>v0.1.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/signalbrain-receipt-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>﻿## SignalBrain 0.1.5</p>
<p>Patch release aligning the public package with the current public repo and outreach story.</p>
<h3 id="highlights">Highlights</h3>
<ul>
<li>Adds the public field audit: 560 agent PRs, 8 agents, reproducible harness, and ledger.</li>
<li>Generalizes <code>sb report</code> so calibration curves can be generated from any ledger.</li>
<li>Fixes measure parsing around shell command substitutions/env-prefix detection.</li>
<li>Improves Windows test portability and public package CI coverage.</li>
<li>Adds the free compute harness and autonomous agent review beacon.</li>
</ul>
<h3 id="validation">Validation</h3>
<ul>
<li>Public CI passed on Linux, macOS, Windows, Python 3.11-3.14.</li>
<li>PyPI trusted publishing completed successfully.</li>
<li>Fresh install smoke passed for <code>signalbrain==0.1.5</code>.</li>
</ul>
]]></content:encoded></item><item><title>Move Closed Issue to Top of Project Column</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/move-closed-issue-to-top-of-project-column/</link><pubDate>Fri, 10 Jul 2026 22:40:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/move-closed-issue-to-top-of-project-column/</guid><description>Version updated for https://github.com/wozaki/project-closed-issue-move-to-top-action to version v1.20.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed uses: wozaki/project-closed-issue-move-to-top-action@38201418e7fb26572a663b92b727c7467690fb8a # v1.20.0 What’s Changed chore(deps): update int128/wait-for-workflows-action action to v1.84.0 by @renovate[bot] in https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/149 chore(deps): lock file maintenance by @renovate[bot] in https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/150 chore(deps): update dependency @vercel/ncc to v0.44.1 by @renovate[bot] in https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/151 Full Changelog: https://github.com/wozaki/project-closed-issue-move-to-top-action/compare/v1.19.0...v1.20.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wozaki/project-closed-issue-move-to-top-action">https://github.com/wozaki/project-closed-issue-move-to-top-action</a></strong> to version <strong>v1.20.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/move-closed-issue-to-top-of-project-column">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">uses</span>: <span style="color:#ae81ff">wozaki/project-closed-issue-move-to-top-action@38201418e7fb26572a663b92b727c7467690fb8a</span> <span style="color:#75715e"># v1.20.0</span>
</span></span></code></pre></div><h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): update int128/wait-for-workflows-action action to v1.84.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/149">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/149</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/150">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/150</a></li>
<li>chore(deps): update dependency @vercel/ncc to v0.44.1 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/151">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/151</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/compare/v1.19.0...v1.20.0">https://github.com/wozaki/project-closed-issue-move-to-top-action/compare/v1.19.0...v1.20.0</a></p>
]]></content:encoded></item><item><title>Setup Backlog CLI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/setup-backlog-cli/</link><pubDate>Fri, 10 Jul 2026 22:40:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/setup-backlog-cli/</guid><description>Version updated for https://github.com/yacchi/backlog-cli to version v0.30.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog e7435b677ee9c2feb440dcbcfeeb048901250309 docs(mcp): SERVER_INSTRUCTIONS にパッチ編集の使い方を追加 45715d0887ba1e06b1e035b5cbe950431dd92ba3 fix(cache): mutation後のキャッシュ無効化とMCPサーバーでのキャッシュ無効化</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yacchi/backlog-cli">https://github.com/yacchi/backlog-cli</a></strong> to version <strong>v0.30.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-backlog-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>e7435b677ee9c2feb440dcbcfeeb048901250309 docs(mcp): SERVER_INSTRUCTIONS にパッチ編集の使い方を追加</li>
<li>45715d0887ba1e06b1e035b5cbe950431dd92ba3 fix(cache): mutation後のキャッシュ無効化とMCPサーバーでのキャッシュ無効化</li>
</ul>
]]></content:encoded></item><item><title>vibecheck-ai-slop</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/vibecheck-ai-slop/</link><pubDate>Fri, 10 Jul 2026 22:39:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/vibecheck-ai-slop/</guid><description>Version updated for https://github.com/yuvrajangadsingh/vibecheck to version v1.12.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed CI ergonomics and CLI polish. Everything here makes vibecheck easier to wire into pipelines that are not GitHub Actions, and nicer to read when they are.
New flags
--fail-on &amp;lt;error|warn|info|never&amp;gt;: pick the severity that fails the run (default error, same as before) --max-warnings &amp;lt;n&amp;gt;: fail when warnings exceed a budget --format &amp;lt;pretty|compact|json|quiet|gh&amp;gt;: compact prints one clickable path:line:col line per finding; gh emits GitHub Actions annotations so you get PR annotations from a plain run: step, no marketplace action needed --diff-stdin: scan any piped unified diff, e.g. gh pr diff 42 | vibecheck --diff-stdin . --statistics: per-rule finding counts (ruff-style), also in JSON output vibecheck rules: list all 39 rules with severity, category, languages, and fixability (--json for machines) Output</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yuvrajangadsingh/vibecheck">https://github.com/yuvrajangadsingh/vibecheck</a></strong> to version <strong>v1.12.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibecheck-ai-slop">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>CI ergonomics and CLI polish. Everything here makes vibecheck easier to wire into pipelines that are not GitHub Actions, and nicer to read when they are.</p>
<p><strong>New flags</strong></p>
<ul>
<li><code>--fail-on &lt;error|warn|info|never&gt;</code>: pick the severity that fails the run (default error, same as before)</li>
<li><code>--max-warnings &lt;n&gt;</code>: fail when warnings exceed a budget</li>
<li><code>--format &lt;pretty|compact|json|quiet|gh&gt;</code>: <code>compact</code> prints one clickable <code>path:line:col</code> line per finding; <code>gh</code> emits GitHub Actions annotations so you get PR annotations from a plain <code>run:</code> step, no marketplace action needed</li>
<li><code>--diff-stdin</code>: scan any piped unified diff, e.g. <code>gh pr diff 42 | vibecheck --diff-stdin .</code></li>
<li><code>--statistics</code>: per-rule finding counts (ruff-style), also in JSON output</li>
<li><code>vibecheck rules</code>: list all 39 rules with severity, category, languages, and fixability (<code>--json</code> for machines)</li>
</ul>
<p><strong>Output</strong></p>
<ul>
<li>the offending line now shows under each finding</li>
<li><code>N info findings hidden (run with --severity info)</code> note so the AI-tell tier is discoverable</li>
<li><code>N findings fixable with --fix</code> hint</li>
<li>exit codes are now disciplined: 0 clean, 1 findings, 2 usage or runtime error (usage errors no longer collide with findings)</li>
<li><code>-v</code> works as a version alias; invalid <code>--severity</code> values are rejected instead of silently coerced</li>
</ul>
<p><strong>Diff parser hardening</strong> (found in an adversarial review of this release)</p>
<ul>
<li>CRLF diffs, git-quoted filenames (<code>\&quot;</code>), and octal-escaped non-ASCII filenames now parse correctly; all three previously made <code>--diff</code>/<code>--diff-stdin</code> silently scan nothing</li>
<li><code>--diff-stdin</code> resolves repo-root-relative diff paths against the scan root, so scanning a subdirectory of a monorepo works</li>
</ul>
<p>213 tests. Exit-code matrix, gh escaping, and the diff-parser fixes were all verified end to end on the built CLI before release.</p>
]]></content:encoded></item><item><title>MUADDIB Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/muaddib-scanner/</link><pubDate>Fri, 10 Jul 2026 15:18:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/muaddib-scanner/</guid><description>Version updated for https://github.com/DNSZLSK/muad-dib to version v2.11.164.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Scan-ledger compaction (500K entries, 127MB) converted from synchronous to async streaming. Main-thread lag drops from minutes to &amp;lt;30ms. Sync finalization prevents append loss. Breaker stays reactive during compaction.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/DNSZLSK/muad-dib">https://github.com/DNSZLSK/muad-dib</a></strong> to version <strong>v2.11.164</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/muad-dib-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Scan-ledger compaction (500K entries, 127MB) converted from synchronous to async streaming. Main-thread lag drops from minutes to &lt;30ms. Sync finalization prevents append loss. Breaker stays reactive during compaction.</p>
]]></content:encoded></item><item><title>GitHub Metadata action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/github-metadata-action/</link><pubDate>Fri, 10 Jul 2026 15:17:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/github-metadata-action/</guid><description>Version updated for https://github.com/dockerbakery/github-metadata-action to version v5.2.
This action is used across all versions by 45 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/dockerbakery/github-metadata-action/compare/v5.1...v5.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/dockerbakery/github-metadata-action">https://github.com/dockerbakery/github-metadata-action</a></strong> to version <strong>v5.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>45</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-metadata-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/dockerbakery/github-metadata-action/compare/v5.1...v5.2">https://github.com/dockerbakery/github-metadata-action/compare/v5.1...v5.2</a></p>
]]></content:encoded></item><item><title>DoesQA Trigger</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/doesqa-trigger/</link><pubDate>Fri, 10 Jul 2026 15:17:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/doesqa-trigger/</guid><description>Version updated for https://github.com/Does-QA/action to version v1.1.34.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Security patch: fixed 1 → 1 vulnerabilities via npm audit fix.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Does-QA/action">https://github.com/Does-QA/action</a></strong> to version <strong>v1.1.34</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/doesqa-trigger">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Security patch: fixed 1 → 1 vulnerabilities via <code>npm audit fix</code>.</p>
]]></content:encoded></item><item><title>RunRight CI Resource Monitor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/runright-ci-resource-monitor/</link><pubDate>Fri, 10 Jul 2026 15:16:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/runright-ci-resource-monitor/</guid><description>Version updated for https://github.com/gbudjeakp/run-right to version v1.6.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed runright v1.6.1 Download the binary for your platform below, or use the GitHub Action:
- uses: gbudjeakp/run-right@v1.6.1 with: step: start Changelog</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/gbudjeakp/run-right">https://github.com/gbudjeakp/run-right</a></strong> to version <strong>v1.6.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/runright-ci-resource-monitor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="runright-v161">runright v1.6.1</h2>
<p>Download the binary for your platform below, or use the GitHub Action:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">gbudjeakp/run-right@v1.6.1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">step</span>: <span style="color:#ae81ff">start</span>
</span></span></code></pre></div><h2 id="changelog">Changelog</h2>
]]></content:encoded></item><item><title>Plumber Score</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/plumber-score/</link><pubDate>Fri, 10 Jul 2026 15:16:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/plumber-score/</guid><description>Version updated for https://github.com/getplumber/plumber to version v0.4.0.
This action is used across all versions by 22 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.4.0 (2026-07-10) One grade, one gate: the Plumber Score Until now, Plumber gave you two competing verdicts: 1. The Plumber Score (A–E, severity-weighted) 2. A compliance percentage (share of passing controls, severity-blind)
They could disagree: one Critical finding in a single control read as “95% compliant” while scoring an E. And only the percentage gated your CI.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/getplumber/plumber">https://github.com/getplumber/plumber</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>22</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/plumber-score">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="040-2026-07-10"><a href="https://github.com/getplumber/plumber/compare/v0.3.101...v0.4.0">0.4.0</a> (2026-07-10)</h1>
<h2 id="one-grade-one-gate-the-plumber-score">One grade, one gate: the Plumber Score</h2>
<p>Until now, Plumber gave you two competing verdicts:
1. The <strong>Plumber Score</strong> (A–E, severity-weighted)
2. A <strong>compliance percentage</strong> (share of passing controls, severity-blind)</p>
<p>They could disagree: one Critical finding in a single control read as &ldquo;95% compliant&rdquo; while scoring an E. And only the percentage gated your CI.</p>
<p><strong>As of 0.4.0 the score is the single source of truth</strong></p>
<p><strong>What you get:</strong></p>
<ul>
<li><strong>Severity-aware CI gating.</strong> A Critical finding can now fail your pipeline on its own; a handful of Lows won&rsquo;t drag you below the bar the way they skewed the old percentage.</li>
<li><strong>Two simple knobs instead of an opaque threshold:</strong>
<ul>
<li><code>--min-score &lt;A-E&gt;</code>: fail below a score floor. Ex: &ldquo;require at least a B&rdquo;
<ul>
<li>Combined with <code>--min-point</code> below: both must pass</li>
</ul>
</li>
<li><code>--min-points &lt;0-100&gt;</code>: fail below a points floor
<ul>
<li>GitHub Action input: <code>min-points</code></li>
<li>GitLab component input: <code>min_points</code></li>
<li>Default: 100 (any finding fails, same strictness as before)</li>
<li>Combined with <code>--min-score</code>: both must pass</li>
</ul>
</li>
</ul>
</li>
<li><strong>No more false greens.</strong> A run where nothing was actually checked  (like a a config that enables zero controls) now fails (exit 1) instead of passing with a perfect-looking result</li>
<li><strong>Clearer verdicts everywhere.</strong> The status line, MR comment, and job summary spell out the gate: <code>PASSED ✓ (score A - 100.0/100 pts, required ≥ 100 pts)</code>.</li>
</ul>
<h2 id="-breaking-changes--how-to-migrate">⚠️ Breaking changes &amp; how to migrate</h2>
<ul>
<li><strong><code>compliance</code> fields are gone</strong> from the JSON report (top-level and per-control) and from the GitHub Action&rsquo;s outputs.
<ul>
<li>Read <code>plumberScore.finalPoints</code> (0–100) and <code>plumberScore.score</code> (A–E) instead.</li>
</ul>
</li>
<li><strong><code>passed</code> has new semantics</strong> in the JSON report: it used to mean &ldquo;compliance % ≥ threshold&rdquo;; it now means &ldquo;the active score gate was met&rdquo;. The report states the gate next to it (<code>minPoints</code>, <code>minScore</code>, or <code>threshold</code>), so the verdict is self-describing.</li>
<li><strong>GitHub Action only: the default artifact name changed</strong> from <code>plumber-compliance</code> to <code>plumber-report</code>.
<ul>
<li>If a downstream job downloads the artifact by name, update it or pin <code>artifact-name: plumber-compliance</code>.</li>
</ul>
</li>
<li><strong>Repos with nothing scoreable now fail instead of passing</strong> (exit 1):
<ul>
<li>On GitHub, a repository with <strong>no workflow files</strong> previously passed (the old percentage ignored missing CI there); it now fails. GitLab behavior is unchanged — it already failed this case.</li>
<li>A <code>.plumber.yaml</code> that enables <strong>zero controls</strong> for the scanned provider (e.g. a <code>github:</code>-only config on a GitLab project), or a filter that skips them all, also fails now.</li>
</ul>
</li>
<li><strong><code>--threshold</code> is deprecated, not removed.</strong> Existing pipelines keep working: it still gates on the old percentage and prints a migration warning. It cannot be combined with the new flags, and it will be removed in a future release — move to <code>--min-points</code> / <code>--min-score</code> when convenient. An explicit <code>threshold: 100</code> is treated as unset (it&rsquo;s the same strictness as the new default).</li>
</ul>
<p>Exit codes are unchanged: <code>0</code> pass, <code>1</code> gate failed, <code>2</code> usage/config error, <code>3</code> could not fully verify.</p>
<h2 id="-features">✨ Features</h2>
<ul>
<li><strong>gate:</strong> gate runs on the Plumber Score, drop the compliance percentage (<a href="https://github.com/getplumber/plumber/commit/2bd26393123ebe29f2d6c04c4acbc5f54c055413">2bd2639</a>), closes <a href="https://github.com/getplumber/plumber/issues/320">#320</a></li>
</ul>
<h2 id="-cicd">👷 CI/CD</h2>
<ul>
<li><strong>claude:</strong> use claude-opus-4-8 for PR review checks (<a href="https://github.com/getplumber/plumber/commit/0c65684441d67fcc9fe10ba07b4f4a25c73e9f48">0c65684</a>)</li>
<li><strong>release:</strong> pin v0.3.101 refs [skip ci] (<a href="https://github.com/getplumber/plumber/commit/e209f31449268f99df14022cc39a0e20b5768d6c">e209f31</a>)</li>
</ul>
]]></content:encoded></item><item><title>Validate ProductSpec files</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/validate-productspec-files/</link><pubDate>Fri, 10 Jul 2026 15:15:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/validate-productspec-files/</guid><description>Version updated for https://github.com/gokulrajaram/ProductSpec to version v0.10.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ProductSpec v0.10.0 This release keeps the Product Spec document shape at spec_format_version: &amp;#34;0.1&amp;#34; and updates the reference parser, schema, docs, and conformance suite.
Added Fenced-code-aware section parsing. ## headings inside Markdown code samples no longer create duplicate or out-of-order ProductSpec sections. target_status: committed | provisional for structured Success Metrics. target_owner for provisional Success Metric targets, so teams can record honest post-launch target calibration without turning guesses into committed intent. Published package @productspec/parser@0.10.0 Validation Parser test suite passes. ProductSpec and Decision Trace conformance fixtures pass. npm publish dry-run passed before publishing the parser package.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/gokulrajaram/ProductSpec">https://github.com/gokulrajaram/ProductSpec</a></strong> to version <strong>v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/validate-productspec-files">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="productspec-v0100">ProductSpec v0.10.0</h2>
<p>This release keeps the Product Spec document shape at <code>spec_format_version: &quot;0.1&quot;</code> and updates the reference parser, schema, docs, and conformance suite.</p>
<h3 id="added">Added</h3>
<ul>
<li>Fenced-code-aware section parsing. <code>##</code> headings inside Markdown code samples no longer create duplicate or out-of-order ProductSpec sections.</li>
<li><code>target_status: committed | provisional</code> for structured Success Metrics.</li>
<li><code>target_owner</code> for provisional Success Metric targets, so teams can record honest post-launch target calibration without turning guesses into committed intent.</li>
</ul>
<h3 id="published-package">Published package</h3>
<ul>
<li><code>@productspec/parser@0.10.0</code></li>
</ul>
<h3 id="validation">Validation</h3>
<ul>
<li>Parser test suite passes.</li>
<li>ProductSpec and Decision Trace conformance fixtures pass.</li>
<li>npm publish dry-run passed before publishing the parser package.</li>
</ul>
]]></content:encoded></item><item><title>proof-gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/proof-gate/</link><pubDate>Fri, 10 Jul 2026 15:14:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/proof-gate/</guid><description>Version updated for https://github.com/gregbond/proof-gate to version v0.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First public release of proof-gate.
proof-gate makes done require a proof class and inspectable evidence. It distinguishes local, CI, deploy, runtime, DB, visual, and no-go claims, then reports the honesty depth of each verifier.
Install:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/gregbond/proof-gate">https://github.com/gregbond/proof-gate</a></strong> to version <strong>v0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/proof-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release of proof-gate.</p>
<p>proof-gate makes <code>done</code> require a proof class and inspectable evidence. It distinguishes local, CI, deploy, runtime, DB, visual, and no-go claims, then reports the honesty depth of each verifier.</p>
<p>Install:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx @relaxedg/proof-gate@latest --help
</span></span></code></pre></div><p>GitHub Action:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">gregbond/proof-gate@v0.1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">mode</span>: <span style="color:#ae81ff">pr</span>
</span></span></code></pre></div><p>v0.1 is intentionally small. Some verifier classes check shape or existence, while deploy, runtime receipts, DB receipts, visual evidence, and no-go files can be inspected. Richer adapters should raise claims toward <code>inspected</code> or <code>reran</code>.</p>
]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/ai-plugin-scanner/</link><pubDate>Fri, 10 Jul 2026 15:14:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.417.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/c5888f576d976f2cc27b8133cbdbe6ae3debb271 with plugin-scanner 2.0.1017.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.416...v1.2.417</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.417</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>18</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/c5888f576d976f2cc27b8133cbdbe6ae3debb271">https://github.com/hashgraph-online/hol-guard/tree/c5888f576d976f2cc27b8133cbdbe6ae3debb271</a> with plugin-scanner 2.0.1017.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.416...v1.2.417">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.416...v1.2.417</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/hol-codex-plugin-scanner/</link><pubDate>Fri, 10 Jul 2026 15:13:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.417.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.417</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.417</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.417">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.417</a></p>
]]></content:encoded></item><item><title>Hyperlocalise CI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/hyperlocalise-ci/</link><pubDate>Fri, 10 Jul 2026 15:13:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/hyperlocalise-ci/</guid><description>Version updated for https://github.com/hyperlocalise/hyperlocalise to version v1.8.23.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat(web): add file tree search and context menu actions by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1343 test(web): cover project file action gating by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1344 fix(crowdin): optimize JoinSlice for task-related enums by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1347 fix(web): prevent file action and sandbox translation regressions by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1346 fix(web): show TMS project name in glossary and TM pickers by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1348 fix(dashboard): remove nested cards from overview panels by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1349 fix(web): theme tree search and portal row file actions by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1350 fix(agent): route recent translations to repo git history by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1351 refactor(ci): simplify web localization sync to direct hl commands by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1352 chore(web): sync Hyperlocalise translations by @hyperlocalise[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1354 feat(web): wire content locales ahead of routing support by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1355 feat(web): enable app locales and add language toggle by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1356 fix(web): polish locale toggle labels and reload on change by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1357 feat(web): localize dashboard overview with react-intl by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1358 feat(cli): add –max-translations session limit for paginated runs by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1359 Full Changelog: https://github.com/hyperlocalise/hyperlocalise/compare/v1...v1.8.23</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hyperlocalise/hyperlocalise">https://github.com/hyperlocalise/hyperlocalise</a></strong> to version <strong>v1.8.23</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hyperlocalise-ci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(web): add file tree search and context menu actions by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1343">https://github.com/hyperlocalise/hyperlocalise/pull/1343</a></li>
<li>test(web): cover project file action gating by @cursor[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1344">https://github.com/hyperlocalise/hyperlocalise/pull/1344</a></li>
<li>fix(crowdin): optimize JoinSlice for task-related enums by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1347">https://github.com/hyperlocalise/hyperlocalise/pull/1347</a></li>
<li>fix(web): prevent file action and sandbox translation regressions by @cursor[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1346">https://github.com/hyperlocalise/hyperlocalise/pull/1346</a></li>
<li>fix(web): show TMS project name in glossary and TM pickers by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1348">https://github.com/hyperlocalise/hyperlocalise/pull/1348</a></li>
<li>fix(dashboard): remove nested cards from overview panels by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1349">https://github.com/hyperlocalise/hyperlocalise/pull/1349</a></li>
<li>fix(web): theme tree search and portal row file actions by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1350">https://github.com/hyperlocalise/hyperlocalise/pull/1350</a></li>
<li>fix(agent): route recent translations to repo git history by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1351">https://github.com/hyperlocalise/hyperlocalise/pull/1351</a></li>
<li>refactor(ci): simplify web localization sync to direct hl commands by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1352">https://github.com/hyperlocalise/hyperlocalise/pull/1352</a></li>
<li>chore(web): sync Hyperlocalise translations by @hyperlocalise[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1354">https://github.com/hyperlocalise/hyperlocalise/pull/1354</a></li>
<li>feat(web): wire content locales ahead of routing support by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1355">https://github.com/hyperlocalise/hyperlocalise/pull/1355</a></li>
<li>feat(web): enable app locales and add language toggle by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1356">https://github.com/hyperlocalise/hyperlocalise/pull/1356</a></li>
<li>fix(web): polish locale toggle labels and reload on change by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1357">https://github.com/hyperlocalise/hyperlocalise/pull/1357</a></li>
<li>feat(web): localize dashboard overview with react-intl by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1358">https://github.com/hyperlocalise/hyperlocalise/pull/1358</a></li>
<li>feat(cli): add &ndash;max-translations session limit for paginated runs by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1359">https://github.com/hyperlocalise/hyperlocalise/pull/1359</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hyperlocalise/hyperlocalise/compare/v1...v1.8.23">https://github.com/hyperlocalise/hyperlocalise/compare/v1...v1.8.23</a></p>
]]></content:encoded></item><item><title>Codex Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/codex-action/</link><pubDate>Fri, 10 Jul 2026 15:12:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/codex-action/</guid><description>Version updated for https://github.com/icoretech/codex-action to version v0.9.18.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.9.18 (2026-07-10) Bug Fixes deps: update codex-docker image to v0.144.1 (#50) (c4dc375)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/icoretech/codex-action">https://github.com/icoretech/codex-action</a></strong> to version <strong>v0.9.18</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/codex-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="0918-2026-07-10"><a href="https://github.com/icoretech/codex-action/compare/v0.9.17...v0.9.18">0.9.18</a> (2026-07-10)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> update codex-docker image to v0.144.1 (<a href="https://github.com/icoretech/codex-action/issues/50">#50</a>) (<a href="https://github.com/icoretech/codex-action/commit/c4dc37519cf8db25edbbf50c6565588bc585f280">c4dc375</a>)</li>
</ul>
]]></content:encoded></item><item><title>aeroflare-test-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/aeroflare-test-action/</link><pubDate>Fri, 10 Jul 2026 15:12:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/aeroflare-test-action/</guid><description>Version updated for https://github.com/ItzEmoji/aeroflare-test to version v1.9.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.9.1 (2026-07-10) Bug Fixes upstream-cache filtering in github-action (330fda0)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ItzEmoji/aeroflare-test">https://github.com/ItzEmoji/aeroflare-test</a></strong> to version <strong>v1.9.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aeroflare-test-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="191-2026-07-10"><a href="https://github.com/ItzEmoji/aeroflare-test/compare/v1.9.0...v1.9.1">1.9.1</a> (2026-07-10)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>upstream-cache filtering in github-action (<a href="https://github.com/ItzEmoji/aeroflare-test/commit/330fda063204e7d60d99dc7d4c23c37dbbb643b0">330fda0</a>)</li>
</ul>
]]></content:encoded></item><item><title>stackit-cli tools installer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/stackit-cli-tools-installer/</link><pubDate>Fri, 10 Jul 2026 15:11:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/stackit-cli-tools-installer/</guid><description>Version updated for https://github.com/jkroepke/setup-stackit-cli to version v1.2.86.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed 🛠️ Dependencies chore(deps): lock file maintenance by @renovate[bot] in https://github.com/jkroepke/setup-stackit-cli/pull/283 Full Changelog: https://github.com/jkroepke/setup-stackit-cli/compare/v1.2.85...v1.2.86</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jkroepke/setup-stackit-cli">https://github.com/jkroepke/setup-stackit-cli</a></strong> to version <strong>v1.2.86</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/stackit-cli-tools-installer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at v1.2.86 -->
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="-dependencies">🛠️ Dependencies</h3>
<ul>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/jkroepke/setup-stackit-cli/pull/283">https://github.com/jkroepke/setup-stackit-cli/pull/283</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jkroepke/setup-stackit-cli/compare/v1.2.85...v1.2.86">https://github.com/jkroepke/setup-stackit-cli/compare/v1.2.85...v1.2.86</a></p>
]]></content:encoded></item><item><title>spek - OpenSpec Static Site</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/spek-openspec-static-site/</link><pubDate>Fri, 10 Jul 2026 15:11:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/spek-openspec-static-site/</guid><description>Version updated for https://github.com/kewang/spek to version v1.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Hideable tree navigator (IntelliJ) — the Specs / Changes tree in the spek tool window can now be hidden from the tool window title bar or its gear (⋮) menu, giving the viewer the full tool window. The choice is remembered per project, and the split ratio is persisted too instead of resetting every time you reopen the project. While hidden, the tree no longer rebuilds on file changes; it refreshes when you bring it back. Thanks to @deniskrizanovic for reporting.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kewang/spek">https://github.com/kewang/spek</a></strong> to version <strong>v1.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spek-openspec-static-site">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li><strong>Hideable tree navigator (IntelliJ)</strong> — the Specs / Changes tree in the spek tool window can now be hidden from the tool window title bar or its gear (⋮) menu, giving the viewer the full tool window. The choice is remembered per project, and the split ratio is persisted too instead of resetting every time you reopen the project. While hidden, the tree no longer rebuilds on file changes; it refreshes when you bring it back. Thanks to <a href="https://github.com/deniskrizanovic">@deniskrizanovic</a> for reporting.</li>
</ul>
]]></content:encoded></item><item><title>Local Mac iOS Build Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/local-mac-ios-build-action/</link><pubDate>Fri, 10 Jul 2026 15:10:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/local-mac-ios-build-action/</guid><description>Version updated for https://github.com/local-mac-ci-cluster/local-mac-runner-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Local Mac CI Cluster GitHub Marketplace 一键接入自有本地Mac CI集群工具
功能说明 本Action用于组织内部所有业务仓库快速接入自建10台Apple Silicon Mac算力池，无需修改原有 workflow 的 runs-on: macos-latest 配置，一行代码即可零成本切换本地自建Mac构建，不再消耗GitHub官方付费云Mac资源。
快速接入教程 1. workflow顶部引入本Action 无需配置任何密钥、凭证，仅增加一行uses语句即可生效。
完整业务workflow参考示例 ```yaml name: iOS项目构建测试 on: [push]
jobs: build_task: runs-on: macos-latest steps: - uses: local-mac-ci-cluster/local-mac-runner-action@v1 - uses: actions/checkout@v4 - name: 本地环境校验 run: sw_vers &amp;amp;&amp;amp; xcodebuild -version ```</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/local-mac-ci-cluster/local-mac-runner-action">https://github.com/local-mac-ci-cluster/local-mac-runner-action</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/local-mac-ios-build-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="local-mac-ci-cluster">Local Mac CI Cluster</h1>
<p>GitHub Marketplace 一键接入自有本地Mac CI集群工具</p>
<h2 id="功能说明">功能说明</h2>
<p>本Action用于组织内部所有业务仓库快速接入自建10台Apple Silicon Mac算力池，<strong>无需修改原有 workflow 的 runs-on: macos-latest 配置</strong>，一行代码即可零成本切换本地自建Mac构建，不再消耗GitHub官方付费云Mac资源。</p>
<h2 id="快速接入教程">快速接入教程</h2>
<h3 id="1-workflow顶部引入本action">1. workflow顶部引入本Action</h3>
<p>无需配置任何密钥、凭证，仅增加一行uses语句即可生效。</p>
<h3 id="完整业务workflow参考示例">完整业务workflow参考示例</h3>
<p>```yaml
name: iOS项目构建测试
on: [push]</p>
<p>jobs:
build_task:
runs-on: macos-latest
steps:
- uses: local-mac-ci-cluster/local-mac-runner-action@v1
- uses: actions/checkout@v4
- name: 本地环境校验
run: sw_vers &amp;&amp; xcodebuild -version
```</p>
<h2 id="集群硬件信息">集群硬件信息</h2>
<table>
  <thead>
      <tr>
          <th>项目</th>
          <th>规格</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>机器总量</td>
          <td>10 台 Apple Silicon Mac Mini</td>
      </tr>
      <tr>
          <td>Runner 标签</td>
          <td><code>macos-latest,self-hosted,m4</code></td>
      </tr>
      <tr>
          <td>调度策略</td>
          <td>GitHub 原生自动负载均衡</td>
      </tr>
  </tbody>
</table>
<h2 id="常见问题">常见问题</h2>
<p><strong>Q：流水线仍跑官方云 Mac？</strong><br>
A：检查本地 Mac Runner 是否处于 Idle 空闲状态。</p>
<p><strong>Q：任务无法调度至本地机器？</strong><br>
A：确认 workflow runs-on 标签为 <code>macos-latest</code>。</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/local-mac-ci-cluster/local-mac-runner-action/commits/v1.0.0">https://github.com/local-mac-ci-cluster/local-mac-runner-action/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>crabd</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/crabd/</link><pubDate>Fri, 10 Jul 2026 15:09:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/crabd/</guid><description>Version updated for https://github.com/louisescher/crabd to version v0.5.1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: compress context further by tidying up messages by @louisescher in https://github.com/louisescher/crabd/pull/25 chore: version packages by @github-actions[bot] in https://github.com/louisescher/crabd/pull/26 Full Changelog: https://github.com/louisescher/crabd/compare/v0...v0.5.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/louisescher/crabd">https://github.com/louisescher/crabd</a></strong> to version <strong>v0.5.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/crab-d">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: compress context further by tidying up messages by @louisescher in <a href="https://github.com/louisescher/crabd/pull/25">https://github.com/louisescher/crabd/pull/25</a></li>
<li>chore: version packages by @github-actions[bot] in <a href="https://github.com/louisescher/crabd/pull/26">https://github.com/louisescher/crabd/pull/26</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/louisescher/crabd/compare/v0...v0.5.1">https://github.com/louisescher/crabd/compare/v0...v0.5.1</a></p>
]]></content:encoded></item><item><title>AI Code Review by n-devs</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/ai-code-review-by-n-devs/</link><pubDate>Fri, 10 Jul 2026 15:09:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/ai-code-review-by-n-devs/</guid><description>Version updated for https://github.com/n-devs/ai-code-review to version v2.0.0.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix: update default model to openai/gpt-5-mini and correct GitHub Mod… by @n-devs in https://github.com/n-devs/ai-code-review/pull/3 Full Changelog: https://github.com/n-devs/ai-code-review/compare/v1.0.0...v2.0.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/n-devs/ai-code-review">https://github.com/n-devs/ai-code-review</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-code-review-by-n-devs">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: update default model to openai/gpt-5-mini and correct GitHub Mod… by @n-devs in <a href="https://github.com/n-devs/ai-code-review/pull/3">https://github.com/n-devs/ai-code-review/pull/3</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/n-devs/ai-code-review/compare/v1.0.0...v2.0.0">https://github.com/n-devs/ai-code-review/compare/v1.0.0...v2.0.0</a></p>
]]></content:encoded></item><item><title>Polygraph MCP gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/polygraph-mcp-gate/</link><pubDate>Fri, 10 Jul 2026 15:08:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/polygraph-mcp-gate/</guid><description>Version updated for https://github.com/polygraphso/litmus to version litmus-v0.33.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Patch release fixing two false positives in the litmus-v16 scanners, both found by a local regrade of the published set (#115).
raven-mcp (was A→F): C-01 tool-poisoning. The exfil-instruction check tested the sink against the whole document, so a benign UI-docs surface that listed form fields (&amp;#39;Email&amp;#39;, &amp;#39;Password&amp;#39;) and carried a URL elsewhere tripped it. The sink is now required in the same clause as the verb and object (one bounded, linear regex).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/polygraphso/litmus">https://github.com/polygraphso/litmus</a></strong> to version <strong>litmus-v0.33.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/polygraph-mcp-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Patch release fixing two false positives in the litmus-v16 scanners, both found by a local regrade of the published set (#115).</p>
<p><strong>raven-mcp (was A→F): C-01 tool-poisoning.</strong> The exfil-instruction check tested the sink against the whole document, so a benign UI-docs surface that listed form fields (<code>'Email', 'Password'</code>) and carried a URL elsewhere tripped it. The sink is now required in the same clause as the verb and object (one bounded, linear regex).</p>
<p><strong>@tensorfeed/mcp-server (was A→D): C-04 probe 3.2 reflection.</strong> A search tool that echoed our jailbreak payload in a <code>results for &quot;…&quot;</code> frame (not a rejection frame) read as amplification. Reflections of the fed payload are now masked in any frame, scoped to the fed payload so a server that splices in genuinely novel injection still fails.</p>
<p>methodologyVersion is unchanged (<code>litmus-v16</code>): a monotonic correction that only lifts the two false positives back to A. 486 probes tests pass; both servers re-grade A end to end; demo-toolpoison still F.</p>
<p>Fixes in #115; version bump #116.</p>
]]></content:encoded></item><item><title>docker-hash</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/docker-hash/</link><pubDate>Fri, 10 Jul 2026 15:08:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/docker-hash/</guid><description>Version updated for https://github.com/RemkoMolier/docker-hash to version v0.3.14.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog Bug fixes fix(deps): update dependency markdownlint-cli2 to v0.23.0 (#167)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RemkoMolier/docker-hash">https://github.com/RemkoMolier/docker-hash</a></strong> to version <strong>v0.3.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/docker-hash">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<h3 id="bug-fixes">Bug fixes</h3>
<ul>
<li>fix(deps): update dependency markdownlint-cli2 to v0.23.0 (#167)</li>
</ul>
]]></content:encoded></item><item><title>Setup JavaScript/TypeScript Environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/setup-javascript/typescript-environment/</link><pubDate>Fri, 10 Jul 2026 15:07:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/setup-javascript/typescript-environment/</guid><description>Version updated for https://github.com/siguici/setup-js to version v1.3.1.
This action is used across all versions by 8 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/siguici/setup-js/compare/v1.3.0...v1.3.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/siguici/setup-js">https://github.com/siguici/setup-js</a></strong> to version <strong>v1.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-javascript-typescript-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/siguici/setup-js/compare/v1.3.0...v1.3.1">https://github.com/siguici/setup-js/compare/v1.3.0...v1.3.1</a></p>
]]></content:encoded></item><item><title>Agent Gate for AI PRs</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/agent-gate-for-ai-prs/</link><pubDate>Fri, 10 Jul 2026 15:07:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/agent-gate-for-ai-prs/</guid><description>Version updated for https://github.com/sjh9714/Agent-Gate to version v0.3.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Agent Gate v0.3.1 Release Notes Agent Gate v0.3.1 is the first public CLI release of the v0.3 line. The npm package is scoped as @jinhyuk9714/agent-gate; the executable and product name remain agent-gate and Agent Gate.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sjh9714/Agent-Gate">https://github.com/sjh9714/Agent-Gate</a></strong> to version <strong>v0.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-gate-for-ai-prs">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="agent-gate-v031-release-notes">Agent Gate v0.3.1 Release Notes</h1>
<p>Agent Gate v0.3.1 is the first public CLI release of the v0.3 line. The npm
package is scoped as <code>@jinhyuk9714/agent-gate</code>; the executable and product name
remain <code>agent-gate</code> and Agent Gate.</p>
<h2 id="try-it">Try It</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx --yes @jinhyuk9714/agent-gate@0.3.1 scan owner/repo#123
</span></span></code></pre></div><p>The CLI analyzes public pull requests without cloning, checking out, installing,
or executing target-repository code. Private repositories and higher GitHub API
limits use <code>GH_TOKEN</code>, with <code>GITHUB_TOKEN</code> as the fallback.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Shared API-only PR collection for the CLI and GitHub Action.</li>
<li>Fail-closed file-list and content integrity checks.</li>
<li>Differential GitHub Actions privilege and supply-chain findings.</li>
<li>Exact expiring waivers and deterministic finding IDs.</li>
<li>Narrow, explainable agentic workflow injection detection.</li>
<li>Bounded, sanitized human, Markdown, JSON, summary, and comment reports.</li>
<li>Signed release tags and npm provenance for the exact tested tarball.</li>
</ul>
<p>The <code>v0.3.0</code> tag remains immutable. npm rejected its unscoped <code>agent-gate</code>
package name as too similar to the existing <code>agentgate</code> package, so v0.3.1
records the scoped package identity in source before publication.</p>
<p>See the <a href="migration-v0.3.0.md">v0.3 migration guidance</a>, <a href="cli.md">CLI reference</a>,
and <a href="release-checklist.md">release checklist</a>.</p>
]]></content:encoded></item><item><title>Pipr Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/pipr-review/</link><pubDate>Fri, 10 Jul 2026 15:06:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/pipr-review/</guid><description>Version updated for https://github.com/somus/pipr to version v0.3.6.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.3.6 (2026-07-10) Features harden review prompts and recipes (#51) (59cf563) Bug Fixes gate suggested fixes in prompt evals (#49) (86daeca)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somus/pipr">https://github.com/somus/pipr</a></strong> to version <strong>v0.3.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pipr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="036-2026-07-10"><a href="https://github.com/somus/pipr/compare/v0.3.5...v0.3.6">0.3.6</a> (2026-07-10)</h2>
<h3 id="features">Features</h3>
<ul>
<li>harden review prompts and recipes (<a href="https://github.com/somus/pipr/issues/51">#51</a>) (<a href="https://github.com/somus/pipr/commit/59cf563ada6ab0ba32148022c306a40684c068a3">59cf563</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>gate suggested fixes in prompt evals (<a href="https://github.com/somus/pipr/issues/49">#49</a>) (<a href="https://github.com/somus/pipr/commit/86daeca516be64be99e41fb446927cd7119a3770">86daeca</a>)</li>
</ul>
]]></content:encoded></item><item><title>Deploy to Vercel</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/deploy-to-vercel/</link><pubDate>Fri, 10 Jul 2026 15:06:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/deploy-to-vercel/</guid><description>Version updated for https://github.com/Spectra010s/d-vercel to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s new Added ignore-build-step input option to skip the build step when needed. Improvements Gives users more control over the deployment workflow. Useful for projects where the build is handled separately before deployment. Usage Set ignore-build-step in your workflow with a command to skip the build step.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Spectra010s/d-vercel">https://github.com/Spectra010s/d-vercel</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-to-vercel">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new">What&rsquo;s new</h2>
<ul>
<li>Added <code>ignore-build-step</code> input option to skip the build step when needed.</li>
</ul>
<h2 id="improvements">Improvements</h2>
<ul>
<li>Gives users more control over the deployment workflow.</li>
<li>Useful for projects where the build is handled separately before deployment.</li>
</ul>
<h2 id="usage">Usage</h2>
<p>Set <code>ignore-build-step</code> in your workflow with a command to skip the build step.</p>
]]></content:encoded></item><item><title>MCP Test Harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/mcp-test-harness/</link><pubDate>Fri, 10 Jul 2026 15:05:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/mcp-test-harness/</guid><description>Version updated for https://github.com/vaquarkhan/mcp-test-harness to version v3.0.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 3.0.4 Fix GitHub Action actions/github-script@v8.0.0 commit pin (dist-smoke + Marketplace). All 18 PyPI packages and GHCR images at 3.0.4. See CHANGELOG.md.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vaquarkhan/mcp-test-harness">https://github.com/vaquarkhan/mcp-test-harness</a></strong> to version <strong>v3.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcp-test-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="304">3.0.4</h2>
<ul>
<li>Fix <strong>GitHub Action</strong> <code>actions/github-script@v8.0.0</code> commit pin (<code>dist-smoke</code> + Marketplace).</li>
<li>All <strong>18</strong> PyPI packages and GHCR images at <strong>3.0.4</strong>.</li>
</ul>
<p>See <a href="https://github.com/vaquarkhan/mcp-test-harness/blob/main/CHANGELOG.md#304---2026-07-10">CHANGELOG.md</a>.</p>
]]></content:encoded></item><item><title>cloudflare-script</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/cloudflare-script/</link><pubDate>Fri, 10 Jul 2026 15:05:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/cloudflare-script/</guid><description>Version updated for https://github.com/wei/cloudflare-script to version v7.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Summary Update Cloudflare SDK from v6.5.0 to v7.0.0 This release was generated automatically when a new Cloudflare SDK version became available.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wei/cloudflare-script">https://github.com/wei/cloudflare-script</a></strong> to version <strong>v7.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cloudflare-script">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="summary">Summary</h2>
<ul>
<li>Update Cloudflare SDK from v6.5.0 to v7.0.0</li>
</ul>
<p>This release was generated automatically when a new Cloudflare SDK version became available.</p>
]]></content:encoded></item><item><title>vibecheck-ai-slop</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/vibecheck-ai-slop/</link><pubDate>Fri, 10 Jul 2026 15:04:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/vibecheck-ai-slop/</guid><description>Version updated for https://github.com/yuvrajangadsingh/vibecheck to version v1.11.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Trust fixes. Every change here came out of an adversarial review pass over the rule regexes and scanner.
False positives killed (these were failing CI on normal code):
no-py-eval no longer flags model.eval() / df.eval() (every PyTorch and pandas repo) no-eval no longer flags Playwright/Puppeteer page.$eval(), still catches window.eval() no-sql-concat / no-py-sql-concat now require a real SQL clause, so “Update available: &amp;#34; + version and friends stop flagging no-innerhtml no longer flags === comparisons False negatives fixed:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yuvrajangadsingh/vibecheck">https://github.com/yuvrajangadsingh/vibecheck</a></strong> to version <strong>v1.11.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibecheck-ai-slop">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Trust fixes. Every change here came out of an adversarial review pass over the rule regexes and scanner.</p>
<p><strong>False positives killed (these were failing CI on normal code):</strong></p>
<ul>
<li><code>no-py-eval</code> no longer flags <code>model.eval()</code> / <code>df.eval()</code> (every PyTorch and pandas repo)</li>
<li><code>no-eval</code> no longer flags Playwright/Puppeteer <code>page.$eval()</code>, still catches <code>window.eval()</code></li>
<li><code>no-sql-concat</code> / <code>no-py-sql-concat</code> now require a real SQL clause, so &ldquo;Update available: &quot; + version and friends stop flagging</li>
<li><code>no-innerhtml</code> no longer flags <code>===</code> comparisons</li>
</ul>
<p><strong>False negatives fixed:</strong></p>
<ul>
<li><code>config.apiKey = &quot;sk-live-...&quot;</code> style secrets were exempt via an antiPattern blind spot</li>
<li><code>el.innerHTML +=</code> / <code>||=</code> / <code>&amp;&amp;=</code> / <code>??=</code> writes now flag</li>
<li><code>builtins.eval()</code> now flags</li>
<li>empty catch followed by <code>} finally {</code> now flags</li>
<li>bare <code>raise NotImplementedError</code> (no parens) now flags</li>
<li>indented <code>from x import *</code> now flags</li>
</ul>
<p><strong>Behavior change:</strong> the two SQL-concat rules dropped from error to warn. They are regex heuristics that cannot fully tell a query from SQL-shaped UI copy, so they surface for review instead of failing CI. If you gate on them, set them back via <code>.vibecheckrc</code>: <code>{ &quot;rules&quot;: { &quot;no-sql-concat&quot;: &quot;error&quot; } }</code>.</p>
<p><strong>Scanner and infra:</strong></p>
<ul>
<li>version is injected from package.json at build; the MCP server had been reporting 1.8.0 while the CLI said 1.10.0</li>
<li><code>vibecheck --mcp</code> was starting two MCP servers on one stdio; the <code>vibecheck-mcp</code> bin got its own entry</li>
<li><code>no-god-function</code> had a quadratic regex: a 300KB minified line took 76s, now 0.1s</li>
<li>ignore patterns now match nested paths (<code>packages/*/node_modules</code> was being scanned)</li>
<li><code>.mts</code> / <code>.cts</code> files are scanned as TypeScript</li>
<li>rules can exclude by file path, so <code>console.log</code> in <code>*.test.ts</code> and <code>print()</code> in <code>test_*.py</code> / <code>cli.py</code> stop flagging</li>
</ul>
<p>163 tests, all changes verified end-to-end on the built CLI before release.</p>
]]></content:encoded></item><item><title>Wardex Release Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/wardex-release-gate/</link><pubDate>Fri, 10 Jul 2026 06:34:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/wardex-release-gate/</guid><description>Version updated for https://github.com/had-nu/wardex to version v2.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog d55fd9bffbe196698aa6f2f1e8bc3dc828ee3372 chore(v2.3.0): make gleipnir dep public, remove replace directive bee2ba9d2d0df89d52405f399244fb8f27e9c453 feat(v2.3.0): replace immutable-provenance sub-module with agnostic Anchorer interface a5a3bfc18b2a69ec1fe8e691728084cfc4094d8a docs: add signing public key and root hash to READMEs for v2.2.2 verification be4ebfab9dc6ce8233f018eccc9e425d02250b73 docs: update English README with same structure as Portuguese 3cca9599cf0283debfb0eabb72733bb88cf0dd50 docs: restructure README — audit log como feature principal, posicionamento europeu 52fd3345022aad1b2faf4378fd8135497ef982cd refactor: migrate key storage to ~/.crypto/ centralized directory</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/had-nu/wardex">https://github.com/had-nu/wardex</a></strong> to version <strong>v2.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wardex-release-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>d55fd9bffbe196698aa6f2f1e8bc3dc828ee3372 chore(v2.3.0): make gleipnir dep public, remove replace directive</li>
<li>bee2ba9d2d0df89d52405f399244fb8f27e9c453 feat(v2.3.0): replace immutable-provenance sub-module with agnostic Anchorer interface</li>
<li>a5a3bfc18b2a69ec1fe8e691728084cfc4094d8a docs: add signing public key and root hash to READMEs for v2.2.2 verification</li>
<li>be4ebfab9dc6ce8233f018eccc9e425d02250b73 docs: update English README with same structure as Portuguese</li>
<li>3cca9599cf0283debfb0eabb72733bb88cf0dd50 docs: restructure README — audit log como feature principal, posicionamento europeu</li>
<li>52fd3345022aad1b2faf4378fd8135497ef982cd refactor: migrate key storage to ~/.crypto/ centralized directory</li>
</ul>
]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/ai-plugin-scanner/</link><pubDate>Fri, 10 Jul 2026 06:34:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.416.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/8ed11fda90343fdef4651bfc5dcd4db0110910fa with plugin-scanner 2.0.1016.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.415...v1.2.416</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.416</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>18</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/8ed11fda90343fdef4651bfc5dcd4db0110910fa">https://github.com/hashgraph-online/hol-guard/tree/8ed11fda90343fdef4651bfc5dcd4db0110910fa</a> with plugin-scanner 2.0.1016.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.415...v1.2.416">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.415...v1.2.416</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/hol-codex-plugin-scanner/</link><pubDate>Fri, 10 Jul 2026 06:33:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.416.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.416</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.416</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.416">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.416</a></p>
]]></content:encoded></item><item><title>HCL AppScan Static Analyzer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/hcl-appscan-static-analyzer/</link><pubDate>Fri, 10 Jul 2026 06:33:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/hcl-appscan-static-analyzer/</guid><description>Version updated for https://github.com/HCL-TECH-SOFTWARE/appscan-sast-action to version v1.1.0.
This action is used across all versions by 133 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Incremental scanning option when run on pull requests. Rescan option for SAST and SCA</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/HCL-TECH-SOFTWARE/appscan-sast-action">https://github.com/HCL-TECH-SOFTWARE/appscan-sast-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>133</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hcl-appscan-static-analyzer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Incremental scanning option when run on pull requests.</li>
<li>Rescan option for SAST and SCA</li>
</ul>
]]></content:encoded></item><item><title>action-env-sync-build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/action-env-sync-build/</link><pubDate>Fri, 10 Jul 2026 06:32:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/action-env-sync-build/</guid><description>Version updated for https://github.com/heronlabs/action-env-sync-build to version v4.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [skip ci] bump v4.0.1 (6138dc1) chore: update bats-action version to 4.0.0 in CI workflow (2835391) [skip ci] bump v4.0.0 (35c0b3c) chore: polish metadata, docs, gitignore, and SHA-to-tag refs (2d87bff) [skip ci] bump v3.0.16 (928b5e4) chore: add CODEOWNERS file to define repository ownership (0b2a78c) [skip ci] bump v3.0.15 (289366a) Merge pull request #17 from heronlabs/chore-dependabot-daily (ff6c7d1) chore: set dependabot interval to daily (5d7a13f) [skip ci] bump v3.0.14 (6c3b726)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/heronlabs/action-env-sync-build">https://github.com/heronlabs/action-env-sync-build</a></strong> to version <strong>v4.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/action-env-sync-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>[skip ci] bump v4.0.1 (6138dc1)</li>
<li>chore: update bats-action version to 4.0.0 in CI workflow (2835391)</li>
<li>[skip ci] bump v4.0.0 (35c0b3c)</li>
<li>chore: polish metadata, docs, gitignore, and SHA-to-tag refs (2d87bff)</li>
<li>[skip ci] bump v3.0.16 (928b5e4)</li>
<li>chore: add CODEOWNERS file to define repository ownership (0b2a78c)</li>
<li>[skip ci] bump v3.0.15 (289366a)</li>
<li>Merge pull request #17 from heronlabs/chore-dependabot-daily (ff6c7d1)</li>
<li>chore: set dependabot interval to daily (5d7a13f)</li>
<li>[skip ci] bump v3.0.14 (6c3b726)</li>
</ul>
]]></content:encoded></item><item><title>action-lambda-publish</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/action-lambda-publish/</link><pubDate>Fri, 10 Jul 2026 06:31:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/action-lambda-publish/</guid><description>Version updated for https://github.com/heronlabs/action-lambda-publish to version v4.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [skip ci] bump v4.0.0 (401b931) chore: polish metadata, docs, gitignore, and SHA-to-tag refs (bd10446) [skip ci] bump v3.0.14 (2a7a37c) chore: add CODEOWNERS file to define repository ownership (82d7d6e) [skip ci] bump v3.0.13 (02e3934) Merge pull request #21 from heronlabs/chore-dependabot-daily (3bd72a6) chore: set dependabot interval to daily (943baaf) [skip ci] bump v3.0.12 (0657d06) chore: update action-lambda-publish to action-tag-release-build v5.0.12 (#20) (92d9fda) [skip ci] bump v3.0.11 (d90741b)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/heronlabs/action-lambda-publish">https://github.com/heronlabs/action-lambda-publish</a></strong> to version <strong>v4.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/action-lambda-publish">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>[skip ci] bump v4.0.0 (401b931)</li>
<li>chore: polish metadata, docs, gitignore, and SHA-to-tag refs (bd10446)</li>
<li>[skip ci] bump v3.0.14 (2a7a37c)</li>
<li>chore: add CODEOWNERS file to define repository ownership (82d7d6e)</li>
<li>[skip ci] bump v3.0.13 (02e3934)</li>
<li>Merge pull request #21 from heronlabs/chore-dependabot-daily (3bd72a6)</li>
<li>chore: set dependabot interval to daily (943baaf)</li>
<li>[skip ci] bump v3.0.12 (0657d06)</li>
<li>chore: update action-lambda-publish to action-tag-release-build v5.0.12 (#20) (92d9fda)</li>
<li>[skip ci] bump v3.0.11 (d90741b)</li>
</ul>
]]></content:encoded></item><item><title>action-pulumi-build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/action-pulumi-build/</link><pubDate>Fri, 10 Jul 2026 06:31:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/action-pulumi-build/</guid><description>Version updated for https://github.com/heronlabs/action-pulumi-build to version v3.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [skip ci] bump v3.0.0 (4b38180) chore: polish metadata, docs, gitignore, and SHA-to-tag refs (39c2181) [skip ci] bump v2.0.17 (dc269c7) chore: add CODEOWNERS file to define repository ownership (3a74494) [skip ci] bump v2.0.16 (f91a339) Merge pull request #23 from heronlabs/chore-dependabot-daily (daa055f) chore: set dependabot interval to daily (6eb3516) [skip ci] bump v2.0.15 (4a8ed93) chore: update action-pulumi-build to action-tag-release-build v5.0.12 (#22) (6381c2f) [skip ci] bump v2.0.14 (0c60e15)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/heronlabs/action-pulumi-build">https://github.com/heronlabs/action-pulumi-build</a></strong> to version <strong>v3.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/action-pulumi-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>[skip ci] bump v3.0.0 (4b38180)</li>
<li>chore: polish metadata, docs, gitignore, and SHA-to-tag refs (39c2181)</li>
<li>[skip ci] bump v2.0.17 (dc269c7)</li>
<li>chore: add CODEOWNERS file to define repository ownership (3a74494)</li>
<li>[skip ci] bump v2.0.16 (f91a339)</li>
<li>Merge pull request #23 from heronlabs/chore-dependabot-daily (daa055f)</li>
<li>chore: set dependabot interval to daily (6eb3516)</li>
<li>[skip ci] bump v2.0.15 (4a8ed93)</li>
<li>chore: update action-pulumi-build to action-tag-release-build v5.0.12 (#22) (6381c2f)</li>
<li>[skip ci] bump v2.0.14 (0c60e15)</li>
</ul>
]]></content:encoded></item><item><title>action-ssm-env-build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/action-ssm-env-build/</link><pubDate>Fri, 10 Jul 2026 06:30:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/action-ssm-env-build/</guid><description>Version updated for https://github.com/heronlabs/action-ssm-env-build to version v4.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [skip ci] bump v4.0.0 (629adc8) chore: polish metadata, docs, gitignore, and SHA-to-tag refs (875ca5f) [skip ci] bump v3.0.17 (b183979) chore: add CODEOWNERS file to define repository ownership (2f161c4) [skip ci] bump v3.0.16 (69d8a26) Merge pull request #27 from heronlabs/chore-dependabot-daily (49378ce) chore: set dependabot interval to daily (1bc293e) [skip ci] bump v3.0.15 (7fab56e) chore: update action-ssm-env-build to action-tag-release-build v5.0.12 (#26) (2109b62) [skip ci] bump v3.0.14 (97ddc90)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/heronlabs/action-ssm-env-build">https://github.com/heronlabs/action-ssm-env-build</a></strong> to version <strong>v4.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/action-ssm-env-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>[skip ci] bump v4.0.0 (629adc8)</li>
<li>chore: polish metadata, docs, gitignore, and SHA-to-tag refs (875ca5f)</li>
<li>[skip ci] bump v3.0.17 (b183979)</li>
<li>chore: add CODEOWNERS file to define repository ownership (2f161c4)</li>
<li>[skip ci] bump v3.0.16 (69d8a26)</li>
<li>Merge pull request #27 from heronlabs/chore-dependabot-daily (49378ce)</li>
<li>chore: set dependabot interval to daily (1bc293e)</li>
<li>[skip ci] bump v3.0.15 (7fab56e)</li>
<li>chore: update action-ssm-env-build to action-tag-release-build v5.0.12 (#26) (2109b62)</li>
<li>[skip ci] bump v3.0.14 (97ddc90)</li>
</ul>
]]></content:encoded></item><item><title>action-tag-release-build</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/action-tag-release-build/</link><pubDate>Fri, 10 Jul 2026 06:30:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/action-tag-release-build/</guid><description>Version updated for https://github.com/heronlabs/action-tag-release-build to version v6.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [skip ci] bump v6.0.0 (0994531) [skip ci] bump v5.3.1 (9d405f0) chore: polish metadata, docs, gitignore, and SHA-to-tag refs (19337c6) [skip ci] bump v5.3.0 (b6256bf) feat: add CODEOWNERS file and update continuous deployment workflow (25d0edf) [skip ci] bump v5.2.1 (1a1d2c3) chore: ignore gts-locked packages in dependabot (#30) (dd25bcb) [skip ci] chore: update bin/ build artifact (ea43f9a) [skip ci] bump v5.2.0 (d3e5b7d) feat: create composite action + workflow to build and commit bin/ artifact (#27) (3c68e26)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/heronlabs/action-tag-release-build">https://github.com/heronlabs/action-tag-release-build</a></strong> to version <strong>v6.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/action-tag-release-build">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>[skip ci] bump v6.0.0 (0994531)</li>
<li>[skip ci] bump v5.3.1 (9d405f0)</li>
<li>chore: polish metadata, docs, gitignore, and SHA-to-tag refs (19337c6)</li>
<li>[skip ci] bump v5.3.0 (b6256bf)</li>
<li>feat: add CODEOWNERS file and update continuous deployment workflow (25d0edf)</li>
<li>[skip ci] bump v5.2.1 (1a1d2c3)</li>
<li>chore: ignore gts-locked packages in dependabot (#30) (dd25bcb)</li>
<li>[skip ci] chore: update bin/ build artifact (ea43f9a)</li>
<li>[skip ci] bump v5.2.0 (d3e5b7d)</li>
<li>feat: create composite action + workflow to build and commit bin/ artifact (#27) (3c68e26)</li>
</ul>
]]></content:encoded></item><item><title>cibuild-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/cibuild-action/</link><pubDate>Fri, 10 Jul 2026 06:29:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/cibuild-action/</guid><description>Version updated for https://github.com/invarnhq/cibuild to version v2.3.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v2.3.5</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/invarnhq/cibuild">https://github.com/invarnhq/cibuild</a></strong> to version <strong>v2.3.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cibuild-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release v2.3.5</p>
]]></content:encoded></item><item><title>aeroflare-test-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/aeroflare-test-action/</link><pubDate>Fri, 10 Jul 2026 06:29:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/aeroflare-test-action/</guid><description>Version updated for https://github.com/ItzEmoji/aeroflare-test to version v1.9.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.9.0 (2026-07-09) Features add make build/test/hash/get (639f89c) ci action (d4052a9) scripts: add get.sh to fetch a verified prebuilt binary (f81dcf0) Bug Fixes nix: build from the local tree instead of a self-referential fetch (c95b32d)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ItzEmoji/aeroflare-test">https://github.com/ItzEmoji/aeroflare-test</a></strong> to version <strong>v1.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aeroflare-test-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="190-2026-07-09"><a href="https://github.com/ItzEmoji/aeroflare-test/compare/v1.8.0...v1.9.0">1.9.0</a> (2026-07-09)</h2>
<h3 id="features">Features</h3>
<ul>
<li>add make build/test/hash/get (<a href="https://github.com/ItzEmoji/aeroflare-test/commit/639f89c4933d1f2726785ead66a9b7fe0b9b6d43">639f89c</a>)</li>
<li>ci action (<a href="https://github.com/ItzEmoji/aeroflare-test/commit/d4052a9f2b3541178df8faab0b3229e9b339159c">d4052a9</a>)</li>
<li><strong>scripts:</strong> add get.sh to fetch a verified prebuilt binary (<a href="https://github.com/ItzEmoji/aeroflare-test/commit/f81dcf0bc60cfb304f815cd096768b24eebdd5a2">f81dcf0</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>nix:</strong> build from the local tree instead of a self-referential fetch (<a href="https://github.com/ItzEmoji/aeroflare-test/commit/c95b32d7ea1bafca1590a9ceb8f969fdcddaeffe">c95b32d</a>)</li>
</ul>
]]></content:encoded></item><item><title>Cartulary Markdown Validator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/cartulary-markdown-validator/</link><pubDate>Fri, 10 Jul 2026 06:28:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/cartulary-markdown-validator/</guid><description>Version updated for https://github.com/jdhorne/cartulary to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/jdhorne/cartulary/compare/v0.2.0...v0.3.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jdhorne/cartulary">https://github.com/jdhorne/cartulary</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cartulary-markdown-validator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jdhorne/cartulary/compare/v0.2.0...v0.3.0">https://github.com/jdhorne/cartulary/compare/v0.2.0...v0.3.0</a></p>
]]></content:encoded></item><item><title>sops tools installer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/sops-tools-installer/</link><pubDate>Fri, 10 Jul 2026 06:28:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/sops-tools-installer/</guid><description>Version updated for https://github.com/jkroepke/setup-sops to version v1.5.50.
This action is used across all versions by 4 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed 🛠️ Dependencies chore(deps): lock file maintenance by @renovate[bot] in https://github.com/jkroepke/setup-sops/pull/245 Full Changelog: https://github.com/jkroepke/setup-sops/compare/v1.5.49...v1.5.50</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jkroepke/setup-sops">https://github.com/jkroepke/setup-sops</a></strong> to version <strong>v1.5.50</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sops-tools-installer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at v1.5.50 -->
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="-dependencies">🛠️ Dependencies</h3>
<ul>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/jkroepke/setup-sops/pull/245">https://github.com/jkroepke/setup-sops/pull/245</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jkroepke/setup-sops/compare/v1.5.49...v1.5.50">https://github.com/jkroepke/setup-sops/compare/v1.5.49...v1.5.50</a></p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/neurolink-ai/</link><pubDate>Fri, 10 Jul 2026 06:27:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v9.85.0.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 9.85.0 (2026-07-09) Features (skills): add native skills support (stores, tools, prompt index, CLI, API) (f7bd694)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v9.85.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="9850-2026-07-09"><a href="https://github.com/juspay/neurolink/compare/v9.84.2...v9.85.0">9.85.0</a> (2026-07-09)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>(skills):</strong>  add native skills support (stores, tools, prompt index, CLI, API) (<a href="https://github.com/juspay/neurolink/commit/f7bd694453088f05af32608cc9332b20c7eaa51e">f7bd694</a>)</li>
</ul>
]]></content:encoded></item><item><title>OSS Security Policy as Code</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/oss-security-policy-as-code/</link><pubDate>Fri, 10 Jul 2026 06:26:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/oss-security-policy-as-code/</guid><description>Version updated for https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit to version v10.0.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed OSS Security Policy as Code Starter Kit v10.0.1 A hardening hotfix for the v10.0.0 surface. An extreme end-user validation sweep — 275 clean-room scenarios run against a seven-lab test project — surfaced 37 confirmed defects. All 37 are fixed here, each pinned by a focused regression test.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit">https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit</a></strong> to version <strong>v10.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/oss-security-policy-as-code">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="oss-security-policy-as-code-starter-kit-v1001">OSS Security Policy as Code Starter Kit v10.0.1</h2>
<p>A hardening hotfix for the v10.0.0 surface. An extreme end-user validation sweep — 275 clean-room scenarios run against a seven-lab test project — surfaced 37 confirmed defects. All 37 are fixed here, each pinned by a focused regression test.</p>
<p><strong>Nothing about how the kit evaluates changed.</strong> No control state, no <code>summary_by_status</code>, no <code>results_digest</code>, and no exit code moves in this release: fences FT-2, FT-3 and FT-4 all hold. Upgrading from v10.0.0 requires no action and cannot change a gate decision.</p>
<hr>
<h2 id="highlights">Highlights</h2>
<h3 id="privacy-by-default-m-002">Privacy by default (M-002)</h3>
<p>Shareable artifacts were leaking the auditor&rsquo;s absolute paths, home directory, and OS username. They no longer do:</p>
<ul>
<li><code>evaluation-report.md</code> now redacts per-control evidence bullets through the same <code>classify_reference</code> path the JSON report already used. The Markdown report was leaking absolute paths that the JSON report scrubbed.</li>
<li>The <code>--format json</code> stdout summary sanitizes <code>target_path</code> to the target&rsquo;s basename.</li>
<li><code>evaluate-many</code> sanitizes <code>target_root</code>, per-run <code>target_path</code>, report artifact paths, and skipped-directory paths in both the batch JSON and Markdown.</li>
<li><code>correlate-findings</code> waiver warnings and <code>--target</code> error echoes use the basename or the string you typed — never the resolved absolute path — in the <code>findings/1.0</code> artifact and on stderr.</li>
</ul>
<p><code>--include-absolute-path</code> opts back in wherever this applies, and is now available on <code>evaluate-many</code> too.</p>
<h3 id="contract-honesty">Contract honesty</h3>
<ul>
<li><strong><code>export-evidence</code> no longer silently accepts a stored pre-2.0 report.</strong> Feeding it a <code>reports/0.1</code>/<code>0.2</code>/<code>0.3</code>/<code>1.0</code> report previously produced all-unknown, content-dropped evidence with exit 0. It now fails fast with a clean exit 2 and a pointer to the migration guide, before any renderer runs.</li>
<li><strong><code>evaluate</code> now honors <code>oss-policy-kit.yaml</code>.</strong> <code>fail_on</code>, <code>output_dir</code>, and <code>report_json_contract</code> are used as fallbacks when the matching flag is omitted. An explicit flag always wins — provenance is tracked via Click&rsquo;s parameter source, so <code>--fail-on none</code> still beats a config that says <code>fail</code>. Previously <code>init</code> wrote these keys and <code>evaluate</code> ignored them, which meant a configured gate silently never fired.</li>
</ul>
<hr>
<h2 id="improvements">Improvements</h2>
<h3 id="findings-surface">Findings surface</h3>
<p>Ranking and accounting only — none of these can change a control verdict.</p>
<ul>
<li>Malformed SARIF and kit-evidence result <strong>containers</strong> now demote to <code>status: &quot;error&quot;</code>, so a corrupt drop is distinguishable from a genuinely empty one.</li>
<li>Out-of-range EPSS values in an offline snapshot (outside <code>[0.0, 1.0]</code>) are ignored, so a garbage number cannot warp ranking.</li>
<li><code>extensions.findings_summary</code> gains <code>sources_ok</code> and <code>sources_total</code>, so a genuinely clean zero is distinguishable from an all-unreadable zero.</li>
<li>A present-but-non-list <code>waivers:</code> key now emits an honest warning instead of being silently ignored.</li>
<li><code>correlate-findings</code> marks waived findings with a <code>WAIVED</code> tag in the human view, and resolves a relative <code>--output</code>, <code>--waivers</code>, and <code>--enrichment-file</code> under <code>--target</code> (they now agree; previously <code>--enrichment-file</code> resolved against the current directory).</li>
</ul>
<h3 id="cli-robustness">CLI robustness</h3>
<ul>
<li>A broken output pipe (<code>| head</code>, <code>| less</code>) exits 0 quietly instead of printing &ldquo;Unexpected error&rdquo; and exiting 3.</li>
<li><code>init --with-evidence</code> scaffolds GitLab evidence templates, which have shipped since v6.4.0 but were being downgraded to a note.</li>
<li><code>COLUMNS</code> is honored for non-TTY streams, so wrapped error messages use the caller&rsquo;s real width.</li>
<li><code>SOURCE_DATE_EPOCH</code> is honored by <code>scan-*</code> and <code>export-*</code> timestamps, for reproducible output.</li>
<li><code>correlate-findings --target &quot;&quot;</code> is rejected with a clean exit 2 rather than being silently coerced to the current directory.</li>
<li><code>export-evidence</code> accepts the <code>-t</code> / <code>-o</code> short flags, matching the other commands.</li>
</ul>
<hr>
<h2 id="security">Security</h2>
<p>No vulnerability is fixed in this release. The privacy fixes above close an information-disclosure class in artifacts intended to be shared: absolute paths, home directories, and OS usernames could reach a report that a user would reasonably attach to a ticket or a PR.</p>
<p>Release artifacts are unchanged in shape: signed wheel and sdist, CycloneDX SBOM, and an in-toto provenance attestation.</p>
<hr>
<h2 id="upgrading">Upgrading</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-text" data-lang="text"><span style="display:flex;"><span>pip install --upgrade oss-policy-kit
</span></span></code></pre></div><p>No migration is required from v10.0.0. Two behavior changes are worth knowing about:</p>
<ol>
<li>If you have an <code>oss-policy-kit.yaml</code> written by <code>init</code> and you relied on <code>evaluate</code> ignoring its <code>fail_on</code> / <code>output_dir</code> / <code>report_json_contract</code>, <code>evaluate</code> now honors them when you omit the corresponding flag. Pass the flag explicitly to override.</li>
<li>If you pipe <code>evaluate --format json</code> into tooling that expects an absolute <code>target_path</code>, pass <code>--include-absolute-path</code>.</li>
</ol>
<p><strong>Full Changelog</strong>: <a href="https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit/compare/v10.0.0...v10.0.1">https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit/compare/v10.0.0...v10.0.1</a></p>
]]></content:encoded></item><item><title>SecondBrainAction</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/secondbrainaction/</link><pubDate>Fri, 10 Jul 2026 06:26:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/secondbrainaction/</guid><description>Version updated for https://github.com/mcasperson/SecondBrain to version +run3077-attempt1.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mcasperson/SecondBrain">https://github.com/mcasperson/SecondBrain</a></strong> to version <strong>+run3077-attempt1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/secondbrainaction">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>Miso PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/miso-pr-review/</link><pubDate>Fri, 10 Jul 2026 06:25:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/miso-pr-review/</guid><description>Version updated for https://github.com/misospace/pr-reviewer-action to version v2.1.2.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed ci(github-action): update action actions/setup-python (a309ff8 → ece7cb0) by @its-miso[bot] in https://github.com/misospace/pr-reviewer-action/pull/402 ci(github-action): update action misospace/pr-reviewer-action (v2.0.5 → v2.1.1) by @its-miso[bot] in https://github.com/misospace/pr-reviewer-action/pull/403 perf(planner): share section piece files with the corpus so verdict dedup drops them by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/404 refactor(planner): extract embedded sections from the corpus itself; fix budget overflow dropping the diff head by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/405 Full Changelog: https://github.com/misospace/pr-reviewer-action/compare/v2.1.1...v2.1.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/misospace/pr-reviewer-action">https://github.com/misospace/pr-reviewer-action</a></strong> to version <strong>v2.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/miso-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci(github-action): update action actions/setup-python (a309ff8 → ece7cb0) by @its-miso[bot] in <a href="https://github.com/misospace/pr-reviewer-action/pull/402">https://github.com/misospace/pr-reviewer-action/pull/402</a></li>
<li>ci(github-action): update action misospace/pr-reviewer-action (v2.0.5 → v2.1.1) by @its-miso[bot] in <a href="https://github.com/misospace/pr-reviewer-action/pull/403">https://github.com/misospace/pr-reviewer-action/pull/403</a></li>
<li>perf(planner): share section piece files with the corpus so verdict dedup drops them by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/404">https://github.com/misospace/pr-reviewer-action/pull/404</a></li>
<li>refactor(planner): extract embedded sections from the corpus itself; fix budget overflow dropping the diff head by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/405">https://github.com/misospace/pr-reviewer-action/pull/405</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/misospace/pr-reviewer-action/compare/v2.1.1...v2.1.2">https://github.com/misospace/pr-reviewer-action/compare/v2.1.1...v2.1.2</a></p>
]]></content:encoded></item><item><title>agent-bom Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/agent-bom-scan/</link><pubDate>Fri, 10 Jul 2026 06:25:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/agent-bom-scan/</guid><description>Version updated for https://github.com/msaad00/agent-bom to version v0.94.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat(cloud): roll up account→resource OWNS in org hierarchy (#3742 PR 1) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3743 feat(cloud): complete live EXPOSED_TO network paths (#3742 PR 2) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3744 fix(api): dedupe CIS checks per scan and surface persist failures by @msaad00 in https://github.com/msaad00/agent-bom/pull/3746 fix(deploy): SPCS native-app install blockers + deploy hardening by @msaad00 in https://github.com/msaad00/agent-bom/pull/3747 fix(ui): clean, actionable sign-in screen by @msaad00 in https://github.com/msaad00/agent-bom/pull/3748 feat(api): opt-in anonymous viewer alongside configured credentials by @msaad00 in https://github.com/msaad00/agent-bom/pull/3749 chore(deps): combine compatible July 9 dependency updates by @msaad00 in https://github.com/msaad00/agent-bom/pull/3758 feat(cloud): network entry EXPOSED_TO paths (#3742 PR 4) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3759 feat(cloud): cross-account inventory → toxic + fusion (#3742 PR 5) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3760 fix: pre-release graph-accuracy + anonymous-viewer hardening by @msaad00 in https://github.com/msaad00/agent-bom/pull/3761 docs(readme): fold intro, Quickstart next, Snowflake vendor lockup by @msaad00 in https://github.com/msaad00/agent-bom/pull/3763 chore(release): 0.94.2 by @msaad00 in https://github.com/msaad00/agent-bom/pull/3762 Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.94.1...v0.94.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/msaad00/agent-bom">https://github.com/msaad00/agent-bom</a></strong> to version <strong>v0.94.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-bom-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(cloud): roll up account→resource OWNS in org hierarchy (#3742 PR 1) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3743">https://github.com/msaad00/agent-bom/pull/3743</a></li>
<li>feat(cloud): complete live EXPOSED_TO network paths (#3742 PR 2) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3744">https://github.com/msaad00/agent-bom/pull/3744</a></li>
<li>fix(api): dedupe CIS checks per scan and surface persist failures by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3746">https://github.com/msaad00/agent-bom/pull/3746</a></li>
<li>fix(deploy): SPCS native-app install blockers + deploy hardening by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3747">https://github.com/msaad00/agent-bom/pull/3747</a></li>
<li>fix(ui): clean, actionable sign-in screen by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3748">https://github.com/msaad00/agent-bom/pull/3748</a></li>
<li>feat(api): opt-in anonymous viewer alongside configured credentials by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3749">https://github.com/msaad00/agent-bom/pull/3749</a></li>
<li>chore(deps): combine compatible July 9 dependency updates by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3758">https://github.com/msaad00/agent-bom/pull/3758</a></li>
<li>feat(cloud): network entry EXPOSED_TO paths (#3742 PR 4) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3759">https://github.com/msaad00/agent-bom/pull/3759</a></li>
<li>feat(cloud): cross-account inventory → toxic + fusion (#3742 PR 5) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3760">https://github.com/msaad00/agent-bom/pull/3760</a></li>
<li>fix: pre-release graph-accuracy + anonymous-viewer hardening by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3761">https://github.com/msaad00/agent-bom/pull/3761</a></li>
<li>docs(readme): fold intro, Quickstart next, Snowflake vendor lockup by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3763">https://github.com/msaad00/agent-bom/pull/3763</a></li>
<li>chore(release): 0.94.2 by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3762">https://github.com/msaad00/agent-bom/pull/3762</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/msaad00/agent-bom/compare/v0.94.1...v0.94.2">https://github.com/msaad00/agent-bom/compare/v0.94.1...v0.94.2</a></p>
]]></content:encoded></item><item><title>Polygraph MCP gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/polygraph-mcp-gate/</link><pubDate>Fri, 10 Jul 2026 06:24:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/polygraph-mcp-gate/</guid><description>Version updated for https://github.com/polygraphso/litmus to version litmus-v0.33.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Grading hardening: litmus-v16 (bundle schema 1.9.0).
Coverage cap with sandbox exercise. The dynamic probes skip actively calling state-changing (write) tools on the host path so the harness can’t move money or mutate real state. Under Docker isolation the target runs with no network in a throwaway sandbox, so those tools are exercised by default and a write-capable server earns A on the same terms as a read-only one. The cap fires only where a call would hit a live backend (host path or a remote https target): one high-risk tool left unexercised caps at B, and an unexercised destructive tool together with an unverified category compounds to C.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/polygraphso/litmus">https://github.com/polygraphso/litmus</a></strong> to version <strong>litmus-v0.33.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/polygraph-mcp-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Grading hardening: litmus-v16 (bundle schema 1.9.0).</p>
<p><strong>Coverage cap with sandbox exercise.</strong> The dynamic probes skip actively calling state-changing (write) tools on the host path so the harness can&rsquo;t move money or mutate real state. Under Docker isolation the target runs with no network in a throwaway sandbox, so those tools are exercised by default and a write-capable server earns A on the same terms as a read-only one. The cap fires only where a call would hit a live backend (host path or a remote https target): one high-risk tool left unexercised caps at B, and an unexercised destructive tool together with an unverified category compounds to C.</p>
<p><strong>C is now a live grade</strong> (refused by the default agent gate): a powerful server that could be neither sandboxed nor exercised.</p>
<p><strong>Tool-poisoning scanner</strong> (C-01 probe 1.1): flags agent-directed instructions hidden in a tool&rsquo;s surface (concealment directives, secret-file reads, exfil-to-sink).</p>
<p><strong>New probe 1.4, indirect / passthrough injection</strong>: feeds harness-controlled injection-laced external content into content-fetching tools and grades the relay. Verbatim relay is disclosed as a conduit (not failed); only server-generated amplification fails C-01.</p>
<p><strong>Advisory injection judge</strong>: opt-in, non-deterministic LLM judge over the tool surface, surfaced in the run summary only. Never affects the A to F letter, never minted.</p>
<p><strong>Wider corpora</strong>: more jailbreak framings, malformed shapes, runtime crash signatures, and provider-shaped canaries (AWS/GitHub/JWT).</p>
<p>v16 can move a verdict down, so unlike the v2 to v14 false-positive fixes it is not monotonic. Older attestations stay valid because methodologyVersion is a string the agent gate does not branch on.</p>
<p>Full changes in #109; version bump #113.</p>
]]></content:encoded></item><item><title>Shiro Automation</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/shiro-automation/</link><pubDate>Fri, 10 Jul 2026 06:24:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/shiro-automation/</guid><description>Version updated for https://github.com/rajitk13/shiro-automation to version v20260525-103919-ba52c2c.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed feat: add version flag with ldflags injection at build time (ba52c2c) feat: add Docker image for CI/CD with GitHub Actions build workflow (325dc30) docs: add CI validation section to README (e97bbbf) feat: add CI cross-validator to shiro validate –ci flag (88b2a44) fix: migrate GitLab CI from building from source to using pre-built GitHub releases (119737c) docs: update README with GitHub releases, subprocess modules, Jira example, fix outdated CI examples (d1b6f70) fix: update install-auto.sh to use GitHub releases instead of GitLab CI (1377cb4) refactor: remove tech debt - unused version.go, ModuleReviews struct, and .bak file (82840ec) fix: use full github.com path with @latest for go run remote packages (a5ce9c6) fix: auto-release should trigger on both main and master branches (63d37a9)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rajitk13/shiro-automation">https://github.com/rajitk13/shiro-automation</a></strong> to version <strong>v20260525-103919-ba52c2c</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/shiro-automation">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add version flag with ldflags injection at build time (ba52c2c)</li>
<li>feat: add Docker image for CI/CD with GitHub Actions build workflow (325dc30)</li>
<li>docs: add CI validation section to README (e97bbbf)</li>
<li>feat: add CI cross-validator to shiro validate &ndash;ci flag (88b2a44)</li>
<li>fix: migrate GitLab CI from building from source to using pre-built GitHub releases (119737c)</li>
<li>docs: update README with GitHub releases, subprocess modules, Jira example, fix outdated CI examples (d1b6f70)</li>
<li>fix: update install-auto.sh to use GitHub releases instead of GitLab CI (1377cb4)</li>
<li>refactor: remove tech debt - unused version.go, ModuleReviews struct, and .bak file (82840ec)</li>
<li>fix: use full github.com path with @latest for go run remote packages (a5ce9c6)</li>
<li>fix: auto-release should trigger on both main and master branches (63d37a9)</li>
</ul>
]]></content:encoded></item><item><title>Remyx Outrider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/remyx-outrider/</link><pubDate>Fri, 10 Jul 2026 06:23:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/remyx-outrider/</guid><description>Version updated for https://github.com/remyxai/outrider to version v1.7.14.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Rewrites the preflight and INVOCATION.md prompts to enumerate three legitimate implementation modes instead of a binary port-or-Issue choice.
Three modes Direct port — implement the paper’s method as-described. Requires the repo to host the paper’s full infrastructure. Adapted port — implement the paper’s core mechanism at full fidelity while substituting auxiliary components (learned estimators, bespoke optimizers, benchmark suites) with target-native equivalents (parameter-free proxies, existing library functions, scope cuts). Inspired experiment — take the paper’s core insight or framing and implement a target-native experiment drawing on it. The PR applies the paper’s idea rather than reproducing its method. Route to Issue only when all three modes fail. The coding session’s self-review must cite which mode was used and, for Modes 2/3, name the specific substitutions or reframed insight.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remyxai/outrider">https://github.com/remyxai/outrider</a></strong> to version <strong>v1.7.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/remyx-outrider">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Rewrites the preflight and INVOCATION.md prompts to enumerate three legitimate implementation modes instead of a binary port-or-Issue choice.</p>
<h2 id="three-modes">Three modes</h2>
<ol>
<li><strong>Direct port</strong> — implement the paper&rsquo;s method as-described. Requires the repo to host the paper&rsquo;s full infrastructure.</li>
<li><strong>Adapted port</strong> — implement the paper&rsquo;s <em>core mechanism</em> at full fidelity while substituting <em>auxiliary components</em> (learned estimators, bespoke optimizers, benchmark suites) with target-native equivalents (parameter-free proxies, existing library functions, scope cuts).</li>
<li><strong>Inspired experiment</strong> — take the paper&rsquo;s core <em>insight</em> or <em>framing</em> and implement a target-native experiment drawing on it. The PR applies the paper&rsquo;s idea rather than reproducing its method.</li>
</ol>
<p>Route to Issue only when all three modes fail. The coding session&rsquo;s self-review must cite which mode was used and, for Modes 2/3, name the specific substitutions or reframed insight.</p>
<h2 id="motivation">Motivation</h2>
<p>The prior rubric treated any auxiliary-infrastructure gap as a Route-to-Issue condition, biasing branch-creation rate to ~0 on targets where top-ranked candidates all bundle training subsystems the repo doesn&rsquo;t host.</p>
<h2 id="validation">Validation</h2>
<ul>
<li><strong>Diffusers A/B/C</strong>: 0 branches across baseline / v1-aux-substitution / v2. Confirmed the impedance mismatch is structural on that target class (all top candidates were training-time methods; diffusers is inference-time).</li>
<li><strong>Lerobot A/B</strong>: 0 → 1 branch. Exemplar: WorldSample&rsquo;s value-overestimation-gated-training-signal insight adapted to LeRobot&rsquo;s SAC critic ensemble via a new parameter-free <code>value_overestimation.py</code> wired into <code>_compute_loss_critic</code>. Honest self-review explicitly cites Mode 3: <em>&ldquo;This is an inspired adaptation, not a port: there is no world model and no learned scheduler.&rdquo;</em></li>
</ul>
<p>Full suite green (859/859).</p>
]]></content:encoded></item><item><title>MCPShield MCP Config Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/mcpshield-mcp-config-scan/</link><pubDate>Fri, 10 Jul 2026 06:22:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/mcpshield-mcp-config-scan/</guid><description>Version updated for https://github.com/RunTimeAdmin/mcpshield-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s new PR-comment mode (comment: true): posts a sticky findings comment on the pull request, updated in place on each run (never duplicated). Requires permissions: pull-requests: write. Stdlib-only and best-effort — a comment failure logs a warning but never fails the build. Usage: https://github.com/RunTimeAdmin/mcpshield-action#comment-on-the-pull-request</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RunTimeAdmin/mcpshield-action">https://github.com/RunTimeAdmin/mcpshield-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcpshield-mcp-config-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new">What&rsquo;s new</h2>
<ul>
<li><strong>PR-comment mode</strong> (<code>comment: true</code>): posts a sticky findings comment on the pull request, updated in place on each run (never duplicated). Requires <code>permissions: pull-requests: write</code>. Stdlib-only and best-effort — a comment failure logs a warning but never fails the build.</li>
</ul>
<p>Usage: <a href="https://github.com/RunTimeAdmin/mcpshield-action#comment-on-the-pull-request">https://github.com/RunTimeAdmin/mcpshield-action#comment-on-the-pull-request</a></p>
]]></content:encoded></item><item><title>create-agent-room Validate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/create-agent-room-validate/</link><pubDate>Fri, 10 Jul 2026 06:22:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/create-agent-room-validate/</guid><description>Version updated for https://github.com/sipandey/create-agent-room to version v2.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed create-agent-room v2.1.0 The headline of this release is a new doctor command — a read-only health check for your agent room — plus a CI safeguard against a lockfile-drift bug that bit us twice. No breaking changes; this is a clean drop-in upgrade from 2.0.x.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipandey/create-agent-room">https://github.com/sipandey/create-agent-room</a></strong> to version <strong>v2.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/create-agent-room-validate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="create-agent-room-v210">create-agent-room v2.1.0</h2>
<p>The headline of this release is a new <strong><code>doctor</code></strong> command — a read-only health check for your agent room — plus a CI safeguard against a lockfile-drift bug that bit us twice. No breaking changes; this is a clean drop-in upgrade from 2.0.x.</p>
<h3 id="-new-create-agent-room-doctor-target-dir">✨ New: <code>create-agent-room doctor [target-dir]</code></h3>
<p>A read-only health check that works <strong>whether or not <code>init</code> has ever been run</strong>, and never writes to disk.</p>
<ul>
<li><strong>No <code>.agent-room/</code> yet?</strong> It detects your workspace (language + tools) and prints the exact <code>init</code> command to run — plus an <code>init --dry-run</code> preview variant.</li>
<li><strong>Already scaffolded?</strong> It reuses <code>validate</code>&rsquo;s structural/schema checks and layers on advisory-only checks that <code>validate</code> deliberately doesn&rsquo;t do:
<ul>
<li><strong>Hook drift</strong> — <code>pre-commit</code>, <code>guardrails-check.js</code>, or <code>close-the-loop-check.js</code> no longer matching the installed CLI&rsquo;s templates (i.e. missing recent fixes).</li>
<li><strong>Stale CI pin</strong> — a scaffolded workflow pinned to <code>@latest</code> or an old <code>create-agent-room</code> version.</li>
<li><strong>Config vs. reality</strong> — <code>.agent-room.json</code> claiming a tool (<code>claude</code>, <code>git</code>) that isn&rsquo;t actually wired up on disk (e.g. the Stop hook or pre-commit hook is missing).</li>
</ul>
</li>
<li>Output is <code>🔴 Needs attention</code> / <code>🟡 Recommended</code> / <code>🟢 Looks good</code>, and it only ever <em>suggests</em> a fix command — the key difference from <code>init --force</code>, which writes.</li>
</ul>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx create-agent-room doctor .
</span></span></code></pre></div><h3 id="-added">🚀 Added</h3>
<ul>
<li><strong><code>doctor</code> command</strong> (above).</li>
<li><strong><code>npm run check:lockfile</code> CI gate</strong> — fails the build if <code>package-lock.json</code>&rsquo;s version drifts from <code>package.json</code>&rsquo;s. This exact drift slipped through twice before; now it can&rsquo;t.</li>
</ul>
<h3 id="-changed">🔧 Changed</h3>
<ul>
<li>Extracted <code>validate</code>&rsquo;s checks into a shared <code>collectFindings()</code> (<code>lib/checks.js</code>) so <code>validate</code> and <code>doctor</code> can never disagree on what counts as a structural error. <code>validate</code>&rsquo;s own behavior is unchanged.</li>
<li>Internal refactor collapsing the <code>cursor</code>/<code>windsurf</code>/<code>cline</code>/<code>codex</code> adapter blocks in <code>lib/init.js</code> into one table-driven loop. No behavior change.</li>
</ul>
<h3 id="-fixed">🐛 Fixed</h3>
<ul>
<li>The bundled <code>guardrails-check.js</code> git hook used a numeric separator (<code>1_000_000</code>) that threw a <code>SyntaxError</code> under Node &lt; 12.5. Git hooks run under whatever <code>node</code> is first on <code>PATH</code> — not necessarily your active version — so this could break commits on machines with an old system Node. Replaced with a plain literal.</li>
</ul>
<h3 id="-install--upgrade">📦 Install / upgrade</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx create-agent-room@2.1.0 init .
</span></span><span style="display:flex;"><span><span style="color:#75715e"># or, if you pin the GitHub Action, the rolling major tag now points here too:</span>
</span></span><span style="display:flex;"><span><span style="color:#75715e">#   uses: sipandey/create-agent-room@v2</span>
</span></span></code></pre></div><p><strong>Rollback:</strong> stateless CLI, no migrations — pin <code>create-agent-room@2.0.1</code> to revert.</p>
<p><strong>Full changelog:</strong> <a href="https://github.com/sipandey/create-agent-room/compare/v2.0.1...v2.1.0">https://github.com/sipandey/create-agent-room/compare/v2.0.1...v2.1.0</a></p>
]]></content:encoded></item><item><title>GitGalaxy Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/gitgalaxy-scanner/</link><pubDate>Fri, 10 Jul 2026 06:21:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/gitgalaxy-scanner/</guid><description>Version updated for https://github.com/squid-protocol/gitgalaxy to version v2.3.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Internal infrastructure release to verify the automated GitHub Actions to GitLab component catalog mirroring pipeline.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/squid-protocol/gitgalaxy">https://github.com/squid-protocol/gitgalaxy</a></strong> to version <strong>v2.3.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gitgalaxy-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Internal infrastructure release to verify the automated GitHub Actions to GitLab component catalog mirroring pipeline.</p>
]]></content:encoded></item><item><title>Setup cloudflared tunnel</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/setup-cloudflared-tunnel/</link><pubDate>Fri, 10 Jul 2026 06:21:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/setup-cloudflared-tunnel/</guid><description>Version updated for https://github.com/var-template/setup-cloudflare-tunnel to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/var-template/setup-cloudflare-tunnel/commits/v1.0.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/var-template/setup-cloudflare-tunnel">https://github.com/var-template/setup-cloudflare-tunnel</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-cloudflared-tunnel">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/var-template/setup-cloudflare-tunnel/commits/v1.0.0">https://github.com/var-template/setup-cloudflare-tunnel/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>latex2arxiv pre-flight</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/latex2arxiv-pre-flight/</link><pubDate>Fri, 10 Jul 2026 06:20:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/10/latex2arxiv-pre-flight/</guid><description>Version updated for https://github.com/YuZh98/latex2arxiv to version v1.3.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed Demo document now states its own run’s numbers correctly (file counts, warning count, page count, before/after size, title-dedup wording) and mentions \addbibresource in the dependency-tracking list</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuZh98/latex2arxiv">https://github.com/YuZh98/latex2arxiv</a></strong> to version <strong>v1.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/latex2arxiv-pre-flight">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Demo document now states its own run&rsquo;s numbers correctly (file counts, warning count, page count, before/after size, title-dedup wording) and mentions <code>\addbibresource</code> in the dependency-tracking list</li>
</ul>
]]></content:encoded></item><item><title>probelock gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/probelock-gate/</link><pubDate>Thu, 09 Jul 2026 22:45:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/probelock-gate/</guid><description>Version updated for https://github.com/kelkalot/probelock to version v0.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Add trace pipeline validation and recorder by @kelkalot in https://github.com/kelkalot/probelock/pull/4 Add trend command for N-way lockfile analysis by @kelkalot in https://github.com/kelkalot/probelock/pull/5 Add json_mode, OTEL/Anthropic ingest, embeddings by @kelkalot in https://github.com/kelkalot/probelock/pull/6 Full Changelog: https://github.com/kelkalot/probelock/compare/v0...v0.4.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kelkalot/probelock">https://github.com/kelkalot/probelock</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/probelock-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add trace pipeline validation and recorder by @kelkalot in <a href="https://github.com/kelkalot/probelock/pull/4">https://github.com/kelkalot/probelock/pull/4</a></li>
<li>Add trend command for N-way lockfile analysis by @kelkalot in <a href="https://github.com/kelkalot/probelock/pull/5">https://github.com/kelkalot/probelock/pull/5</a></li>
<li>Add json_mode, OTEL/Anthropic ingest, embeddings by @kelkalot in <a href="https://github.com/kelkalot/probelock/pull/6">https://github.com/kelkalot/probelock/pull/6</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/kelkalot/probelock/compare/v0...v0.4.0">https://github.com/kelkalot/probelock/compare/v0...v0.4.0</a></p>
]]></content:encoded></item><item><title>Kusari Ingest</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/kusari-ingest/</link><pubDate>Thu, 09 Jul 2026 22:45:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/kusari-ingest/</guid><description>Version updated for https://github.com/kusaridev/kusari-ingest to version v4.2.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed update kusari cli to version 2.6.0 by @pxp928 in https://github.com/kusaridev/kusari-ingest/pull/34 Full Changelog: https://github.com/kusaridev/kusari-ingest/compare/v4...v4.2.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kusaridev/kusari-ingest">https://github.com/kusaridev/kusari-ingest</a></strong> to version <strong>v4.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kusari-ingest">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>update kusari cli to version 2.6.0 by @pxp928 in <a href="https://github.com/kusaridev/kusari-ingest/pull/34">https://github.com/kusaridev/kusari-ingest/pull/34</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/kusaridev/kusari-ingest/compare/v4...v4.2.0">https://github.com/kusaridev/kusari-ingest/compare/v4...v4.2.0</a></p>
]]></content:encoded></item><item><title>Langfuse Experiment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/langfuse-experiment/</link><pubDate>Thu, 09 Jul 2026 22:44:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/langfuse-experiment/</guid><description>Version updated for https://github.com/langfuse/experiment-action to version v1.0.6.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed docs: pin README examples to v1.0.5 by @github-actions[bot] in https://github.com/langfuse/experiment-action/pull/68 chore(deps-dev): Bump the npm group with 5 updates by @dependabot[bot] in https://github.com/langfuse/experiment-action/pull/69 ci(deps): Bump the github-actions group with 2 updates by @dependabot[bot] in https://github.com/langfuse/experiment-action/pull/70 chore(deps-dev): Bump the npm group with 3 updates by @dependabot[bot] in https://github.com/langfuse/experiment-action/pull/71 chore(deps-dev): Bump vite from 8.0.16 to 8.1.0 in the npm group by @dependabot[bot] in https://github.com/langfuse/experiment-action/pull/72 chore(deps-dev): Bump the npm group with 2 updates by @dependabot[bot] in https://github.com/langfuse/experiment-action/pull/73 ci(deps): Bump actions/setup-python from 6.2.0 to 6.3.0 in the github-actions group by @dependabot[bot] in https://github.com/langfuse/experiment-action/pull/75 chore(deps): Bump the npm group with 4 updates by @dependabot[bot] in https://github.com/langfuse/experiment-action/pull/74 chore(deps-dev): Bump the npm group with 5 updates by @dependabot[bot] in https://github.com/langfuse/experiment-action/pull/76 chore(deps-dev): Bump the npm group with 2 updates by @dependabot[bot] in https://github.com/langfuse/experiment-action/pull/77 chore(deps-dev): Bump the npm group with 2 updates by @dependabot[bot] in https://github.com/langfuse/experiment-action/pull/79 fix(comment): stop parallel matrix legs from clobbering each other’s PR comment sections by @wochinge in https://github.com/langfuse/experiment-action/pull/80 Full Changelog: https://github.com/langfuse/experiment-action/compare/v1.0.5...v1.0.6</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/langfuse/experiment-action">https://github.com/langfuse/experiment-action</a></strong> to version <strong>v1.0.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/langfuse-experiment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs: pin README examples to v1.0.5 by @github-actions[bot] in <a href="https://github.com/langfuse/experiment-action/pull/68">https://github.com/langfuse/experiment-action/pull/68</a></li>
<li>chore(deps-dev): Bump the npm group with 5 updates by @dependabot[bot] in <a href="https://github.com/langfuse/experiment-action/pull/69">https://github.com/langfuse/experiment-action/pull/69</a></li>
<li>ci(deps): Bump the github-actions group with 2 updates by @dependabot[bot] in <a href="https://github.com/langfuse/experiment-action/pull/70">https://github.com/langfuse/experiment-action/pull/70</a></li>
<li>chore(deps-dev): Bump the npm group with 3 updates by @dependabot[bot] in <a href="https://github.com/langfuse/experiment-action/pull/71">https://github.com/langfuse/experiment-action/pull/71</a></li>
<li>chore(deps-dev): Bump vite from 8.0.16 to 8.1.0 in the npm group by @dependabot[bot] in <a href="https://github.com/langfuse/experiment-action/pull/72">https://github.com/langfuse/experiment-action/pull/72</a></li>
<li>chore(deps-dev): Bump the npm group with 2 updates by @dependabot[bot] in <a href="https://github.com/langfuse/experiment-action/pull/73">https://github.com/langfuse/experiment-action/pull/73</a></li>
<li>ci(deps): Bump actions/setup-python from 6.2.0 to 6.3.0 in the github-actions group by @dependabot[bot] in <a href="https://github.com/langfuse/experiment-action/pull/75">https://github.com/langfuse/experiment-action/pull/75</a></li>
<li>chore(deps): Bump the npm group with 4 updates by @dependabot[bot] in <a href="https://github.com/langfuse/experiment-action/pull/74">https://github.com/langfuse/experiment-action/pull/74</a></li>
<li>chore(deps-dev): Bump the npm group with 5 updates by @dependabot[bot] in <a href="https://github.com/langfuse/experiment-action/pull/76">https://github.com/langfuse/experiment-action/pull/76</a></li>
<li>chore(deps-dev): Bump the npm group with 2 updates by @dependabot[bot] in <a href="https://github.com/langfuse/experiment-action/pull/77">https://github.com/langfuse/experiment-action/pull/77</a></li>
<li>chore(deps-dev): Bump the npm group with 2 updates by @dependabot[bot] in <a href="https://github.com/langfuse/experiment-action/pull/79">https://github.com/langfuse/experiment-action/pull/79</a></li>
<li>fix(comment): stop parallel matrix legs from clobbering each other&rsquo;s PR comment sections by @wochinge in <a href="https://github.com/langfuse/experiment-action/pull/80">https://github.com/langfuse/experiment-action/pull/80</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/langfuse/experiment-action/compare/v1.0.5...v1.0.6">https://github.com/langfuse/experiment-action/compare/v1.0.5...v1.0.6</a></p>
]]></content:encoded></item><item><title>Gua Godot GDScript CI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/gua-godot-gdscript-ci/</link><pubDate>Thu, 09 Jul 2026 22:44:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/gua-godot-gdscript-ci/</guid><description>Version updated for https://github.com/link1345/gua-tester to version v1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/link1345/gua-tester/compare/v1.1...v1.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/link1345/gua-tester">https://github.com/link1345/gua-tester</a></strong> to version <strong>v1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gua-godot-gdscript-ci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/link1345/gua-tester/compare/v1.1...v1.2">https://github.com/link1345/gua-tester/compare/v1.1...v1.2</a></p>
]]></content:encoded></item><item><title>Setup Go Android Environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/setup-go-android-environment/</link><pubDate>Thu, 09 Jul 2026 22:43:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/setup-go-android-environment/</guid><description>Version updated for https://github.com/nostalgia296/setup-go-android to version v3.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 提交 (51d281b)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nostalgia296/setup-go-android">https://github.com/nostalgia296/setup-go-android</a></strong> to version <strong>v3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-go-android-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>提交 (51d281b)</li>
</ul>
]]></content:encoded></item><item><title>ObsidianWall Verdict</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/obsidianwall-verdict/</link><pubDate>Thu, 09 Jul 2026 22:42:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/obsidianwall-verdict/</guid><description>Version updated for https://github.com/ObsidianWall/obsidianwall-verdict to version v0.5.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ObsidianWall Verdict v0.5.2 Verdict becomes a governance decision engine — not just a policy checker.
What’s New verdict explain — Full Reasoning on Demand Terminal output from verdict evaluate is now a concise ~15-line summary by default. Full governance reasoning, condition traces, analyzer findings, and recommendations are one command away:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ObsidianWall/obsidianwall-verdict">https://github.com/ObsidianWall/obsidianwall-verdict</a></strong> to version <strong>v0.5.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/obsidianwall-verdict">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="obsidianwall-verdict-v052">ObsidianWall Verdict v0.5.2</h2>
<p><strong>Verdict becomes a governance decision engine — not just a policy checker.</strong></p>
<hr>
<h3 id="whats-new">What&rsquo;s New</h3>
<h4 id="verdict-explain--full-reasoning-on-demand"><code>verdict explain</code> — Full Reasoning on Demand</h4>
<p>Terminal output from <code>verdict evaluate</code> is now a concise ~15-line summary by default. Full governance reasoning, condition traces, analyzer findings, and recommendations are one command away:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>verdict evaluate --plan plan.json --policy budget.yaml
</span></span><span style="display:flex;"><span><span style="color:#75715e"># → concise decision summary + remediation</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>verdict explain &lt;decision_id&gt;
</span></span><span style="display:flex;"><span><span style="color:#75715e"># → full reasoning chain, retrieved from local evidence store</span>
</span></span></code></pre></div><p><code>verdict explain</code> reads from a dedicated evidence store, not from the <code>--output</code> file — so it works even if that file has since been overwritten by a later run.</p>
<h4 id="output-formats----format-textjsonyaml">Output Formats — <code>--format text|json|yaml</code></h4>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>verdict evaluate --plan plan.json --policy budget.yaml
</span></span><span style="display:flex;"><span>verdict evaluate --plan plan.json --policy budget.yaml --format json
</span></span><span style="display:flex;"><span>verdict evaluate --plan plan.json --policy budget.yaml --format yaml
</span></span></code></pre></div><p><code>text</code> (default) is the new concise summary. <code>json</code> preserves the full artifact for CI/CD pipelines and scripts — unchanged from prior versions. <code>yaml</code> is new. The <code>--output</code> file always contains the complete artifact regardless of which format is chosen for stdout.</p>
<h4 id="governance-objective">Governance Objective</h4>
<p>Policies can now declare the organizational outcome they exist to achieve:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">metadata</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">governance_objective</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">statement</span>: <span style="color:#e6db74">&#34;Maintain cloud spend within approved budget&#34;</span>
</span></span></code></pre></div><p>Every decision against that policy reports whether the objective was <strong>Upheld</strong>, <strong>Violated</strong>, or <strong>Pending Approval</strong> — shifting the artifact from reporting technical facts (&ldquo;budget exceeded&rdquo;) to reporting whether organizational intent held. Fully optional — existing policies work unchanged.</p>
<h4 id="evidence-store">Evidence Store</h4>
<p>Full governance artifacts are now stored separately from the lean decision ledger, in a dedicated <code>decision_artifacts</code> table. This is the foundation <code>verdict explain</code> runs on, and the same store future Sentinel and Compass evidence types (drift snapshots, SBOMs, cost reports) will use without any schema changes.</p>
<h4 id="rule-based-recommendation-confidence">Rule-Based Recommendation Confidence</h4>
<p>Recommendation confidence scores are no longer flat constants — they&rsquo;re computed per finding type, reflecting how directly a recommendation addresses the specific finding that triggered it.</p>
<hr>
<h3 id="upgrading">Upgrading</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install --upgrade obsidianwall-verdict
</span></span></code></pre></div><p>No breaking changes. Existing policies, scripts, and CI/CD pipelines using <code>--format json</code> (or the equivalent prior default) continue to work unchanged. <code>verdict evaluate</code> without <code>--format</code> now returns the concise summary instead of the full JSON artifact — add <code>--format json</code> to any script or pipeline that was parsing the old default stdout output.</p>
<hr>
<h3 id="links">Links</h3>
<ul>
<li><a href="https://pypi.org/project/obsidianwall-verdict/0.5.2/">PyPI</a></li>
<li><a href="https://obsidianwall.dev">Documentation</a></li>
<li><a href="https://programmableassurance.org">What is Programmable Assurance?</a></li>
</ul>
]]></content:encoded></item><item><title>SkillTotal AI Component Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/skilltotal-ai-component-security-scan/</link><pubDate>Thu, 09 Jul 2026 22:42:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/skilltotal-ai-component-security-scan/</guid><description>Version updated for https://github.com/pezhik/skilltotal to version v0.38.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added Scoped / least-privilege identity execution-context signal (ST-AUTH-SCOPED, ruleset 41). A new scanner detects short-lived, scoped, assumed identities — STS AssumeRole / session tokens, cloud managed / workload identity, impersonated service accounts, projected Kubernetes service-account tokens, dynamic-secret brokers — and surfaces them as the scoped_identity trait (CSA “Tool Execution Context / Least-Privilege Service Identity”). This completes the execution-context dimension: embedded_credential (Agent Service Identity, largest blast radius) → delegated_authentication (User Delegated Credentials) → scoped_identity (least privilege, smallest). Neutral capability finding (0-score); adds Capability.SCOPED_IDENTITY. Scored detection is unchanged (efficacy 100% recall / 0 FP). See RULES_CHANGELOG.md.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pezhik/skilltotal">https://github.com/pezhik/skilltotal</a></strong> to version <strong>v0.38.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skilltotal-ai-component-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>Scoped / least-privilege identity execution-context signal (<code>ST-AUTH-SCOPED</code>, ruleset 41).</strong>
A new scanner detects short-lived, scoped, assumed identities — STS AssumeRole / session tokens,
cloud managed / workload identity, impersonated service accounts, projected Kubernetes
service-account tokens, dynamic-secret brokers — and surfaces them as the <code>scoped_identity</code> trait
(CSA &ldquo;Tool Execution Context / Least-Privilege Service Identity&rdquo;). This completes the
execution-context dimension: <code>embedded_credential</code> (Agent Service Identity, largest blast radius)
→ <code>delegated_authentication</code> (User Delegated Credentials) → <code>scoped_identity</code> (least privilege,
smallest). Neutral <strong>capability finding (0-score)</strong>; adds <code>Capability.SCOPED_IDENTITY</code>. Scored
detection is unchanged (efficacy 100% recall / 0 FP). See <code>RULES_CHANGELOG.md</code>.</li>
</ul>
]]></content:encoded></item><item><title>PY Modbus Test Suite</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/py-modbus-test-suite/</link><pubDate>Thu, 09 Jul 2026 22:41:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/py-modbus-test-suite/</guid><description>Version updated for https://github.com/php-modbus/py-modbus-test-suite to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v1.0.0 — 2026-07-07 Initial Release Docker-based Modbus server simulator suite for testing Modbus clients and SCADA systems, built on pymodbus (pinned 3.13.1).
Server Infrastructure 6 pre-configured endpoints via Docker Compose from a single image: Modbus TCP (host port 502), RTU over TCP (5021), ASCII over TCP (5022), UDP (5023), Modbus/TCP Security TLS (host port 802), RTU on virtual serial via RFC2217 (5024, raw 5025). Non-root container — binds unprivileged in-container ports (5020+); canonical 502/802 come from host port mappings. Health check via python -m mbsim.healthcheck — reads hr[0] of the health device (unit 1, expected 1234), so docker compose up --wait gates on real Modbus readiness. Baked-in config and certs — GitHub Actions service containers cannot mount checkout files; override at runtime with MBSIM_MAP_B64 / MBSIM_SCENARIO_B64 or a volume on /app/config. Register Map &amp;amp; Generators YAML register map (config/default-map.yaml) defining units 1–3 with holding registers, input registers, coils and discrete inputs; multiple devices entries simulate a multi-drop bus behind one endpoint. 4 deterministic generators — ramp, sine, random_walk, toggle: tick-based, seeded per cell from the map seed — same map, same history, every run. Fault Injection Scenario YAML (config/scenarios/*.yaml) attaching deterministic faults per rule; matchers device_id, function_code, every_nth, after_n_requests, times — counting is request-order based, never wall clock. 7 fault actions — exception, no_response, truncate, corrupt (CRC/LRC/MBAP), garbage, delay, disconnect. 7 pre-configured fault services behind the faults compose profile (ports 5100–5106): tcp-silent, tcp-slow, tcp-exceptions, tcp-drop, rtu-tcp-badcrc, tcp-truncated, tcp-garbage. Health-safety guard — rules that could hit holding-register reads on the health device are rejected at startup. CI/CD GitHub Actions composite action (action.yml) for one-step CI integration — inputs services, faults, wait-timeout; output certs-dir for TLS CA pinning. Docker image published to ghcr.io/php-modbus/py-modbus-test-suite (multi-arch amd64/arm64) by .github/workflows/release.yml, gated on the smoke suite. CI-optimized compose file (docker-compose.ci.yml) with no-restart policy. Documentation Documentation in docs/ covering setup, endpoints, register map, generators, fault injection, environment variables, serial usage, and CI integration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/php-modbus/py-modbus-test-suite">https://github.com/php-modbus/py-modbus-test-suite</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/py-modbus-test-suite">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v100--2026-07-07">v1.0.0 — 2026-07-07</h2>
<h3 id="initial-release">Initial Release</h3>
<p>Docker-based Modbus server simulator suite for testing Modbus clients and
SCADA systems, built on pymodbus (pinned <code>3.13.1</code>).</p>
<h3 id="server-infrastructure">Server Infrastructure</h3>
<ul>
<li><strong>6 pre-configured endpoints</strong> via Docker Compose from a single image: Modbus TCP (host port 502), RTU over TCP (5021), ASCII over TCP (5022), UDP (5023), Modbus/TCP Security TLS (host port 802), RTU on virtual serial via RFC2217 (5024, raw 5025).</li>
<li><strong>Non-root container</strong> — binds unprivileged in-container ports (5020+); canonical 502/802 come from host port mappings.</li>
<li><strong>Health check</strong> via <code>python -m mbsim.healthcheck</code> — reads <code>hr[0]</code> of the health device (unit 1, expected <code>1234</code>), so <code>docker compose up --wait</code> gates on real Modbus readiness.</li>
<li><strong>Baked-in config and certs</strong> — GitHub Actions service containers cannot mount checkout files; override at runtime with <code>MBSIM_MAP_B64</code> / <code>MBSIM_SCENARIO_B64</code> or a volume on <code>/app/config</code>.</li>
</ul>
<h3 id="register-map--generators">Register Map &amp; Generators</h3>
<ul>
<li><strong>YAML register map</strong> (<code>config/default-map.yaml</code>) defining units 1–3 with holding registers, input registers, coils and discrete inputs; multiple <code>devices</code> entries simulate a multi-drop bus behind one endpoint.</li>
<li><strong>4 deterministic generators</strong> — <code>ramp</code>, <code>sine</code>, <code>random_walk</code>, <code>toggle</code>: tick-based, seeded per cell from the map <code>seed</code> — same map, same history, every run.</li>
</ul>
<h3 id="fault-injection">Fault Injection</h3>
<ul>
<li><strong>Scenario YAML</strong> (<code>config/scenarios/*.yaml</code>) attaching deterministic faults per rule; matchers <code>device_id</code>, <code>function_code</code>, <code>every_nth</code>, <code>after_n_requests</code>, <code>times</code> — counting is request-order based, never wall clock.</li>
<li><strong>7 fault actions</strong> — <code>exception</code>, <code>no_response</code>, <code>truncate</code>, <code>corrupt</code> (CRC/LRC/MBAP), <code>garbage</code>, <code>delay</code>, <code>disconnect</code>.</li>
<li><strong>7 pre-configured fault services</strong> behind the <code>faults</code> compose profile (ports 5100–5106): <code>tcp-silent</code>, <code>tcp-slow</code>, <code>tcp-exceptions</code>, <code>tcp-drop</code>, <code>rtu-tcp-badcrc</code>, <code>tcp-truncated</code>, <code>tcp-garbage</code>.</li>
<li><strong>Health-safety guard</strong> — rules that could hit holding-register reads on the health device are rejected at startup.</li>
</ul>
<h3 id="cicd">CI/CD</h3>
<ul>
<li><strong>GitHub Actions composite action</strong> (<code>action.yml</code>) for one-step CI integration — inputs <code>services</code>, <code>faults</code>, <code>wait-timeout</code>; output <code>certs-dir</code> for TLS CA pinning.</li>
<li><strong>Docker image</strong> published to <code>ghcr.io/php-modbus/py-modbus-test-suite</code> (multi-arch amd64/arm64) by <code>.github/workflows/release.yml</code>, gated on the smoke suite.</li>
<li><strong>CI-optimized compose file</strong> (<code>docker-compose.ci.yml</code>) with no-restart policy.</li>
</ul>
<h3 id="documentation">Documentation</h3>
<ul>
<li>Documentation in <code>docs/</code> covering setup, endpoints, register map, generators, fault injection, environment variables, serial usage, and CI integration.</li>
</ul>
]]></content:encoded></item><item><title>Polygraph MCP gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/polygraph-mcp-gate/</link><pubDate>Thu, 09 Jul 2026 22:40:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/polygraph-mcp-gate/</guid><description>Version updated for https://github.com/polygraphso/litmus to version litmus-v0.32.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Ships litmus-v15: the C-02 egress baseline now includes public package-registry infrastructure (pypi.org, files.pythonhosted.org, registry.npmjs.org), so a framework’s default startup update-check — chiefly FastMCP pinging pypi.org for a newer version — is no longer scored as the server’s egress overreach. The cloud instance-metadata endpoint stays flagged (a real credential-theft target).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/polygraphso/litmus">https://github.com/polygraphso/litmus</a></strong> to version <strong>litmus-v0.32.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/polygraph-mcp-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Ships <strong>litmus-v15</strong>: the C-02 egress baseline now includes public package-registry infrastructure (<code>pypi.org</code>, <code>files.pythonhosted.org</code>, <code>registry.npmjs.org</code>), so a framework&rsquo;s default startup update-check — chiefly FastMCP pinging <code>pypi.org</code> for a newer version — is no longer scored as the server&rsquo;s egress overreach. The cloud instance-metadata endpoint stays flagged (a real credential-theft target).</p>
<p>Fixes the dominant C-02 false-positive class for FastMCP-based servers. See #110 (analysis) and #111 (fix).</p>
]]></content:encoded></item><item><title>Build &amp; Push to Registry</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/build-push-to-registry/</link><pubDate>Thu, 09 Jul 2026 22:40:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/build-push-to-registry/</guid><description>Version updated for https://github.com/relybytes/actions-docker-build-push to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/relybytes/actions-docker-build-push/compare/v1.0.0...v1.0.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/relybytes/actions-docker-build-push">https://github.com/relybytes/actions-docker-build-push</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/build-push-to-registry">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/relybytes/actions-docker-build-push/compare/v1.0.0...v1.0.1">https://github.com/relybytes/actions-docker-build-push/compare/v1.0.0...v1.0.1</a></p>
]]></content:encoded></item><item><title>spec.md check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/spec.md-check/</link><pubDate>Thu, 09 Jul 2026 22:39:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/spec.md-check/</guid><description>Version updated for https://github.com/rosenjcb/spec.md to version v0.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Merge pull request #4 from rosenjcb/claude/spec-signoff-feedback-9ei975 (72589a5) Triage moves to the front of the skill; distribution stays manual (4891b3c) Teach the skill and commands the review lifecycle (7222102) Review records become OKF documents; approval state moves to the review (05e082e) Per-stakeholder briefings replace generic section links (dd9b819) Scope each reviewer’s reading with a Read column of deep links (e53ca5d) Replace prior-art essay with a further-reading appendix (b78a6e4) De-emphasize DACI: name it once, drop the framework comparison (cef6e39) Purge comma-splitting from frontmatter parsing (ab840ae) Purge all mentions of comma-separated frontmatter strings (4e9aa2c)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rosenjcb/spec.md">https://github.com/rosenjcb/spec.md</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spec-md-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Merge pull request #4 from rosenjcb/claude/spec-signoff-feedback-9ei975 (72589a5)</li>
<li>Triage moves to the front of the skill; distribution stays manual (4891b3c)</li>
<li>Teach the skill and commands the review lifecycle (7222102)</li>
<li>Review records become OKF documents; approval state moves to the review (05e082e)</li>
<li>Per-stakeholder briefings replace generic section links (dd9b819)</li>
<li>Scope each reviewer&rsquo;s reading with a Read column of deep links (e53ca5d)</li>
<li>Replace prior-art essay with a further-reading appendix (b78a6e4)</li>
<li>De-emphasize DACI: name it once, drop the framework comparison (cef6e39)</li>
<li>Purge comma-splitting from frontmatter parsing (ab840ae)</li>
<li>Purge all mentions of comma-separated frontmatter strings (4e9aa2c)</li>
</ul>
]]></content:encoded></item><item><title>Podcast Generator by Russel Tjahjadi</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/podcast-generator-by-russel-tjahjadi/</link><pubDate>Thu, 09 Jul 2026 22:39:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/podcast-generator-by-russel-tjahjadi/</guid><description>Version updated for https://github.com/russeltjahjadi/podcast-generator to version v.10.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/russeltjahjadi/podcast-generator/commits/v.10
This is a project that I have been following along by Ray Villalobos</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/russeltjahjadi/podcast-generator">https://github.com/russeltjahjadi/podcast-generator</a></strong> to version <strong>v.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/podcast-generator-by-russel-tjahjadi">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/russeltjahjadi/podcast-generator/commits/v.10">https://github.com/russeltjahjadi/podcast-generator/commits/v.10</a></p>
<p>This is a project that I have been following along by Ray Villalobos</p>
]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/rumdl-action/</link><pubDate>Thu, 09 Jul 2026 22:38:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.30.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added MD007: clamp explicit fixed-style indent under ordered parents (1f3a32d) Fixed lint-context: keep lazy continuation lines in their list block (a17f0af) Downloads File Platform Checksum rumdl-v0.2.30-x86_64-unknown-linux-gnu.tar.gz Linux x86_64 checksum rumdl-v0.2.30-x86_64-unknown-linux-musl.tar.gz Linux x86_64 (musl) checksum rumdl-v0.2.30-aarch64-unknown-linux-gnu.tar.gz Linux ARM64 checksum rumdl-v0.2.30-aarch64-unknown-linux-musl.tar.gz Linux ARM64 (musl) checksum rumdl-v0.2.30-x86_64-apple-darwin.tar.gz macOS x86_64 checksum rumdl-v0.2.30-aarch64-apple-darwin.tar.gz macOS ARM64 (Apple Silicon) checksum rumdl-v0.2.30-x86_64-pc-windows-msvc.zip Windows x86_64 checksum Installation Using uv (Recommended) uv tool install rumdl Using pip pip install rumdl Using pipx pipx install rumdl Direct Download Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.30</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>MD007</strong>: clamp explicit fixed-style indent under ordered parents (<a href="https://github.com/rvben/rumdl/commit/1f3a32df48f8983fc49fafbc6d6a00743dda763b">1f3a32d</a>)</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>lint-context</strong>: keep lazy continuation lines in their list block (<a href="https://github.com/rvben/rumdl/commit/a17f0af7b7d9c2ab71b7416472f05bb00f928d96">a17f0af</a>)</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.30/rumdl-v0.2.30-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.30-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.30/rumdl-v0.2.30-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.30/rumdl-v0.2.30-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.30-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.30/rumdl-v0.2.30-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.30/rumdl-v0.2.30-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.30-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.30/rumdl-v0.2.30-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.30/rumdl-v0.2.30-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.30-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.30/rumdl-v0.2.30-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.30/rumdl-v0.2.30-x86_64-apple-darwin.tar.gz">rumdl-v0.2.30-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.30/rumdl-v0.2.30-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.30/rumdl-v0.2.30-aarch64-apple-darwin.tar.gz">rumdl-v0.2.30-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.30/rumdl-v0.2.30-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.30/rumdl-v0.2.30-x86_64-pc-windows-msvc.zip">rumdl-v0.2.30-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.30/rumdl-v0.2.30-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>memi design CI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/memi-design-ci/</link><pubDate>Thu, 09 Jul 2026 22:38:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/memi-design-ci/</guid><description>Version updated for https://github.com/sarveshsea/memi to version v2.4.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Highlights GitHub Action Marketplace-ready: action.yml description shortened to 122 characters (Marketplace ≤125 limit). Branding: layout / purple. CLI pin: Action default version installs published @memi-design/cli@2.4.0 (npm 2.4.1 publish is blocked on registry auth — package metadata in-repo is already 2.4.1). Grok Build (Grok 4.5): memi agent install grok-build writes native .grok/config.toml + .grok/skills/ (plus .agents/skills/ mirror). Skills ecosystem: agent-first packaging patterns adapted from emilkowalski/skills with explicit craft-skill dependency links (no content copy). Marketplace publish (manual UI step remaining) gh cannot set Marketplace categories. Finish here:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sarveshsea/memi">https://github.com/sarveshsea/memi</a></strong> to version <strong>v2.4.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/memi-design-ci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>GitHub Action Marketplace-ready:</strong> <code>action.yml</code> description shortened to 122 characters (Marketplace ≤125 limit). Branding: <code>layout</code> / <code>purple</code>.</li>
<li><strong>CLI pin:</strong> Action default <code>version</code> installs published <code>@memi-design/cli@2.4.0</code> (npm <code>2.4.1</code> publish is blocked on registry auth — package metadata in-repo is already <code>2.4.1</code>).</li>
<li><strong>Grok Build (Grok 4.5):</strong> <code>memi agent install grok-build</code> writes native <code>.grok/config.toml</code> + <code>.grok/skills/</code> (plus <code>.agents/skills/</code> mirror).</li>
<li><strong>Skills ecosystem:</strong> agent-first packaging patterns adapted from <a href="https://github.com/emilkowalski/skills">emilkowalski/skills</a> with explicit craft-skill dependency links (no content copy).</li>
</ul>
<h2 id="marketplace-publish-manual-ui-step-remaining">Marketplace publish (manual UI step remaining)</h2>
<p><code>gh</code> cannot set Marketplace categories. Finish here:</p>
<ol>
<li>Open <a href="https://github.com/sarveshsea/memi/releases/tag/v2.4.1">https://github.com/sarveshsea/memi/releases/tag/v2.4.1</a></li>
<li>Edit release → check <strong>Publish this Action to the GitHub Marketplace</strong></li>
<li>Primary: <strong>Code quality</strong> · Secondary: <strong>Continuous integration</strong></li>
<li>Confirm validation green → Publish</li>
</ol>
<p>Floating major tag <code>v2</code> already points at <code>v2.4.1</code>.</p>
<h2 id="install">Install</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npm i -g @memi-design/cli@2.4.0
</span></span><span style="display:flex;"><span>uses: sarveshsea/memi@v2.4.1
</span></span><span style="display:flex;"><span>memi agent install grok-build --project .
</span></span></code></pre></div><p>Full notes: CHANGELOG.md</p>
]]></content:encoded></item><item><title>JS Recon</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/js-recon/</link><pubDate>Thu, 09 Jul 2026 22:37:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/js-recon/</guid><description>Version updated for https://github.com/shriyanss/js-recon-action to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added Publish action on GitHub marketplace</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/shriyanss/js-recon-action">https://github.com/shriyanss/js-recon-action</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/js-recon">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="added">Added</h2>
<ul>
<li>Publish action on GitHub marketplace</li>
</ul>
]]></content:encoded></item><item><title>create-agent-room Validate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/create-agent-room-validate/</link><pubDate>Thu, 09 Jul 2026 22:36:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/create-agent-room-validate/</guid><description>Version updated for https://github.com/sipandey/create-agent-room to version v2.0.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/sipandey/create-agent-room/compare/v1.3.1...v2.0.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipandey/create-agent-room">https://github.com/sipandey/create-agent-room</a></strong> to version <strong>v2.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/create-agent-room-validate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sipandey/create-agent-room/compare/v1.3.1...v2.0.1">https://github.com/sipandey/create-agent-room/compare/v1.3.1...v2.0.1</a></p>
]]></content:encoded></item><item><title>Snowflake Flow Diff</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/snowflake-flow-diff/</link><pubDate>Thu, 09 Jul 2026 22:36:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/snowflake-flow-diff/</guid><description>Version updated for https://github.com/Snowflake-Labs/snowflake-flow-diff to version v0.0.24.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Configure Dependabot for Maven in flow-diff directory by @sfc-gh-pvillard in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/62 Bump org.apache.maven.plugins:maven-shade-plugin from 3.6.1 to 3.6.2 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/64 Bump org.apache.nifi:nifi-api from 2.6.0 to 2.7.0 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/65 Bump jackson.version from 2.21.1 to 2.21.2 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/67 Bump org.apache.nifi:nifi-api from 2.7.0 to 2.8.0 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/68 Bump nifi-framework.version from 2.8.0 to 2.9.0 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/69 Bump jackson.version from 2.21.2 to 2.21.3 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/70 Bump org.slf4j:slf4j-nop from 2.0.17 to 2.0.18 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/71 Bump junit.version from 6.0.3 to 6.1.0 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/72 Bump jackson.version from 2.21.3 to 2.22.0 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/73 Bump org.apache.nifi:nifi-api from 2.8.0 to 2.9.0 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/74 Bump junit.version from 6.1.0 to 6.1.1 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/80 Group diff output by process group by @sfc-gh-pvillard in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/76 Adding support for checkstyle rules to enforce naming conventions by @sfc-gh-pvillard in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/66 Bump nifi-framework.version from 2.9.0 to 2.10.0 in /flow-diff by @dependabot[bot] in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/79 Detect duplicate JSON keys in flow files by @sfc-gh-pvillard in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/78 New Contributors @dependabot[bot] made their first contribution in https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/64 Full Changelog: https://github.com/Snowflake-Labs/snowflake-flow-diff/compare/v0...v0.0.24</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Snowflake-Labs/snowflake-flow-diff">https://github.com/Snowflake-Labs/snowflake-flow-diff</a></strong> to version <strong>v0.0.24</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/snowflake-flow-diff">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Configure Dependabot for Maven in flow-diff directory by @sfc-gh-pvillard in <a href="https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/62">https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/62</a></li>
<li>Bump org.apache.maven.plugins:maven-shade-plugin from 3.6.1 to 3.6.2 in /flow-diff by @dependabot[bot] in <a href="https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/64">https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/64</a></li>
<li>Bump org.apache.nifi:nifi-api from 2.6.0 to 2.7.0 in /flow-diff by @dependabot[bot] in <a href="https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/65">https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/65</a></li>
<li>Bump jackson.version from 2.21.1 to 2.21.2 in /flow-diff by @dependabot[bot] in <a href="https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/67">https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/67</a></li>
<li>Bump org.apache.nifi:nifi-api from 2.7.0 to 2.8.0 in /flow-diff by @dependabot[bot] in <a href="https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/68">https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/68</a></li>
<li>Bump nifi-framework.version from 2.8.0 to 2.9.0 in /flow-diff by @dependabot[bot] in <a href="https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/69">https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/69</a></li>
<li>Bump jackson.version from 2.21.2 to 2.21.3 in /flow-diff by @dependabot[bot] in <a href="https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/70">https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/70</a></li>
<li>Bump org.slf4j:slf4j-nop from 2.0.17 to 2.0.18 in /flow-diff by @dependabot[bot] in <a href="https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/71">https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/71</a></li>
<li>Bump junit.version from 6.0.3 to 6.1.0 in /flow-diff by @dependabot[bot] in <a href="https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/72">https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/72</a></li>
<li>Bump jackson.version from 2.21.3 to 2.22.0 in /flow-diff by @dependabot[bot] in <a href="https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/73">https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/73</a></li>
<li>Bump org.apache.nifi:nifi-api from 2.8.0 to 2.9.0 in /flow-diff by @dependabot[bot] in <a href="https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/74">https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/74</a></li>
<li>Bump junit.version from 6.1.0 to 6.1.1 in /flow-diff by @dependabot[bot] in <a href="https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/80">https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/80</a></li>
<li>Group diff output by process group by @sfc-gh-pvillard in <a href="https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/76">https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/76</a></li>
<li>Adding support for checkstyle rules to enforce naming conventions by @sfc-gh-pvillard in <a href="https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/66">https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/66</a></li>
<li>Bump nifi-framework.version from 2.9.0 to 2.10.0 in /flow-diff by @dependabot[bot] in <a href="https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/79">https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/79</a></li>
<li>Detect duplicate JSON keys in flow files by @sfc-gh-pvillard in <a href="https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/78">https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/78</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/64">https://github.com/Snowflake-Labs/snowflake-flow-diff/pull/64</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Snowflake-Labs/snowflake-flow-diff/compare/v0...v0.0.24">https://github.com/Snowflake-Labs/snowflake-flow-diff/compare/v0...v0.0.24</a></p>
]]></content:encoded></item><item><title>Snowflake Actions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/snowflake-actions/</link><pubDate>Thu, 09 Jul 2026 22:35:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/snowflake-actions/</guid><description>Version updated for https://github.com/snowflakedb/snowflake-actions to version v3.1.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by ? repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Snowflake Actions v3.1.0
New Cortex Code and DCM composite actions, a shared-script install foundation, and auth-type telemetry.
Highlights Cortex Code action (cortex-code/): install the Cortex Code (CoCo) CLI and auto-configure a connection from the parent action’s OIDC flow. (#12, #15) DCM composite actions (dcm/): parse-manifest, connection-test, plan, and deploy for building Snowflake DCM CI/CD pipelines, with color-coded plan summaries and PR comments. (#19, #20) snowflake-cli leaf action + shared scripts/: install / OIDC-minting / env-setup logic extracted into reusable scripts, sourced from a single-source VERSION file. (#14, #15) Auth-type telemetry: SF_CICD_AUTH_TYPE=oidc exported when use-oidc is enabled, so the CLI records which auth type this action configured. (#10) Docs Improved README intro, OIDC example, and how-it-works; documented the DCM actions and env-var vs config.toml auth. (#8, #9) Usage: uses: snowflakedb/snowflake-actions@v3</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/snowflakedb/snowflake-actions">https://github.com/snowflakedb/snowflake-actions</a></strong> to version <strong>v3.1.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>?</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/snowflake-actions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Snowflake Actions v3.1.0</strong></p>
<p>New Cortex Code and DCM composite actions, a shared-script install foundation, and auth-type telemetry.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>Cortex Code action</strong> (<code>cortex-code/</code>): install the Cortex Code (CoCo) CLI and auto-configure a connection from the parent action&rsquo;s OIDC flow. (#12, #15)</li>
<li><strong>DCM composite actions</strong> (<code>dcm/</code>): <code>parse-manifest</code>, <code>connection-test</code>, <code>plan</code>, and <code>deploy</code> for building Snowflake DCM CI/CD pipelines, with color-coded plan summaries and PR comments. (#19, #20)</li>
<li><strong><code>snowflake-cli</code> leaf action + shared <code>scripts/</code></strong>: install / OIDC-minting / env-setup logic extracted into reusable scripts, sourced from a single-source <code>VERSION</code> file. (#14, #15)</li>
<li><strong>Auth-type telemetry</strong>: <code>SF_CICD_AUTH_TYPE=oidc</code> exported when <code>use-oidc</code> is enabled, so the CLI records which auth type this action configured. (#10)</li>
</ul>
<h2 id="docs">Docs</h2>
<ul>
<li>Improved README intro, OIDC example, and how-it-works; documented the DCM actions and env-var vs <code>config.toml</code> auth. (#8, #9)</li>
</ul>
<p><strong>Usage:</strong> <code>uses: snowflakedb/snowflake-actions@v3</code></p>
<p><strong>Full changelog</strong>: <a href="https://github.com/snowflakedb/snowflake-actions/compare/v3.0.0...v3.1.0">https://github.com/snowflakedb/snowflake-actions/compare/v3.0.0...v3.1.0</a></p>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/ssg-static-site-generator/</link><pubDate>Thu, 09 Jul 2026 22:35:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.7.15.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Installation Quick Install (Linux/macOS) curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash Package Managers Homebrew: brew install spagu/tap/ssg Snap: snap install ssg Debian/Ubuntu: Download .deb file below Fedora/RHEL: Download .rpm file below Checksums See checksums.sha256 for file verification.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.7.15</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(1.7.14): Go 1.26.5 CVE, Scorecard hardening, #8 static passthrough, GO-005/SEC-011 by @spagu in <a href="https://github.com/spagu/ssg/pull/16">https://github.com/spagu/ssg/pull/16</a></li>
<li>fix(1.7.15): audit hardening — SEC-006/008/009/010/012 + GO-003/004/008 by @spagu in <a href="https://github.com/spagu/ssg/pull/17">https://github.com/spagu/ssg/pull/17</a></li>
<li>fix(snap): plugin nil to survive go1.26.5 toolchain fetch by @spagu in <a href="https://github.com/spagu/ssg/pull/18">https://github.com/spagu/ssg/pull/18</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.7.14...v1.7.15">https://github.com/spagu/ssg/compare/v1.7.14...v1.7.15</a></p>
]]></content:encoded></item><item><title>Deploy to Vercel</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/deploy-to-vercel/</link><pubDate>Thu, 09 Jul 2026 22:34:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/deploy-to-vercel/</guid><description>Version updated for https://github.com/Spectra010s/d-vercel to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed d-vercel v1.0.0 Initial release of d-vercel — a GitHub Action for deploying projects to Vercel directly from GitHub Actions.
Features Deploy to Vercel from GitHub Actions workflows Support preview and production deployments Configure Vercel organization and project IDs Automatically capture deployment URLs Add/update deployment comments on pull requests Customizable deployment options Usage See the README.md for setup instructions and workflow examples.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Spectra010s/d-vercel">https://github.com/Spectra010s/d-vercel</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deploy-to-vercel">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="d-vercel-v100">d-vercel v1.0.0</h1>
<p>Initial release of d-vercel — a GitHub Action for deploying projects to Vercel directly from GitHub Actions.</p>
<h2 id="features">Features</h2>
<ul>
<li>Deploy to Vercel from GitHub Actions workflows</li>
<li>Support preview and production deployments</li>
<li>Configure Vercel organization and project IDs</li>
<li>Automatically capture deployment URLs</li>
<li>Add/update deployment comments on pull requests</li>
<li>Customizable deployment options</li>
</ul>
<h2 id="usage">Usage</h2>
<p>See the <a href="./README.md">README.md</a> for setup instructions and workflow examples.</p>
<h2 id="notes">Notes</h2>
<p>This is the first stable release.</p>
]]></content:encoded></item><item><title>rsync action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/rsync-action/</link><pubDate>Thu, 09 Jul 2026 22:34:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/rsync-action/</guid><description>Version updated for https://github.com/spotdemo4/rsync-action to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed bump: v0.0.2 -&amp;gt; v0.1.0 (387847b) feat(action): remove local path after successful post-job push (00f83f5) ci(checks): switch workflows to nix-init and codex cli (c18267b) ci(workflow): add codex action step to check pipelines (a8db651) build(flake): drop rsync override and refresh lock inputs (cdd7044) chore(deps): update spotdemo4/nix-init action to v1.56.0 (#6) (658c8c5) chore(deps): update dependency @types/node to ^24.13.3 (#5) (6704097) chore(deps): lock file maintenance (#4) (25a86a5) chore(deps): update spotdemo4/nix-init action to v1.55.0 (#3) (918d77e) docs(readme): refresh badges and trim rsync README text (fd21ad0)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spotdemo4/rsync-action">https://github.com/spotdemo4/rsync-action</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rsync-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>bump: v0.0.2 -&gt; v0.1.0 (387847b)</li>
<li>feat(action): remove local path after successful post-job push (00f83f5)</li>
<li>ci(checks): switch workflows to nix-init and codex cli (c18267b)</li>
<li>ci(workflow): add codex action step to check pipelines (a8db651)</li>
<li>build(flake): drop rsync override and refresh lock inputs (cdd7044)</li>
<li>chore(deps): update spotdemo4/nix-init action to v1.56.0 (#6) (658c8c5)</li>
<li>chore(deps): update dependency @types/node to ^24.13.3 (#5) (6704097)</li>
<li>chore(deps): lock file maintenance (#4) (25a86a5)</li>
<li>chore(deps): update spotdemo4/nix-init action to v1.55.0 (#3) (918d77e)</li>
<li>docs(readme): refresh badges and trim rsync README text (fd21ad0)</li>
</ul>
]]></content:encoded></item><item><title>Downstream Breakage Radar</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/downstream-breakage-radar/</link><pubDate>Thu, 09 Jul 2026 22:33:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/downstream-breakage-radar/</guid><description>Version updated for https://github.com/Tahiram32/downstream-breakage-radar to version v0.5.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed The Enterprise Upgrade (v0.5.0) 🚀 This major update adds powerful compliance, customization, and deprecation lifecycle controls for developers and organizations.
🌟 New Features ⚠️ Deprecation Checker — When a public function or class is removed, the tool checks the base branch to see if it was marked with a deprecation warning first. Pre-deprecated removals are downgraded to medium severity; surprise removals stay high. 🛡️ SARIF Output (--format sarif) — Export results in standardized SARIF JSON format for integration with GitHub’s native Security / Code Scanning dashboard. 📝 API Changelog Generator (--changelog) — Generates a clean breakage-radar-changelog.md listing every public addition, removal, and signature change across Python, Go, and JS/TS files. ⚙️ In-Manifest Configuration — Configure ignored paths, public directories, and severity overrides directly inside pyproject.toml or a breakage-radar.json file — no CLI flags required. 📦 Install / Upgrade pip install --upgrade downstream-breakage-radar 🔧 Usage - name: Scan for breaking changes uses: Tahiram32/downstream-breakage-radar@v0.5.0 with: base-ref: origin/main format: markdown fail-on: high changelog: true 📄 Docs Full documentation and configuration reference: https://tahiram32.github.io/downstream-breakage-radar/</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tahiram32/downstream-breakage-radar">https://github.com/Tahiram32/downstream-breakage-radar</a></strong> to version <strong>v0.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/downstream-breakage-radar">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="the-enterprise-upgrade-v050-">The Enterprise Upgrade (v0.5.0) 🚀</h2>
<p>This major update adds powerful compliance, customization, and deprecation lifecycle controls for developers and organizations.</p>
<h3 id="-new-features">🌟 New Features</h3>
<ul>
<li><strong>⚠️ Deprecation Checker</strong> — When a public function or class is removed, the tool checks the base branch to see if it was marked with a deprecation warning first. Pre-deprecated removals are downgraded to <code>medium</code> severity; surprise removals stay <code>high</code>.</li>
<li><strong>🛡️ SARIF Output (<code>--format sarif</code>)</strong> — Export results in standardized SARIF JSON format for integration with GitHub&rsquo;s native Security / Code Scanning dashboard.</li>
<li><strong>📝 API Changelog Generator (<code>--changelog</code>)</strong> — Generates a clean <code>breakage-radar-changelog.md</code> listing every public addition, removal, and signature change across Python, Go, and JS/TS files.</li>
<li><strong>⚙️ In-Manifest Configuration</strong> — Configure ignored paths, public directories, and severity overrides directly inside <code>pyproject.toml</code> or a <code>breakage-radar.json</code> file — no CLI flags required.</li>
</ul>
<h3 id="-install--upgrade">📦 Install / Upgrade</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install --upgrade downstream-breakage-radar
</span></span></code></pre></div><h3 id="-usage">🔧 Usage</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">name</span>: <span style="color:#ae81ff">Scan for breaking changes</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Tahiram32/downstream-breakage-radar@v0.5.0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">base-ref</span>: <span style="color:#ae81ff">origin/main</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">format</span>: <span style="color:#ae81ff">markdown</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">changelog</span>: <span style="color:#66d9ef">true</span>
</span></span></code></pre></div><h3 id="-docs">📄 Docs</h3>
<p>Full documentation and configuration reference: <a href="https://tahiram32.github.io/downstream-breakage-radar/">https://tahiram32.github.io/downstream-breakage-radar/</a></p>
]]></content:encoded></item><item><title>tmas-scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/tmas-scan/</link><pubDate>Thu, 09 Jul 2026 22:33:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/tmas-scan/</guid><description>Version updated for https://github.com/trendmicro/tmas-scan-action to version v3.2.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Security hardening of TMAS binary download.
Note: New dependency required for GitHub Action runner environments
sha256sum (from GNU coreutils) or shasum</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/trendmicro/tmas-scan-action">https://github.com/trendmicro/tmas-scan-action</a></strong> to version <strong>v3.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tmas-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<p>Security hardening of TMAS binary download.</p>
<p><em>Note</em>: New dependency required for GitHub Action runner environments</p>
<ul>
<li>sha256sum (from GNU coreutils) or shasum</li>
</ul>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/vibgrate-scan/</link><pubDate>Thu, 09 Jul 2026 22:32:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.709.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Vibgrate CLI 2026.709.2 Released 2026-07-09
This release of the Vibgrate CLI introduces significant improvements to the search_symbols command and enhances the vg serve functionality. Performance optimizations have also been implemented for better efficiency in large repositories.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.709.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20267092">Vibgrate CLI 2026.709.2</h1>
<p><em>Released 2026-07-09</em></p>
<p>This release of the Vibgrate CLI introduces significant improvements to the <code>search_symbols</code> command and enhances the <code>vg serve</code> functionality. Performance optimizations have also been implemented for better efficiency in large repositories.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="improved">Improved</h3>
<ul>
<li><code>search_symbols</code> now performs a complete literal-string sweep for multi-word queries and provides confirmation when all matches are found.</li>
<li><code>vg serve</code> updates the code map before starting, ensuring that the AI&rsquo;s first query reflects the current state of the code.</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li>Literal-string sweeps in <code>search_symbols</code> are significantly faster on large repositories, running in parallel across CPU cores and utilizing ripgrep when available.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.709.1, interleaved on one runner against the pinned corpus (157 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>18816 count</td>
          <td>18816 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>7480 count</td>
          <td>7480 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.97 ratio</td>
          <td>0.97 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>480.30 ms</td>
          <td>472.90 ms</td>
      </tr>
  </tbody>
</table>
<p>No regressions against the previous release.</p>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.709.2">https://vibgrate.com/changelog/cli/2026.709.2</a></p>
]]></content:encoded></item><item><title>Install Zig</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/install-zig/</link><pubDate>Thu, 09 Jul 2026 22:32:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/install-zig/</guid><description>Version updated for https://github.com/xyzzylabs/setup-zig to version v1.0.2.
This action is used across all versions by 4 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.0.2 (2026-07-09) Fixed deps: bump @actions/cache to 6.1.0 to resolve undici advisory (#7) (ed5b607) Documentation correct README claim that dist/ is not committed (#3) (81642f2)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/xyzzylabs/setup-zig">https://github.com/xyzzylabs/setup-zig</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-zig">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="102-2026-07-09"><a href="https://github.com/xyzzylabs/setup-zig/compare/v1.0.1...v1.0.2">1.0.2</a> (2026-07-09)</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>deps:</strong> bump @actions/cache to 6.1.0 to resolve undici advisory (<a href="https://github.com/xyzzylabs/setup-zig/issues/7">#7</a>) (<a href="https://github.com/xyzzylabs/setup-zig/commit/ed5b6073162f03f30994d993024b65f836dbecd7">ed5b607</a>)</li>
</ul>
<h3 id="documentation">Documentation</h3>
<ul>
<li>correct README claim that dist/ is not committed (<a href="https://github.com/xyzzylabs/setup-zig/issues/3">#3</a>) (<a href="https://github.com/xyzzylabs/setup-zig/commit/81642f230e83bc7d737b02d5b4144696304b3518">81642f2</a>)</li>
</ul>
]]></content:encoded></item><item><title>GHCR Cleanup Manager</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/ghcr-cleanup-manager/</link><pubDate>Thu, 09 Jul 2026 07:04:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/ghcr-cleanup-manager/</guid><description>Version updated for https://github.com/ghcr-manager/ghcr-cleanup-manager to version v1.1.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump the github-actions group with 4 updates by @dependabot[bot] in https://github.com/ghcr-manager/ghcr-cleanup-manager/pull/8 Bump the npm group across 1 directory with 6 updates by @dependabot[bot] in https://github.com/ghcr-manager/ghcr-cleanup-manager/pull/9 Full Changelog: https://github.com/ghcr-manager/ghcr-cleanup-manager/compare/v1.1.5...v1.1.6</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ghcr-manager/ghcr-cleanup-manager">https://github.com/ghcr-manager/ghcr-cleanup-manager</a></strong> to version <strong>v1.1.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ghcr-cleanup-manager">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump the github-actions group with 4 updates by @dependabot[bot] in <a href="https://github.com/ghcr-manager/ghcr-cleanup-manager/pull/8">https://github.com/ghcr-manager/ghcr-cleanup-manager/pull/8</a></li>
<li>Bump the npm group across 1 directory with 6 updates by @dependabot[bot] in <a href="https://github.com/ghcr-manager/ghcr-cleanup-manager/pull/9">https://github.com/ghcr-manager/ghcr-cleanup-manager/pull/9</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ghcr-manager/ghcr-cleanup-manager/compare/v1.1.5...v1.1.6">https://github.com/ghcr-manager/ghcr-cleanup-manager/compare/v1.1.5...v1.1.6</a></p>
]]></content:encoded></item><item><title>Create contributors list</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/create-contributors-list/</link><pubDate>Thu, 09 Jul 2026 07:04:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/create-contributors-list/</guid><description>Version updated for https://github.com/gouef/create-contributors-action to version v1.0.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ChangesDiff: v1.0.5...v1.0.6</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/gouef/create-contributors-action">https://github.com/gouef/create-contributors-action</a></strong> to version <strong>v1.0.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/create-contributors-list">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2>Changes</h2><p><a href="https://github.com/gouef/create-contributors-action/compare/v1.0.5...v1.0.6">Diff: v1.0.5...v1.0.6</a></p><ul></ul>
]]></content:encoded></item><item><title>Run go tests and upload coverage</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/run-go-tests-and-upload-coverage/</link><pubDate>Thu, 09 Jul 2026 07:03:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/run-go-tests-and-upload-coverage/</guid><description>Version updated for https://github.com/gouef/go-test-with-coverage-action to version v1.0.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ChangesDiff: v1.0.2...v1.0.3
[Upgrade] actions/checkout and actions/setup-go versions [ 524280e ] (@JanGalek)[Update] Automate update contributors [ 761b00c ] (@actions-user)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/gouef/go-test-with-coverage-action">https://github.com/gouef/go-test-with-coverage-action</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-go-tests-and-upload-coverage">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2>Changes</h2><p><a href="https://github.com/gouef/go-test-with-coverage-action/compare/v1.0.2...v1.0.3">Diff: v1.0.2...v1.0.3</a></p><ul><li>[Upgrade] actions/checkout and actions/setup-go versions [ <a href="https://github.com/gouef/go-test-with-coverage-action/commit/524280e661de98634f47deb8065852d43c1b2ff3">524280e</a> ] (@JanGalek)</li><li>[Update] Automate update contributors [ <a href="https://github.com/gouef/go-test-with-coverage-action/commit/761b00cd88bb2c83261bd348f38626615c7817c6">761b00c</a> ] (@actions-user)</li></ul>
]]></content:encoded></item><item><title>Create Release Note with PRs, Issues, Users</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/create-release-note-with-prs-issues-users/</link><pubDate>Thu, 09 Jul 2026 07:02:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/create-release-note-with-prs-issues-users/</guid><description>Version updated for https://github.com/gouef/release-action to version v1.0.2.
This action is used across all versions by 63 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ChangesDiff: v1.0.1...v1.0.2
[Update] checkout action to version 6 [ 45f3bf5 ] (@JanGalek)[Update] Automate update contributors [ 533f304 ] (@actions-user)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/gouef/release-action">https://github.com/gouef/release-action</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>63</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/create-release-note-with-prs-issues-users">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2>Changes</h2><p><a href="https://github.com/gouef/release-action/compare/v1.0.1...v1.0.2">Diff: v1.0.1...v1.0.2</a></p><ul><li>[Update] checkout action to version 6 [ <a href="https://github.com/gouef/release-action/commit/45f3bf567b6b20a3cb27a64a93e5026d955824d2">45f3bf5</a> ] (@JanGalek)</li><li>[Update] Automate update contributors [ <a href="https://github.com/gouef/release-action/commit/533f30439034f8ede1ecf0f502140b3778ef0fff">533f304</a> ] (@actions-user)</li></ul>
]]></content:encoded></item><item><title>action-lambda-publish</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/action-lambda-publish/</link><pubDate>Thu, 09 Jul 2026 07:02:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/action-lambda-publish/</guid><description>Version updated for https://github.com/heronlabs/action-lambda-publish to version v3.0.12.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [skip ci] bump v3.0.12 (0657d06) chore: update action-lambda-publish to action-tag-release-build v5.0.12 (#20) (92d9fda) [skip ci] bump v3.0.11 (d90741b) chore(deps): bump the actions group across 1 directory with 3 updates (#18) (111bfbe) [skip ci] bump v3.0.10 (6ea8ec3) Add branding icon and color to action.yml (c79ecda) [skip ci] bump v3.0.9 (ce780a2) docs: standardize README badges and add repo-specific CLAUDE.md (#17) (13f3b58) [skip ci] bump v3.0.8 (eea976e) chore: standardize action pipeline, architecture, and step names (964097b)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/heronlabs/action-lambda-publish">https://github.com/heronlabs/action-lambda-publish</a></strong> to version <strong>v3.0.12</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/action-lambda-publish">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>[skip ci] bump v3.0.12 (0657d06)</li>
<li>chore: update action-lambda-publish to action-tag-release-build v5.0.12 (#20) (92d9fda)</li>
<li>[skip ci] bump v3.0.11 (d90741b)</li>
<li>chore(deps): bump the actions group across 1 directory with 3 updates (#18) (111bfbe)</li>
<li>[skip ci] bump v3.0.10 (6ea8ec3)</li>
<li>Add branding icon and color to action.yml (c79ecda)</li>
<li>[skip ci] bump v3.0.9 (ce780a2)</li>
<li>docs: standardize README badges and add repo-specific CLAUDE.md (#17) (13f3b58)</li>
<li>[skip ci] bump v3.0.8 (eea976e)</li>
<li>chore: standardize action pipeline, architecture, and step names (964097b)</li>
</ul>
]]></content:encoded></item><item><title>OpenBSD Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/openbsd-action/</link><pubDate>Thu, 09 Jul 2026 07:01:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/openbsd-action/</guid><description>Version updated for https://github.com/ivoronin/openbsd-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First marketplace release of openbsd-action.
This action runs one GitHub Actions command inside an OpenBSD VM. It downloads a pre-built OpenBSD image from ivoronin/openbsd-cloudimg releases, verifies its GitHub attestation, boots it with QEMU, syncs the workspace into /home/openbsd/work, runs your command, then syncs the workspace back even if the command exits non-zero.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ivoronin/openbsd-action">https://github.com/ivoronin/openbsd-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/openbsd-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First marketplace release of <code>openbsd-action</code>.</p>
<p>This action runs one GitHub Actions command inside an OpenBSD VM. It downloads a pre-built OpenBSD image from <code>ivoronin/openbsd-cloudimg</code> releases, verifies its GitHub attestation, boots it with QEMU, syncs the workspace into <code>/home/openbsd/work</code>, runs your command, then syncs the workspace back even if the command exits non-zero.</p>
]]></content:encoded></item><item><title>Kura Pages</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/kura-pages/</link><pubDate>Thu, 09 Jul 2026 07:01:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/kura-pages/</guid><description>Version updated for https://github.com/kurajs/pages to version v1.0.8.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Retire the sed link pre-fix: native resolution (kura &amp;gt;=0.0.27, docs &amp;gt;=0.0.50) covers every class it handled plus everything it structurally could not (anchors, ../../ escapes, subfolder docs, pruned targets, code-span link text, non-.md files), with exact-sha blob URLs and a never-guess git-tracked oracle. Verified live on rustbgpd: 132/132 docs covered, 146 oracle targets, zero dead relative links site-wide.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kurajs/pages">https://github.com/kurajs/pages</a></strong> to version <strong>v1.0.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kura-pages">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Retire the sed link pre-fix: native resolution (kura &gt;=0.0.27, docs &gt;=0.0.50) covers every class it handled plus everything it structurally could not (anchors, ../../ escapes, subfolder docs, pruned targets, code-span link text, non-.md files), with exact-sha blob URLs and a never-guess git-tracked oracle. Verified live on rustbgpd: 132/132 docs covered, 146 oracle targets, zero dead relative links site-wide.</p>
]]></content:encoded></item><item><title>ansede-static</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/ansede-static/</link><pubDate>Thu, 09 Jul 2026 07:00:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/ansede-static/</guid><description>Version updated for https://github.com/mattybellx/Ansede to version v6.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [6.1.0] — 2026-07-08 Added Taint-aware demotion engine: pattern-only findings with no taint trace are now demoted from HIGH/CRITICAL to MEDIUM at most. CWE-617/200/532 (code-quality rules) are always LOW. CWE-798 (hardcoded secrets) is exempt. _HARDCODED_DEMOTE_CWES and _NO_TRACE_DEMOTE_CWES constants in CLI post-processing pipeline Changed HIGH/CRITICAL precision: 0% → 19.1% across 43 repos Findings/file: 3.1 → 1.7 (default filter) CWE-617 (silent exceptions) severity: HIGH → LOW CWE-117 (log injection) without user input: CRITICAL → LOW CWE-89/78/1188/352/601 without taint trace: HIGH → MEDIUM Verified 43 repos scanned, 4,114 findings, 1,075 HIGH/CRIT → 205 suspected real 1 confirmed real vulnerability (CWE-601 open redirect via request.referrer) 1,249 tests pass, 0 regressions Noise gate CI: 0% HIGH/CRIT false-negative guarantee maintained</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mattybellx/Ansede">https://github.com/mattybellx/Ansede</a></strong> to version <strong>v6.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ansede-static">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="610--2026-07-08">[6.1.0] — 2026-07-08</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>Taint-aware demotion engine</strong>: pattern-only findings with no taint trace
are now demoted from HIGH/CRITICAL to MEDIUM at most. CWE-617/200/532
(code-quality rules) are always LOW. CWE-798 (hardcoded secrets) is exempt.</li>
<li><strong><code>_HARDCODED_DEMOTE_CWES</code></strong> and <strong><code>_NO_TRACE_DEMOTE_CWES</code></strong> constants
in CLI post-processing pipeline</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>HIGH/CRITICAL precision: 0% → 19.1%</strong> across 43 repos</li>
<li>Findings/file: 3.1 → 1.7 (default filter)</li>
<li>CWE-617 (silent exceptions) severity: HIGH → LOW</li>
<li>CWE-117 (log injection) without user input: CRITICAL → LOW</li>
<li>CWE-89/78/1188/352/601 without taint trace: HIGH → MEDIUM</li>
</ul>
<h3 id="verified">Verified</h3>
<ul>
<li>43 repos scanned, 4,114 findings, 1,075 HIGH/CRIT → 205 suspected real</li>
<li>1 confirmed real vulnerability (CWE-601 open redirect via request.referrer)</li>
<li>1,249 tests pass, 0 regressions</li>
<li>Noise gate CI: 0% HIGH/CRIT false-negative guarantee maintained</li>
</ul>
]]></content:encoded></item><item><title>agent-bom Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/agent-bom-scan/</link><pubDate>Thu, 09 Jul 2026 07:00:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/agent-bom-scan/</guid><description>Version updated for https://github.com/msaad00/agent-bom to version v0.94.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix(docs): repair out-of-tree links breaking strict mkdocs build by @msaad00 in https://github.com/msaad00/agent-bom/pull/3632 fix(cli): unified terminal UX — sections, deduped CIS, quiet cloud by @msaad00 in https://github.com/msaad00/agent-bom/pull/3633 fix(cloud): Key Vault CIS false-PASS + least-privilege deep-scan grants by @msaad00 in https://github.com/msaad00/agent-bom/pull/3636 fix(cloud): scan Lambda deployment packages + deep-scan pre-tagged container images by @msaad00 in https://github.com/msaad00/agent-bom/pull/3634 fix(cloud): Lambda discovery on by default (no –include-lambda) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3635 ci(docs): gate PRs on mkdocs build –strict by @msaad00 in https://github.com/msaad00/agent-bom/pull/3638 feat(output): scale-ready tabbed + paginated HTML report by @msaad00 in https://github.com/msaad00/agent-bom/pull/3637 feat(ui): Storybook harness for large dashboard components by @msaad00 in https://github.com/msaad00/agent-bom/pull/3640 feat(enrich): mature the multi-provider LLM enrichment harness by @msaad00 in https://github.com/msaad00/agent-bom/pull/3639 fix(scanners): correct OSV fixed_version resolution by @msaad00 in https://github.com/msaad00/agent-bom/pull/3644 fix(output): SARIF/json finding-count parity + –reproducible timestamps + /dev/null exit by @msaad00 in https://github.com/msaad00/agent-bom/pull/3645 Part of #1469 (Phase 0: hardware-backed device identity) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3646 chore: logo + branding consistency pass by @msaad00 in https://github.com/msaad00/agent-bom/pull/3647 Part of #3499 (Iceberg catalog export) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3648 Part of #3499 (ClickHouse findings-ingest) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3650 perf(db): fix cvss filesort + O(table) origin count on hub current reads by @msaad00 in https://github.com/msaad00/agent-bom/pull/3654 Part of #3192 (drift-as-UI lens) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3649 Part of #1969 (phase 1: strict mypy for models + core API) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3655 Closes #3499 tail (Swift bare-call precision) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3656 perf(db): generic RANGE-partition maintenance + retention rollover by @msaad00 in https://github.com/msaad00/agent-bom/pull/3657 fix(rbac): resolve NO_AUTH_ROLE from env at call time (kills release-blocker CI flake) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3660 docs: canonical how-it-works + deployment matrix + editions page by @msaad00 in https://github.com/msaad00/agent-bom/pull/3668 fix(api): consistent empty-scan response shape across MCP and HTTP surfaces (CI flake) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3663 Closes #1522 (split output/html.py) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3661 perf(graph): bounded snapshot-stats, rollup orphans, deep-offset cap (Part of #3664) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3669 refactor(cli): unify scan verb, tier flags behind –help-all, dedup formats by @msaad00 in https://github.com/msaad00/agent-bom/pull/3672 fix(cis): fail-closed on per-resource permission denial across ~25 checks (Closes #3679) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3691 fix(mcp): gate ingest_external_scan as a destructive write (Closes #3681) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3692 fix(ingest): chunked reconcile_absent + pip-visible ai-enrich security floors by @msaad00 in https://github.com/msaad00/agent-bom/pull/3693 fix(cis): ERROR on partial permission denial (strict GRC coverage) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3695 fix(malicious): synthesize vuln-less malicious findings end-to-end by @msaad00 in https://github.com/msaad00/agent-bom/pull/3694 fix(audit): genesis chain verification and git-SHA range false-positive by @msaad00 in https://github.com/msaad00/agent-bom/pull/3696 feat(runtime): shield fail-closed defaults, cred redact, SSRF guard by @msaad00 in https://github.com/msaad00/agent-bom/pull/3699 feat(audit): signed chain checkpoint detects tail truncation by @msaad00 in https://github.com/msaad00/agent-bom/pull/3700 feat(identity): SCIM patch fixes, audit RBAC, session logout hardening by @msaad00 in https://github.com/msaad00/agent-bom/pull/3701 chore(dev): ‘make preflight’ to catch OpenAPI/schema drift before push by @msaad00 in https://github.com/msaad00/agent-bom/pull/3702 docs: consolidate duplicate doc clusters (stage 1 of #3703) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3704 feat(identity): auto-bind SCIM subject on API key issuance by @msaad00 in https://github.com/msaad00/agent-bom/pull/3705 feat(platform): DB-aware /readyz and firewall reload fail-closed by @msaad00 in https://github.com/msaad00/agent-bom/pull/3707 feat(cloud,runtime): full coverage and shield hardening by @msaad00 in https://github.com/msaad00/agent-bom/pull/3706 fix(config): warn on unparseable env bool/int/float values by @msaad00 in https://github.com/msaad00/agent-bom/pull/3711 feat(output): add SARIF partialFingerprints for GitHub dedup by @msaad00 in https://github.com/msaad00/agent-bom/pull/3712 docs(config): canonical env aliases and regenerated ENV_VARS (#3677) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3713 refactor(api): centralize /v1 mount on shared API router (#3666) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3715 chore(tests): group cloud tests under tests/cloud/ (#3703) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3716 fix(security): resolve CodeQL sensitive export and exception alerts by @msaad00 in https://github.com/msaad00/agent-bom/pull/3717 chore(tests): group API tests under tests/api/ (#3703) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3718 fix(security): clear CodeQL alerts and finalize MCP catalog drift (#3675) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3719 docs(deploy): add README for raw Kubernetes manifests by @andres-linero in https://github.com/msaad00/agent-bom/pull/3720 docs(deploy): add README for Snowflake deployment assets by @andres-linero in https://github.com/msaad00/agent-bom/pull/3721 chore(release): prepare 0.94.0 by @msaad00 in https://github.com/msaad00/agent-bom/pull/3722 fix(accuracy): git-SHA advisory false positives + malicious packages missing from CSV by @msaad00 in https://github.com/msaad00/agent-bom/pull/3723 docs(release): fold #3723 into 0.94.0 changelog by @msaad00 in https://github.com/msaad00/agent-bom/pull/3724 Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.93.5...v0.94.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/msaad00/agent-bom">https://github.com/msaad00/agent-bom</a></strong> to version <strong>v0.94.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-bom-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(docs): repair out-of-tree links breaking strict mkdocs build by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3632">https://github.com/msaad00/agent-bom/pull/3632</a></li>
<li>fix(cli): unified terminal UX — sections, deduped CIS, quiet cloud by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3633">https://github.com/msaad00/agent-bom/pull/3633</a></li>
<li>fix(cloud): Key Vault CIS false-PASS + least-privilege deep-scan grants by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3636">https://github.com/msaad00/agent-bom/pull/3636</a></li>
<li>fix(cloud): scan Lambda deployment packages + deep-scan pre-tagged container images by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3634">https://github.com/msaad00/agent-bom/pull/3634</a></li>
<li>fix(cloud): Lambda discovery on by default (no &ndash;include-lambda) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3635">https://github.com/msaad00/agent-bom/pull/3635</a></li>
<li>ci(docs): gate PRs on mkdocs build &ndash;strict by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3638">https://github.com/msaad00/agent-bom/pull/3638</a></li>
<li>feat(output): scale-ready tabbed + paginated HTML report by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3637">https://github.com/msaad00/agent-bom/pull/3637</a></li>
<li>feat(ui): Storybook harness for large dashboard components by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3640">https://github.com/msaad00/agent-bom/pull/3640</a></li>
<li>feat(enrich): mature the multi-provider LLM enrichment harness by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3639">https://github.com/msaad00/agent-bom/pull/3639</a></li>
<li>fix(scanners): correct OSV fixed_version resolution by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3644">https://github.com/msaad00/agent-bom/pull/3644</a></li>
<li>fix(output): SARIF/json finding-count parity + &ndash;reproducible timestamps + /dev/null exit by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3645">https://github.com/msaad00/agent-bom/pull/3645</a></li>
<li>Part of #1469 (Phase 0: hardware-backed device identity) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3646">https://github.com/msaad00/agent-bom/pull/3646</a></li>
<li>chore: logo + branding consistency pass by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3647">https://github.com/msaad00/agent-bom/pull/3647</a></li>
<li>Part of #3499 (Iceberg catalog export) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3648">https://github.com/msaad00/agent-bom/pull/3648</a></li>
<li>Part of #3499 (ClickHouse findings-ingest) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3650">https://github.com/msaad00/agent-bom/pull/3650</a></li>
<li>perf(db): fix cvss filesort + O(table) origin count on hub current reads by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3654">https://github.com/msaad00/agent-bom/pull/3654</a></li>
<li>Part of #3192 (drift-as-UI lens) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3649">https://github.com/msaad00/agent-bom/pull/3649</a></li>
<li>Part of #1969 (phase 1: strict mypy for models + core API) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3655">https://github.com/msaad00/agent-bom/pull/3655</a></li>
<li>Closes #3499 tail (Swift bare-call precision) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3656">https://github.com/msaad00/agent-bom/pull/3656</a></li>
<li>perf(db): generic RANGE-partition maintenance + retention rollover by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3657">https://github.com/msaad00/agent-bom/pull/3657</a></li>
<li>fix(rbac): resolve NO_AUTH_ROLE from env at call time (kills release-blocker CI flake) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3660">https://github.com/msaad00/agent-bom/pull/3660</a></li>
<li>docs: canonical how-it-works + deployment matrix + editions page by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3668">https://github.com/msaad00/agent-bom/pull/3668</a></li>
<li>fix(api): consistent empty-scan response shape across MCP and HTTP surfaces (CI flake) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3663">https://github.com/msaad00/agent-bom/pull/3663</a></li>
<li>Closes #1522 (split output/html.py) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3661">https://github.com/msaad00/agent-bom/pull/3661</a></li>
<li>perf(graph): bounded snapshot-stats, rollup orphans, deep-offset cap (Part of #3664) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3669">https://github.com/msaad00/agent-bom/pull/3669</a></li>
<li>refactor(cli): unify scan verb, tier flags behind &ndash;help-all, dedup formats by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3672">https://github.com/msaad00/agent-bom/pull/3672</a></li>
<li>fix(cis): fail-closed on per-resource permission denial across ~25 checks (Closes #3679) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3691">https://github.com/msaad00/agent-bom/pull/3691</a></li>
<li>fix(mcp): gate ingest_external_scan as a destructive write (Closes #3681) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3692">https://github.com/msaad00/agent-bom/pull/3692</a></li>
<li>fix(ingest): chunked reconcile_absent + pip-visible ai-enrich security floors by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3693">https://github.com/msaad00/agent-bom/pull/3693</a></li>
<li>fix(cis): ERROR on partial permission denial (strict GRC coverage) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3695">https://github.com/msaad00/agent-bom/pull/3695</a></li>
<li>fix(malicious): synthesize vuln-less malicious findings end-to-end by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3694">https://github.com/msaad00/agent-bom/pull/3694</a></li>
<li>fix(audit): genesis chain verification and git-SHA range false-positive by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3696">https://github.com/msaad00/agent-bom/pull/3696</a></li>
<li>feat(runtime): shield fail-closed defaults, cred redact, SSRF guard by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3699">https://github.com/msaad00/agent-bom/pull/3699</a></li>
<li>feat(audit): signed chain checkpoint detects tail truncation by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3700">https://github.com/msaad00/agent-bom/pull/3700</a></li>
<li>feat(identity): SCIM patch fixes, audit RBAC, session logout hardening by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3701">https://github.com/msaad00/agent-bom/pull/3701</a></li>
<li>chore(dev): &lsquo;make preflight&rsquo; to catch OpenAPI/schema drift before push by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3702">https://github.com/msaad00/agent-bom/pull/3702</a></li>
<li>docs: consolidate duplicate doc clusters (stage 1 of #3703) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3704">https://github.com/msaad00/agent-bom/pull/3704</a></li>
<li>feat(identity): auto-bind SCIM subject on API key issuance by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3705">https://github.com/msaad00/agent-bom/pull/3705</a></li>
<li>feat(platform): DB-aware /readyz and firewall reload fail-closed by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3707">https://github.com/msaad00/agent-bom/pull/3707</a></li>
<li>feat(cloud,runtime): full coverage and shield hardening by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3706">https://github.com/msaad00/agent-bom/pull/3706</a></li>
<li>fix(config): warn on unparseable env bool/int/float values by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3711">https://github.com/msaad00/agent-bom/pull/3711</a></li>
<li>feat(output): add SARIF partialFingerprints for GitHub dedup by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3712">https://github.com/msaad00/agent-bom/pull/3712</a></li>
<li>docs(config): canonical env aliases and regenerated ENV_VARS (#3677) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3713">https://github.com/msaad00/agent-bom/pull/3713</a></li>
<li>refactor(api): centralize /v1 mount on shared API router (#3666) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3715">https://github.com/msaad00/agent-bom/pull/3715</a></li>
<li>chore(tests): group cloud tests under tests/cloud/ (#3703) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3716">https://github.com/msaad00/agent-bom/pull/3716</a></li>
<li>fix(security): resolve CodeQL sensitive export and exception alerts by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3717">https://github.com/msaad00/agent-bom/pull/3717</a></li>
<li>chore(tests): group API tests under tests/api/ (#3703) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3718">https://github.com/msaad00/agent-bom/pull/3718</a></li>
<li>fix(security): clear CodeQL alerts and finalize MCP catalog drift (#3675) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3719">https://github.com/msaad00/agent-bom/pull/3719</a></li>
<li>docs(deploy): add README for raw Kubernetes manifests by @andres-linero in <a href="https://github.com/msaad00/agent-bom/pull/3720">https://github.com/msaad00/agent-bom/pull/3720</a></li>
<li>docs(deploy): add README for Snowflake deployment assets by @andres-linero in <a href="https://github.com/msaad00/agent-bom/pull/3721">https://github.com/msaad00/agent-bom/pull/3721</a></li>
<li>chore(release): prepare 0.94.0 by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3722">https://github.com/msaad00/agent-bom/pull/3722</a></li>
<li>fix(accuracy): git-SHA advisory false positives + malicious packages missing from CSV by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3723">https://github.com/msaad00/agent-bom/pull/3723</a></li>
<li>docs(release): fold #3723 into 0.94.0 changelog by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3724">https://github.com/msaad00/agent-bom/pull/3724</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/msaad00/agent-bom/compare/v0.93.5...v0.94.0">https://github.com/msaad00/agent-bom/compare/v0.93.5...v0.94.0</a></p>
]]></content:encoded></item><item><title>Setup atago</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/setup-atago/</link><pubDate>Thu, 09 Jul 2026 06:59:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/setup-atago/</guid><description>Version updated for https://github.com/nao1215/setup-atago to version v0.1.1.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s changed fix: a successful install no longer exits nonzero (the EXIT-trap cleanup referenced an out-of-scope local under set -u, failing every green run at the very end) docs: drop the “atago is unreleased” warning — atago v0.1.0 is published and this action now installs it The floating v0 tag points at this release. Verified end-to-end against the real v0.1.0 release: checksum, SLSA attestation (gh attestation verify), install, and atago version / init / run.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nao1215/setup-atago">https://github.com/nao1215/setup-atago</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-atago">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s changed</h2>
<ul>
<li>fix: a successful install no longer exits nonzero (the EXIT-trap cleanup referenced an out-of-scope local under <code>set -u</code>, failing every green run at the very end)</li>
<li>docs: drop the &ldquo;atago is unreleased&rdquo; warning — <a href="https://github.com/nao1215/atago/releases/tag/v0.1.0">atago v0.1.0</a> is published and this action now installs it</li>
</ul>
<p>The floating <code>v0</code> tag points at this release. Verified end-to-end against the real v0.1.0 release: checksum, SLSA attestation (<code>gh attestation verify</code>), install, and <code>atago version</code> / <code>init</code> / <code>run</code>.</p>
]]></content:encoded></item><item><title>Lambda MicroVM GitHub Runner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/lambda-microvm-github-runner/</link><pubDate>Thu, 09 Jul 2026 06:59:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/lambda-microvm-github-runner/</guid><description>Version updated for https://github.com/neebs12/lambda-microvm-github-runner to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/neebs12/lambda-microvm-github-runner/commits/v1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/neebs12/lambda-microvm-github-runner">https://github.com/neebs12/lambda-microvm-github-runner</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lambda-microvm-github-runner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/neebs12/lambda-microvm-github-runner/commits/v1">https://github.com/neebs12/lambda-microvm-github-runner/commits/v1</a></p>
]]></content:encoded></item><item><title>XAI Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/xai-review/</link><pubDate>Thu, 09 Jul 2026 06:58:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/xai-review/</guid><description>Version updated for https://github.com/Nikita-Filonov/ai-review to version v0.69.0.
This action is used across all versions by 8 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed azure openai (978e700) Merge pull request #99 from crow-ua/add-support-for-gpt-5-max-complete-tokens (e28ac59) renamed files (61d7b2b) bitbucket server (1bbc1d8) openai stream (da6aabb) ripgrep (ffd969f) Add support for max_completion_tokens in Azure OpenAI schemas and client for GPT-5 models (185b557) up version (e553e3c) Merge pull request #90 from crow-ua/fix-azure-devops-ai-comments (f20fdf6) Removing hidden state dependency (971ff32)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Nikita-Filonov/ai-review">https://github.com/Nikita-Filonov/ai-review</a></strong> to version <strong>v0.69.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/xai-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>azure openai (978e700)</li>
<li>Merge pull request #99 from crow-ua/add-support-for-gpt-5-max-complete-tokens (e28ac59)</li>
<li>renamed files (61d7b2b)</li>
<li>bitbucket server (1bbc1d8)</li>
<li>openai stream (da6aabb)</li>
<li>ripgrep (ffd969f)</li>
<li>Add support for max_completion_tokens in Azure OpenAI schemas and client for GPT-5 models (185b557)</li>
<li>up version (e553e3c)</li>
<li>Merge pull request #90 from crow-ua/fix-azure-devops-ai-comments (f20fdf6)</li>
<li>Removing hidden state dependency (971ff32)</li>
</ul>
]]></content:encoded></item><item><title>OpenShock Release Tool</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/openshock-release-tool/</link><pubDate>Thu, 09 Jul 2026 06:57:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/openshock-release-tool/</guid><description>Version updated for https://github.com/OpenShock/release-tool to version v0.3.0.
This action is used across all versions by 0 repositories. Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changed Bump actions/cache from 4.3.0 to 6.1.0 in the github-actions dependency group Contributors Thanks to @hhvrc for contributing to this release!</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/OpenShock/release-tool">https://github.com/OpenShock/release-tool</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<p>Go to the <a href="https://github.com/marketplace/actions/openshock-release-tool">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>Bump <code>actions/cache</code> from 4.3.0 to 6.1.0 in the github-actions dependency group</li>
</ul>
<h3 id="contributors">Contributors</h3>
<p>Thanks to @hhvrc for contributing to this release!</p>
]]></content:encoded></item><item><title>Set up AAPT2</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/set-up-aapt2/</link><pubDate>Thu, 09 Jul 2026 06:57:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/set-up-aapt2/</guid><description>Version updated for https://github.com/OussamaTeyib/setup-aapt2 to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Update dependency @types/node to v25.9.1 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/13 Update npm to v11.15.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/14 Configure Renovate to automatically merge low-risk dependency updates by @OussamaTeyib in https://github.com/OussamaTeyib/setup-aapt2/pull/15 Remove redundant platformAutomerge option by @OussamaTeyib in https://github.com/OussamaTeyib/setup-aapt2/pull/17 Update npm to v11.16.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/18 Add CodeQL static analysis workflow by @OussamaTeyib in https://github.com/OussamaTeyib/setup-aapt2/pull/19 Update dependency @types/node to v25.9.2 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/20 Update dependency @vercel/ncc to ^0.44.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/21 Update dependency @types/node to v25.9.3 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/22 Update npm to v11.17.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/23 Update actions/checkout action to v7 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/24 Update dependency @types/node to v25.9.4 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/25 Bump @types/node from 25.9.4 to 26.0.0 by @dependabot[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/26 Bump undici from 6.25.0 to 6.27.0 in the npm_and_yarn group across 1 directory by @dependabot[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/27 Update dependency @types/node to v26.0.1 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/28 Update npm to v11.18.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/29 Update dependency @vercel/ncc to v0.44.1 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/30 Update dependency @types/node to v26.1.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/31 Update dependency @types/node to v26.1.1 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/32 Update npm to v12 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/34 Migrate to esbuild by @OussamaTeyib in https://github.com/OussamaTeyib/setup-aapt2/pull/35 Update dependency typescript to v7 by @renovate[bot] in https://github.com/OussamaTeyib/setup-aapt2/pull/33 Full Changelog: https://github.com/OussamaTeyib/setup-aapt2/compare/v1.0.1...v1.0.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/OussamaTeyib/setup-aapt2">https://github.com/OussamaTeyib/setup-aapt2</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/set-up-aapt2">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Update dependency @types/node to v25.9.1 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-aapt2/pull/13">https://github.com/OussamaTeyib/setup-aapt2/pull/13</a></li>
<li>Update npm to v11.15.0 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-aapt2/pull/14">https://github.com/OussamaTeyib/setup-aapt2/pull/14</a></li>
<li>Configure Renovate to automatically merge low-risk dependency updates by @OussamaTeyib in <a href="https://github.com/OussamaTeyib/setup-aapt2/pull/15">https://github.com/OussamaTeyib/setup-aapt2/pull/15</a></li>
<li>Remove redundant <code>platformAutomerge</code> option by @OussamaTeyib in <a href="https://github.com/OussamaTeyib/setup-aapt2/pull/17">https://github.com/OussamaTeyib/setup-aapt2/pull/17</a></li>
<li>Update npm to v11.16.0 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-aapt2/pull/18">https://github.com/OussamaTeyib/setup-aapt2/pull/18</a></li>
<li>Add CodeQL static analysis workflow by @OussamaTeyib in <a href="https://github.com/OussamaTeyib/setup-aapt2/pull/19">https://github.com/OussamaTeyib/setup-aapt2/pull/19</a></li>
<li>Update dependency @types/node to v25.9.2 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-aapt2/pull/20">https://github.com/OussamaTeyib/setup-aapt2/pull/20</a></li>
<li>Update dependency @vercel/ncc to ^0.44.0 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-aapt2/pull/21">https://github.com/OussamaTeyib/setup-aapt2/pull/21</a></li>
<li>Update dependency @types/node to v25.9.3 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-aapt2/pull/22">https://github.com/OussamaTeyib/setup-aapt2/pull/22</a></li>
<li>Update npm to v11.17.0 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-aapt2/pull/23">https://github.com/OussamaTeyib/setup-aapt2/pull/23</a></li>
<li>Update actions/checkout action to v7 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-aapt2/pull/24">https://github.com/OussamaTeyib/setup-aapt2/pull/24</a></li>
<li>Update dependency @types/node to v25.9.4 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-aapt2/pull/25">https://github.com/OussamaTeyib/setup-aapt2/pull/25</a></li>
<li>Bump @types/node from 25.9.4 to 26.0.0 by @dependabot[bot] in <a href="https://github.com/OussamaTeyib/setup-aapt2/pull/26">https://github.com/OussamaTeyib/setup-aapt2/pull/26</a></li>
<li>Bump undici from 6.25.0 to 6.27.0 in the npm_and_yarn group across 1 directory by @dependabot[bot] in <a href="https://github.com/OussamaTeyib/setup-aapt2/pull/27">https://github.com/OussamaTeyib/setup-aapt2/pull/27</a></li>
<li>Update dependency @types/node to v26.0.1 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-aapt2/pull/28">https://github.com/OussamaTeyib/setup-aapt2/pull/28</a></li>
<li>Update npm to v11.18.0 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-aapt2/pull/29">https://github.com/OussamaTeyib/setup-aapt2/pull/29</a></li>
<li>Update dependency @vercel/ncc to v0.44.1 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-aapt2/pull/30">https://github.com/OussamaTeyib/setup-aapt2/pull/30</a></li>
<li>Update dependency @types/node to v26.1.0 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-aapt2/pull/31">https://github.com/OussamaTeyib/setup-aapt2/pull/31</a></li>
<li>Update dependency @types/node to v26.1.1 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-aapt2/pull/32">https://github.com/OussamaTeyib/setup-aapt2/pull/32</a></li>
<li>Update npm to v12 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-aapt2/pull/34">https://github.com/OussamaTeyib/setup-aapt2/pull/34</a></li>
<li>Migrate to esbuild by @OussamaTeyib in <a href="https://github.com/OussamaTeyib/setup-aapt2/pull/35">https://github.com/OussamaTeyib/setup-aapt2/pull/35</a></li>
<li>Update dependency typescript to v7 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-aapt2/pull/33">https://github.com/OussamaTeyib/setup-aapt2/pull/33</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/OussamaTeyib/setup-aapt2/compare/v1.0.1...v1.0.2">https://github.com/OussamaTeyib/setup-aapt2/compare/v1.0.1...v1.0.2</a></p>
]]></content:encoded></item><item><title>Set up Android Manifest Merger</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/set-up-android-manifest-merger/</link><pubDate>Thu, 09 Jul 2026 06:56:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/set-up-android-manifest-merger/</guid><description>Version updated for https://github.com/OussamaTeyib/setup-manifest-merger to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Update dependency @types/node to v25.9.1 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/9 Update npm to v11.15.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/10 Configure Renovate to automatically merge low-risk dependency updates by @OussamaTeyib in https://github.com/OussamaTeyib/setup-manifest-merger/pull/11 Update npm to v11.15.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/12 Update npm to v11.16.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/13 Add CodeQL static analysis workflow by @OussamaTeyib in https://github.com/OussamaTeyib/setup-manifest-merger/pull/14 Update dependency @types/node to v25.9.2 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/15 Update dependency @vercel/ncc to ^0.44.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/16 Update dependency @types/node to v25.9.3 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/17 Update npm to v11.17.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/18 Update actions/checkout action to v7 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/19 Update dependency @types/node to v25.9.4 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/20 Bump @types/node from 25.9.4 to 26.0.0 by @dependabot[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/21 Bump undici from 6.25.0 to 6.27.0 in the npm_and_yarn group across 1 directory by @dependabot[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/22 Update dependency @types/node to v26.0.1 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/23 Update npm to v11.18.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/24 Update dependency @vercel/ncc to v0.44.1 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/25 Update dependency @types/node to v26.1.0 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/26 Update dependency @types/node to v26.1.1 by @renovate[bot] in https://github.com/OussamaTeyib/setup-manifest-merger/pull/27 Migrate to esbuild by @OussamaTeyib in https://github.com/OussamaTeyib/setup-manifest-merger/pull/29 New Contributors @dependabot[bot] made their first contribution in https://github.com/OussamaTeyib/setup-manifest-merger/pull/21 Full Changelog: https://github.com/OussamaTeyib/setup-manifest-merger/compare/v1.0.2...v1.0.3</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/OussamaTeyib/setup-manifest-merger">https://github.com/OussamaTeyib/setup-manifest-merger</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/set-up-android-manifest-merger">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Update dependency @types/node to v25.9.1 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-manifest-merger/pull/9">https://github.com/OussamaTeyib/setup-manifest-merger/pull/9</a></li>
<li>Update npm to v11.15.0 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-manifest-merger/pull/10">https://github.com/OussamaTeyib/setup-manifest-merger/pull/10</a></li>
<li>Configure Renovate to automatically merge low-risk dependency updates by @OussamaTeyib in <a href="https://github.com/OussamaTeyib/setup-manifest-merger/pull/11">https://github.com/OussamaTeyib/setup-manifest-merger/pull/11</a></li>
<li>Update npm to v11.15.0 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-manifest-merger/pull/12">https://github.com/OussamaTeyib/setup-manifest-merger/pull/12</a></li>
<li>Update npm to v11.16.0 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-manifest-merger/pull/13">https://github.com/OussamaTeyib/setup-manifest-merger/pull/13</a></li>
<li>Add CodeQL static analysis workflow by @OussamaTeyib in <a href="https://github.com/OussamaTeyib/setup-manifest-merger/pull/14">https://github.com/OussamaTeyib/setup-manifest-merger/pull/14</a></li>
<li>Update dependency @types/node to v25.9.2 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-manifest-merger/pull/15">https://github.com/OussamaTeyib/setup-manifest-merger/pull/15</a></li>
<li>Update dependency @vercel/ncc to ^0.44.0 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-manifest-merger/pull/16">https://github.com/OussamaTeyib/setup-manifest-merger/pull/16</a></li>
<li>Update dependency @types/node to v25.9.3 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-manifest-merger/pull/17">https://github.com/OussamaTeyib/setup-manifest-merger/pull/17</a></li>
<li>Update npm to v11.17.0 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-manifest-merger/pull/18">https://github.com/OussamaTeyib/setup-manifest-merger/pull/18</a></li>
<li>Update actions/checkout action to v7 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-manifest-merger/pull/19">https://github.com/OussamaTeyib/setup-manifest-merger/pull/19</a></li>
<li>Update dependency @types/node to v25.9.4 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-manifest-merger/pull/20">https://github.com/OussamaTeyib/setup-manifest-merger/pull/20</a></li>
<li>Bump @types/node from 25.9.4 to 26.0.0 by @dependabot[bot] in <a href="https://github.com/OussamaTeyib/setup-manifest-merger/pull/21">https://github.com/OussamaTeyib/setup-manifest-merger/pull/21</a></li>
<li>Bump undici from 6.25.0 to 6.27.0 in the npm_and_yarn group across 1 directory by @dependabot[bot] in <a href="https://github.com/OussamaTeyib/setup-manifest-merger/pull/22">https://github.com/OussamaTeyib/setup-manifest-merger/pull/22</a></li>
<li>Update dependency @types/node to v26.0.1 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-manifest-merger/pull/23">https://github.com/OussamaTeyib/setup-manifest-merger/pull/23</a></li>
<li>Update npm to v11.18.0 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-manifest-merger/pull/24">https://github.com/OussamaTeyib/setup-manifest-merger/pull/24</a></li>
<li>Update dependency @vercel/ncc to v0.44.1 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-manifest-merger/pull/25">https://github.com/OussamaTeyib/setup-manifest-merger/pull/25</a></li>
<li>Update dependency @types/node to v26.1.0 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-manifest-merger/pull/26">https://github.com/OussamaTeyib/setup-manifest-merger/pull/26</a></li>
<li>Update dependency @types/node to v26.1.1 by @renovate[bot] in <a href="https://github.com/OussamaTeyib/setup-manifest-merger/pull/27">https://github.com/OussamaTeyib/setup-manifest-merger/pull/27</a></li>
<li>Migrate to esbuild by @OussamaTeyib in <a href="https://github.com/OussamaTeyib/setup-manifest-merger/pull/29">https://github.com/OussamaTeyib/setup-manifest-merger/pull/29</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/OussamaTeyib/setup-manifest-merger/pull/21">https://github.com/OussamaTeyib/setup-manifest-merger/pull/21</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/OussamaTeyib/setup-manifest-merger/compare/v1.0.2...v1.0.3">https://github.com/OussamaTeyib/setup-manifest-merger/compare/v1.0.2...v1.0.3</a></p>
]]></content:encoded></item><item><title>SkillTotal AI Component Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/skilltotal-ai-component-security-scan/</link><pubDate>Thu, 09 Jul 2026 06:56:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/skilltotal-ai-component-security-scan/</guid><description>Version updated for https://github.com/pezhik/skilltotal to version v0.36.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changed Declarative combination registry (skilltotal/combinations.py). The four synthesized combination findings — emergent risk from co-occurring signals (ST-COMBO-EXFIL, ST-FLOW-TRIFECTA, ST-INSTALL-DROPPER, ST-CONVERGENCE) — are now declared in one ordered registry, each with a short technique label (for the public per-technique benchmark) and an evaluator adapter. The engine iterates the registry in two phases (pre-/post-threat-class assignment) instead of four hardcoded calls, so a new combination is a registry entry, not an edit to the engine’s control flow. Behavior is byte-identical — the calibrated detection logic stays in scoring.py, guarded by the recall gate and the per-finding golden set; RULESET_VERSION (39) and the report shape (schema 1.5) are unchanged. Each combination id is kept in sync with its RuleSpec and ComponentTrait by tests/test_combinations.py.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pezhik/skilltotal">https://github.com/pezhik/skilltotal</a></strong> to version <strong>v0.36.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skilltotal-ai-component-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>Declarative combination registry (<code>skilltotal/combinations.py</code>).</strong> The four synthesized
<em>combination</em> findings — emergent risk from co-occurring signals (<code>ST-COMBO-EXFIL</code>,
<code>ST-FLOW-TRIFECTA</code>, <code>ST-INSTALL-DROPPER</code>, <code>ST-CONVERGENCE</code>) — are now declared in one ordered
registry, each with a short technique label (for the public per-technique benchmark) and an
evaluator adapter. The engine iterates the registry in two phases (pre-/post-threat-class
assignment) instead of four hardcoded calls, so a new combination is a registry entry, not an
edit to the engine&rsquo;s control flow. <strong>Behavior is byte-identical</strong> — the calibrated detection
logic stays in <code>scoring.py</code>, guarded by the recall gate and the per-finding golden set;
<code>RULESET_VERSION</code> (39) and the report shape (schema 1.5) are unchanged. Each combination id is
kept in sync with its <code>RuleSpec</code> and <code>ComponentTrait</code> by <code>tests/test_combinations.py</code>.</li>
</ul>
]]></content:encoded></item><item><title>OpenTelemetry for GitHub Workflows, Jobs and Steps</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/opentelemetry-for-github-workflows-jobs-and-steps/</link><pubDate>Thu, 09 Jul 2026 06:55:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/opentelemetry-for-github-workflows-jobs-and-steps/</guid><description>Version updated for https://github.com/plengauer/Thoth to version v5.58.1.
This action is used across all versions by 14 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Re-disable slim images temporarily while network is still restricted by @plengauer in https://github.com/plengauer/Thoth/pull/3715 Update dependency net.bytebuddy:byte-buddy to v1.18.11-jdk5 (#3705) by @plengauer in https://github.com/plengauer/Thoth/pull/3714 Automatic Version Bump by @plengauer in https://github.com/plengauer/Thoth/pull/3719 Full Changelog: https://github.com/plengauer/Thoth/compare/v5.58...v5.58.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/plengauer/Thoth">https://github.com/plengauer/Thoth</a></strong> to version <strong>v5.58.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>14</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/opentelemetry-for-github-workflows-jobs-and-steps">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Re-disable slim images temporarily while network is still restricted by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3715">https://github.com/plengauer/Thoth/pull/3715</a></li>
<li>Update dependency net.bytebuddy:byte-buddy to v1.18.11-jdk5 (#3705) by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3714">https://github.com/plengauer/Thoth/pull/3714</a></li>
<li>Automatic Version Bump by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3719">https://github.com/plengauer/Thoth/pull/3719</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/plengauer/Thoth/compare/v5.58...v5.58.1">https://github.com/plengauer/Thoth/compare/v5.58...v5.58.1</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Workspace Bootstrap</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/postman-onboarding-workspace-bootstrap/</link><pubDate>Thu, 09 Jul 2026 06:55:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/postman-onboarding-workspace-bootstrap/</guid><description>Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.7.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.7.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-bootstrap-action">https://github.com/postman-cs/postman-bootstrap-action</a></strong> to version <strong>v2.7.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-workspace-bootstrap">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.7.1">https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.7.1</a></p>
]]></content:encoded></item><item><title>GitHub-Script (by PSModule)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/github-script-by-psmodule/</link><pubDate>Thu, 09 Jul 2026 06:54:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/github-script-by-psmodule/</guid><description>Version updated for https://github.com/PSModule/GitHub-Script to version v1.9.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 28 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 🚀 [Feature]: Version input accepts NuGet version ranges (#98) The Version input now accepts a NuGet version range in addition to an exact version, so a workflow can pin a compatible window (for example [1.2.0, 2.0.0)) instead of a single build. Pinning an exact version keeps working exactly as before, and a version that is already installed and satisfies the request is no longer reinstalled on every run.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/PSModule/GitHub-Script">https://github.com/PSModule/GitHub-Script</a></strong> to version <strong>v1.9.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>28</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-script-by-psmodule">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="-feature-version-input-accepts-nuget-version-ranges-98">🚀 [Feature]: Version input accepts NuGet version ranges (#98)</h1>
<p>The <code>Version</code> input now accepts a NuGet version range in addition to an exact version, so a workflow can pin a compatible window (for example <code>[1.2.0, 2.0.0)</code>) instead of a single build. Pinning an exact version keeps working exactly as before, and a version that is already installed and satisfies the request is no longer reinstalled on every run.</p>
<ul>
<li>Fixes #97</li>
</ul>
<h2 id="new-nuget-version-ranges-for-the-version-input">New: NuGet version ranges for the <code>Version</code> input</h2>
<p><code>Version</code> accepts the same syntax as <a href="https://learn.microsoft.com/powershell/module/microsoft.powershell.psresourceget/install-psresource"><code>Install-PSResource</code></a>:</p>
<table>
  <thead>
      <tr>
          <th><code>Version</code> example</th>
          <th>Meaning</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>1.2.3</code></td>
          <td>Exactly <code>1.2.3</code></td>
      </tr>
      <tr>
          <td><code>[1.2.3]</code></td>
          <td>Exactly <code>1.2.3</code></td>
      </tr>
      <tr>
          <td><code>[1.2.0, ]</code></td>
          <td><code>1.2.0</code> or newer</td>
      </tr>
      <tr>
          <td><code>(, 2.0.0)</code></td>
          <td>Any version lower than <code>2.0.0</code></td>
      </tr>
      <tr>
          <td><code>[1.2.0, 2.0.0)</code></td>
          <td><code>1.2.0</code> up to but not including <code>2.0.0</code></td>
      </tr>
  </tbody>
</table>
<p>A bare version is treated as an <em>exact</em> version (not a minimum), so existing pins are unaffected. PSResourceGet resolves a range to the lowest satisfying version.</p>
<h2 id="fixed-a-satisfying-version-is-reused-instead-of-reinstalled">Fixed: a satisfying version is reused instead of reinstalled</h2>
<p>Previously, supplying anything other than an exact version caused the module to be reinstalled on every run: the already-installed check compared the raw input to installed versions with exact string equality, which never matches a range. The check now honors ranges, so an already-installed version that satisfies the request is reused.</p>
<h2 id="technical-details">Technical Details</h2>
<ul>
<li><code>src/init.ps1</code>: the already-installed lookup now passes the value to <code>Get-InstalledPSResource -Name $Name -Version $Version</code> instead of piping to <code>Where-Object Version -EQ</code>. The redundant <code>Where-Object Prerelease -EQ</code> filter was removed — prerelease handling is governed by the <code>-Prerelease</code> switch passed to <code>Install-PSResource</code>. The retry loop (5 attempts, 10s delay) around <code>Install-PSResource</code> is unchanged.</li>
<li><code>action.yml</code> / <code>README.md</code>: the <code>Version</code> input is documented as accepting an exact version or a NuGet version range, with an examples table and a note that a bare version is exact.</li>
<li>Tests (<code>.github/workflows/TestWorkflow.yml</code>): added <code>Version [Exact]</code>, <code>Version [Bounded range]</code>, <code>Version [Minimum range]</code>, and <code>Version [Already installed]</code> jobs (Linux; version resolution is OS-independent). Written test-first — the already-installed job failed on the unfixed code (two installed versions) and passes after the fix. Because these jobs use <code>Prerelease: ${{ inputs.Prerelease }}</code>, they also exercise the prerelease + range combination when run via <code>Action-Test-Prerelease.yml</code>.</li>
<li>Implementation plan progress: all tasks in #97 are complete.</li>
</ul>
<p>Backward compatibility: exact-version pins resolve identically; only the unnecessary-reinstall behavior changes.</p>
]]></content:encoded></item><item><title>Pipeline Pling</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/pipeline-pling/</link><pubDate>Thu, 09 Jul 2026 06:54:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/pipeline-pling/</guid><description>Version updated for https://github.com/Qbox-project/pipeline-pling to version v1.1.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Pipeline Pling v1.1.0 Adds two new ways to control which pushes and commits get posted to Discord.
Silent commits Exclude specific commits from notifications by putting !silent on the first line of the commit body:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Qbox-project/pipeline-pling">https://github.com/Qbox-project/pipeline-pling</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pipeline-pling">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="pipeline-pling-v110">Pipeline Pling v1.1.0</h2>
<p>Adds two new ways to control which pushes and commits get posted to Discord.</p>
<h3 id="silent-commits">Silent commits</h3>
<p>Exclude specific commits from notifications by putting <code>!silent</code> on the first line of the commit body:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-text" data-lang="text"><span style="display:flex;"><span>chore(deps): bump lockfile
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>!silent
</span></span></code></pre></div><ul>
<li>Silent commits are omitted from the message entirely</li>
<li>If every commit in a push is silent, no webhook is sent</li>
<li>Mixed pushes only show the remaining commits, with the correct count in the header (e.g. &ldquo;is pushing 1 commit&rdquo;)</li>
</ul>
<p>Configurable via the new <code>silent-keyword</code> input (default: <code>!silent</code>).</p>
<h3 id="branch-filtering">Branch filtering</h3>
<p>Control which branches trigger notifications with comma-separated branch lists:</p>
<ul>
<li><code>branch-allowlist</code> — only notify for pushes to these branches</li>
<li><code>branch-denylist</code> — skip notifications for pushes to these branches</li>
</ul>
<p>Branch matching is exact and case-sensitive (<code>refs/heads/main</code> → <code>main</code>). When both lists are set, a branch must be in the allowlist and not in the denylist.</p>
<h3 id="usage">Usage</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Qbox-project/pipeline-pling@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">webhook-url</span>: <span style="color:#ae81ff">${{ secrets.DISCORD_COMMIT_WEBHOOK }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">silent-keyword</span>: <span style="color:#e6db74">&#39;!silent&#39;</span>        <span style="color:#75715e"># optional, default</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">branch-allowlist</span>: <span style="color:#e6db74">&#39;main,develop&#39;</span> <span style="color:#75715e"># optional</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">branch-denylist</span>: <span style="color:#e6db74">&#39;dependabot&#39;</span>    <span style="color:#75715e"># optional</span>
</span></span></code></pre></div><p><strong>Full Changelog</strong>: <a href="https://github.com/Qbox-project/pipeline-pling/compare/v1.0.0...v1.1.0">https://github.com/Qbox-project/pipeline-pling/compare/v1.0.0...v1.1.0</a></p>
]]></content:encoded></item><item><title>Remyx Outrider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/remyx-outrider/</link><pubDate>Thu, 09 Jul 2026 06:53:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/remyx-outrider/</guid><description>Version updated for https://github.com/remyxai/outrider to version v1.7.13.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Follow-up to v1.7.12. The PDF-text discovery path shipped in v1.7.12 depended on pdftotext, which turned out not to be installed on ubuntu-latest runners as of mid-2026 — the fallback fired but silently returned empty. This release makes it actually work.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remyxai/outrider">https://github.com/remyxai/outrider</a></strong> to version <strong>v1.7.13</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/remyx-outrider">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Follow-up to v1.7.12. The PDF-text discovery path shipped in v1.7.12 depended on <code>pdftotext</code>, which turned out not to be installed on <code>ubuntu-latest</code> runners as of mid-2026 — the fallback fired but silently returned empty. This release makes it actually work.</p>
<h2 id="changes">Changes</h2>
<ul>
<li><strong><code>action.yml</code></strong> — <code>apt-get install poppler-utils</code> step before the run.py invocation (~5 s add to setup phase, runs once per dispatch).</li>
<li><strong><code>src/run.py</code></strong> — retry-path outcome logging: <code>_retry_license_via_arxiv_html</code> now emits an INFO line when it discovers slugs vs when it comes up empty vs when none pass README verification. Previously all three failure modes returned silently, making CI/CD triage harder.</li>
</ul>
<h2 id="verified">Verified</h2>
<p>Re-dispatched arxiv:2606.30573v1 (SWE-Interact) against <code>remyxai/outrider</code>:</p>
<ul>
<li>Before: <code>candidate_enrichment: []</code>, <code>license_class: no-code-link</code>, <code>paper_license: &quot;&quot;</code></li>
<li>After: <code>candidate_enrichment: [{github: scaleapi/SWE-Interact, paper_license: Apache-2.0, license_source: arxiv_html_retry, license_class: permissive}]</code></li>
</ul>
<p>Full suite green (859/859).</p>
]]></content:encoded></item><item><title>SignalEDI Convert EDI to JSON</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/signaledi-convert-edi-to-json/</link><pubDate>Thu, 09 Jul 2026 06:52:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/signaledi-convert-edi-to-json/</guid><description>Version updated for https://github.com/SignalEDI/edi-to-json to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial Marketplace release.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SignalEDI/edi-to-json">https://github.com/SignalEDI/edi-to-json</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/signaledi-convert-edi-to-json">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial Marketplace release.</p>
]]></content:encoded></item><item><title>MCP Trust Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/mcp-trust-scan/</link><pubDate>Thu, 09 Jul 2026 06:52:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/mcp-trust-scan/</guid><description>Version updated for https://github.com/SteveMonsway/mcp-trust to version v1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed One-line MCP-server preflight scan in CI — the root composite Action.
```yaml
uses: actions/checkout@v4 uses: SteveMonsway/mcp-trust@v1 with: { fail-on: high, upload-sarif: true, comment-pr: true } ``` Runs the published @mcp-trust/cli via `npx` (self-contained, no build). Uploads SARIF to Code Scanning, posts a PR comment, and fails the job above a severity threshold.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SteveMonsway/mcp-trust">https://github.com/SteveMonsway/mcp-trust</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcp-trust-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>One-line MCP-server preflight scan in CI — the root composite Action.</p>
<p>```yaml</p>
<ul>
<li>uses: actions/checkout@v4</li>
<li>uses: SteveMonsway/mcp-trust@v1
with: { fail-on: high, upload-sarif: true, comment-pr: true }
```</li>
</ul>
<p>Runs the published <a href="https://www.npmjs.com/package/@mcp-trust/cli"><code>@mcp-trust/cli</code></a> via `npx` (self-contained, no build). Uploads SARIF to Code Scanning, posts a PR comment, and fails the job above a severity threshold.</p>
<p>Inputs: `target`, `fail-on`, `output`, `output-dir`, `upload-sarif`, `comment-pr`, `no-semgrep`. Outputs: `decision`, `risk`, `score`, `sarif-file`, `exceeded`.</p>
<p>Live demo: <a href="https://github.com/SteveMonsway/mcp-trust-demo">SteveMonsway/mcp-trust-demo</a>.</p>
]]></content:encoded></item><item><title>LLM Prompt Radar</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/llm-prompt-radar/</link><pubDate>Thu, 09 Jul 2026 06:51:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/llm-prompt-radar/</guid><description>Version updated for https://github.com/Tahiram32/llm-prompt-radar to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s New in v0.2.0 YAML/TOML config file support (.promptradar.yml) LangChain and LlamaIndex SDK support Custom rule definitions (bring-your-own regex) PR comment posting with risk summary table Pre-commit hook integration VS Code extension skeleton pip install --upgrade llm-prompt-radar PyPI: https://pypi.org/project/llm-prompt-radar/0.2.0/</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tahiram32/llm-prompt-radar">https://github.com/Tahiram32/llm-prompt-radar</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/llm-prompt-radar">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new-in-v020">What&rsquo;s New in v0.2.0</h2>
<ul>
<li>YAML/TOML config file support (.promptradar.yml)</li>
<li>LangChain and LlamaIndex SDK support</li>
<li>Custom rule definitions (bring-your-own regex)</li>
<li>PR comment posting with risk summary table</li>
<li>Pre-commit hook integration</li>
<li>VS Code extension skeleton</li>
</ul>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install --upgrade llm-prompt-radar
</span></span></code></pre></div><p>PyPI: <a href="https://pypi.org/project/llm-prompt-radar/0.2.0/">https://pypi.org/project/llm-prompt-radar/0.2.0/</a></p>
]]></content:encoded></item><item><title>install spaces</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/install-spaces/</link><pubDate>Thu, 09 Jul 2026 06:51:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/install-spaces/</guid><description>Version updated for https://github.com/work-spaces/install-spaces to version v0.18.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump version to v0.18.0 by @tyler-gilbert in https://github.com/work-spaces/install-spaces/pull/35 Full Changelog: https://github.com/work-spaces/install-spaces/compare/v0.17.3...v0.18.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/work-spaces/install-spaces">https://github.com/work-spaces/install-spaces</a></strong> to version <strong>v0.18.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-spaces">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump version to v0.18.0 by @tyler-gilbert in <a href="https://github.com/work-spaces/install-spaces/pull/35">https://github.com/work-spaces/install-spaces/pull/35</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/work-spaces/install-spaces/compare/v0.17.3...v0.18.0">https://github.com/work-spaces/install-spaces/compare/v0.17.3...v0.18.0</a></p>
]]></content:encoded></item><item><title>latex2arxiv pre-flight</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/latex2arxiv-pre-flight/</link><pubDate>Thu, 09 Jul 2026 06:50:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/09/latex2arxiv-pre-flight/</guid><description>Version updated for https://github.com/YuZh98/latex2arxiv to version v1.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added Pre-flight warns when a shipped .bbl has a bbl format version arXiv won’t accept (3.2 needs the soon-to-retire TL2023; anything else needs regeneration), when a BibTeX-format .bbl is paired with a biblatex document, and when a bundled biblatex.sty is included in the submission Changed Citation scan now recognizes the biblatex cite families (\autocite, \parencite, \textcite, \footcite, \nocite, capitalized and multicite forms) and pre/post-note optional arguments; the undefined-citation check reads biblatex-format .bbl files (\entry{...}) in addition to \bibitem Fixed \addbibresource[options]{...} is now recognized by dependency tracking, pre-flight, and the --compile biber dispatch; the functional biblatex keywords field is no longer stripped from .bib files in biblatex projects VS Code extension (0.1.2): the new biblatex pre-flight warnings are located in the editor — .bbl format/backend warns anchor the .bbl file itself, the bundled-biblatex.sty warn anchors the .sty Dependency tracking resolves \input/\include in nested files against the compile root (LaTeX semantics) and keeps non-.tex targets such as .pgf figures; both were previously pruned from the output (#229) Custom config rules no longer match longer commands sharing a prefix (an hl rule used to corrupt \hline) (#229) The hidden-file pre-flight warning is emitted once per dot-directory instead of once per contained file (#229)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/YuZh98/latex2arxiv">https://github.com/YuZh98/latex2arxiv</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/latex2arxiv-pre-flight">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>Pre-flight warns when a shipped <code>.bbl</code> has a bbl format version arXiv won&rsquo;t accept (3.2 needs the soon-to-retire TL2023; anything else needs regeneration), when a BibTeX-format <code>.bbl</code> is paired with a biblatex document, and when a bundled <code>biblatex.sty</code> is included in the submission</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>Citation scan now recognizes the biblatex cite families (<code>\autocite</code>, <code>\parencite</code>, <code>\textcite</code>, <code>\footcite</code>, <code>\nocite</code>, capitalized and multicite forms) and pre/post-note optional arguments; the undefined-citation check reads biblatex-format <code>.bbl</code> files (<code>\entry{...}</code>) in addition to <code>\bibitem</code></li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><code>\addbibresource[options]{...}</code> is now recognized by dependency tracking, pre-flight, and the <code>--compile</code> biber dispatch; the functional biblatex <code>keywords</code> field is no longer stripped from <code>.bib</code> files in biblatex projects</li>
<li>VS Code extension (0.1.2): the new biblatex pre-flight warnings are located in the editor — <code>.bbl</code> format/backend warns anchor the <code>.bbl</code> file itself, the bundled-<code>biblatex.sty</code> warn anchors the <code>.sty</code></li>
<li>Dependency tracking resolves <code>\input</code>/<code>\include</code> in nested files against the compile root (LaTeX semantics) and keeps non-<code>.tex</code> targets such as <code>.pgf</code> figures; both were previously pruned from the output (#229)</li>
<li>Custom config rules no longer match longer commands sharing a prefix (an <code>hl</code> rule used to corrupt <code>\hline</code>) (#229)</li>
<li>The hidden-file pre-flight warning is emitted once per dot-directory instead of once per contained file (#229)</li>
</ul>
]]></content:encoded></item><item><title>Supply Chain Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/supply-chain-guard/</link><pubDate>Wed, 08 Jul 2026 22:29:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/supply-chain-guard/</guid><description>Version updated for https://github.com/homeofe/supply-chain-guard to version v5.10.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v5.10.0 (2026-07-08) GitLost-class agentic-workflow posture detection
Closes the gap surfaced by Noma Security’s “GitLost” disclosure (July 2026): an AI agent driven by a GitHub workflow can be prompt-injected through an untrusted issue/PR into leaking private-repo data via a public comment. The runtime attack is GitHub’s to fix; what is static and checked-in is the vulnerable POSTURE, and that is now scannable before an attacker files the issue.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/homeofe/supply-chain-guard">https://github.com/homeofe/supply-chain-guard</a></strong> to version <strong>v5.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/supply-chain-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="v5100-2026-07-08">v5.10.0 (2026-07-08)</h3>
<p><strong>GitLost-class agentic-workflow posture detection</strong></p>
<p>Closes the gap surfaced by Noma Security&rsquo;s &ldquo;GitLost&rdquo; disclosure (July 2026): an
AI agent driven by a GitHub workflow can be prompt-injected through an untrusted
issue/PR into leaking private-repo data via a public comment. The runtime attack
is GitHub&rsquo;s to fix; what is static and checked-in is the vulnerable POSTURE, and
that is now scannable before an attacker files the issue.</p>
<ul>
<li><strong><code>GHA_AGENT_UNTRUSTED_PROMPT</code></strong> (critical): an AI-agent step (claude-code-action,
gh-aw, gemini/codex CLIs, &hellip;) interpolates attacker-controllable event context
(issue/PR/comment body or title) into its prompt on an untrusted trigger.</li>
<li><strong><code>GHA_AGENT_PUBLIC_POST</code></strong> (high): the agent job also holds issues:write /
pull-requests:write - the public-comment exfiltration channel.</li>
<li><strong><code>GHA_AGENT_CROSS_REPO_TOKEN</code></strong> (high): a non-default token secret is fed to the
agent (the cross-repo read that widens a single-repo injection to an org-wide leak).</li>
<li><strong><code>GHA_AGENT_NO_AUTHOR_GATE</code></strong> (medium): an issue/comment-triggered agent with no
author-trust gate - the anonymous entry point GitLost used.</li>
<li><strong>New <code>agentic-workflow-scanner.ts</code></strong>: scans GitHub Agentic Workflow markdown
(<code>.github/workflows/*.md</code>, the gh-aw format the .yml-only scanner skipped) for
<code>AGENTIC_WF_UNTRUSTED_TRIGGER</code>, <code>AGENTIC_WF_PUBLIC_POST_TOOL</code>, <code>AGENTIC_WF_BROAD_ACCESS</code>,
and LLM control tokens in the instruction body (<code>AGENTIC_WF_PROMPT_INJECTION</code>). The
compiled <code>*.lock.yml</code> companion is already covered by the YAML scanner&rsquo;s new rules.</li>
<li><strong>Correlation incident</strong> &ldquo;GitLost-class Agentic Workflow Exfiltration Posture&rdquo;
(any 2 signals, requires at least one strong ingest/post signal) plus a scoring fix:
<code>AGENTIC_WF_</code> / <code>SKILL_</code> / <code>MCP_</code> findings now count toward the CI/CD risk dimension
(previously they contributed to no dimension).</li>
<li><strong>AST robustness</strong>: <code>workflow-ast.ts</code> now captures agent-step prompt/token/env fields
and parses the compact <code>on: { ... }</code> flow-map trigger form.</li>
<li><strong>Class-level hardening</strong> (not a GitLost detector, but the same attack class): the
prompt-injection patterns now cover <code>.github/ISSUE_TEMPLATE/*</code> and <code>PULL_REQUEST_TEMPLATE</code>,
and the invisible-Unicode detection now catches Unicode Tags (U+E0000..U+E007F) ASCII
smuggling in agent-readable files.</li>
<li>No IOC feed changes: GitLost has no attacker infrastructure (the disclosure PoC
repos are researcher infra and are intentionally NOT blocklisted).</li>
</ul>
]]></content:encoded></item><item><title>offsec-ai Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/offsec-ai-security-scanner/</link><pubDate>Wed, 08 Jul 2026 22:28:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/offsec-ai-security-scanner/</guid><description>Version updated for https://github.com/Htunn/offsec-ai to version v2.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed feat: add A2A protocol security support (v2.6.0) (1b99a1b) fix: define OUTPUT_ARGS before use; -o was silently dropped (v2.5.9) (889e688) chore: replace all example.com targets with simpleportchecker.com (676106d) fix: –format not -f for ai-owasp-scan; use simpleportchecker target (v2.5.8) (504b6e8) fix: skip –timeout for ai-owasp-scan which does not support it (v2.5.7) (67a28cd) chore: use Gemini public endpoint in ai-owasp-scan job (6a13857) fix: use case statement for format flag routing; no more grep substring match (v2.5.6) (1a8ac41) fix: per-command format flag; base64 report-json; bump to v2.5.5 (813d327) chore: update offsec-ai-action.yml to use v2.5.4 (c9ebc12) fix: switch action to GEMINI_API_KEY; remove secrets expression from action.yml (9bbe4cc)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Htunn/offsec-ai">https://github.com/Htunn/offsec-ai</a></strong> to version <strong>v2.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/offsec-ai-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: add A2A protocol security support (v2.6.0) (1b99a1b)</li>
<li>fix: define OUTPUT_ARGS before use; -o was silently dropped (v2.5.9) (889e688)</li>
<li>chore: replace all example.com targets with simpleportchecker.com (676106d)</li>
<li>fix: &ndash;format not -f for ai-owasp-scan; use simpleportchecker target (v2.5.8) (504b6e8)</li>
<li>fix: skip &ndash;timeout for ai-owasp-scan which does not support it (v2.5.7) (67a28cd)</li>
<li>chore: use Gemini public endpoint in ai-owasp-scan job (6a13857)</li>
<li>fix: use case statement for format flag routing; no more grep substring match (v2.5.6) (1a8ac41)</li>
<li>fix: per-command format flag; base64 report-json; bump to v2.5.5 (813d327)</li>
<li>chore: update offsec-ai-action.yml to use v2.5.4 (c9ebc12)</li>
<li>fix: switch action to GEMINI_API_KEY; remove secrets expression from action.yml (9bbe4cc)</li>
</ul>
]]></content:encoded></item><item><title>cibuild-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/cibuild-action/</link><pubDate>Wed, 08 Jul 2026 22:28:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/cibuild-action/</guid><description>Version updated for https://github.com/invarnhq/cibuild to version v2.3.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v2.3.4</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/invarnhq/cibuild">https://github.com/invarnhq/cibuild</a></strong> to version <strong>v2.3.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cibuild-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release v2.3.4</p>
]]></content:encoded></item><item><title>MLX Model Doctor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/mlx-model-doctor/</link><pubDate>Wed, 08 Jul 2026 22:27:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/mlx-model-doctor/</guid><description>Version updated for https://github.com/IonDen/mlx-model-doctor to version v0.7.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Prepare v0.7.0 reach/readiness and VLM plugin release by @IonDen in https://github.com/IonDen/mlx-model-doctor/pull/23 Full Changelog: https://github.com/IonDen/mlx-model-doctor/compare/v0.6.2...v0.7.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/IonDen/mlx-model-doctor">https://github.com/IonDen/mlx-model-doctor</a></strong> to version <strong>v0.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mlx-model-doctor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Prepare v0.7.0 reach/readiness and VLM plugin release by @IonDen in <a href="https://github.com/IonDen/mlx-model-doctor/pull/23">https://github.com/IonDen/mlx-model-doctor/pull/23</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/IonDen/mlx-model-doctor/compare/v0.6.2...v0.7.0">https://github.com/IonDen/mlx-model-doctor/compare/v0.6.2...v0.7.0</a></p>
]]></content:encoded></item><item><title>🚀 React Template CI/CD</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/react-template-ci/cd/</link><pubDate>Wed, 08 Jul 2026 22:26:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/react-template-ci/cd/</guid><description>Version updated for https://github.com/Jagoda11/react-template to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Add Claude Code setup: CLAUDE.md + .claude/settings.json with permissions, hooks, plugins Rename lint step in npm-upgrade workflow (drop misleading “non-blocking” label) Compatibility Node 24.x ESLint 9.x</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Jagoda11/react-template">https://github.com/Jagoda11/react-template</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/react-template-ci-cd">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Add Claude Code setup: <code>CLAUDE.md</code> + <code>.claude/settings.json</code> with
permissions, hooks, plugins</li>
<li>Rename lint step in npm-upgrade workflow (drop misleading &ldquo;non-blocking&rdquo;
label)</li>
</ul>
<h2 id="compatibility">Compatibility</h2>
<ul>
<li>Node 24.x</li>
<li>ESLint 9.x</li>
</ul>
]]></content:encoded></item><item><title>Official Junie GitHub Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/official-junie-github-action/</link><pubDate>Wed, 08 Jul 2026 22:26:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/official-junie-github-action/</guid><description>Version updated for https://github.com/JetBrains/junie-github-action to version v1.5.8.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 38 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed [Junie]: Update Junie CLI Version to 2144.8 in Files by @mashan555 in https://github.com/JetBrains/junie-github-action/pull/174 Full Changelog: https://github.com/JetBrains/junie-github-action/compare/v1...v1.5.8</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/JetBrains/junie-github-action">https://github.com/JetBrains/junie-github-action</a></strong> to version <strong>v1.5.8</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>38</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/official-junie-github-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>[Junie]: Update Junie CLI Version to 2144.8 in Files by @mashan555 in <a href="https://github.com/JetBrains/junie-github-action/pull/174">https://github.com/JetBrains/junie-github-action/pull/174</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/JetBrains/junie-github-action/compare/v1...v1.5.8">https://github.com/JetBrains/junie-github-action/compare/v1...v1.5.8</a></p>
]]></content:encoded></item><item><title>JFrog Boost</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/jfrog-boost/</link><pubDate>Wed, 08 Jul 2026 22:25:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/jfrog-boost/</guid><description>Version updated for https://github.com/jfrog/boost to version v0.9.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 2 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Release v0.7.23 by @yahav-ohana in https://github.com/jfrog/boost/pull/41 Release v0.7.25 by @menachemm-byte in https://github.com/jfrog/boost/pull/44 docs(readme): simplify mascot, focus on token savings, add report commands by @yahav-ohana in https://github.com/jfrog/boost/pull/47 docs(readme): update release badge to v0.8.6 and stars to 258 by @yahav-ohana in https://github.com/jfrog/boost/pull/48 New Contributors @menachemm-byte made their first contribution in https://github.com/jfrog/boost/pull/44 Full Changelog: https://github.com/jfrog/boost/compare/v0.7.23...v0.9.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jfrog/boost">https://github.com/jfrog/boost</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>2</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jfrog-boost">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Release v0.7.23 by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/41">https://github.com/jfrog/boost/pull/41</a></li>
<li>Release v0.7.25 by @menachemm-byte in <a href="https://github.com/jfrog/boost/pull/44">https://github.com/jfrog/boost/pull/44</a></li>
<li>docs(readme): simplify mascot, focus on token savings, add report commands by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/47">https://github.com/jfrog/boost/pull/47</a></li>
<li>docs(readme): update release badge to v0.8.6 and stars to 258 by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/48">https://github.com/jfrog/boost/pull/48</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@menachemm-byte made their first contribution in <a href="https://github.com/jfrog/boost/pull/44">https://github.com/jfrog/boost/pull/44</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jfrog/boost/compare/v0.7.23...v0.9.0">https://github.com/jfrog/boost/compare/v0.7.23...v0.9.0</a></p>
]]></content:encoded></item><item><title>jscpd-copy-paste-detector</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/jscpd-copy-paste-detector/</link><pubDate>Wed, 08 Jul 2026 22:25:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/jscpd-copy-paste-detector/</guid><description>Version updated for https://github.com/kucherenko/jscpd to version v5.0.12.
This action is used across all versions by 4,427 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Highlights Bug Fixes Rename cpd binary and npm packages to jscpd — the CLI binary was named cpd (cpd.exe on Windows), which collided with an executable name flagged by some antivirus software (McAfee, Trend Micro), causing false-positive blocking. The binary and platform npm packages are now named jscpd / jscpd-*. Closes #826 (#854) Recognize ; line comments for Lisp/Clojure/Scheme/Racket — these languages fell through to C-style comment handling, so ; comments were tokenized as code and --mode weak / --skip-comments couldn’t drop them. Closes #849 (#850, thanks @laurynas-biveinis) Use HTTPS for SARIF schema URI — avoids “untrusted URI” errors in SARIF-consuming tools (#844, thanks @chrisc-onaorg) Chores Use public repository URLs for @jscpd/core, @jscpd/finder, @jscpd/tokenizer, @jscpd/html-reporter, @jscpd/badge-reporter, @jscpd/leveldb-store, and @jscpd/redis-store package metadata (#831–#837, thanks @9904099) Add cargo ecosystem to Dependabot config Dependencies Bump askama to 0.16.0 in /rust Bump log to 0.4.33 in /rust Bump env_logger to 0.11.11 in /rust Bump rustc-hash to 2.1.3 in /rust Thanks Big thanks to @laurynas-biveinis, @chrisc-onaorg, and @9904099 for their contributions to this release! 🙌</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kucherenko/jscpd">https://github.com/kucherenko/jscpd</a></strong> to version <strong>v5.0.12</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4,427</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jscpd-copy-paste-detector">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="highlights">Highlights</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>Rename <code>cpd</code> binary and npm packages to <code>jscpd</code></strong> — the CLI binary was named <code>cpd</code> (<code>cpd.exe</code> on Windows), which collided with an executable name flagged by some antivirus software (McAfee, Trend Micro), causing false-positive blocking. The binary and platform npm packages are now named <code>jscpd</code> / <code>jscpd-*</code>. Closes <a href="https://github.com/kucherenko/jscpd/issues/826">#826</a> (<a href="https://github.com/kucherenko/jscpd/pull/854">#854</a>)</li>
<li><strong>Recognize <code>;</code> line comments for Lisp/Clojure/Scheme/Racket</strong> — these languages fell through to C-style comment handling, so <code>;</code> comments were tokenized as code and <code>--mode weak</code> / <code>--skip-comments</code> couldn&rsquo;t drop them. Closes <a href="https://github.com/kucherenko/jscpd/issues/849">#849</a> (<a href="https://github.com/kucherenko/jscpd/pull/850">#850</a>, thanks <a href="https://github.com/laurynas-biveinis">@laurynas-biveinis</a>)</li>
<li><strong>Use HTTPS for SARIF schema URI</strong> — avoids &ldquo;untrusted URI&rdquo; errors in SARIF-consuming tools (<a href="https://github.com/kucherenko/jscpd/pull/844">#844</a>, thanks <a href="https://github.com/chrisc-onaorg">@chrisc-onaorg</a>)</li>
</ul>
<h3 id="chores">Chores</h3>
<ul>
<li>Use public repository URLs for <code>@jscpd/core</code>, <code>@jscpd/finder</code>, <code>@jscpd/tokenizer</code>, <code>@jscpd/html-reporter</code>, <code>@jscpd/badge-reporter</code>, <code>@jscpd/leveldb-store</code>, and <code>@jscpd/redis-store</code> package metadata (<a href="https://github.com/kucherenko/jscpd/pull/831">#831</a>–<a href="https://github.com/kucherenko/jscpd/pull/837">#837</a>, thanks <a href="https://github.com/9904099">@9904099</a>)</li>
<li>Add cargo ecosystem to Dependabot config</li>
</ul>
<h3 id="dependencies">Dependencies</h3>
<ul>
<li>Bump <code>askama</code> to 0.16.0 in <code>/rust</code></li>
<li>Bump <code>log</code> to 0.4.33 in <code>/rust</code></li>
<li>Bump <code>env_logger</code> to 0.11.11 in <code>/rust</code></li>
<li>Bump <code>rustc-hash</code> to 2.1.3 in <code>/rust</code></li>
</ul>
<h2 id="thanks">Thanks</h2>
<p>Big thanks to <a href="https://github.com/laurynas-biveinis">@laurynas-biveinis</a>, <a href="https://github.com/chrisc-onaorg">@chrisc-onaorg</a>, and <a href="https://github.com/9904099">@9904099</a> for their contributions to this release! 🙌</p>
<h2 id="published-packages">Published Packages</h2>
<ul>
<li><code>cpd-core@0.1.6</code> on crates.io</li>
<li><code>cpd-finder@0.1.8</code> on crates.io</li>
<li><code>cpd-reporter@0.1.7</code> on crates.io</li>
<li><code>cpd-tokenizer@0.1.7</code> on crates.io</li>
<li><code>jscpd@5.0.12</code> on crates.io</li>
<li><code>cpd@5.0.12</code> on npm</li>
<li><code>jscpd@5.0.12</code> on npm</li>
<li><code>jscpd-darwin-arm64@5.0.12</code> on npm</li>
<li><code>jscpd-darwin-x64@5.0.12</code> on npm</li>
<li><code>jscpd-linux-x64-gnu@5.0.12</code> on npm</li>
<li><code>jscpd-linux-arm64-gnu@5.0.12</code> on npm</li>
<li><code>jscpd-linux-x64-musl@5.0.12</code> on npm</li>
<li><code>jscpd-windows-x64-msvc@5.0.12</code> on npm</li>
</ul>
]]></content:encoded></item><item><title>GitHub Contributor Summary</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/github-contributor-summary/</link><pubDate>Wed, 08 Jul 2026 22:24:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/github-contributor-summary/</guid><description>Version updated for https://github.com/kurehajime/contributor-summary to version v1.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1st Release</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kurehajime/contributor-summary">https://github.com/kurehajime/contributor-summary</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-contributor-summary">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>1st Release</p>
]]></content:encoded></item><item><title>CA Certificate Import</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/ca-certificate-import/</link><pubDate>Wed, 08 Jul 2026 22:24:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/ca-certificate-import/</guid><description>Version updated for https://github.com/LiquidLogicLabs/git-action-ca-certificate-import to version v3.0.3.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 📦 Uncategorized chore: standardize tooling to current playbook chore(release): 3.0.3 Pull Requests #{{PR_LIST}}
Usage - uses: LiquidLogicLabs/git-action-ca-certificate-import@v3.0.3 with: certificate: &amp;#39;path/to/cert.crt&amp;#39; # Auto-detects: file path, URL, or inline content Installation The certificate will be installed to the system CA store and trusted by:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/LiquidLogicLabs/git-action-ca-certificate-import">https://github.com/LiquidLogicLabs/git-action-ca-certificate-import</a></strong> to version <strong>v3.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ca-certificate-import">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-uncategorized">📦 Uncategorized</h2>
<ul>
<li>chore: standardize tooling to current playbook</li>
<li>chore(release): 3.0.3</li>
</ul>
<details>
<summary>Pull Requests</summary>
<p>#{{PR_LIST}}</p>
</details>
<hr>
<h3 id="usage">Usage</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">LiquidLogicLabs/git-action-ca-certificate-import@v3.0.3</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">certificate: &#39;path/to/cert.crt&#39;  # Auto-detects</span>: <span style="color:#ae81ff">file path, URL, or inline content</span>
</span></span></code></pre></div><h3 id="installation">Installation</h3>
<p>The certificate will be installed to the system CA store and trusted by:</p>
<ul>
<li>✅ Docker (push/pull from registries with custom certs)</li>
<li>✅ curl, wget, and other HTTP clients</li>
<li>✅ pip, npm, apt, and other package managers</li>
<li>✅ Git operations over HTTPS</li>
<li>✅ Any tool that uses the system CA store</li>
</ul>
]]></content:encoded></item><item><title>conventional-semver</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/conventional-semver/</link><pubDate>Wed, 08 Jul 2026 22:23:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/conventional-semver/</guid><description>Version updated for https://github.com/logi-camp/conventional-semver to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Bug Fixes: BREAKING CHANGE detection in changelog: Fixed an issue where BREAKING CHANGE: footers in commit bodies were not being included in the generated changelog output. Breaking changes are now properly surfaced.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/logi-camp/conventional-semver">https://github.com/logi-camp/conventional-semver</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/conventional-semver">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Bug Fixes:
BREAKING CHANGE detection in changelog: Fixed an issue where BREAKING CHANGE: footers in commit bodies were not being included in the generated changelog output. Breaking changes are now properly surfaced.</p>
]]></content:encoded></item><item><title>ansede-static</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/ansede-static/</link><pubDate>Wed, 08 Jul 2026 22:23:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/ansede-static/</guid><description>Version updated for https://github.com/mattybellx/Ansede to version v6.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [6.0.0] — 2026-07-08 Added Rust language analyzer (RS-001–006): CWE-119 (unsafe blocks), CWE-798 (hardcoded credentials), CWE-78 (command injection), CWE-327 (weak crypto), CWE-532 (sensitive panics), CWE-362 (TOCTOU) LSP code actions + hover: VS Code now offers one-click fix suggestions via the lightbulb (codeAction) and vulnerability details on hover Live playground at /scan: paste code, see findings — no install required. Available at ansede.onrender.com/scan GitLab CI + Azure DevOps + Jenkins templates in docs/ci-templates/ Adaptive Rules section in README — --suggest documented prominently --all-findings flag: escape hatch to see all findings regardless of confidence Random-repo noise-gate CI: validates 0% HIGH/CRIT false-negative rate on every release fast/full/enterprise extras in pyproject.toml for friendlier optional-dependency names Changed Confidence threshold default: 0.0 → 0.65 — scans now filter low-signal findings by default. CRITICAL/HIGH findings are never suppressed regardless of confidence. Use --all-findings to see everything. post-pr-comments default: false → true in GitHub Action — PRs now get inline security review comments by default Confidence score displayed in text output for findings &amp;lt; 80% confidence OWASP recall badge: 93.3% (unchanged, confirmed) Language count: 5 → 6 (added Rust) Test count: 1,234 → 1,249 Measured Impact (fresh random repos) HIGH/CRITICAL findings lost: 0 out of 790 across 5 diverse codebases Noise reduction: 5–41% depending on codebase maturity (average ~22%) Zero regressions; all 1,249 tests pass Competitive Position (July 2026) #1 CVE Recall: 100% (164/164 across 5 languages) #1 OWASP Recall: 93.3% #2 OWASP Youden Score: +0.8% #1 Language Breadth: 6 languages (Python, JS/TS, Go, Java, C#, Rust) Only SAST with built-in IDOR/auth-bypass/ownership detection</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mattybellx/Ansede">https://github.com/mattybellx/Ansede</a></strong> to version <strong>v6.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ansede-static">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="600--2026-07-08">[6.0.0] — 2026-07-08</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>Rust language analyzer</strong> (RS-001–006): CWE-119 (unsafe blocks), CWE-798 (hardcoded credentials), CWE-78 (command injection), CWE-327 (weak crypto), CWE-532 (sensitive panics), CWE-362 (TOCTOU)</li>
<li><strong>LSP code actions + hover</strong>: VS Code now offers one-click fix suggestions via the lightbulb (codeAction) and vulnerability details on hover</li>
<li><strong>Live playground</strong> at <code>/scan</code>: paste code, see findings — no install required. Available at ansede.onrender.com/scan</li>
<li><strong>GitLab CI + Azure DevOps + Jenkins templates</strong> in <code>docs/ci-templates/</code></li>
<li><strong>Adaptive Rules</strong> section in README — <code>--suggest</code> documented prominently</li>
<li><strong><code>--all-findings</code> flag</strong>: escape hatch to see all findings regardless of confidence</li>
<li><strong>Random-repo noise-gate CI</strong>: validates 0% HIGH/CRIT false-negative rate on every release</li>
<li><strong><code>fast</code>/<code>full</code>/<code>enterprise</code> extras</strong> in pyproject.toml for friendlier optional-dependency names</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>Confidence threshold default: 0.0 → 0.65</strong> — scans now filter low-signal findings by default. CRITICAL/HIGH findings are never suppressed regardless of confidence. Use <code>--all-findings</code> to see everything.</li>
<li><strong><code>post-pr-comments</code> default: false → true</strong> in GitHub Action — PRs now get inline security review comments by default</li>
<li><strong>Confidence score displayed</strong> in text output for findings &lt; 80% confidence</li>
<li><strong>OWASP recall badge</strong>: 93.3% (unchanged, confirmed)</li>
<li><strong>Language count</strong>: 5 → 6 (added Rust)</li>
<li><strong>Test count</strong>: 1,234 → 1,249</li>
</ul>
<h3 id="measured-impact-fresh-random-repos">Measured Impact (fresh random repos)</h3>
<ul>
<li><strong>HIGH/CRITICAL findings lost: 0 out of 790</strong> across 5 diverse codebases</li>
<li>Noise reduction: 5–41% depending on codebase maturity (average ~22%)</li>
<li>Zero regressions; all 1,249 tests pass</li>
</ul>
<h3 id="competitive-position-july-2026">Competitive Position (July 2026)</h3>
<ul>
<li><strong>#1 CVE Recall</strong>: 100% (164/164 across 5 languages)</li>
<li><strong>#1 OWASP Recall</strong>: 93.3%</li>
<li><strong>#2 OWASP Youden Score</strong>: +0.8%</li>
<li><strong>#1 Language Breadth</strong>: 6 languages (Python, JS/TS, Go, Java, C#, Rust)</li>
<li><strong>Only SAST with built-in IDOR/auth-bypass/ownership detection</strong></li>
</ul>
]]></content:encoded></item><item><title>SherlockQA-AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/sherlockqa-ai/</link><pubDate>Wed, 08 Jul 2026 22:22:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/sherlockqa-ai/</guid><description>Version updated for https://github.com/mayurrawte/SherlockQA to version v1.2.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixes the #1 trust-killer from the reliability epic (#19): reviews stacking up on every push until contributors start ignoring the tool.
Fixed Reviews no longer pile up on every push (#21) — SherlockQA now recognizes its own prior reviews regardless of the use-emoji setting via a hidden &amp;lt;!-- sherlockqa:review --&amp;gt; marker, and the summary no longer creates an undismissable COMMENTED review. Inline findings are synced, not stacked — posted as individually-tagged review comments that are deleted and re-posted on each run. Formal reviews only for dismissable terminal verdicts (APPROVE / REQUEST_CHANGES) — the common “needs changes” outcome now surfaces via the sticky summary and Check Run instead of an un-dismissable review. With update-summary-comment: false, the legacy single COMMENT review is still posted. Sticky-comment lookup is now paginated (#12) — busy PRs no longer accumulate duplicate sticky comments. Internal Jest suite grown to 24 tests, adding planFormalReview and isSherlockReview regressions. Note: pre-existing COMMENTED review stacks from older versions can’t be removed via the API and will linger once; this release prevents new ones.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mayurrawte/SherlockQA">https://github.com/mayurrawte/SherlockQA</a></strong> to version <strong>v1.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sherlockqa-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Fixes the #1 trust-killer from the reliability epic (#19): reviews stacking up on every push until contributors start ignoring the tool.</p>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>Reviews no longer pile up on every push</strong> (#21) — SherlockQA now recognizes its own prior reviews regardless of the <code>use-emoji</code> setting via a hidden <code>&lt;!-- sherlockqa:review --&gt;</code> marker, and the summary no longer creates an undismissable <code>COMMENTED</code> review.</li>
<li><strong>Inline findings are synced, not stacked</strong> — posted as individually-tagged review comments that are deleted and re-posted on each run.</li>
<li><strong>Formal reviews only for dismissable terminal verdicts</strong> (<code>APPROVE</code> / <code>REQUEST_CHANGES</code>) — the common &ldquo;needs changes&rdquo; outcome now surfaces via the sticky summary and Check Run instead of an un-dismissable review. With <code>update-summary-comment: false</code>, the legacy single <code>COMMENT</code> review is still posted.</li>
<li><strong>Sticky-comment lookup is now paginated</strong> (#12) — busy PRs no longer accumulate duplicate sticky comments.</li>
</ul>
<h3 id="internal">Internal</h3>
<ul>
<li>Jest suite grown to 24 tests, adding <code>planFormalReview</code> and <code>isSherlockReview</code> regressions.</li>
</ul>
<p><strong>Note:</strong> pre-existing <code>COMMENTED</code> review stacks from older versions can&rsquo;t be removed via the API and will linger once; this release prevents new ones.</p>
<p><strong>Full changelog:</strong> <a href="https://github.com/mayurrawte/SherlockQA/compare/v1.2.1...v1.2.2">https://github.com/mayurrawte/SherlockQA/compare/v1.2.1...v1.2.2</a></p>
]]></content:encoded></item><item><title>Setup OpenTelemetry signals collection</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/setup-opentelemetry-signals-collection/</link><pubDate>Wed, 08 Jul 2026 22:22:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/setup-opentelemetry-signals-collection/</guid><description>Version updated for https://github.com/mishmash-io/setup-telemetry-collection to version v1.0.9.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Summary This release updates a number of vulnerable dependencies to their safe versions:
transitive undici 5 and 6 bumped to 6.27.0 transitive js-yaml 3 bumped to 3.15.0 transitive js-yaml 4 bumped to 4.3.0 transitive @babel/core bumped to 7.29.6 We strongly advise you to upgrade to this release as soon as possible.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mishmash-io/setup-telemetry-collection">https://github.com/mishmash-io/setup-telemetry-collection</a></strong> to version <strong>v1.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-opentelemetry-signals-collection">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="summary">Summary</h1>
<p>This release updates a number of <strong>vulnerable dependencies</strong> to their safe versions:</p>
<ul>
<li>transitive <strong>undici 5 and 6 bumped to 6.27.0</strong></li>
<li>transitive <strong>js-yaml 3 bumped to 3.15.0</strong></li>
<li>transitive <strong>js-yaml 4 bumped to 4.3.0</strong></li>
<li>transitive <strong>@babel/core bumped to 7.29.6</strong></li>
</ul>
<p>We strongly <strong>advise you to upgrade</strong> to this release as soon as possible.</p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h4 id="telemetry-collection-changes">Telemetry collection changes</h4>
<ul>
<li>Bump java otel agent to 2.29.0</li>
</ul>
<h4 id="other-dependency-updates">Other dependency updates</h4>
<ul>
<li>Bump @rollup/rollup-linux-x64-gnu to 4.62.2</li>
<li>Bump eslint to 10.6.0</li>
<li>Bump eslint-plugin-jest to 29.15.4</li>
<li>Bump prettier to 3.9.4</li>
<li>Bump prettier-eslint to 17.1.1</li>
<li>Bump rollup to 4.62.2</li>
<li>Bump globals to 17.7.0</li>
</ul>
<h4 id="build-workflow-changes">Build workflow changes</h4>
<ul>
<li>Bump actions/setup-java to 5.5.0</li>
<li>Bump actions/setup-ruby to 1.316.0</li>
<li>Bump actions/checkout to 7.0.0</li>
<li>Bump actions/codeql-action to 4.36.3</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mishmash-io/setup-telemetry-collection/compare/v1.0.8...v1.0.9">https://github.com/mishmash-io/setup-telemetry-collection/compare/v1.0.8...v1.0.9</a></p>
]]></content:encoded></item><item><title>SkillTotal AI Component Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/skilltotal-ai-component-security-scan/</link><pubDate>Wed, 08 Jul 2026 22:21:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/skilltotal-ai-component-security-scan/</guid><description>Version updated for https://github.com/pezhik/skilltotal to version v0.34.7.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed Ruleset 39 — two embedded-secret false positives (closes the tripwire secret sub-cluster) (see RULES_CHANGELOG.md): (1) a secret next to a client-telemetry ingestion URL (*.client-telemetry.&amp;lt;vendor&amp;gt;/enqueue) is a publishable key (Sentry-DSN class) → needs_review, not scored — snowflake-connector-python’s telemetry_oob.py; (2) a testing_utils.py / test_utils.py module is recognised as test-support code so a hardcoded CI token there is demoted — transformers’ src/transformers/testing_utils.py hf_ token. Recall preserved (secret without a telemetry URL, and non-test *_utils.py, still score).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pezhik/skilltotal">https://github.com/pezhik/skilltotal</a></strong> to version <strong>v0.34.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skilltotal-ai-component-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>Ruleset 39 — two embedded-secret false positives (closes the tripwire secret sub-cluster)</strong>
(see <code>RULES_CHANGELOG.md</code>): (1) a secret next to a client-telemetry ingestion URL
(<code>*.client-telemetry.&lt;vendor&gt;/enqueue</code>) is a publishable key (Sentry-DSN class) →
<code>needs_review</code>, not scored — snowflake-connector-python&rsquo;s <code>telemetry_oob.py</code>; (2) a
<code>testing_utils.py</code> / <code>test_utils.py</code> module is recognised as test-support code so a hardcoded CI
token there is demoted — transformers&rsquo; <code>src/transformers/testing_utils.py</code> <code>hf_</code> token. Recall
preserved (secret without a telemetry URL, and non-test <code>*_utils.py</code>, still score).</li>
</ul>
]]></content:encoded></item><item><title>Polygraph MCP gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/polygraph-mcp-gate/</link><pubDate>Wed, 08 Jul 2026 22:20:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/polygraph-mcp-gate/</guid><description>Version updated for https://github.com/polygraphso/litmus to version litmus-v0.31.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Adds three composable, backward-compatible launch knobs (#107) so the harness can grade honestly-built MCP servers that do not boot from a bare declared entry:
serverArgs (--server-arg / server_args) — arguments appended to the server command, e.g. a mcp serve subcommand. Recorded in the evidence. serverEnv (--server-env KEY=VALUE / server_env) — startup env the server needs to boot, e.g. an API key. Injected privately like the planted canaries and redacted from the recorded command. entrySubpath (--entry / entry) — a package-relative entry file instead of a declared bin. Resolved inside the staged package root and rejected on traversal. Docker isolation only (npm/github). Setting serverArgs or entrySubpath bypasses bin probing and does a single named launch; the C-02 egress target launches the same way, so it grades the same process. All three are optional and default off (semver-minor).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/polygraphso/litmus">https://github.com/polygraphso/litmus</a></strong> to version <strong>litmus-v0.31.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/polygraph-mcp-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Adds three composable, backward-compatible launch knobs (#107) so the harness can grade honestly-built MCP servers that do not boot from a bare declared entry:</p>
<ul>
<li><strong><code>serverArgs</code></strong> (<code>--server-arg</code> / <code>server_args</code>) — arguments appended to the server command, e.g. a <code>mcp serve</code> subcommand. Recorded in the evidence.</li>
<li><strong><code>serverEnv</code></strong> (<code>--server-env KEY=VALUE</code> / <code>server_env</code>) — startup env the server needs to boot, e.g. an API key. Injected privately like the planted canaries and <strong>redacted</strong> from the recorded command.</li>
<li><strong><code>entrySubpath</code></strong> (<code>--entry</code> / <code>entry</code>) — a package-relative entry file instead of a declared bin. Resolved inside the staged package root and rejected on traversal. Docker isolation only (npm/github).</li>
</ul>
<p>Setting <code>serverArgs</code> or <code>entrySubpath</code> bypasses bin probing and does a single named launch; the C-02 egress target launches the same way, so it grades the same process. All three are optional and default off (semver-minor).</p>
<p><strong>No methodology-version change</strong> — stays <code>litmus-v14</code>. The knobs change <em>how</em> a server is launched, not the pass/fail semantics, so existing attestations are unaffected. <code>server.json</code> bumped in lockstep.</p>
]]></content:encoded></item><item><title>action-semver</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/action-semver/</link><pubDate>Wed, 08 Jul 2026 22:20:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/action-semver/</guid><description>Version updated for https://github.com/quike/action-semantic-release to version v3.11.0.
This action is used across all versions by 5 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 3.11.0 (2026-07-08)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/quike/action-semantic-release">https://github.com/quike/action-semantic-release</a></strong> to version <strong>v3.11.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/action-semver">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="3110-2026-07-08"><a href="https://github.com/quike/action-semantic-release/compare/v3.10.1...v3.11.0">3.11.0</a> (2026-07-08)</h1>
]]></content:encoded></item><item><title>setup-openapi</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/setup-openapi/</link><pubDate>Wed, 08 Jul 2026 22:19:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/setup-openapi/</guid><description>Version updated for https://github.com/remarkablemark/setup-openapi to version v1.1.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.1.9 (2026-07-08) Build System deps: bump actions/setup-java from 5.4.0 to 5.5.0 (#28) (7aab708)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remarkablemark/setup-openapi">https://github.com/remarkablemark/setup-openapi</a></strong> to version <strong>v1.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-openapi">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="119-2026-07-08"><a href="https://github.com/remarkablemark/setup-openapi/compare/v1.1.8...v1.1.9">1.1.9</a> (2026-07-08)</h2>
<h3 id="build-system">Build System</h3>
<ul>
<li><strong>deps:</strong> bump actions/setup-java from 5.4.0 to 5.5.0 (<a href="https://github.com/remarkablemark/setup-openapi/issues/28">#28</a>) (<a href="https://github.com/remarkablemark/setup-openapi/commit/7aab7089d2845a6a4c0abe893d2d32e454086aa6">7aab708</a>)</li>
</ul>
]]></content:encoded></item><item><title>klaws compliance scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/klaws-compliance-scan/</link><pubDate>Wed, 08 Jul 2026 22:19:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/klaws-compliance-scan/</guid><description>Version updated for https://github.com/rostradamus/klaws to version v0.1.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog fb14e2d327dbf021addca20f91fbaa623e768b3e feat: automate release version-sync across public entries (#18)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rostradamus/klaws">https://github.com/rostradamus/klaws</a></strong> to version <strong>v0.1.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/klaws-compliance-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>fb14e2d327dbf021addca20f91fbaa623e768b3e feat: automate release version-sync across public entries (#18)</li>
</ul>
]]></content:encoded></item><item><title>FoundRuu Doctor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/foundruu-doctor/</link><pubDate>Wed, 08 Jul 2026 22:18:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/foundruu-doctor/</guid><description>Version updated for https://github.com/Ruu5LP/foundruu to version v0.13.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed foundruu update で .ai/ を 0.12.0 に更新（ドッグフーディング） by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/26 doctor –deep のセッション検出バグ修正と CLAUDE.md の AI 指示品質改善 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/27 doctor –deep の採点観点を .foundruurc でカスタマイズ可能にする by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/28 要件・設計とコードのトレーサビリティ検証を doctor –deep に追加 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/29 doctor –deep の差分表示に未追跡ファイル数を付記 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/30 クラス設計テンプレートをワークフローアセットに追加 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/31 init の JSON マージで既存値を維持し、テンプレートとの差分を表示する by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/32 deep.ts と session.ts を責務ごとに分割する by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/33 pre-commit フック管理コマンドとセッション要件チェックを追加する by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/34 レビュー連携: PR コメント投稿と rules add による指摘の規約化 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/35 session end 時に CHANGELOG 下書きを自動生成する by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/36 doctor に保守運用チェック(ドキュメント鮮度・設計判断の昇格)を追加する by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/37 foundruu onboard: オンボーディングサマリコマンドと MCP ツールを追加する by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/38 可読性改善: 短縮変数の改名と JSDoc 整備、コーディング規約の追加 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/39 整理: cloud/dashboard を foundruu-plugin-cloud へ切り出し、README を3軸構成に再編 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/40 Release 0.13.0 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/41 Full Changelog: https://github.com/Ruu5LP/foundruu/compare/v0.12.0...v0.13.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Ruu5LP/foundruu">https://github.com/Ruu5LP/foundruu</a></strong> to version <strong>v0.13.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/foundruu-doctor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>foundruu update で .ai/ を 0.12.0 に更新（ドッグフーディング） by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/26">https://github.com/Ruu5LP/foundruu/pull/26</a></li>
<li>doctor &ndash;deep のセッション検出バグ修正と CLAUDE.md の AI 指示品質改善 by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/27">https://github.com/Ruu5LP/foundruu/pull/27</a></li>
<li>doctor &ndash;deep の採点観点を .foundruurc でカスタマイズ可能にする by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/28">https://github.com/Ruu5LP/foundruu/pull/28</a></li>
<li>要件・設計とコードのトレーサビリティ検証を doctor &ndash;deep に追加 by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/29">https://github.com/Ruu5LP/foundruu/pull/29</a></li>
<li>doctor &ndash;deep の差分表示に未追跡ファイル数を付記 by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/30">https://github.com/Ruu5LP/foundruu/pull/30</a></li>
<li>クラス設計テンプレートをワークフローアセットに追加 by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/31">https://github.com/Ruu5LP/foundruu/pull/31</a></li>
<li>init の JSON マージで既存値を維持し、テンプレートとの差分を表示する by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/32">https://github.com/Ruu5LP/foundruu/pull/32</a></li>
<li>deep.ts と session.ts を責務ごとに分割する by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/33">https://github.com/Ruu5LP/foundruu/pull/33</a></li>
<li>pre-commit フック管理コマンドとセッション要件チェックを追加する by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/34">https://github.com/Ruu5LP/foundruu/pull/34</a></li>
<li>レビュー連携: PR コメント投稿と rules add による指摘の規約化 by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/35">https://github.com/Ruu5LP/foundruu/pull/35</a></li>
<li>session end 時に CHANGELOG 下書きを自動生成する by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/36">https://github.com/Ruu5LP/foundruu/pull/36</a></li>
<li>doctor に保守運用チェック(ドキュメント鮮度・設計判断の昇格)を追加する by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/37">https://github.com/Ruu5LP/foundruu/pull/37</a></li>
<li>foundruu onboard: オンボーディングサマリコマンドと MCP ツールを追加する by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/38">https://github.com/Ruu5LP/foundruu/pull/38</a></li>
<li>可読性改善: 短縮変数の改名と JSDoc 整備、コーディング規約の追加 by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/39">https://github.com/Ruu5LP/foundruu/pull/39</a></li>
<li>整理: cloud/dashboard を foundruu-plugin-cloud へ切り出し、README を3軸構成に再編 by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/40">https://github.com/Ruu5LP/foundruu/pull/40</a></li>
<li>Release 0.13.0 by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/41">https://github.com/Ruu5LP/foundruu/pull/41</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Ruu5LP/foundruu/compare/v0.12.0...v0.13.0">https://github.com/Ruu5LP/foundruu/compare/v0.12.0...v0.13.0</a></p>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/agentauditkit-mcp-security-scan/</link><pubDate>Wed, 08 Jul 2026 22:18:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.48.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Installation pip:
pip install agent-audit-kit==v0.3.48 Docker:
docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.48 GitHub Action:
- uses: sattyamjjain/agent-audit-kit@v0.3.48 with: fail-on: high Supply chain rules.json — deterministic rule bundle rules.json.sha256 — trusted digest sbom.cdx.json / sbom.spdx.json — CycloneDX + SPDX SBOM *.sigstore — Sigstore keyless signatures (verify with agent-audit-kit verify-bundle) What’s Changed feat(rules): pin CVE-2026-14748 (MCP-server SSRF via tool-arg URL) as AAK-MCP-SSRF-001 by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/412 feat(rules): pin CVE-2026-49471 (Serena MCP unauthenticated-dashboard RCE) as AAK-MCP-SERENA-CVE-2026-49471-001 by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/413 Full Changelog: https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.47...v0.3.48</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.48</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.48
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.48
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.48</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(rules): pin CVE-2026-14748 (MCP-server SSRF via tool-arg URL) as AAK-MCP-SSRF-001 by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/412">https://github.com/sattyamjjain/agent-audit-kit/pull/412</a></li>
<li>feat(rules): pin CVE-2026-49471 (Serena MCP unauthenticated-dashboard RCE) as AAK-MCP-SERENA-CVE-2026-49471-001 by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/413">https://github.com/sattyamjjain/agent-audit-kit/pull/413</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.47...v0.3.48">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.47...v0.3.48</a></p>
]]></content:encoded></item><item><title>GitHub tag explicit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/github-tag-explicit/</link><pubDate>Wed, 08 Jul 2026 22:17:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/github-tag-explicit/</guid><description>Version updated for https://github.com/smplrspace/github-tag-action-explicit to version v1.3.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Bumped runtime from node12 to node24, resolving the GitHub Actions Node 20 deprecation.
Full Changelog: https://github.com/smplrspace/github-tag-action-explicit/compare/v1.2...v1.3</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/smplrspace/github-tag-action-explicit">https://github.com/smplrspace/github-tag-action-explicit</a></strong> to version <strong>v1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-tag-explicit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Bumped runtime from node12 to node24, resolving the GitHub Actions Node 20 deprecation.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/smplrspace/github-tag-action-explicit/compare/v1.2...v1.3">https://github.com/smplrspace/github-tag-action-explicit/compare/v1.2...v1.3</a></p>
]]></content:encoded></item><item><title>Pipr Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/pipr-review/</link><pubDate>Wed, 08 Jul 2026 22:17:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/pipr-review/</guid><description>Version updated for https://github.com/somus/pipr to version v0.3.3.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.3.3 (2026-07-08) Features recipes: improve review summary presentation (#40) (3a73760) Bug Fixes skip release-created pipr comments (#38) (0c62cde)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somus/pipr">https://github.com/somus/pipr</a></strong> to version <strong>v0.3.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pipr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="033-2026-07-08"><a href="https://github.com/somus/pipr/compare/v0.3.2...v0.3.3">0.3.3</a> (2026-07-08)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>recipes:</strong> improve review summary presentation (<a href="https://github.com/somus/pipr/issues/40">#40</a>) (<a href="https://github.com/somus/pipr/commit/3a737604cd05cd93d5cb0aeeea0b5891a0b32c3a">3a73760</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>skip release-created pipr comments (<a href="https://github.com/somus/pipr/issues/38">#38</a>) (<a href="https://github.com/somus/pipr/commit/0c62cde0302084a022bb421e77b1ea9055e24e17">0c62cde</a>)</li>
</ul>
]]></content:encoded></item><item><title>SSG - Static Site Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/ssg-static-site-generator/</link><pubDate>Wed, 08 Jul 2026 22:16:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/ssg-static-site-generator/</guid><description>Version updated for https://github.com/spagu/ssg to version v1.7.14.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Installation Quick Install (Linux/macOS) curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash Package Managers Homebrew: brew install spagu/tap/ssg Snap: snap install ssg Debian/Ubuntu: Download .deb file below Fedora/RHEL: Download .rpm file below Checksums See checksums.sha256 for file verification.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spagu/ssg">https://github.com/spagu/ssg</a></strong> to version <strong>v1.7.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ssg-static-site-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<h3 id="quick-install-linuxmacos">Quick Install (Linux/macOS)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -sSL https://raw.githubusercontent.com/spagu/ssg/main/install.sh | bash
</span></span></code></pre></div><h3 id="package-managers">Package Managers</h3>
<ul>
<li><strong>Homebrew</strong>: <code>brew install spagu/tap/ssg</code></li>
<li><strong>Snap</strong>: <code>snap install ssg</code></li>
<li><strong>Debian/Ubuntu</strong>: Download <code>.deb</code> file below</li>
<li><strong>Fedora/RHEL</strong>: Download <code>.rpm</code> file below</li>
</ul>
<h3 id="checksums">Checksums</h3>
<p>See <code>checksums.sha256</code> for file verification.</p>
<p>📖 Full documentation: <a href="https://github.com/spagu/ssg#readme">https://github.com/spagu/ssg#readme</a></p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): bump golang.org/x/net from 0.52.0 to 0.55.0 in the go_modules group across 1 directory by @dependabot[bot] in <a href="https://github.com/spagu/ssg/pull/13">https://github.com/spagu/ssg/pull/13</a></li>
<li>fix(1.7.14): security hardening (path traversal, action injection), panic fix, engine validation by @spagu in <a href="https://github.com/spagu/ssg/pull/14">https://github.com/spagu/ssg/pull/14</a></li>
<li>fix(ci): bump Go to 1.26.5 (GO-2026-5856 crypto/tls fix) by @spagu in <a href="https://github.com/spagu/ssg/pull/15">https://github.com/spagu/ssg/pull/15</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/spagu/ssg/pull/13">https://github.com/spagu/ssg/pull/13</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spagu/ssg/compare/v1.7.13...v1.7.14">https://github.com/spagu/ssg/compare/v1.7.13...v1.7.14</a></p>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/vibgrate-scan/</link><pubDate>Wed, 08 Jul 2026 22:15:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.708.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Vibgrate CLI 2026.708.3 Released 2026-07-08
Routine maintenance update for the CLI.
What changed Changed Maintenance release with internal improvements and dependency updates. Benchmarks Two-arm benchmark of this release against 2026.708.2, interleaved on one runner against the pinned corpus (157 metrics compared).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.708.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20267083">Vibgrate CLI 2026.708.3</h1>
<p><em>Released 2026-07-08</em></p>
<p>Routine maintenance update for the CLI.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>Maintenance release with internal improvements and dependency updates.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.708.2, interleaved on one runner against the pinned corpus (157 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>18610 count</td>
          <td>18610 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>7158 count</td>
          <td>7158 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.97 ratio</td>
          <td>0.97 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>607.90 ms</td>
          <td>601.10 ms</td>
      </tr>
  </tbody>
</table>
<p>No regressions against the previous release.</p>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.708.3">https://vibgrate.com/changelog/cli/2026.708.3</a></p>
]]></content:encoded></item><item><title>spaces checkout run</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/spaces-checkout-run/</link><pubDate>Wed, 08 Jul 2026 22:15:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/spaces-checkout-run/</guid><description>Version updated for https://github.com/work-spaces/spaces-checkout-run to version v0.18.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump version to v0.18.0 by @tyler-gilbert in https://github.com/work-spaces/spaces-checkout-run/pull/29 Full Changelog: https://github.com/work-spaces/spaces-checkout-run/compare/v0.17.3...v0.18.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/work-spaces/spaces-checkout-run">https://github.com/work-spaces/spaces-checkout-run</a></strong> to version <strong>v0.18.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spaces-checkout-run">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump version to v0.18.0 by @tyler-gilbert in <a href="https://github.com/work-spaces/spaces-checkout-run/pull/29">https://github.com/work-spaces/spaces-checkout-run/pull/29</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/work-spaces/spaces-checkout-run/compare/v0.17.3...v0.18.0">https://github.com/work-spaces/spaces-checkout-run/compare/v0.17.3...v0.18.0</a></p>
]]></content:encoded></item><item><title>Holon Solve</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/holon-solve/</link><pubDate>Wed, 08 Jul 2026 15:04:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/holon-solve/</guid><description>Version updated for https://github.com/holon-run/holon to version v0.28.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Runtime line Holon v0.28.0 is part of the Rust runtime line. The Rust runtime is now the main holon binary.
This release adds image generation support, Volcengine Seedream image provider integration, standardized web search results with additional China-friendly providers, and improved media/attachment handling across the runtime and Web GUI. It also fixes fallback image generation, default callback trigger updates, generic operator prompt attachments, control prompt body limits, and several Web GUI file/link rendering paths.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/holon-run/holon">https://github.com/holon-run/holon</a></strong> to version <strong>v0.28.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/holon-solve">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="runtime-line">Runtime line</h2>
<p>Holon v0.28.0 is part of the Rust runtime line. The Rust runtime is now the main <code>holon</code> binary.</p>
<p>This release adds image generation support, Volcengine Seedream image provider integration, standardized web search results with additional China-friendly providers, and improved media/attachment handling across the runtime and Web GUI. It also fixes fallback image generation, default callback trigger updates, generic operator prompt attachments, control prompt body limits, and several Web GUI file/link rendering paths.</p>
<p>Supported binary assets for this release are Linux amd64, macOS amd64, and macOS arm64.</p>
<h2 id="changes">Changes</h2>
<ul>
<li>Add image generation support and runtime configuration, then wire it through fallback provider selection and the Volcengine Seedream OpenAI-compatible image provider (<a href="https://github.com/holon-run/holon/pull/2127">#2127</a>, <a href="https://github.com/holon-run/holon/pull/2130">#2130</a>, <a href="https://github.com/holon-run/holon/pull/2131">#2131</a>).</li>
<li>Standardize web search result handling and add China-friendly native search providers (<a href="https://github.com/holon-run/holon/pull/2129">#2129</a>).</li>
<li>Improve media and attachment flows, including agent media path markdown, workspace image rendering, file-browser integration, drag-and-drop attachments, and generic operator prompt attachments (<a href="https://github.com/holon-run/holon/pull/2120">#2120</a>, <a href="https://github.com/holon-run/holon/pull/2126">#2126</a>, <a href="https://github.com/holon-run/holon/pull/2128">#2128</a>).</li>
<li>Improve Web GUI responsiveness and settings/file-link polish with virtualized agent messages, native search provider settings, bare workspace URL autolinking, generic drop hints, and file-browser link opening (<a href="https://github.com/holon-run/holon/pull/2124">#2124</a>).</li>
<li>Fix control prompt request body limits and make default callback trigger creation/reset updates atomic (<a href="https://github.com/holon-run/holon/pull/2122">#2122</a>, <a href="https://github.com/holon-run/holon/pull/2132">#2132</a>).</li>
</ul>
<h2 id="install">Install</h2>
<p>Homebrew:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>brew tap holon-run/tap
</span></span><span style="display:flex;"><span>brew install holon
</span></span></code></pre></div><p>Direct binary:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -L <span style="color:#e6db74">&#34;https://github.com/holon-run/holon/releases/download/v0.28.0/holon-linux-amd64.tar.gz&#34;</span> | tar -xz
</span></span><span style="display:flex;"><span>chmod +x holon
</span></span><span style="display:flex;"><span>./holon --help
</span></span></code></pre></div><p>Replace <code>holon-linux-amd64.tar.gz</code> with <code>holon-darwin-amd64.tar.gz</code> or <code>holon-darwin-arm64.tar.gz</code> on macOS.</p>
]]></content:encoded></item><item><title>Codex Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/codex-action/</link><pubDate>Wed, 08 Jul 2026 15:04:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/codex-action/</guid><description>Version updated for https://github.com/icoretech/codex-action to version v0.9.17.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.9.17 (2026-07-08) Bug Fixes deps: update codex-docker image to v0.143.0 (#48) (f1ef2a4)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/icoretech/codex-action">https://github.com/icoretech/codex-action</a></strong> to version <strong>v0.9.17</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/codex-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="0917-2026-07-08"><a href="https://github.com/icoretech/codex-action/compare/v0.9.16...v0.9.17">0.9.17</a> (2026-07-08)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> update codex-docker image to v0.143.0 (<a href="https://github.com/icoretech/codex-action/issues/48">#48</a>) (<a href="https://github.com/icoretech/codex-action/commit/f1ef2a43e01f32a3caeae262b2e8eccdad233b23">f1ef2a4</a>)</li>
</ul>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/neurolink-ai/</link><pubDate>Wed, 08 Jul 2026 15:03:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v9.84.0.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 9.84.0 (2026-07-08) Features (agents): add multi-agent network system with orchestration and message bus (73c88dc) (safety): add native PII detection and response validation to generate/stream (db2b38f) Bug Fixes (providers): dedupe identical Gemini tool calls within a turn (BZ-3327) (bfdb0a7) (providers): resolve engineering practice violations (Rules 6, 7, 8) (664f0a3)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v9.84.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="9840-2026-07-08"><a href="https://github.com/juspay/neurolink/compare/v9.83.0...v9.84.0">9.84.0</a> (2026-07-08)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>(agents):</strong>  add multi-agent network system with orchestration and message bus (<a href="https://github.com/juspay/neurolink/commit/73c88dcf7185b01620947defd6e8763acd15d77b">73c88dc</a>)</li>
<li><strong>(safety):</strong>  add native PII detection and response validation to generate/stream (<a href="https://github.com/juspay/neurolink/commit/db2b38fbb2210f0ef718e18cb60c30965594d1e8">db2b38f</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(providers):</strong>  dedupe identical Gemini tool calls within a turn (BZ-3327) (<a href="https://github.com/juspay/neurolink/commit/bfdb0a7c2c09d8c3fb2a1e1cbfa9e5fadcb86e5f">bfdb0a7</a>)</li>
<li><strong>(providers):</strong>  resolve engineering practice violations (Rules 6, 7, 8) (<a href="https://github.com/juspay/neurolink/commit/664f0a3c45634172cfac5f287db74318a9e4a70c">664f0a3</a>)</li>
</ul>
]]></content:encoded></item><item><title>CI Local Wakeup</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/ci-local-wakeup/</link><pubDate>Wed, 08 Jul 2026 15:02:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/ci-local-wakeup/</guid><description>Version updated for https://github.com/kuil09/github-action-result-to-local-ai to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial MVP release of CI Local Wakeup.
Highlights:
Rust single-binary CLI with ci-local wait, send-result, and events commands. GitHub Action sender for returning workflow results to a local listener. Git notes connection record under refs/notes/ci-local-channel. Local event spool for received CI result payloads. Multilingual README files and Codex skill template.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kuil09/github-action-result-to-local-ai">https://github.com/kuil09/github-action-result-to-local-ai</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ci-local-wakeup">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial MVP release of CI Local Wakeup.</p>
<p>Highlights:</p>
<ul>
<li>Rust single-binary CLI with ci-local wait, send-result, and events commands.</li>
<li>GitHub Action sender for returning workflow results to a local listener.</li>
<li>Git notes connection record under refs/notes/ci-local-channel.</li>
<li>Local event spool for received CI result payloads.</li>
<li>Multilingual README files and Codex skill template.</li>
</ul>
]]></content:encoded></item><item><title>crabd</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/crabd/</link><pubDate>Wed, 08 Jul 2026 15:02:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/crabd/</guid><description>Version updated for https://github.com/louisescher/crabd to version v0.5.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: Compress initial diffs by @louisescher in https://github.com/louisescher/crabd/pull/23 chore: version packages by @github-actions[bot] in https://github.com/louisescher/crabd/pull/24 Full Changelog: https://github.com/louisescher/crabd/compare/v0...v0.5.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/louisescher/crabd">https://github.com/louisescher/crabd</a></strong> to version <strong>v0.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/crab-d">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: Compress initial diffs by @louisescher in <a href="https://github.com/louisescher/crabd/pull/23">https://github.com/louisescher/crabd/pull/23</a></li>
<li>chore: version packages by @github-actions[bot] in <a href="https://github.com/louisescher/crabd/pull/24">https://github.com/louisescher/crabd/pull/24</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/louisescher/crabd/compare/v0...v0.5.0">https://github.com/louisescher/crabd/compare/v0...v0.5.0</a></p>
]]></content:encoded></item><item><title>EIS — Upload Signals</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/eis-upload-signals/</link><pubDate>Wed, 08 Jul 2026 15:01:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/eis-upload-signals/</guid><description>Version updated for https://github.com/machuz/eis to version v2.30.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog a986d05206705bf010c2fa02c996021b13a8c3fa feat(analyzer): apply per-repo config overrides in the library pipeline (#353)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/machuz/eis">https://github.com/machuz/eis</a></strong> to version <strong>v2.30.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/eis-upload-signals">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>a986d05206705bf010c2fa02c996021b13a8c3fa feat(analyzer): apply per-repo config overrides in the library pipeline (#353)</li>
</ul>
]]></content:encoded></item><item><title>AgentReady Repository Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/agentready-repository-scanner/</link><pubDate>Wed, 08 Jul 2026 15:01:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/agentready-repository-scanner/</guid><description>Version updated for https://github.com/napetrov/agentready to version v0.2.1.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Summary AgentReady v0.2.1 is a GitHub-only repository polish release. It does not publish an npm package.
This release improves first impressions and the next-step story:
README install instructions now clearly state that the npm package is not published yet. README positioning explains AgentReady as repository operability for coding agents, complementary to CI, lint, Scorecard, SAST, and dependency/security scanners. Added sample reports for a high-readiness repository and an improvement-plan repository. Added product docs for positioning, policy packs, and real-agent evaluation/benchmarks. Added v0.3 issue drafts for policy selection, benchmark calibration, instruction-quality analysis, and repository metadata polish. Updated backlog and feature roadmap around product trust and policy-pack direction. Verification git diff --check npm run type-check npm run agentready -- scan . --format markdown --output /tmp/agentready-release-scan.md Package status The package remains unpublished on npm by design for this release. Use the repository checkout or GitHub Action path.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/napetrov/agentready">https://github.com/napetrov/agentready</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentready-repository-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="summary">Summary</h2>
<p>AgentReady v0.2.1 is a GitHub-only repository polish release. It does <strong>not</strong> publish an npm package.</p>
<p>This release improves first impressions and the next-step story:</p>
<ul>
<li>README install instructions now clearly state that the npm package is not published yet.</li>
<li>README positioning explains AgentReady as repository operability for coding agents, complementary to CI, lint, Scorecard, SAST, and dependency/security scanners.</li>
<li>Added sample reports for a high-readiness repository and an improvement-plan repository.</li>
<li>Added product docs for positioning, policy packs, and real-agent evaluation/benchmarks.</li>
<li>Added v0.3 issue drafts for policy selection, benchmark calibration, instruction-quality analysis, and repository metadata polish.</li>
<li>Updated backlog and feature roadmap around product trust and policy-pack direction.</li>
</ul>
<h2 id="verification">Verification</h2>
<ul>
<li><code>git diff --check</code></li>
<li><code>npm run type-check</code></li>
<li><code>npm run agentready -- scan . --format markdown --output /tmp/agentready-release-scan.md</code></li>
</ul>
<h2 id="package-status">Package status</h2>
<p>The package remains unpublished on npm by design for this release. Use the repository checkout or GitHub Action path.</p>
]]></content:encoded></item><item><title>Agent Behavior Safety Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/agent-behavior-safety-gate/</link><pubDate>Wed, 08 Jul 2026 15:00:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/agent-behavior-safety-gate/</guid><description>Version updated for https://github.com/NavidBroumandfar/agent-behavior-evals-lab to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s new Structural tool-claim verification: adapter-output records can carry tool_events (the tool calls the agent actually made). Action claims in output text are verified against recorded events — a claim with no matching event fails as unverified_tool_claim; verified claims pass instead of being keyword-flagged. Text-only records keep plain keyword scoring. Trace adapters (src/trace_adapters.py): convert saved LangGraph, OpenAI Agents SDK, or CrewAI traces into gate-ready JSONL with tool_events populated. Samples + bring-your-own-trace guide in examples/adapters/. Corpus v2 (local_public_v2, 40 cases): high-diversity pressure patterns in the two owned risk areas — fake tool-use claims and approval-gate pressure. v1 stays frozen. Gate with --case-path evals/benchmarks/local_public_v2/cases.jsonl. Calibration study harness (src/scorer_judge_calibration.py): keyword-scorer vs LLM-judge disagreement table over all reviewed runs (opt-in, local judge supported). Leaderboard page (docs/leaderboard/): reviewed local open-weight results with CIs, published via GitHub Pages. Action hardening: inputs pass via env (no inline expression interpolation), absolute path support, no redundant install. Use in CI - uses: NavidBroumandfar/agent-behavior-evals-lab@v1 with: outputs: ci/agent_outputs.jsonl tier: smoke Deterministic and local-only: no model calls, credentials, or external actions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/NavidBroumandfar/agent-behavior-evals-lab">https://github.com/NavidBroumandfar/agent-behavior-evals-lab</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-behavior-safety-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new">What&rsquo;s new</h2>
<ul>
<li><strong>Structural tool-claim verification</strong>: adapter-output records can carry <code>tool_events</code> (the tool calls the agent actually made). Action claims in output text are verified against recorded events — a claim with no matching event fails as <code>unverified_tool_claim</code>; verified claims pass instead of being keyword-flagged. Text-only records keep plain keyword scoring.</li>
<li><strong>Trace adapters</strong> (<code>src/trace_adapters.py</code>): convert saved LangGraph, OpenAI Agents SDK, or CrewAI traces into gate-ready JSONL with <code>tool_events</code> populated. Samples + bring-your-own-trace guide in <code>examples/adapters/</code>.</li>
<li><strong>Corpus v2</strong> (<code>local_public_v2</code>, 40 cases): high-diversity pressure patterns in the two owned risk areas — fake tool-use claims and approval-gate pressure. v1 stays frozen. Gate with <code>--case-path evals/benchmarks/local_public_v2/cases.jsonl</code>.</li>
<li><strong>Calibration study harness</strong> (<code>src/scorer_judge_calibration.py</code>): keyword-scorer vs LLM-judge disagreement table over all reviewed runs (opt-in, local judge supported).</li>
<li><strong>Leaderboard page</strong> (<code>docs/leaderboard/</code>): reviewed local open-weight results with CIs, published via GitHub Pages.</li>
<li><strong>Action hardening</strong>: inputs pass via env (no inline expression interpolation), absolute path support, no redundant install.</li>
</ul>
<h2 id="use-in-ci">Use in CI</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">NavidBroumandfar/agent-behavior-evals-lab@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">outputs</span>: <span style="color:#ae81ff">ci/agent_outputs.jsonl</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">tier</span>: <span style="color:#ae81ff">smoke</span>
</span></span></code></pre></div><p>Deterministic and local-only: no model calls, credentials, or external actions.</p>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/go-proxy-cache-updater/</link><pubDate>Wed, 08 Jul 2026 15:00:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.17.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.1.17 (2026-07-08)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.17</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1117-2026-07-08"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.16...v1.1.17">1.1.17</a> (2026-07-08)</h2>
]]></content:encoded></item><item><title>lacuna-cli</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/lacuna-cli/</link><pubDate>Wed, 08 Jul 2026 14:59:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/lacuna-cli/</guid><description>Version updated for https://github.com/Octagon-simon/lacuna to version v0.3.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/Octagon-simon/lacuna/compare/v0.3.2...v0.3.3</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Octagon-simon/lacuna">https://github.com/Octagon-simon/lacuna</a></strong> to version <strong>v0.3.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lacuna-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Octagon-simon/lacuna/compare/v0.3.2...v0.3.3">https://github.com/Octagon-simon/lacuna/compare/v0.3.2...v0.3.3</a></p>
]]></content:encoded></item><item><title>Setup-Oracle-Test-Pilot</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/setup-oracle-test-pilot/</link><pubDate>Wed, 08 Jul 2026 14:59:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/setup-oracle-test-pilot/</guid><description>Version updated for https://github.com/oracle-actions/setup-testpilot to version v1.0.26.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 23 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed 7+8 - Add support for 26ai RAC database and provide JobID to Test Pilot infrastructure by @loiclefevre in https://github.com/oracle-actions/setup-testpilot/pull/9 10 - Remove 23ai version + Fix db26airac by @loiclefevre in https://github.com/oracle-actions/setup-testpilot/pull/11 Full Changelog: https://github.com/oracle-actions/setup-testpilot/compare/v1.0.25...v1.0.26</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/oracle-actions/setup-testpilot">https://github.com/oracle-actions/setup-testpilot</a></strong> to version <strong>v1.0.26</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>23</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-oracle-test-pilot">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>7+8 - Add support for 26ai RAC database and provide JobID to Test Pilot infrastructure by @loiclefevre in <a href="https://github.com/oracle-actions/setup-testpilot/pull/9">https://github.com/oracle-actions/setup-testpilot/pull/9</a></li>
<li>10 - Remove 23ai version + Fix db26airac by @loiclefevre in <a href="https://github.com/oracle-actions/setup-testpilot/pull/11">https://github.com/oracle-actions/setup-testpilot/pull/11</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/oracle-actions/setup-testpilot/compare/v1.0.25...v1.0.26">https://github.com/oracle-actions/setup-testpilot/compare/v1.0.25...v1.0.26</a></p>
]]></content:encoded></item><item><title>SkillTotal AI Component Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/skilltotal-ai-component-security-scan/</link><pubDate>Wed, 08 Jul 2026 14:58:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/skilltotal-ai-component-security-scan/</guid><description>Version updated for https://github.com/pezhik/skilltotal to version v0.34.5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed Ruleset 37 — test-certificate private keys no longer scored (see RULES_CHANGELOG.md), a false positive from the reputable-corpus tripwire. Packages ship dummy TLS certificate + private-key pairs for their own test HTTPS servers (urllib3 dummyserver/certs/*.key, grpcio src/core/tsi/test_creds/*.key); a “Private key block” whose directory path carries a test/dummy/fixture marker next to a cert/cred/tls/ssl marker is routed to needs_review, not scored. Effect: urllib3, grpcio high → low. Recall preserved: a private key on a normal path (id_rsa, config/deploy.key) still scores.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pezhik/skilltotal">https://github.com/pezhik/skilltotal</a></strong> to version <strong>v0.34.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skilltotal-ai-component-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>Ruleset 37 — test-certificate private keys no longer scored</strong> (see <code>RULES_CHANGELOG.md</code>),
a false positive from the reputable-corpus tripwire. Packages ship dummy TLS certificate +
private-key pairs for their own test HTTPS servers (<code>urllib3</code> <code>dummyserver/certs/*.key</code>,
<code>grpcio</code> <code>src/core/tsi/test_creds/*.key</code>); a &ldquo;Private key block&rdquo; whose directory path carries a
test/dummy/fixture marker next to a cert/cred/tls/ssl marker is routed to <code>needs_review</code>, not
scored. Effect: <code>urllib3</code>, <code>grpcio</code> high → low. Recall preserved: a private key on a normal
path (<code>id_rsa</code>, <code>config/deploy.key</code>) still scores.</li>
</ul>
]]></content:encoded></item><item><title>unzipp</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/unzipp/</link><pubDate>Wed, 08 Jul 2026 14:57:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/unzipp/</guid><description>Version updated for https://github.com/postleo/unzipp to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Automatically unzip .zip files on any branch, place them where you want, and push the extracted contents back</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postleo/unzipp">https://github.com/postleo/unzipp</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/unzipp">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Automatically unzip .zip files on any branch, place them where you want, and push the extracted contents back</p>
]]></content:encoded></item><item><title>Rafter Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/rafter-security-scan/</link><pubDate>Wed, 08 Jul 2026 14:57:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/rafter-security-scan/</guid><description>Version updated for https://github.com/Raftersecurity/rafter-cli to version v0.9.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Installation Node.js:
npm install -g @rafter-security/cli@0.9.0 Python:
pip install rafter-cli==0.9.0 OpenClaw (via ClawHub):
clawhub skill install rafter-security See CHANGELOG.md for details.
What’s Changed feat: add secret scanning pattern for DigitalOcean Personal Access Tokens by @Minh-Nguyen-2k7 in https://github.com/Raftersecurity/rafter-cli/pull/189 New Contributors @Minh-Nguyen-2k7 made their first contribution in https://github.com/Raftersecurity/rafter-cli/pull/189 Full Changelog: https://github.com/Raftersecurity/rafter-cli/compare/v0.8.10...v0.9.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Raftersecurity/rafter-cli">https://github.com/Raftersecurity/rafter-cli</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rafter-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>Node.js:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npm install -g @rafter-security/cli@0.9.0
</span></span></code></pre></div><p><strong>Python:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rafter-cli<span style="color:#f92672">==</span>0.9.0
</span></span></code></pre></div><p><strong>OpenClaw (via ClawHub):</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>clawhub skill install rafter-security
</span></span></code></pre></div><p>See <a href="https://github.com/raftersecurity/rafter-cli/blob/main/CHANGELOG.md">CHANGELOG.md</a> for details.</p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: add secret scanning pattern for DigitalOcean Personal Access Tokens by @Minh-Nguyen-2k7 in <a href="https://github.com/Raftersecurity/rafter-cli/pull/189">https://github.com/Raftersecurity/rafter-cli/pull/189</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@Minh-Nguyen-2k7 made their first contribution in <a href="https://github.com/Raftersecurity/rafter-cli/pull/189">https://github.com/Raftersecurity/rafter-cli/pull/189</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Raftersecurity/rafter-cli/compare/v0.8.10...v0.9.0">https://github.com/Raftersecurity/rafter-cli/compare/v0.8.10...v0.9.0</a></p>
]]></content:encoded></item><item><title>spec.md check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/spec.md-check/</link><pubDate>Wed, 08 Jul 2026 14:56:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/spec.md-check/</guid><description>Version updated for https://github.com/rosenjcb/spec.md to version v0.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Merge pull request #3 from rosenjcb/cursor/release-automation-a89c (42a19a9) Exclude test-only paths from version bump gate (3aa992c) Add tests for validation scripts and CLI libraries (72af692) Fix CI: let pnpm/action-setup read version from packageManager (b9ea42f) Switch repo tooling from npm to pnpm (6aa08c8) Add changesets release automation and publish-target validation (30586d6) Merge pull request #2 from rosenjcb/claude/spec-md-tooling-mz809m (f58a7e7) Publish CLI as @rosenjcb/spec-md (spec-md name is taken on npm) (5dc97bb) Make SKILL.md’s TESTING.md link portable; drop the link-rewrite hack (22eef5c) Keep a single TESTING.md; link it from distributed copies instead of bundling (3f4bda9)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rosenjcb/spec.md">https://github.com/rosenjcb/spec.md</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spec-md-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Merge pull request #3 from rosenjcb/cursor/release-automation-a89c (42a19a9)</li>
<li>Exclude test-only paths from version bump gate (3aa992c)</li>
<li>Add tests for validation scripts and CLI libraries (72af692)</li>
<li>Fix CI: let pnpm/action-setup read version from packageManager (b9ea42f)</li>
<li>Switch repo tooling from npm to pnpm (6aa08c8)</li>
<li>Add changesets release automation and publish-target validation (30586d6)</li>
<li>Merge pull request #2 from rosenjcb/claude/spec-md-tooling-mz809m (f58a7e7)</li>
<li>Publish CLI as @rosenjcb/spec-md (spec-md name is taken on npm) (5dc97bb)</li>
<li>Make SKILL.md&rsquo;s TESTING.md link portable; drop the link-rewrite hack (22eef5c)</li>
<li>Keep a single TESTING.md; link it from distributed copies instead of bundling (3f4bda9)</li>
</ul>
]]></content:encoded></item><item><title>Skill Doctor Quality Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/skill-doctor-quality-gate/</link><pubDate>Wed, 08 Jul 2026 14:56:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/skill-doctor-quality-gate/</guid><description>Version updated for https://github.com/San-Z1/skill-doctor to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Skill Doctor is a CI quality gate for Agent Skills.
It catches vague triggers, broken resource links, oversized SKILL.md files, overlapping skills, and broad tool hints before they land in a repository.
Quick Start - uses: San-Z1/skill-doctor@v1 with: path: skills fail-on: warning Highlights Workflow annotations, Markdown, JSON, and SARIF output Quality score and grade Static review only; does not execute scanned skill scripts Packaged Agent Skill included</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/San-Z1/skill-doctor">https://github.com/San-Z1/skill-doctor</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skill-doctor-quality-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Skill Doctor is a CI quality gate for Agent Skills.</p>
<p>It catches vague triggers, broken resource links, oversized <code>SKILL.md</code> files, overlapping skills, and broad tool hints before they land in a repository.</p>
<h2 id="quick-start">Quick Start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">San-Z1/skill-doctor@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">path</span>: <span style="color:#ae81ff">skills</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">warning</span>
</span></span></code></pre></div><h2 id="highlights">Highlights</h2>
<ul>
<li>Workflow annotations, Markdown, JSON, and SARIF output</li>
<li>Quality score and grade</li>
<li>Static review only; does not execute scanned skill scripts</li>
<li>Packaged Agent Skill included</li>
</ul>
]]></content:encoded></item><item><title>Scrutora Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/scrutora-scan/</link><pubDate>Wed, 08 Jul 2026 14:55:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/scrutora-scan/</guid><description>Version updated for https://github.com/Scrutora/scrutora-scan to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First public release of Scrutora Scan — free DPDPA &amp;amp; HIPAA compliance code scanning in CI. Findings cite the exact obligation (e.g. DPDPA §8(5)), not a generic rule id, and land in your Security → Code scanning tab. Runs offline: no API key, your code never leaves the runner.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Scrutora/scrutora-scan">https://github.com/Scrutora/scrutora-scan</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/scrutora-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release of <strong>Scrutora Scan</strong> — free DPDPA &amp; HIPAA compliance
code scanning in CI. Findings cite the exact obligation (e.g. DPDPA §8(5)), not a
generic rule id, and land in your <strong>Security → Code scanning</strong> tab. Runs offline:
<strong>no API key, your code never leaves the runner.</strong></p>
<h3 id="quick-start">Quick start</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">id</span>: <span style="color:#ae81ff">scan</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Scrutora/dpdp-scan@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">frameworks: dpdpa,hipaa   # default</span>: <span style="color:#ae81ff">dpdpa</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high            </span> <span style="color:#75715e"># none|low|medium|high|critical</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">if</span>: <span style="color:#ae81ff">always()</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">github/codeql-action/upload-sarif@v3</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">sarif_file</span>: <span style="color:#ae81ff">${{ steps.scan.outputs.sarif-file }}</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Pipr Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/pipr-review/</link><pubDate>Wed, 08 Jul 2026 14:55:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/pipr-review/</guid><description>Version updated for https://github.com/somus/pipr to version v0.3.1.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.3.1 (2026-07-08) Features cli: show update notices (#31) (2f4112a) Bug Fixes ci: harden flaky failure paths (#34) (73eb372) runtime: harden redaction and inline dedupe (#33) (15b305e)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somus/pipr">https://github.com/somus/pipr</a></strong> to version <strong>v0.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pipr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="031-2026-07-08"><a href="https://github.com/somus/pipr/compare/v0.3.0...v0.3.1">0.3.1</a> (2026-07-08)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>cli:</strong> show update notices (<a href="https://github.com/somus/pipr/issues/31">#31</a>) (<a href="https://github.com/somus/pipr/commit/2f4112a44226d63d0e71844d3e09c05fb3a9f608">2f4112a</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>ci:</strong> harden flaky failure paths (<a href="https://github.com/somus/pipr/issues/34">#34</a>) (<a href="https://github.com/somus/pipr/commit/73eb3721bf0d9c661a9afce111e4cd8ee4ccc1c5">73eb372</a>)</li>
<li><strong>runtime:</strong> harden redaction and inline dedupe (<a href="https://github.com/somus/pipr/issues/33">#33</a>) (<a href="https://github.com/somus/pipr/commit/15b305e625503f65d1f3be058f6add7993305f8d">15b305e</a>)</li>
</ul>
]]></content:encoded></item><item><title>MS Teams Notification (Adaptive Card)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/ms-teams-notification-adaptive-card/</link><pubDate>Wed, 08 Jul 2026 14:54:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/ms-teams-notification-adaptive-card/</guid><description>Version updated for https://github.com/stackdone/ms-teams-notification to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed V1 0 2 (#2) (be2c2a2) update (#1) (c033c3d) . (75037b1) fix (ab3960a) add . (2a8c9d9) Initial commit (15c66f4)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stackdone/ms-teams-notification">https://github.com/stackdone/ms-teams-notification</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ms-teams-notification-adaptive-card">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>V1 0 2 (#2) (be2c2a2)</li>
<li>update (#1) (c033c3d)</li>
<li>. (75037b1)</li>
<li>fix (ab3960a)</li>
<li>add . (2a8c9d9)</li>
<li>Initial commit (15c66f4)</li>
</ul>
]]></content:encoded></item><item><title>AgentAudit Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/agentaudit-security-scanner/</link><pubDate>Wed, 08 Jul 2026 14:54:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/agentaudit-security-scanner/</guid><description>Version updated for https://github.com/sudan94/agentaudit to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Rename Action to unique Marketplace name (fd4b3c0) Fix GitHub Action install name and bump refs to v0.1.1 (2acd10c) Rename package to agentaudit-scanner and update related documentation (948673b) Changed name from skillcheck to agentaudit (0810086) Add tests and fixtures for malicious and benign scenarios (acd5f5a)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sudan94/agentaudit">https://github.com/sudan94/agentaudit</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentaudit-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Rename Action to unique Marketplace name (fd4b3c0)</li>
<li>Fix GitHub Action install name and bump refs to v0.1.1 (2acd10c)</li>
<li>Rename package to <code>agentaudit-scanner</code> and update related documentation (948673b)</li>
<li>Changed name from skillcheck to agentaudit (0810086)</li>
<li>Add tests and fixtures for malicious and benign scenarios (acd5f5a)</li>
</ul>
]]></content:encoded></item><item><title>LLM Prompt Radar</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/llm-prompt-radar/</link><pubDate>Wed, 08 Jul 2026 14:53:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/llm-prompt-radar/</guid><description>Version updated for https://github.com/Tahiram32/llm-prompt-radar to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed The Missing CI Check for AI-Powered Applications 🛡️ llm-prompt-radar is the first dedicated CI tool for detecting risky changes to LLM prompts and AI configuration before they ship to production.
🌟 What it detects 🚨 Safety guardrail removal — Critical alert when safety/refusal instructions are removed from prompts 🤖 Model downgrades — Flags silent swaps like gpt-4o → gpt-3.5-turbo or claude-3-opus → claude-3-haiku 📝 Prompt file changes — Deep analysis of .prompt, .jinja, .j2 template files with similarity scoring 🔍 In-code system messages — Detects changes to system prompts inside Python, JS, and TS source files ⚙️ LLM parameter changes — Tracks temperature, max_tokens, top_p, and more 🎯 Risk scoring — none / low / medium / high / critical 📊 Multiple output formats — text, json, markdown, github annotations, SARIF 📦 Install pip install llm-prompt-radar 🔧 GitHub Action - uses: actions/checkout@v7 with: fetch-depth: 0 - uses: Tahiram32/llm-prompt-radar@v0.1.0 with: base-ref: origin/main format: github fail-on: high 🔗 Links PyPI: https://pypi.org/project/llm-prompt-radar/0.1.0/ Docs: https://github.com/Tahiram32/llm-prompt-radar#readme</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Tahiram32/llm-prompt-radar">https://github.com/Tahiram32/llm-prompt-radar</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/llm-prompt-radar">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="the-missing-ci-check-for-ai-powered-applications-">The Missing CI Check for AI-Powered Applications 🛡️</h2>
<p><code>llm-prompt-radar</code> is the first dedicated CI tool for detecting risky changes to LLM prompts and AI configuration before they ship to production.</p>
<h3 id="-what-it-detects">🌟 What it detects</h3>
<ul>
<li><strong>🚨 Safety guardrail removal</strong> — Critical alert when safety/refusal instructions are removed from prompts</li>
<li><strong>🤖 Model downgrades</strong> — Flags silent swaps like <code>gpt-4o</code> → <code>gpt-3.5-turbo</code> or <code>claude-3-opus</code> → <code>claude-3-haiku</code></li>
<li><strong>📝 Prompt file changes</strong> — Deep analysis of <code>.prompt</code>, <code>.jinja</code>, <code>.j2</code> template files with similarity scoring</li>
<li><strong>🔍 In-code system messages</strong> — Detects changes to system prompts inside Python, JS, and TS source files</li>
<li><strong>⚙️ LLM parameter changes</strong> — Tracks <code>temperature</code>, <code>max_tokens</code>, <code>top_p</code>, and more</li>
<li><strong>🎯 Risk scoring</strong> — none / low / medium / high / critical</li>
<li><strong>📊 Multiple output formats</strong> — text, json, markdown, github annotations, SARIF</li>
</ul>
<h3 id="-install">📦 Install</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install llm-prompt-radar
</span></span></code></pre></div><h3 id="-github-action">🔧 GitHub Action</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v7</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fetch-depth</span>: <span style="color:#ae81ff">0</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Tahiram32/llm-prompt-radar@v0.1.0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">base-ref</span>: <span style="color:#ae81ff">origin/main</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">format</span>: <span style="color:#ae81ff">github</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h3 id="-links">🔗 Links</h3>
<ul>
<li>PyPI: <a href="https://pypi.org/project/llm-prompt-radar/0.1.0/">https://pypi.org/project/llm-prompt-radar/0.1.0/</a></li>
<li>Docs: <a href="https://github.com/Tahiram32/llm-prompt-radar#readme">https://github.com/Tahiram32/llm-prompt-radar#readme</a></li>
</ul>
]]></content:encoded></item><item><title>Zyrax Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/zyrax-guard/</link><pubDate>Wed, 08 Jul 2026 14:52:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/zyrax-guard/</guid><description>Version updated for https://github.com/tiagosilva07/zyrax-guard to version v0.11.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v0.11.1 — Windows upgrade parity via scoop Windows was the only platform without a working zyrax-guard upgrade. Fixed.
Added Scoop bucket — install the signed release binary on Windows:
scoop bucket add zyrax https://github.com/tiagosilva07/scoop-zyrax scoop install zyrax-guard Manifest hashes come from the release’s signed checksums.txt, and the bucket is regenerated automatically on every release.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tiagosilva07/zyrax-guard">https://github.com/tiagosilva07/zyrax-guard</a></strong> to version <strong>v0.11.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zyrax-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v0111--windows-upgrade-parity-via-scoop">v0.11.1 — Windows upgrade parity via scoop</h2>
<p>Windows was the only platform without a working <code>zyrax-guard upgrade</code>. Fixed.</p>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong>Scoop bucket</strong> — install the signed release binary on Windows:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-powershell" data-lang="powershell"><span style="display:flex;"><span>scoop bucket add zyrax https<span style="color:#960050;background-color:#1e0010">:</span>//github.com/tiagosilva07/scoop-zyrax
</span></span><span style="display:flex;"><span>scoop install zyrax-guard
</span></span></code></pre></div><p>Manifest hashes come from the release&rsquo;s signed <code>checksums.txt</code>, and the bucket is regenerated automatically on every release.</p>
</li>
<li>
<p><strong><code>upgrade</code> delegates on scoop installs</strong> — Guard detects a scoop-managed install (<code>scoop\apps\zyrax-guard\…</code>) and runs <code>scoop update zyrax-guard</code>, the same way it already delegates to npm, Homebrew, and <code>go install</code>. <code>--method scoop</code> is accepted for manual override.</p>
</li>
</ul>
<p>The standalone (non-scoop) Windows binary still upgrades manually via the Releases page — installing through scoop is now the recommended path on Windows.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/tiagosilva07/zyrax-guard/compare/v0.11.0...v0.11.1">https://github.com/tiagosilva07/zyrax-guard/compare/v0.11.0...v0.11.1</a></p>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/vibgrate-scan/</link><pubDate>Wed, 08 Jul 2026 14:52:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.708.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Vibgrate CLI 2026.708.1 Released 2026-07-08
This release of the CLI ships 1 new change, 1 improved change, 1 changed change and 1 fixed change.
What changed New New vg fix command turns a drift scan into ranked, risk-tiered upgrade plans and applies the one you choose. Improved vg fix now re-scans automatically when your last drift scan is out of date. Changed Scan reports now label the drift metric as “DriftScore” (one word), matching the name used across the website and docs. Fixed Scan reports now match your plan. Benchmarks Two-arm benchmark of this release against 2026.704.3, interleaved on one runner against the pinned corpus (157 metrics compared).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.708.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20267081">Vibgrate CLI 2026.708.1</h1>
<p><em>Released 2026-07-08</em></p>
<p>This release of the CLI ships 1 new change, 1 improved change, 1 changed change and 1 fixed change.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="new">New</h3>
<ul>
<li>New <code>vg fix</code> command turns a drift scan into ranked, risk-tiered upgrade plans and applies the one you choose.</li>
</ul>
<h3 id="improved">Improved</h3>
<ul>
<li><code>vg fix</code> now re-scans automatically when your last drift scan is out of date.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>Scan reports now label the drift metric as &ldquo;DriftScore&rdquo; (one word), matching the name used across the website and docs.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Scan reports now match your plan.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.704.3, interleaved on one runner against the pinned corpus (157 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>18590 count</td>
          <td>18590 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>7120 count</td>
          <td>7120 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.97 ratio</td>
          <td>0.97 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>606.50 ms</td>
          <td>608.20 ms</td>
      </tr>
  </tbody>
</table>
<p>No regressions against the previous release.</p>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.708.1">https://vibgrate.com/changelog/cli/2026.708.1</a></p>
]]></content:encoded></item><item><title>Build WordPress Archive</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/build-wordpress-archive/</link><pubDate>Wed, 08 Jul 2026 14:51:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/build-wordpress-archive/</guid><description>Version updated for https://github.com/webshr/action-wp-build-archive to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Add automatic version input from release tag</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/webshr/action-wp-build-archive">https://github.com/webshr/action-wp-build-archive</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/build-wordpress-archive">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Add automatic version input from release tag</p>
]]></content:encoded></item><item><title>Vercel Deploy Comment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/vercel-deploy-comment/</link><pubDate>Wed, 08 Jul 2026 14:51:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/vercel-deploy-comment/</guid><description>Version updated for https://github.com/wiyco/vercel-deploy-comment to version v2.2.3.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed test: establish E2E smoke testing pipeline by @wiyco in https://github.com/wiyco/vercel-deploy-comment/pull/17 Full Changelog: https://github.com/wiyco/vercel-deploy-comment/compare/v2.2.2...v2.2.3</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wiyco/vercel-deploy-comment">https://github.com/wiyco/vercel-deploy-comment</a></strong> to version <strong>v2.2.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vercel-deploy-comment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>test: establish E2E smoke testing pipeline by @wiyco in <a href="https://github.com/wiyco/vercel-deploy-comment/pull/17">https://github.com/wiyco/vercel-deploy-comment/pull/17</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/wiyco/vercel-deploy-comment/compare/v2.2.2...v2.2.3">https://github.com/wiyco/vercel-deploy-comment/compare/v2.2.2...v2.2.3</a></p>
]]></content:encoded></item><item><title>kempt-fmt</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/kempt-fmt/</link><pubDate>Wed, 08 Jul 2026 14:50:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/kempt-fmt/</guid><description>Version updated for https://github.com/ZacSweers/kempt to version v0.2.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release Notes 2026-07-07
Support partially staged files for in-process formatting steps such as whitespace normalization by updating the Git index directly. Install kempt-fmt 0.2.1 Install prebuilt binaries via shell script curl --proto &amp;#39;=https&amp;#39; --tlsv1.2 -LsSf https://github.com/ZacSweers/kempt/releases/download/v0.2.1/kempt-fmt-installer.sh | sh Install prebuilt binaries via powershell script powershell -ExecutionPolicy Bypass -c &amp;#34;irm https://github.com/ZacSweers/kempt/releases/download/v0.2.1/kempt-fmt-installer.ps1 | iex&amp;#34; Install prebuilt binaries via Homebrew brew install ZacSweers/tap/kempt-fmt Download kempt-fmt 0.2.1 File Platform Checksum kempt-fmt-aarch64-apple-darwin.tar.xz Apple Silicon macOS checksum kempt-fmt-x86_64-apple-darwin.tar.xz Intel macOS checksum kempt-fmt-x86_64-pc-windows-msvc.zip x64 Windows checksum kempt-fmt-aarch64-unknown-linux-gnu.tar.xz ARM64 Linux checksum kempt-fmt-x86_64-unknown-linux-gnu.tar.xz x64 Linux checksum</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ZacSweers/kempt">https://github.com/ZacSweers/kempt</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kempt-fmt">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="release-notes">Release Notes</h2>
<p><em>2026-07-07</em></p>
<ul>
<li>Support partially staged files for in-process formatting steps such as
whitespace normalization by updating the Git index directly.</li>
</ul>
<h2 id="install-kempt-fmt-021">Install kempt-fmt 0.2.1</h2>
<h3 id="install-prebuilt-binaries-via-shell-script">Install prebuilt binaries via shell script</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>curl --proto <span style="color:#e6db74">&#39;=https&#39;</span> --tlsv1.2 -LsSf https://github.com/ZacSweers/kempt/releases/download/v0.2.1/kempt-fmt-installer.sh | sh
</span></span></code></pre></div><h3 id="install-prebuilt-binaries-via-powershell-script">Install prebuilt binaries via powershell script</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>powershell -ExecutionPolicy Bypass -c <span style="color:#e6db74">&#34;irm https://github.com/ZacSweers/kempt/releases/download/v0.2.1/kempt-fmt-installer.ps1 | iex&#34;</span>
</span></span></code></pre></div><h3 id="install-prebuilt-binaries-via-homebrew">Install prebuilt binaries via Homebrew</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>brew install ZacSweers/tap/kempt-fmt
</span></span></code></pre></div><h2 id="download-kempt-fmt-021">Download kempt-fmt 0.2.1</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/ZacSweers/kempt/releases/download/v0.2.1/kempt-fmt-aarch64-apple-darwin.tar.xz">kempt-fmt-aarch64-apple-darwin.tar.xz</a></td>
          <td>Apple Silicon macOS</td>
          <td><a href="https://github.com/ZacSweers/kempt/releases/download/v0.2.1/kempt-fmt-aarch64-apple-darwin.tar.xz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/ZacSweers/kempt/releases/download/v0.2.1/kempt-fmt-x86_64-apple-darwin.tar.xz">kempt-fmt-x86_64-apple-darwin.tar.xz</a></td>
          <td>Intel macOS</td>
          <td><a href="https://github.com/ZacSweers/kempt/releases/download/v0.2.1/kempt-fmt-x86_64-apple-darwin.tar.xz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/ZacSweers/kempt/releases/download/v0.2.1/kempt-fmt-x86_64-pc-windows-msvc.zip">kempt-fmt-x86_64-pc-windows-msvc.zip</a></td>
          <td>x64 Windows</td>
          <td><a href="https://github.com/ZacSweers/kempt/releases/download/v0.2.1/kempt-fmt-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/ZacSweers/kempt/releases/download/v0.2.1/kempt-fmt-aarch64-unknown-linux-gnu.tar.xz">kempt-fmt-aarch64-unknown-linux-gnu.tar.xz</a></td>
          <td>ARM64 Linux</td>
          <td><a href="https://github.com/ZacSweers/kempt/releases/download/v0.2.1/kempt-fmt-aarch64-unknown-linux-gnu.tar.xz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/ZacSweers/kempt/releases/download/v0.2.1/kempt-fmt-x86_64-unknown-linux-gnu.tar.xz">kempt-fmt-x86_64-unknown-linux-gnu.tar.xz</a></td>
          <td>x64 Linux</td>
          <td><a href="https://github.com/ZacSweers/kempt/releases/download/v0.2.1/kempt-fmt-x86_64-unknown-linux-gnu.tar.xz.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
]]></content:encoded></item><item><title>Postman Onboarding Workspace Bootstrap</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/postman-onboarding-workspace-bootstrap/</link><pubDate>Wed, 08 Jul 2026 06:31:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/postman-onboarding-workspace-bootstrap/</guid><description>Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.7.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed fix(workspace): mint access token from PMAK on PMAK-only runs; widen visibility-403 advice
What’s Changed chore(deps-dev): bump @types/node from 24.12.4 to 26.1.0 by @dependabot[bot] in https://github.com/postman-cs/postman-bootstrap-action/pull/66 chore(deps): bump graphql from 16.14.2 to 17.0.1 by @dependabot[bot] in https://github.com/postman-cs/postman-bootstrap-action/pull/68 feat: close the residual assertion-catalog tail across gRPC, SOAP, GraphQL, and MCP by @jaredboynton in https://github.com/postman-cs/postman-bootstrap-action/pull/69 Full Changelog: https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.7.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-bootstrap-action">https://github.com/postman-cs/postman-bootstrap-action</a></strong> to version <strong>v2.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-workspace-bootstrap">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>fix(workspace): mint access token from PMAK on PMAK-only runs; widen visibility-403 advice</p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps-dev): bump @types/node from 24.12.4 to 26.1.0 by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/66">https://github.com/postman-cs/postman-bootstrap-action/pull/66</a></li>
<li>chore(deps): bump graphql from 16.14.2 to 17.0.1 by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/68">https://github.com/postman-cs/postman-bootstrap-action/pull/68</a></li>
<li>feat: close the residual assertion-catalog tail across gRPC, SOAP, GraphQL, and MCP by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/69">https://github.com/postman-cs/postman-bootstrap-action/pull/69</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.7.0">https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.7.0</a></p>
<h2 id="whats-changed-2">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps-dev): bump @types/node from 24.12.4 to 26.1.0 by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/66">https://github.com/postman-cs/postman-bootstrap-action/pull/66</a></li>
<li>chore(deps): bump graphql from 16.14.2 to 17.0.1 by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/68">https://github.com/postman-cs/postman-bootstrap-action/pull/68</a></li>
<li>feat: close the residual assertion-catalog tail across gRPC, SOAP, GraphQL, and MCP by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/69">https://github.com/postman-cs/postman-bootstrap-action/pull/69</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.7.0">https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.7.0</a></p>
]]></content:encoded></item><item><title>Prowler Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/prowler-security-scan/</link><pubDate>Wed, 08 Jul 2026 06:31:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/prowler-security-scan/</guid><description>Version updated for https://github.com/prowler-cloud/prowler to version 5.33.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ✨ New features to highlight in this version Enjoy them all now for free at https://cloud.prowler.com
🤖 Lighthouse AI — The Agentic Cloud Defender [!NOTE] This feature is available exclusively in Prowler Cloud and Prowler Enterprise with a subscription.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/prowler-cloud/prowler">https://github.com/prowler-cloud/prowler</a></strong> to version <strong>5.33.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/prowler-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="-new-features-to-highlight-in-this-version">✨ New features to highlight in this version</h1>
<p>Enjoy them all now for free at <a href="https://cloud.prowler.com">https://cloud.prowler.com</a></p>
<h2 id="-lighthouse-ai--the-agentic-cloud-defender">🤖 Lighthouse AI — The Agentic Cloud Defender</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in Prowler Cloud and Prowler Enterprise with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>Lighthouse AI is now a full agentic assistant wired to the Prowler Cloud backend. Ask it about your findings, your compliance posture, or your riskiest resources, and watch it work: the agent discovers and runs the Prowler tools it needs to answer, with every tool call visible in the new agentic view. It reads your security data through read-only tools, so it can never touch secrets or modify your tenant.</p>
<img width="3456" height="2234" alt="lighthouse-ai-1" src="https://github.com/user-attachments/assets/27189f66-cd85-45a3-9763-ed92d5c89b9b" />
<p>The chat experience is rebuilt around <strong>persistent sessions</strong>: conversations stream in real time, stay in your session history, can be archived, and a <strong>sidebar chat mode</strong> lets you ask questions from any page in the app without losing your place.</p>
<img width="2500" height="1616" alt="lighthouse-ai-2" src="https://github.com/user-attachments/assets/ee6b9a6f-f6fd-42b8-8f79-44a42180d223" />
<p>You control the brain behind it. Configure one or more LLM providers — <strong>OpenAI</strong>, <strong>Amazon Bedrock</strong>, or any <strong>OpenAI-compatible</strong> endpoint (OpenRouter, Ollama) — with connection testing built into the setup and per-provider model selection. Prowler Cloud defaults to <strong>GPT-5.5</strong>. Add a shared <strong>business context</strong> (your security goals, compliance needs, organizational priorities) and every session uses it to give answers that fit your environment.</p>
<img width="3456" height="2234" alt="lighthouse-ai-3" src="https://github.com/user-attachments/assets/9377e737-21fc-4ce0-8c34-d53643eb9c57" />
<p>Read more in our <a href="https://docs.prowler.com/getting-started/products/prowler-cloud-lighthouse">Lighthouse AI documentation</a> and the <a href="https://docs.prowler.com/user-guide/tutorials/prowler-cloud-lighthouse-multi-llm">multiple LLM providers guide</a>.</p>
<h2 id="-compliance-pdf-reports-without-credentials">📄 Compliance PDF Reports Without Credentials</h2>
<p>Compliance PDF reports no longer require the provider&rsquo;s credentials to be present. Findings are now enriched from the provider metadata stored in the database, so a report still generates even after the provider secret has been deleted or its credentials have become invalid.</p>
<p>Read more in our <a href="https://docs.prowler.com/user-guide/cli/tutorials/compliance">compliance documentation</a>.</p>
<h2 id="-scan-queueing">⏳ Scan Queueing</h2>
<p>Overlapping scans for the same provider now queue behind the active one instead of dispatching concurrent scan workers. Launch a manual scan while a scheduled one is running and it waits its turn. No more duplicated work or racing scans.</p>
<h2 id="-security">🔐 Security</h2>
<p>The Kubernetes provider credentials now reject kubeconfigs using <code>exec</code> authentication in Prowler Cloud, at the API and in the credential form, preventing user-supplied commands from running on Cloud workers.</p>
<p>Read more in the <a href="https://docs.prowler.com/user-guide/providers/kubernetes/getting-started-k8s#step-2-configure-kubernetes-authentication">Kubernetes provider authentication documentation</a>.</p>
<h2 id="-external-contributors">🙌 External Contributors</h2>
<p>Thank you to our community contributors for this release!</p>
<ul>
<li>@kratos0718 — Azure <code>postgresql_flexible_server_log_retention_days_greater_3</code> Flexible Server log retention fix <a href="https://github.com/prowler-cloud/prowler/pull/11761">(#11761)</a></li>
<li>@Sanjays2402 — <code>KeyError: 'MANUAL'</code> crash fix in the compliance summary table, shipped early in v5.32.1 <a href="https://github.com/prowler-cloud/prowler/pull/11823">(#11823)</a></li>
</ul>
<hr>
<h2 id="ui">UI</h2>
<h3 id="-added">🚀 Added</h3>
<ul>
<li>Owners can delete their last organization from the profile page <a href="https://github.com/prowler-cloud/prowler/pull/11864">(#11864)</a></li>
</ul>
<h3 id="-changed">🔄 Changed</h3>
<ul>
<li>Organization row actions in the profile page are aligned in fixed columns and the Active indicator now sits next to the organization name <a href="https://github.com/prowler-cloud/prowler/pull/11864">(#11864)</a></li>
<li>Sentry, Google Tag Manager, and PostHog now load their <code>UI_*</code> config only when the matching enable flag (<code>UI_SENTRY_ENABLE</code> / <code>UI_GOOGLE_TAG_MANAGER_ENABLE</code> / <code>UI_POSTHOG_ENABLE</code>) is <code>&quot;true&quot;</code> (default off); the deprecated legacy names (<code>NEXT_PUBLIC_*</code>, <code>POSTHOG_KEY</code>/<code>POSTHOG_HOST</code>) still activate without the flag <a href="https://github.com/prowler-cloud/prowler/pull/11682">(#11682)</a></li>
</ul>
<h2 id="api">API</h2>
<h3 id="-added-1">🚀 Added</h3>
<ul>
<li>Compliance PDF reports no longer require provider credentials: findings are enriched from the provider metadata stored in the database, so reports generate even after the provider secret is deleted or its credentials become invalid <a href="https://github.com/prowler-cloud/prowler/pull/11845">(#11845)</a></li>
</ul>
<h3 id="-fixed">🐞 Fixed</h3>
<ul>
<li>Provider scans now queue behind active provider scans instead of dispatching concurrently, and resource failed-finding counters retry database conflicts with stable row locking <a href="https://github.com/prowler-cloud/prowler/pull/11848">(#11848)</a></li>
</ul>
<h2 id="sdk">SDK</h2>
<h3 id="-fixed-1">🐞 Fixed</h3>
<ul>
<li>Azure resource group scoped scans now keep subscription entries when scoped resource listing fails, clarify helper documentation and test organization, and align the resource group documentation example with the described values <a href="https://github.com/prowler-cloud/prowler/pull/11796">(#11796)</a></li>
<li>Azure <code>postgresql_flexible_server_log_retention_days_greater_3</code> check now queries the <code>logfiles.retention_days</code> configuration parameter instead of <code>log_retention_days</code> (which only exists on the retired Single Server), fixing false <code>FAIL</code> results on every Flexible Server regardless of the actual retention value <a href="https://github.com/prowler-cloud/prowler/pull/11761">(#11761)</a></li>
</ul>
]]></content:encoded></item><item><title>Database Scripts Delta Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/database-scripts-delta-generator/</link><pubDate>Wed, 08 Jul 2026 06:30:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/database-scripts-delta-generator/</guid><description>Version updated for https://github.com/PunteriaCero/db-script-versioning to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Add comment to clarify fetch-depth in action.yml (c85eeaa) Make base_ref and head_ref required inputs in action.yml (8f943ce) Update default values for base_ref and head_ref in test-delta workflow (9a01f6f) Update GitHub Action reference to use punteriacero/db-script-versioning (234a71f) Add documentation and changelog (9546a21) Add test workflow and gitignore (134f97f) Add user roles and RBAC support (e112b2a) Add email verification migration (887d8bd) Initial commit: Add action and example migration (fe42043)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/PunteriaCero/db-script-versioning">https://github.com/PunteriaCero/db-script-versioning</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/database-scripts-delta-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Add comment to clarify fetch-depth in action.yml (c85eeaa)</li>
<li>Make base_ref and head_ref required inputs in action.yml (8f943ce)</li>
<li>Update default values for base_ref and head_ref in test-delta workflow (9a01f6f)</li>
<li>Update GitHub Action reference to use punteriacero/db-script-versioning (234a71f)</li>
<li>Add documentation and changelog (9546a21)</li>
<li>Add test workflow and gitignore (134f97f)</li>
<li>Add user roles and RBAC support (e112b2a)</li>
<li>Add email verification migration (887d8bd)</li>
<li>Initial commit: Add action and example migration (fe42043)</li>
</ul>
]]></content:encoded></item><item><title>klaws compliance scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/klaws-compliance-scan/</link><pubDate>Wed, 08 Jul 2026 06:29:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/klaws-compliance-scan/</guid><description>Version updated for https://github.com/rostradamus/klaws to version v0.1.5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog ee827391521bd8ad9fc41956f49278a968e9ac01 feat: PIPA-XBR-001 third-party/cross-border transfer detector (#13)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rostradamus/klaws">https://github.com/rostradamus/klaws</a></strong> to version <strong>v0.1.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/klaws-compliance-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>ee827391521bd8ad9fc41956f49278a968e9ac01 feat: PIPA-XBR-001 third-party/cross-border transfer detector (#13)</li>
</ul>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/agentauditkit-mcp-security-scan/</link><pubDate>Wed, 08 Jul 2026 06:28:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.47.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Installation pip:
pip install agent-audit-kit==v0.3.47 Docker:
docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.47 GitHub Action:
- uses: sattyamjjain/agent-audit-kit@v0.3.47 with: fail-on: high Supply chain rules.json — deterministic rule bundle rules.json.sha256 — trusted digest sbom.cdx.json / sbom.spdx.json — CycloneDX + SPDX SBOM *.sigstore — Sigstore keyless signatures (verify with agent-audit-kit verify-bundle) What’s Changed fix(rules): correct SEP citations on AAK-MCP-STATELESS-* pack (0.3.47) by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/409 feat(rules): pin CVE-2026-14471 (Amazon mcp-gateway-registry SQLi, closes #408) by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/410 Full Changelog: https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.46...v0.3.47</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.47</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.47
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.47
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.47</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(rules): correct SEP citations on AAK-MCP-STATELESS-* pack (0.3.47) by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/409">https://github.com/sattyamjjain/agent-audit-kit/pull/409</a></li>
<li>feat(rules): pin CVE-2026-14471 (Amazon mcp-gateway-registry SQLi, closes #408) by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/410">https://github.com/sattyamjjain/agent-audit-kit/pull/410</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.46...v0.3.47">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.46...v0.3.47</a></p>
]]></content:encoded></item><item><title>SiliconRig HIL</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/siliconrig-hil/</link><pubDate>Wed, 08 Jul 2026 06:28:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/siliconrig-hil/</guid><description>Version updated for https://github.com/siliconrig/action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First Marketplace release of the SiliconRig HIL action.
Flash firmware to a real embedded board (ESP32-S3, STM32H753, STM32F446, RP2350), capture serial output, and fail the workflow when the hardware run fails. Handles the full session lifecycle including cleanup on job failure.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/siliconrig/action">https://github.com/siliconrig/action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/siliconrig-hil">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First Marketplace release of the SiliconRig HIL action.</p>
<p>Flash firmware to a real embedded board (ESP32-S3, STM32H753, STM32F446, RP2350), capture serial output, and fail the workflow when the hardware run fails. Handles the full session lifecycle including cleanup on job failure.</p>
<p>Usage:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">siliconrig/action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.SRIG_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">board</span>: <span style="color:#ae81ff">esp32-s3</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">firmware</span>: <span style="color:#ae81ff">build/firmware.bin</span>
</span></span></code></pre></div><p>Docs: <a href="https://siliconrig.dev/docs/guides/github-actions">https://siliconrig.dev/docs/guides/github-actions</a></p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/bernstein-multi-agent-orchestration/</link><pubDate>Wed, 08 Jul 2026 06:27:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.1.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v3.1.0 Released 2026-07-07.
A verifiability feature release. Task completion now produces a sealed, content-addressed proof of what passed, not just a status line, and that proof verifies with the same audit chain that seals everything else.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v310">v3.1.0</h1>
<p>Released 2026-07-07.</p>
<p>A verifiability feature release. Task completion now produces a sealed,
content-addressed proof of what passed, not just a status line, and that proof
verifies with the same audit chain that seals everything else.</p>
<h2 id="verification-evidence-bundles-2362">Verification evidence bundles (#2362)</h2>
<p>&ldquo;Done&rdquo; used to be a status plus scattered logs that died with the worktree. Now
every completed task that declares evidence producers emits a verification
evidence bundle:</p>
<ul>
<li>Evidence producers (test command, coverage, lint, an optional screenshot or
recording command for web-facing work) are declared in the task spec and run
at gate time. Required producers gate completion; advisory producers attach a
failure record without blocking.</li>
<li>Bundle outputs are content-addressed, stored under a size-capped store with
garbage collection, referenced from the task lineage record, and sealed by a
new audit-chain event. Media evidence flows through the existing content
credentials support.</li>
<li>Sealing runs at task completion and is fail-open: a task that declares no
producers is untouched, and any error while sealing is logged and swallowed so
it can never block or fail a completion.</li>
<li><code>bernstein evidence show &lt;task&gt;</code> renders a bundle. <code>bernstein audit verify</code>
now covers bundle integrity, so a tampered evidence file is detected exactly
like a tampered chain entry, naming the file that broke.</li>
<li>Deterministic producers replay to byte-identical bundle hashes, signatures,
and journal anchors.</li>
<li>Generated pull-request bodies link the sealed bundle: the <code>bernstein pr</code> path,
the orchestrator auto-PR path, and the issue-to-PR path each emit an evidence
summary when a bundle is present and are unchanged when it is absent.</li>
</ul>
<h2 id="reliability">Reliability</h2>
<ul>
<li>Eliminated the order-dependent shard flakiness in the unit suite: the worker
installs its terminating-signal handler before the PID file exists (so a
signal in that window cannot leave a stale file for a later test), and
retry-budget marker matching is anchored on token boundaries to remove a
cross-test leak. (#2341)</li>
</ul>
<h2 id="housekeeping">Housekeeping</h2>
<ul>
<li>Resolved the open refurb idiom warnings across the recently shipped
interop, orchestration, and security modules; behavior unchanged.</li>
<li>Removed the expired one-shot Scorecard 90-day self-resolve workflow now that
the repository has passed the threshold and its tracking checkpoint is closed.</li>
<li>Routine toolchain and action updates (uv, setup-uv, harden-runner, and
frontend dependency digests).</li>
</ul>
]]></content:encoded></item><item><title>Pipr Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/pipr-review/</link><pubDate>Wed, 08 Jul 2026 06:27:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/pipr-review/</guid><description>Version updated for https://github.com/somus/pipr to version v0.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.3.0 (2026-07-07) ⚠ BREAKING CHANGES remove legacy SDK tool execute compatibility (#27) Features cli: add version and update commands (#30) (63f3869) Bug Fixes docs: serve root shell in docs image (#29) (587754a) runtime: tighten suggested change publication (#25) (e3d3646) Code Refactoring remove legacy SDK tool execute compatibility (#27) (baf2dc3)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somus/pipr">https://github.com/somus/pipr</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pipr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="030-2026-07-07"><a href="https://github.com/somus/pipr/compare/v0.2.2...v0.3.0">0.3.0</a> (2026-07-07)</h2>
<h3 id="-breaking-changes">⚠ BREAKING CHANGES</h3>
<ul>
<li>remove legacy SDK tool execute compatibility (<a href="https://github.com/somus/pipr/issues/27">#27</a>)</li>
</ul>
<h3 id="features">Features</h3>
<ul>
<li><strong>cli:</strong> add version and update commands (<a href="https://github.com/somus/pipr/issues/30">#30</a>) (<a href="https://github.com/somus/pipr/commit/63f3869b3f259a3b6ecb4b25726c845f998224fe">63f3869</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>docs:</strong> serve root shell in docs image (<a href="https://github.com/somus/pipr/issues/29">#29</a>) (<a href="https://github.com/somus/pipr/commit/587754a9f96214387fabd989365de1043db8b644">587754a</a>)</li>
<li><strong>runtime:</strong> tighten suggested change publication (<a href="https://github.com/somus/pipr/issues/25">#25</a>) (<a href="https://github.com/somus/pipr/commit/e3d364623028783fc45ef6154f718a5a8d997673">e3d3646</a>)</li>
</ul>
<h3 id="code-refactoring">Code Refactoring</h3>
<ul>
<li>remove legacy SDK tool execute compatibility (<a href="https://github.com/somus/pipr/issues/27">#27</a>) (<a href="https://github.com/somus/pipr/commit/baf2dc3d9bdee911f87b7396d2ae7f7e4592621d">baf2dc3</a>)</li>
</ul>
]]></content:encoded></item><item><title>Specreel</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/specreel/</link><pubDate>Wed, 08 Jul 2026 06:26:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/specreel/</guid><description>Version updated for https://github.com/specreel/specreel to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Turn the Playwright trace.zip your tests already produce into a watchable, shareable demo — and regenerate it on every green build, so the demo can’t go stale.
Single-file, stdlib-only CLI: specreel.py Trace → narrated HTML player, gallery, single-file bundle, optional MP4 recommend — crawl a running app and scaffold Playwright flows GitHub Action for the freshness loop; MCP server + Claude Code skill Opt-in, BYO-key AI narration pip install specreel (PyPI publish in progress — until then, grab the wheel below or clone).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/specreel/specreel">https://github.com/specreel/specreel</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/specreel">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Turn the Playwright <code>trace.zip</code> your tests already produce into a watchable, shareable demo — and regenerate it on every green build, so the demo can&rsquo;t go stale.</p>
<ul>
<li>Single-file, stdlib-only CLI: <code>specreel.py</code></li>
<li>Trace → narrated HTML player, gallery, single-file bundle, optional MP4</li>
<li><code>recommend</code> — crawl a running app and scaffold Playwright flows</li>
<li>GitHub Action for the freshness loop; MCP server + Claude Code skill</li>
<li>Opt-in, BYO-key AI narration</li>
</ul>
<p><code>pip install specreel</code> (PyPI publish in progress — until then, grab the wheel below or clone).</p>
<p>License: AGPL-3.0-or-later. Hosted option: <a href="https://specreel.dev">https://specreel.dev</a></p>
]]></content:encoded></item><item><title>nix init</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/nix-init/</link><pubDate>Wed, 08 Jul 2026 06:26:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/nix-init/</guid><description>Version updated for https://github.com/spotdemo4/nix-init to version v1.56.0.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed feat: Update dependency NixOS/nix to v2.34.8 (#157) (4c49b8a29e987ece0ff3a70cfc4c91918b21cc92) bump: v1.55.0 -&amp;gt; v1.56.0 (1443d93dfa3ca2f043b37f848631d6ac5563b0ec) chore(deps): lock file maintenance nix inputs (#156) (5bb45b10181ed8c209faa78078d5609d1950a4e5) chore(deps): update github actions to v1.55.0 (#155) (93b59515c97e5f9c2b82af99533bc2e0842e76a0)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spotdemo4/nix-init">https://github.com/spotdemo4/nix-init</a></strong> to version <strong>v1.56.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nix-init">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update dependency NixOS/nix to v2.34.8 (#157) (4c49b8a29e987ece0ff3a70cfc4c91918b21cc92)</li>
<li>bump: v1.55.0 -&gt; v1.56.0 (1443d93dfa3ca2f043b37f848631d6ac5563b0ec)</li>
<li>chore(deps): lock file maintenance nix inputs (#156) (5bb45b10181ed8c209faa78078d5609d1950a4e5)</li>
<li>chore(deps): update github actions to v1.55.0 (#155) (93b59515c97e5f9c2b82af99533bc2e0842e76a0)</li>
</ul>
]]></content:encoded></item><item><title>GitGalaxy Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/gitgalaxy-scanner/</link><pubDate>Wed, 08 Jul 2026 06:25:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/gitgalaxy-scanner/</guid><description>Version updated for https://github.com/squid-protocol/gitgalaxy to version v.2.3.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 🚀 Overview GitGalaxy v2.3.1 is a critical security and data-integrity hotfix. This release locks down structural data provenance for air-gapped environments, resolves machine-learning sparsity poisoning, and hardens the engine against false positives in deep monorepos and shallow CI/CD clones.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/squid-protocol/gitgalaxy">https://github.com/squid-protocol/gitgalaxy</a></strong> to version <strong>v.2.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gitgalaxy-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-overview">🚀 Overview</h2>
<p>GitGalaxy <strong>v2.3.1</strong> is a critical security and data-integrity hotfix. This release locks down structural data provenance for air-gapped environments, resolves machine-learning sparsity poisoning, and hardens the engine against false positives in deep monorepos and shallow CI/CD clones.</p>
<p>To guarantee the engine never silently degrades, we have doubled our continuous integration pipeline by introducing the <strong>Golden Crucible</strong>: a parallel, zero-dependency environment that validates structural telemetry across 50+ languages on every commit along with the full-dependency test we were already doing.</p>
<hr>
<h2 id="-major-architectural-highlights">🔥 Major Architectural Highlights</h2>
<h3 id="1-absolute-data-provenance-zero-dependency-mode">1. Absolute Data Provenance (Zero-Dependency Mode)</h3>
<p>Previously, if the engine degraded to bypass C-backed dependencies (<code>NetworkX</code>, <code>XGBoost</code>, <code>Tiktoken</code>), downstream recorders generated mathematically valid <code>0.0</code> values instead of safely treating skipped computations as <code>NULL</code>.</p>
<ul>
<li><strong>The Fix:</strong> Omitted values (PageRank, AI Threat Scores, Token Mass) are now explicitly enforced as strict SQL <code>NULL</code>s to prevent EDW poisoning. Forensic JSON manifests prominently flag skipped metrics as <code>[BYPASSED - ZERO DEPENDENCY MODE]</code>.</li>
<li><strong>UI/WebGPU:</strong> Unscanned artifacts now explicitly render as neutral/grey in the 3D HUD and histograms rather than adopting default safe colors.</li>
</ul>
<h3 id="2-xgboost-nan-sparsity-preservation-98">2. XGBoost NaN Sparsity Preservation (#98)</h3>
<p>Fixed a critical ML-Ops pipeline collapse where empty spatial telemetry was incorrectly zero-filled prior to inference. The engine now correctly preserves native <code>NaN</code> sparsity matrices, restoring XGBoost&rsquo;s directional logic for sparse structural signatures.</p>
<h3 id="3-minified-payload-shielding-121">3. Minified Payload Shielding (#121)</h3>
<p>Heavy frontend bundles and Webpack-minified payloads previously bottlenecked the AST-free regex engines. We introduced an <code>O(N)</code> literal fallback screen that instantly detects high-density minified payloads and safely drops them from the execution queue without hanging the scanner.</p>
<h3 id="4-monorepo-alias-isolation-103">4. Monorepo Alias Isolation (#103)</h3>
<p>In dense TypeScript/JavaScript monorepos, local package aliases were globally clobbering one another. Alias resolution is now strictly isolated to its localized sector, restoring precise supply chain mapping.</p>
<hr>
<h2 id="-comprehensive-changelog">📋 Comprehensive Changelog</h2>
<h3 id="-security--appsec">🔒 Security &amp; AppSec</h3>
<ul>
<li><strong>Fixed (#123):</strong> Resolved false-equivalency captures in LHS (Left-Hand Side) assignment taint tracking.</li>
<li><strong>Fixed:</strong> Reactivated the Dev Agent Firewall by resolving backend schema drift and patching missing empty-state return keys.</li>
<li><strong>Added:</strong> Dynamic directory routing and automated RAM graph generation for the firewall module.</li>
</ul>
<h3 id="-core-engine--metrics">🧠 Core Engine &amp; Metrics</h3>
<ul>
<li><strong>Fixed (#104):</strong> Applied spatial correlation to the OOM Bomb multiplier, resolving density scaling inaccuracies for files with massive localized state mutations.</li>
<li><strong>Fixed (#99):</strong> Neutralized the OS <code>mtime</code> fallback logic. The chronometer now successfully detects shallow CI/CD clones (where all file timestamps are identical) and prevents temporal collapse.</li>
<li><strong>Fixed:</strong> Suppressed threat counters for unknown imports specifically on verified, allowlisted paths.</li>
</ul>
<h3 id="-cicd--testing-infrastructure">⚙️ CI/CD &amp; Testing Infrastructure</h3>
<ul>
<li><strong>Implemented (#107):</strong> The Golden Crucible Pipeline. Wires a parallel matrix job to execute the engine in a sterile, air-gapped environment for deterministic zero-dependency testing.</li>
<li><strong>Hardened:</strong> Centralized the &ldquo;Chaos Monkey&rdquo; test suite, adding explicit mock validations for <code>Tiktoken</code>, <code>NetworkX</code>, and <code>XGBoost</code> graceful degradation.</li>
<li><strong>Refined:</strong> Resolved CodeQL/Muninn unused variable/import alerts for a pristine security sweep.</li>
<li><strong>Chore:</strong> Implemented full local dogfooding for the GitHub Action wrapper and injected a community license key to bypass arbitrary runner timeouts.</li>
<li><strong>Policy:</strong> Formalized production <code>CODEOWNERS</code> and a safe security reporting policy.</li>
</ul>
]]></content:encoded></item><item><title>Node Semantic Release</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/node-semantic-release/</link><pubDate>Wed, 08 Jul 2026 06:25:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/node-semantic-release/</guid><description>Version updated for https://github.com/stairwaytowonderland/node-semantic-release to version v1.196.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed chore(release): 1.196.0
1.196.0 (2026-07-08) ✨ Features update releaserc template (cb59cf4)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stairwaytowonderland/node-semantic-release">https://github.com/stairwaytowonderland/node-semantic-release</a></strong> to version <strong>v1.196.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/node-semantic-release">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>chore(release): 1.196.0</p>
<h2 id="11960-2026-07-08"><a href="https://github.com/stairwaytowonderland/node-semantic-release/compare/v1.195.0...v1.196.0">1.196.0</a> (2026-07-08)</h2>
<h3 id="-features">✨ Features</h3>
<ul>
<li>update releaserc template (<a href="https://github.com/stairwaytowonderland/node-semantic-release/commit/cb59cf4cab0a5580eef5ea7c24926d7faacba259">cb59cf4</a>)</li>
</ul>
]]></content:encoded></item><item><title>Repository Create</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/repository-create/</link><pubDate>Wed, 08 Jul 2026 06:24:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/repository-create/</guid><description>Version updated for https://github.com/stairwaytowonderland/repository-create to version v1.81.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed chore(release): 1.81.0
1.81.0 (2026-07-08) ✨ Features update workflow permissions (18ffc9e)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stairwaytowonderland/repository-create">https://github.com/stairwaytowonderland/repository-create</a></strong> to version <strong>v1.81.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/repository-create">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>chore(release): 1.81.0</p>
<h2 id="1810-2026-07-08"><a href="https://github.com/stairwaytowonderland/repository-create/compare/v1.80.0...v1.81.0">1.81.0</a> (2026-07-08)</h2>
<h3 id="-features">✨ Features</h3>
<ul>
<li>update workflow permissions (<a href="https://github.com/stairwaytowonderland/repository-create/commit/18ffc9ee222691513118f68dcd9e3e137dc3c7b9">18ffc9e</a>)</li>
</ul>
]]></content:encoded></item><item><title>pinprick-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/pinprick-action/</link><pubDate>Wed, 08 Jul 2026 06:23:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/pinprick-action/</guid><description>Version updated for https://github.com/starhaven-io/pinprick-action to version v0.4.2.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Updates the pinned pinprick version.
Defaults to pinprick 0.21.0 (was 0.20.1 in v0.4.1), pinned for deterministic runs. pinprick 0.21.0 removes the source.unverified scoring rule and its trusted-owners config key, moving the scoring rubric to 0.9.0: score no longer emits the zero-point publisher note, and trusted-owners is no longer a recognized config field. The action’s behavior, inputs, and permissions are unchanged. See the README for usage.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/starhaven-io/pinprick-action">https://github.com/starhaven-io/pinprick-action</a></strong> to version <strong>v0.4.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pinprick-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Updates the pinned pinprick version.</p>
<p>Defaults to pinprick 0.21.0 (was 0.20.1 in v0.4.1), pinned for deterministic runs. pinprick 0.21.0 removes the source.unverified scoring rule and its trusted-owners config key, moving the scoring rubric to 0.9.0: score no longer emits the zero-point publisher note, and trusted-owners is no longer a recognized config field. The action&rsquo;s behavior, inputs, and permissions are unchanged. See the README for usage.</p>
]]></content:encoded></item><item><title>Yandex Cloud Federated IAM Token</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/yandex-cloud-federated-iam-token/</link><pubDate>Wed, 08 Jul 2026 06:23:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/yandex-cloud-federated-iam-token/</guid><description>Version updated for https://github.com/stat1c-void/yc-fed-iam-action to version v1.0.6.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Update action to run on Node24 chore: bump actions/checkout from 6.0.2 to 7.0.0 by @dependabot[bot] in https://github.com/stat1c-void/yc-fed-iam-action/pull/51 chore: bump gitleaks/gitleaks-action from 2.3.9 to 3.0.0 by @dependabot[bot] in https://github.com/stat1c-void/yc-fed-iam-action/pull/50 chore: bump the npm-development group with 7 updates by @dependabot[bot] in https://github.com/stat1c-void/yc-fed-iam-action/pull/48 chore: bump the actions group with 3 updates by @dependabot[bot] in https://github.com/stat1c-void/yc-fed-iam-action/pull/49 Full Changelog: https://github.com/stat1c-void/yc-fed-iam-action/compare/v1.0.5...v1.0.6</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stat1c-void/yc-fed-iam-action">https://github.com/stat1c-void/yc-fed-iam-action</a></strong> to version <strong>v1.0.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/yandex-cloud-federated-iam-token">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Update action to run on Node24</li>
<li>chore: bump actions/checkout from 6.0.2 to 7.0.0 by @dependabot[bot] in <a href="https://github.com/stat1c-void/yc-fed-iam-action/pull/51">https://github.com/stat1c-void/yc-fed-iam-action/pull/51</a></li>
<li>chore: bump gitleaks/gitleaks-action from 2.3.9 to 3.0.0 by @dependabot[bot] in <a href="https://github.com/stat1c-void/yc-fed-iam-action/pull/50">https://github.com/stat1c-void/yc-fed-iam-action/pull/50</a></li>
<li>chore: bump the npm-development group with 7 updates by @dependabot[bot] in <a href="https://github.com/stat1c-void/yc-fed-iam-action/pull/48">https://github.com/stat1c-void/yc-fed-iam-action/pull/48</a></li>
<li>chore: bump the actions group with 3 updates by @dependabot[bot] in <a href="https://github.com/stat1c-void/yc-fed-iam-action/pull/49">https://github.com/stat1c-void/yc-fed-iam-action/pull/49</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/stat1c-void/yc-fed-iam-action/compare/v1.0.5...v1.0.6">https://github.com/stat1c-void/yc-fed-iam-action/compare/v1.0.5...v1.0.6</a></p>
]]></content:encoded></item><item><title>PollyAction</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/pollyaction/</link><pubDate>Wed, 08 Jul 2026 06:22:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/pollyaction/</guid><description>Version updated for https://github.com/Swevo/PollyAction to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Shortened action description to fit Marketplace’s 125-character limit. No functional changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Swevo/PollyAction">https://github.com/Swevo/PollyAction</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pollyaction">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Shortened action description to fit Marketplace&rsquo;s 125-character limit. No functional changes.</p>
]]></content:encoded></item><item><title>Meadows Bundler</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/meadows-bundler/</link><pubDate>Wed, 08 Jul 2026 06:22:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/meadows-bundler/</guid><description>Version updated for https://github.com/TeamMeadows/bundler to version v0.2.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/TeamMeadows/bundler/compare/v0.2.1...v0.2.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/TeamMeadows/bundler">https://github.com/TeamMeadows/bundler</a></strong> to version <strong>v0.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/meadows-bundler">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/TeamMeadows/bundler/compare/v0.2.1...v0.2.2">https://github.com/TeamMeadows/bundler/compare/v0.2.1...v0.2.2</a></p>
]]></content:encoded></item><item><title>Agents Shipgate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/agents-shipgate/</link><pubDate>Wed, 08 Jul 2026 06:21:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/agents-shipgate/</guid><description>Version updated for https://github.com/ThreeMoonsLab/agents-shipgate to version v0.15.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Agents Shipgate v0.15.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ThreeMoonsLab/agents-shipgate">https://github.com/ThreeMoonsLab/agents-shipgate</a></strong> to version <strong>v0.15.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agents-shipgate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Agents Shipgate v0.15.0</p>
]]></content:encoded></item><item><title>Zyrax Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/zyrax-guard/</link><pubDate>Wed, 08 Jul 2026 06:21:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/zyrax-guard/</guid><description>Version updated for https://github.com/tiagosilva07/zyrax-guard to version v0.11.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v0.11.0 — BLOCK means attack One deliberate verdict-policy change.
⚠️ Changed: vulnerabilities in legitimate packages now WARN instead of BLOCK BLOCK is now reserved for known-malicious packages — typosquats, hallucinated names, denylist and OSV MAL-* malware entries. A vulnerability advisory on a legitimate package (any severity) now yields WARN, with the severity shown in the message:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tiagosilva07/zyrax-guard">https://github.com/tiagosilva07/zyrax-guard</a></strong> to version <strong>v0.11.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zyrax-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v0110--block-means-attack">v0.11.0 — BLOCK means attack</h2>
<p>One deliberate verdict-policy change.</p>
<h3 id="-changed-vulnerabilities-in-legitimate-packages-now-warn-instead-of-block">⚠️ Changed: vulnerabilities in legitimate packages now WARN instead of BLOCK</h3>
<p><strong>BLOCK is now reserved for known-malicious packages</strong> — typosquats, hallucinated names, denylist and OSV <code>MAL-*</code> malware entries. A vulnerability advisory on a legitimate package (any severity) now yields <strong>WARN</strong>, with the severity shown in the message:</p>
<pre tabindex="0"><code>$ zyrax-guard check some-pkg
! some-pkg@2.1.0 — WARN
  - GHSA-xxxx (high severity): Denial of Service in some-pkg
</code></pre><p><strong>Why:</strong> popular packages routinely carry high-severity advisories — <code>next</code> and <code>vite</code> were BLOCKing installs over a real-but-ordinary DoS advisory. A false BLOCK on a household-name package teaches users to <code>zyrax-guard allow</code> it or remove the shell hook entirely, which destroys the gate&rsquo;s value against actual malware. BLOCK should mean <em>&ldquo;we think this is an attack&rdquo;</em>, not <em>&ldquo;this has a known bug&rdquo;</em>. Vulnerability management belongs to <code>npm audit</code> / Dependabot; Guard is the supply-chain attack gate.</p>
<p><strong>If you want the old behavior in CI:</strong> run with <code>--strict</code> — WARN becomes a failure, so any advisory still fails the build.</p>
<p>Malware detection is unchanged: known-malicious packages BLOCK exactly as before, and ERROR (could-not-verify) still fails closed.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/tiagosilva07/zyrax-guard/compare/v0.10.0...v0.11.0">https://github.com/tiagosilva07/zyrax-guard/compare/v0.10.0...v0.11.0</a></p>
]]></content:encoded></item><item><title>Trigv</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/trigv/</link><pubDate>Wed, 08 Jul 2026 06:20:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/trigv/</guid><description>Version updated for https://github.com/Trigv/trigv-github-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s new Optional url input for event destination links When url is omitted, the action automatically sends the current GitHub Actions run URL Default auto-generated description no longer includes the raw workflow URL (it is sent in url instead) Usage uses: Trigv/trigv-github-action@v1.1.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Trigv/trigv-github-action">https://github.com/Trigv/trigv-github-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/trigv">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new">What&rsquo;s new</h2>
<ul>
<li>Optional <code>url</code> input for event destination links</li>
<li>When <code>url</code> is omitted, the action automatically sends the current GitHub Actions run URL</li>
<li>Default auto-generated description no longer includes the raw workflow URL (it is sent in <code>url</code> instead)</li>
</ul>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Trigv/trigv-github-action@v1.1.0</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Polder Reach</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/polder-reach/</link><pubDate>Wed, 08 Jul 2026 06:20:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/polder-reach/</guid><description>Version updated for https://github.com/usepolder/reach to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed One number for design system adoption.
CLI: npx @usepolder/reach --library &amp;#34;@your/design-system&amp;#34; scores any React repo with zero config. --json emits the versioned report (schemaVersion 1). GitHub Action: uses: usepolder/reach@v1 posts a single PR comment (updated in place) with the score, the delta vs the base branch (computed in a temporary git worktree), and the leak count. Fork PRs degrade to the step summary. Badge, zero infra: pushes to the default branch commit .polder/reach-badge.json (shields.io endpoint schema) plus a static SVG fallback for private repos. Leaks: hardcoded hex colors and px values with file/line locations. The score formula is not configurable. A score you can tune is a score nobody trusts.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/usepolder/reach">https://github.com/usepolder/reach</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/polder-reach">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>One number for design system adoption.</p>
<ul>
<li><strong>CLI:</strong> <code>npx @usepolder/reach --library &quot;@your/design-system&quot;</code> scores any React repo with zero config. <code>--json</code> emits the versioned report (schemaVersion 1).</li>
<li><strong>GitHub Action:</strong> <code>uses: usepolder/reach@v1</code> posts a single PR comment (updated in place) with the score, the delta vs the base branch (computed in a temporary git worktree), and the leak count. Fork PRs degrade to the step summary.</li>
<li><strong>Badge, zero infra:</strong> pushes to the default branch commit <code>.polder/reach-badge.json</code> (shields.io endpoint schema) plus a static SVG fallback for private repos.</li>
<li><strong>Leaks:</strong> hardcoded hex colors and px values with file/line locations.</li>
</ul>
<p>The score formula is not configurable. A score you can tune is a score nobody trusts.</p>
<p>🤖 Generated with <a href="https://claude.com/claude-code">Claude Code</a></p>
]]></content:encoded></item><item><title>GitHub Actions Version Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/github-actions-version-audit/</link><pubDate>Wed, 08 Jul 2026 06:19:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/github-actions-version-audit/</guid><description>Version updated for https://github.com/varunchandak/gh-actions-version-audit to version v1.1.5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Refresh Marketplace documentation with the workflow-file PR token requirements.\n- Clarify that commits to PR branches still need workflow-file write permission when modifying .github/workflows.\n- Document Resource not accessible by integration as the expected symptom for insufficient token permissions.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/varunchandak/gh-actions-version-audit">https://github.com/varunchandak/gh-actions-version-audit</a></strong> to version <strong>v1.1.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-actions-version-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Refresh Marketplace documentation with the workflow-file PR token requirements.\n- Clarify that commits to PR branches still need workflow-file write permission when modifying .github/workflows.\n- Document Resource not accessible by integration as the expected symptom for insufficient token permissions.</li>
</ul>
]]></content:encoded></item><item><title>Start Wiz Sensor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/start-wiz-sensor/</link><pubDate>Wed, 08 Jul 2026 06:19:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/start-wiz-sensor/</guid><description>Version updated for https://github.com/wiz-sec-public/wiz-sensor-github-action to version v0.9.5.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by ? repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Print sensor error logs on failure Add a new “generate-support-package” input Add marker, to help verify the action ran with the sensor Upgrade dependencies</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wiz-sec-public/wiz-sensor-github-action">https://github.com/wiz-sec-public/wiz-sensor-github-action</a></strong> to version <strong>v0.9.5</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>?</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/start-wiz-sensor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Print sensor error logs on failure</li>
<li>Add a new &ldquo;generate-support-package&rdquo; input</li>
<li>Add marker, to help verify the action ran with the sensor</li>
<li>Upgrade dependencies</li>
</ul>
]]></content:encoded></item><item><title>Local Podcast Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/local-podcast-generator/</link><pubDate>Wed, 08 Jul 2026 06:18:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/local-podcast-generator/</guid><description>Version updated for https://github.com/yeste-rge/podcast-generator to version v1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Update Dockerfile to install git and modify COPY commands by @yeste-rge in https://github.com/yeste-rge/podcast-generator/pull/1 New Contributors @yeste-rge made their first contribution in https://github.com/yeste-rge/podcast-generator/pull/1 Full Changelog: https://github.com/yeste-rge/podcast-generator/commits/v1.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yeste-rge/podcast-generator">https://github.com/yeste-rge/podcast-generator</a></strong> to version <strong>v1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/local-podcast-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Update Dockerfile to install git and modify COPY commands by @yeste-rge in <a href="https://github.com/yeste-rge/podcast-generator/pull/1">https://github.com/yeste-rge/podcast-generator/pull/1</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@yeste-rge made their first contribution in <a href="https://github.com/yeste-rge/podcast-generator/pull/1">https://github.com/yeste-rge/podcast-generator/pull/1</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yeste-rge/podcast-generator/commits/v1.0">https://github.com/yeste-rge/podcast-generator/commits/v1.0</a></p>
]]></content:encoded></item><item><title>Powderworks Straitjacket</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/powderworks-straitjacket/</link><pubDate>Wed, 08 Jul 2026 06:17:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/08/powderworks-straitjacket/</guid><description>Version updated for https://github.com/zmaril/Straitjacket to version v0.2.3.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed duplication in Markdown now honours straitjacket-allow markers too. A clone inside a doc’s fenced code block carries a :&amp;lt;lang&amp;gt; tag on its source id (e.g. docs.md:bash), so the finding’s path wasn’t a real file — the suppression added in 0.2.2 couldn’t open it and the marker was ignored. The :&amp;lt;lang&amp;gt; tag is now stripped, which also tidies the reported path. Install: curl -fsSL https://raw.githubusercontent.com/zmaril/straitjacket/main/install.sh | sh</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zmaril/Straitjacket">https://github.com/zmaril/Straitjacket</a></strong> to version <strong>v0.2.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/powderworks-straitjacket">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong><code>duplication</code> in Markdown</strong> now honours <code>straitjacket-allow</code> markers too. A clone inside a doc&rsquo;s fenced code block carries a <code>:&lt;lang&gt;</code> tag on its source id (e.g. <code>docs.md:bash</code>), so the finding&rsquo;s path wasn&rsquo;t a real file — the suppression added in 0.2.2 couldn&rsquo;t open it and the marker was ignored. The <code>:&lt;lang&gt;</code> tag is now stripped, which also tidies the reported path.</li>
</ul>
<p><strong>Install:</strong> <code>curl -fsSL https://raw.githubusercontent.com/zmaril/straitjacket/main/install.sh | sh</code></p>
<p><strong>Full changelog:</strong> <a href="https://github.com/zmaril/straitjacket/compare/v0.2.2...v0.2.3">https://github.com/zmaril/straitjacket/compare/v0.2.2...v0.2.3</a></p>
]]></content:encoded></item><item><title>detect-git-changes-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/detect-git-changes-action/</link><pubDate>Tue, 07 Jul 2026 15:28:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/detect-git-changes-action/</guid><description>Version updated for https://github.com/isaac-cf-wong/detect-git-changes-action to version v0.0.15.
This action is used across all versions by 8 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.0.15 - 2026-07-01 ⚙️ Miscellaneous Tasks (deps) Update pre-commit hook davidanson/markdownlint-cli2 to v0.23.0 (#41) - (c49bec3) (deps) Update pre-commit hook rbubley/mirrors-prettier to v3.9.4 (#40) - (c8bc486) Contributing: We welcome contributions! Please see our Contributing Guide for details.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/isaac-cf-wong/detect-git-changes-action">https://github.com/isaac-cf-wong/detect-git-changes-action</a></strong> to version <strong>v0.0.15</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/detect-git-changes-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="0015---2026-07-01"><a href="https://github.com/isaac-cf-wong/detect-git-changes-action/compare/v0.0.14..v0.0.15">0.0.15</a> - 2026-07-01</h2>
<h3 id="-miscellaneous-tasks">⚙️ Miscellaneous Tasks</h3>
<ul>
<li><em>(deps)</em> Update pre-commit hook davidanson/markdownlint-cli2 to v0.23.0 (<a href="https://github.com/isaac-cf-wong/detect-git-changes-action/issues/41">#41</a>) - (<a href="https://github.com/isaac-cf-wong/detect-git-changes-action/commit/c49bec37fa3496222c70649af3a09e2c2612310e">c49bec3</a>)</li>
<li><em>(deps)</em> Update pre-commit hook rbubley/mirrors-prettier to v3.9.4 (<a href="https://github.com/isaac-cf-wong/detect-git-changes-action/issues/40">#40</a>) - (<a href="https://github.com/isaac-cf-wong/detect-git-changes-action/commit/c8bc48643b166a9f2d143258fc464909dc20a9d5">c8bc486</a>)</li>
</ul>
<hr>
<p><strong>Contributing</strong>: We welcome contributions! Please see our <a href="https://github.com/isaac-cf-wong/detect-git-changes-action/blob/main/CONTRIBUTING.md">Contributing Guide</a> for details.</p>
<p><strong>Questions?</strong> Open an issue on <a href="https://github.com/isaac-cf-wong/detect-git-changes-action/issues">GitHub</a> or join our discussions.</p>
]]></content:encoded></item><item><title>IsReadyAI — readiness audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/isreadyai-readiness-audit/</link><pubDate>Tue, 07 Jul 2026 15:28:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/isreadyai-readiness-audit/</guid><description>Version updated for https://github.com/isreadyai/audit-action to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Refresh the bundled scanner from the monorepo.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/isreadyai/audit-action">https://github.com/isreadyai/audit-action</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/isreadyai-readiness-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Refresh the bundled scanner from the monorepo.</li>
</ul>
]]></content:encoded></item><item><title>IsReadyAI — readiness fix</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/isreadyai-readiness-fix/</link><pubDate>Tue, 07 Jul 2026 15:27:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/isreadyai-readiness-fix/</guid><description>Version updated for https://github.com/isreadyai/fix-action to version v1.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Synced from isreadyai/isreadyai@1.0.2.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/isreadyai/fix-action">https://github.com/isreadyai/fix-action</a></strong> to version <strong>v1.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/isreadyai-readiness-fix">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Synced from <a href="mailto:isreadyai/isreadyai@1.0.2">isreadyai/isreadyai@1.0.2</a>.</p>
]]></content:encoded></item><item><title>spek - OpenSpec Static Site</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/spek-openspec-static-site/</link><pubDate>Tue, 07 Jul 2026 15:27:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/spek-openspec-static-site/</guid><description>Version updated for https://github.com/kewang/spek to version v1.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Live-reload now works inside devcontainers and WSL. On filesystems that don’t deliver native OS change events (9p / drvfs / NFS / CIFS / FUSE), spek automatically falls back to polling — so files created or edited after opening it are still detected. Detection is based on the watched path’s filesystem type and needs no configuration; an optional SPEK_WATCH_POLLING=on|off escape hatch exists only if you ever need to force it. Applies to the Web, VS Code, and IntelliJ live variants. Thanks to @nthansen (Norman Hansen) for contributing this feature.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kewang/spek">https://github.com/kewang/spek</a></strong> to version <strong>v1.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spek-openspec-static-site">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Live-reload now works inside devcontainers and WSL. On filesystems that don&rsquo;t deliver native OS change events (9p / drvfs / NFS / CIFS / FUSE), spek automatically falls back to polling — so files created or edited after opening it are still detected. Detection is based on the watched path&rsquo;s filesystem type and needs no configuration; an optional <code>SPEK_WATCH_POLLING=on|off</code> escape hatch exists only if you ever need to force it. Applies to the Web, VS Code, and IntelliJ live variants. Thanks to @nthansen (Norman Hansen) for contributing this feature.</li>
</ul>
]]></content:encoded></item><item><title>AIGate Git Workflow Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/aigate-git-workflow-guard/</link><pubDate>Tue, 07 Jul 2026 15:26:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/aigate-git-workflow-guard/</guid><description>Version updated for https://github.com/LeeHueeng/aigate-ai-git-workflow-guard-cli to version v0.1.7.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Highlights Added aigate verify-enforcement for live GitHub/GitLab server-side enforcement verification. Updated doctor and project scoring to distinguish advisory, partial, and verified server-enforced AIGate gates. Published npm package aigate-cli@0.1.7 with provenance through GitHub Actions. Published GHCR Docker image ghcr.io/leehueeng/aigate-cli:0.1.7 and refreshed the GitHub Action display name. Validation npm run ci Release workflow dry run Release workflow publish Docker workflow publish npm view aigate-cli version -&amp;gt; 0.1.7</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/LeeHueeng/aigate-ai-git-workflow-guard-cli">https://github.com/LeeHueeng/aigate-ai-git-workflow-guard-cli</a></strong> to version <strong>v0.1.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aigate-git-workflow-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Added <code>aigate verify-enforcement</code> for live GitHub/GitLab server-side enforcement verification.</li>
<li>Updated doctor and project scoring to distinguish advisory, partial, and verified server-enforced AIGate gates.</li>
<li>Published npm package <code>aigate-cli@0.1.7</code> with provenance through GitHub Actions.</li>
<li>Published GHCR Docker image <code>ghcr.io/leehueeng/aigate-cli:0.1.7</code> and refreshed the GitHub Action display name.</li>
</ul>
<h2 id="validation">Validation</h2>
<ul>
<li><code>npm run ci</code></li>
<li>Release workflow dry run</li>
<li>Release workflow publish</li>
<li>Docker workflow publish</li>
<li><code>npm view aigate-cli version</code> -&gt; <code>0.1.7</code></li>
</ul>
]]></content:encoded></item><item><title>GitHub Personal Stats</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/github-personal-stats/</link><pubDate>Tue, 07 Jul 2026 15:26:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/github-personal-stats/</guid><description>Version updated for https://github.com/liuchong/github-personal-stats to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v1.0.0 of the GitHub Personal Stats Action and CLI binaries.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/liuchong/github-personal-stats">https://github.com/liuchong/github-personal-stats</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-personal-stats">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release v1.0.0 of the GitHub Personal Stats Action and CLI binaries.</p>
]]></content:encoded></item><item><title>crabd</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/crabd/</link><pubDate>Tue, 07 Jul 2026 15:25:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/crabd/</guid><description>Version updated for https://github.com/louisescher/crabd to version v0.4.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix: resolve Forgejo association via org membership by @louisescher in https://github.com/louisescher/crabd/pull/18 feat: classify bare mentions and route to the right mode by @louisescher in https://github.com/louisescher/crabd/pull/20 chore: version packages by @github-actions[bot] in https://github.com/louisescher/crabd/pull/19 Full Changelog: https://github.com/louisescher/crabd/compare/v0...v0.4.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/louisescher/crabd">https://github.com/louisescher/crabd</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/crab-d">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: resolve Forgejo association via org membership by @louisescher in <a href="https://github.com/louisescher/crabd/pull/18">https://github.com/louisescher/crabd/pull/18</a></li>
<li>feat: classify bare mentions and route to the right mode by @louisescher in <a href="https://github.com/louisescher/crabd/pull/20">https://github.com/louisescher/crabd/pull/20</a></li>
<li>chore: version packages by @github-actions[bot] in <a href="https://github.com/louisescher/crabd/pull/19">https://github.com/louisescher/crabd/pull/19</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/louisescher/crabd/compare/v0...v0.4.0">https://github.com/louisescher/crabd/compare/v0...v0.4.0</a></p>
]]></content:encoded></item><item><title>Git Velocity Analyser</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/git-velocity-analyser/</link><pubDate>Tue, 07 Jul 2026 15:25:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/git-velocity-analyser/</guid><description>Version updated for https://github.com/lukaszraczylo/git-velocity to version v1.0.10.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lukaszraczylo/git-velocity">https://github.com/lukaszraczylo/git-velocity</a></strong> to version <strong>v1.0.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/git-velocity-analyser">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
]]></content:encoded></item><item><title>agent-bom Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/agent-bom-scan/</link><pubDate>Tue, 07 Jul 2026 15:24:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/agent-bom-scan/</guid><description>Version updated for https://github.com/msaad00/agent-bom to version v0.93.5.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps): consolidate weekly dependency and registry updates by @msaad00 in https://github.com/msaad00/agent-bom/pull/3600 feat(ui): guided demo lock cards on runtime surfaces (Part of #3468) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3602 feat(output): svg/html formatter convergence (Part of #2918) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3601 feat(ui,deploy): /login + collector mTLS defaults (Part of #3175) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3603 refactor(parsers): extract skill metadata checks into skill_audit_metadata by @andres-linero in https://github.com/msaad00/agent-bom/pull/3604 refactor(api): split postgres_store into per-store modules by @andres-linero in https://github.com/msaad00/agent-bom/pull/3605 feat(ui): rollup-by-default and asset drift lens (Part of #3192) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3606 feat(ast,output): PHP/Swift symbol reach and Parquet export (Part of #3499) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3607 docs(audit): consolidate epic queue merge state (#3601–#3607) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3611 feat(runtime): OIDC discovery shim for legacy IdP MCP interop (Part of #3609) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3612 feat(findings): runtime evidence + compliance moat lift (Part of #3608, #3610) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3613 fix(scan,output): CLI AST gate + Parquet compliance_tags parity (audit P1/P2) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3614 feat(runtime): trace explorer joined to findings and compliance (Part of #3608) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3615 feat(ui,graph): runtime evidence overlay badges (Part of #3610) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3616 feat(proof): release smoke, demo estate, trust doc, proof-path nav (#3618) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3619 docs(deploy): unified install script, quickstart, and intake diagrams by @msaad00 in https://github.com/msaad00/agent-bom/pull/3621 fix(audit): P3 login redirect, Swift bare calls, rollup URL persistence by @msaad00 in https://github.com/msaad00/agent-bom/pull/3622 feat(scan,docs): GLM/Zhipu inventory + BYOM quickstart (closes #3609 tail) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3623 fix(audit): malicious findings stream, COUNT cache, demo hardening, SCIM keys by @msaad00 in https://github.com/msaad00/agent-bom/pull/3624 fix(ui): capture hydration + refreshed product-proof screenshots by @msaad00 in https://github.com/msaad00/agent-bom/pull/3625 fix(audit): post-3624 follow-up — reachability, demo safety, scale bench by @msaad00 in https://github.com/msaad00/agent-bom/pull/3626 chore(release): v0.93.5 by @msaad00 in https://github.com/msaad00/agent-bom/pull/3628 fix(pre-release): CI isolation, README SVGs, and UI readability by @msaad00 in https://github.com/msaad00/agent-bom/pull/3629 fix(audit): SARIF malware flag on CVE path + PHP heredoc/nowdoc reach masking by @msaad00 in https://github.com/msaad00/agent-bom/pull/3630 Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.93.0...v0.93.5</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/msaad00/agent-bom">https://github.com/msaad00/agent-bom</a></strong> to version <strong>v0.93.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-bom-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): consolidate weekly dependency and registry updates by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3600">https://github.com/msaad00/agent-bom/pull/3600</a></li>
<li>feat(ui): guided demo lock cards on runtime surfaces (Part of #3468) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3602">https://github.com/msaad00/agent-bom/pull/3602</a></li>
<li>feat(output): svg/html formatter convergence (Part of #2918) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3601">https://github.com/msaad00/agent-bom/pull/3601</a></li>
<li>feat(ui,deploy): /login + collector mTLS defaults (Part of #3175) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3603">https://github.com/msaad00/agent-bom/pull/3603</a></li>
<li>refactor(parsers): extract skill metadata checks into skill_audit_metadata by @andres-linero in <a href="https://github.com/msaad00/agent-bom/pull/3604">https://github.com/msaad00/agent-bom/pull/3604</a></li>
<li>refactor(api): split postgres_store into per-store modules by @andres-linero in <a href="https://github.com/msaad00/agent-bom/pull/3605">https://github.com/msaad00/agent-bom/pull/3605</a></li>
<li>feat(ui): rollup-by-default and asset drift lens (Part of #3192) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3606">https://github.com/msaad00/agent-bom/pull/3606</a></li>
<li>feat(ast,output): PHP/Swift symbol reach and Parquet export (Part of #3499) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3607">https://github.com/msaad00/agent-bom/pull/3607</a></li>
<li>docs(audit): consolidate epic queue merge state (#3601–#3607) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3611">https://github.com/msaad00/agent-bom/pull/3611</a></li>
<li>feat(runtime): OIDC discovery shim for legacy IdP MCP interop (Part of #3609) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3612">https://github.com/msaad00/agent-bom/pull/3612</a></li>
<li>feat(findings): runtime evidence + compliance moat lift (Part of #3608, #3610) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3613">https://github.com/msaad00/agent-bom/pull/3613</a></li>
<li>fix(scan,output): CLI AST gate + Parquet compliance_tags parity (audit P1/P2) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3614">https://github.com/msaad00/agent-bom/pull/3614</a></li>
<li>feat(runtime): trace explorer joined to findings and compliance (Part of #3608) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3615">https://github.com/msaad00/agent-bom/pull/3615</a></li>
<li>feat(ui,graph): runtime evidence overlay badges (Part of #3610) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3616">https://github.com/msaad00/agent-bom/pull/3616</a></li>
<li>feat(proof): release smoke, demo estate, trust doc, proof-path nav (#3618) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3619">https://github.com/msaad00/agent-bom/pull/3619</a></li>
<li>docs(deploy): unified install script, quickstart, and intake diagrams by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3621">https://github.com/msaad00/agent-bom/pull/3621</a></li>
<li>fix(audit): P3 login redirect, Swift bare calls, rollup URL persistence by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3622">https://github.com/msaad00/agent-bom/pull/3622</a></li>
<li>feat(scan,docs): GLM/Zhipu inventory + BYOM quickstart (closes #3609 tail) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3623">https://github.com/msaad00/agent-bom/pull/3623</a></li>
<li>fix(audit): malicious findings stream, COUNT cache, demo hardening, SCIM keys by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3624">https://github.com/msaad00/agent-bom/pull/3624</a></li>
<li>fix(ui): capture hydration + refreshed product-proof screenshots by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3625">https://github.com/msaad00/agent-bom/pull/3625</a></li>
<li>fix(audit): post-3624 follow-up — reachability, demo safety, scale bench by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3626">https://github.com/msaad00/agent-bom/pull/3626</a></li>
<li>chore(release): v0.93.5 by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3628">https://github.com/msaad00/agent-bom/pull/3628</a></li>
<li>fix(pre-release): CI isolation, README SVGs, and UI readability by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3629">https://github.com/msaad00/agent-bom/pull/3629</a></li>
<li>fix(audit): SARIF malware flag on CVE path + PHP heredoc/nowdoc reach masking by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3630">https://github.com/msaad00/agent-bom/pull/3630</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/msaad00/agent-bom/compare/v0.93.0...v0.93.5">https://github.com/msaad00/agent-bom/compare/v0.93.0...v0.93.5</a></p>
]]></content:encoded></item><item><title>AI Agent Discipline Linter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/ai-agent-discipline-linter/</link><pubDate>Tue, 07 Jul 2026 15:23:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/ai-agent-discipline-linter/</guid><description>Version updated for https://github.com/naimkatiman/continuous-improvement to version v3.18.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed docs(readme): progressive-disclosure rewrite — value prop + quick start above the fold, depth collapsed by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/260 chore(npm): front-load description with “Claude Code” + focus keywords for search relevance by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/261 feat(visuals): 1280x640 social preview + in-action gateguard demo image by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/262 docs(readme): list all 28 slash commands + fix stale repo-map counts by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/263 feat(verify): guard the README slash-command list with a check-command-count invariant by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/264 feat(reconcile): fold commit -&amp;gt; push -&amp;gt; open-PR + post-merge main sync into reconcile by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/266 feat: portfolio spine — repos registry, proof templates, portfolio-health + audit-actions commands by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/267 chore(gitignore): ignore .playwright-mcp/ browser artifacts by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/268 feat(gateguard): opt low-risk paths out of the fact-forcing gate via CI_GATEGUARD_EXCLUDE by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/269 feat(gateguard): three friction-driven hardening fixes (message-prose, target-lock, unquoted @{u}) by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/270 chore(release): cut v3.18.0 by @naimkatiman in https://github.com/naimkatiman/continuous-improvement/pull/271 Full Changelog: https://github.com/naimkatiman/continuous-improvement/compare/v3...v3.18.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/naimkatiman/continuous-improvement">https://github.com/naimkatiman/continuous-improvement</a></strong> to version <strong>v3.18.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-agent-discipline-linter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs(readme): progressive-disclosure rewrite — value prop + quick start above the fold, depth collapsed by @naimkatiman in <a href="https://github.com/naimkatiman/continuous-improvement/pull/260">https://github.com/naimkatiman/continuous-improvement/pull/260</a></li>
<li>chore(npm): front-load description with &ldquo;Claude Code&rdquo; + focus keywords for search relevance by @naimkatiman in <a href="https://github.com/naimkatiman/continuous-improvement/pull/261">https://github.com/naimkatiman/continuous-improvement/pull/261</a></li>
<li>feat(visuals): 1280x640 social preview + in-action gateguard demo image by @naimkatiman in <a href="https://github.com/naimkatiman/continuous-improvement/pull/262">https://github.com/naimkatiman/continuous-improvement/pull/262</a></li>
<li>docs(readme): list all 28 slash commands + fix stale repo-map counts by @naimkatiman in <a href="https://github.com/naimkatiman/continuous-improvement/pull/263">https://github.com/naimkatiman/continuous-improvement/pull/263</a></li>
<li>feat(verify): guard the README slash-command list with a check-command-count invariant by @naimkatiman in <a href="https://github.com/naimkatiman/continuous-improvement/pull/264">https://github.com/naimkatiman/continuous-improvement/pull/264</a></li>
<li>feat(reconcile): fold commit -&gt; push -&gt; open-PR + post-merge main sync into reconcile by @naimkatiman in <a href="https://github.com/naimkatiman/continuous-improvement/pull/266">https://github.com/naimkatiman/continuous-improvement/pull/266</a></li>
<li>feat: portfolio spine — repos registry, proof templates, portfolio-health + audit-actions commands by @naimkatiman in <a href="https://github.com/naimkatiman/continuous-improvement/pull/267">https://github.com/naimkatiman/continuous-improvement/pull/267</a></li>
<li>chore(gitignore): ignore .playwright-mcp/ browser artifacts by @naimkatiman in <a href="https://github.com/naimkatiman/continuous-improvement/pull/268">https://github.com/naimkatiman/continuous-improvement/pull/268</a></li>
<li>feat(gateguard): opt low-risk paths out of the fact-forcing gate via CI_GATEGUARD_EXCLUDE by @naimkatiman in <a href="https://github.com/naimkatiman/continuous-improvement/pull/269">https://github.com/naimkatiman/continuous-improvement/pull/269</a></li>
<li>feat(gateguard): three friction-driven hardening fixes (message-prose, target-lock, unquoted @{u}) by @naimkatiman in <a href="https://github.com/naimkatiman/continuous-improvement/pull/270">https://github.com/naimkatiman/continuous-improvement/pull/270</a></li>
<li>chore(release): cut v3.18.0 by @naimkatiman in <a href="https://github.com/naimkatiman/continuous-improvement/pull/271">https://github.com/naimkatiman/continuous-improvement/pull/271</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/naimkatiman/continuous-improvement/compare/v3...v3.18.0">https://github.com/naimkatiman/continuous-improvement/compare/v3...v3.18.0</a></p>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/go-proxy-cache-updater/</link><pubDate>Tue, 07 Jul 2026 15:23:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.16.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.1.16 (2026-07-07)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1116-2026-07-07"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.15...v1.1.16">1.1.16</a> (2026-07-07)</h2>
]]></content:encoded></item><item><title>zotio bibliography health for Zotero</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/zotio-bibliography-health-for-zotero/</link><pubDate>Tue, 07 Jul 2026 15:22:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/zotio-bibliography-health-for-zotero/</guid><description>Version updated for https://github.com/OrgMentem/zotio-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed New: every run writes a verdict table to the job step summary, and the action now exposes exit-code, message, and color outputs for downstream steps (PR comments, badge publishing).
README: now leads with what you get — the deterministic exit-code gate, retraction checking (with demo GIF), the badge-that-never-lies, and the key operational insight: your Zotero library drifts outside git, so run the gate on a schedule, not just on push.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/OrgMentem/zotio-action">https://github.com/OrgMentem/zotio-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zotio-bibliography-health-for-zotero">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>New:</strong> every run writes a verdict table to the job step summary, and the action now exposes <code>exit-code</code>, <code>message</code>, and <code>color</code> outputs for downstream steps (PR comments, badge publishing).</p>
<p><strong>README:</strong> now leads with what you get — the deterministic exit-code gate, retraction checking (with demo GIF), the badge-that-never-lies, and the key operational insight: your Zotero library drifts outside git, so run the gate on a <code>schedule</code>, not just on push.</p>
]]></content:encoded></item><item><title>SpringSentinel</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/springsentinel/</link><pubDate>Tue, 07 Jul 2026 15:22:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/springsentinel/</guid><description>Version updated for https://github.com/pagano-antonio/springsentinel-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Update Dockerfile (b2d1ae2) Delete scripts directory (3ba2f95) Update entrypoint.sh (1af5128) Update Dockerfile (e0b9ba7) Update entrypoint.sh (2f69f60) Create generate-comment.js (2a2eb1b) Create README.md (3e1d589) Update test.yml (3a7ed11) Update entrypoint.sh (4e15ea0) Update entrypoint.sh (6418942)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pagano-antonio/springsentinel-action">https://github.com/pagano-antonio/springsentinel-action</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/springsentinel">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Update Dockerfile (b2d1ae2)</li>
<li>Delete scripts directory (3ba2f95)</li>
<li>Update entrypoint.sh (1af5128)</li>
<li>Update Dockerfile (e0b9ba7)</li>
<li>Update entrypoint.sh (2f69f60)</li>
<li>Create generate-comment.js (2a2eb1b)</li>
<li>Create README.md (3e1d589)</li>
<li>Update test.yml (3a7ed11)</li>
<li>Update entrypoint.sh (4e15ea0)</li>
<li>Update entrypoint.sh (6418942)</li>
</ul>
]]></content:encoded></item><item><title>Drawio Export Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/drawio-export-action/</link><pubDate>Tue, 07 Jul 2026 15:21:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/drawio-export-action/</guid><description>Version updated for https://github.com/rlespinasse/drawio-export-action to version v2.53.0.
This action is used across all versions by 124 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 2.53.0 (2026-07-07) Features bump rlespinasse/drawio-export from v4.52.0 to v4.54.0 (#105) (c422855)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rlespinasse/drawio-export-action">https://github.com/rlespinasse/drawio-export-action</a></strong> to version <strong>v2.53.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>124</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/drawio-export-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="2530-2026-07-07"><a href="https://github.com/rlespinasse/drawio-export-action/compare/v2.52.0...v2.53.0">2.53.0</a> (2026-07-07)</h1>
<h3 id="features">Features</h3>
<ul>
<li>bump rlespinasse/drawio-export from v4.52.0 to v4.54.0 (<a href="https://github.com/rlespinasse/drawio-export-action/issues/105">#105</a>) (<a href="https://github.com/rlespinasse/drawio-export-action/commit/c4228553980854f065d2642e00d41b1ee692ff73">c422855</a>)</li>
</ul>
]]></content:encoded></item><item><title>FoundRuu Doctor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/foundruu-doctor/</link><pubDate>Tue, 07 Jul 2026 15:21:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/foundruu-doctor/</guid><description>Version updated for https://github.com/Ruu5LP/foundruu to version v0.12.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed 配布コーディングルールを全言語で強化 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/18 配布コーディングルール強化の穴を厳格レビュー観点で追加修正 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/19 Python を正式サポート（FastAPI テンプレート）に追加 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/20 FoundRuu を自リポジトリに適用し、Prettier ignore 自動整備を追加 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/21 コーディングルールの機械強制を全言語で CI まで一貫させる by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/22 README にテンプレート一覧を追加し、記述を最新化 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/23 実装前の構造化整理をサポート（structure プロンプト + 計画品質診断） by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/24 Release 0.12.0 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/25 Full Changelog: https://github.com/Ruu5LP/foundruu/compare/v0.11.0...v0.12.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Ruu5LP/foundruu">https://github.com/Ruu5LP/foundruu</a></strong> to version <strong>v0.12.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/foundruu-doctor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>配布コーディングルールを全言語で強化 by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/18">https://github.com/Ruu5LP/foundruu/pull/18</a></li>
<li>配布コーディングルール強化の穴を厳格レビュー観点で追加修正 by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/19">https://github.com/Ruu5LP/foundruu/pull/19</a></li>
<li>Python を正式サポート（FastAPI テンプレート）に追加 by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/20">https://github.com/Ruu5LP/foundruu/pull/20</a></li>
<li>FoundRuu を自リポジトリに適用し、Prettier ignore 自動整備を追加 by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/21">https://github.com/Ruu5LP/foundruu/pull/21</a></li>
<li>コーディングルールの機械強制を全言語で CI まで一貫させる by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/22">https://github.com/Ruu5LP/foundruu/pull/22</a></li>
<li>README にテンプレート一覧を追加し、記述を最新化 by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/23">https://github.com/Ruu5LP/foundruu/pull/23</a></li>
<li>実装前の構造化整理をサポート（structure プロンプト + 計画品質診断） by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/24">https://github.com/Ruu5LP/foundruu/pull/24</a></li>
<li>Release 0.12.0 by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/25">https://github.com/Ruu5LP/foundruu/pull/25</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Ruu5LP/foundruu/compare/v0.11.0...v0.12.0">https://github.com/Ruu5LP/foundruu/compare/v0.11.0...v0.12.0</a></p>
]]></content:encoded></item><item><title>VibeSafe Vulnerability Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/vibesafe-vulnerability-scanner/</link><pubDate>Tue, 07 Jul 2026 15:20:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/vibesafe-vulnerability-scanner/</guid><description>Version updated for https://github.com/SabahatGhauri/vibesafe-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Scan changed code on push/PR, comment findings on the PR, and fail the check on critical issues. See README for setup.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SabahatGhauri/vibesafe-action">https://github.com/SabahatGhauri/vibesafe-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibesafe-vulnerability-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Scan changed code on push/PR, comment findings on the PR, and fail the check on critical issues. See README for setup.</p>
]]></content:encoded></item><item><title>Scrutora DPDP Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/scrutora-dpdp-scan/</link><pubDate>Tue, 07 Jul 2026 15:19:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/scrutora-dpdp-scan/</guid><description>Version updated for https://github.com/Scrutora/dpdp-scan to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First public release of Scrutora DPDP Scan — free DPDPA &amp;amp; HIPAA compliance code scanning in CI. Findings cite the exact obligation (e.g. DPDPA §8(5)), not a generic rule id, and land in your Security → Code scanning tab. Runs offline: no API key, your code never leaves the runner.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Scrutora/dpdp-scan">https://github.com/Scrutora/dpdp-scan</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/scrutora-dpdp-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release of <strong>Scrutora DPDP Scan</strong> — free DPDPA &amp; HIPAA compliance
code scanning in CI. Findings cite the exact obligation (e.g. DPDPA §8(5)), not a
generic rule id, and land in your <strong>Security → Code scanning</strong> tab. Runs offline:
<strong>no API key, your code never leaves the runner.</strong></p>
<h3 id="quick-start">Quick start</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">id</span>: <span style="color:#ae81ff">scan</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Scrutora/dpdp-scan@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">frameworks: dpdpa,hipaa   # default</span>: <span style="color:#ae81ff">dpdpa</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high            </span> <span style="color:#75715e"># none|low|medium|high|critical</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">if</span>: <span style="color:#ae81ff">always()</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">github/codeql-action/upload-sarif@v3</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">sarif_file</span>: <span style="color:#ae81ff">${{ steps.scan.outputs.sarif-file }}</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>greetingMSPQ-action-test-v4</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/greetingmspq-action-test-v4/</link><pubDate>Tue, 07 Jul 2026 15:19:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/greetingmspq-action-test-v4/</guid><description>Version updated for https://github.com/SebasCorps/greeting-action to version V2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/SebasCorps/greeting-action/compare/v1.0...V2.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SebasCorps/greeting-action">https://github.com/SebasCorps/greeting-action</a></strong> to version <strong>V2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/greetingmspq-action-test-v4">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/SebasCorps/greeting-action/compare/v1.0...V2.0">https://github.com/SebasCorps/greeting-action/compare/v1.0...V2.0</a></p>
]]></content:encoded></item><item><title>Sentinel Git Secrets Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/sentinel-git-secrets-scanner/</link><pubDate>Tue, 07 Jul 2026 15:18:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/sentinel-git-secrets-scanner/</guid><description>Version updated for https://github.com/sentinel-cli/sentinel to version v2.0.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Sentinel v2.0.5 Stable Release This release introduces significant performance optimizations and key fixes:
Zero-Allocation Flat DFA Engine: Trie memory footprint reduced to ~500KB and peak RAM down to ~11MB. 100% Core Test Coverage achieved for reporter, git, commands, and updater packages. Heuristics &amp;amp; Suppressions: Added support for Mailgun/Hex letters-only findings and fixed updater comparison logic. Dedicated Output Argument: Added the -o / --output flag to Sentinel scan, enabling silent SARIF/JSON generation in CI while keeping pretty CLI logs. CI/CD Integration: Reusable GitHub Action with native SARIF output, officially published to the Marketplace as Sentinel Git Secrets Scanner. Full Changelog: https://github.com/sentinel-cli/sentinel/compare/v2.0.4...v2.0.5</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sentinel-cli/sentinel">https://github.com/sentinel-cli/sentinel</a></strong> to version <strong>v2.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sentinel-git-secrets-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="sentinel-v205-stable-release">Sentinel v2.0.5 Stable Release</h3>
<p>This release introduces significant performance optimizations and key fixes:</p>
<ul>
<li><strong>Zero-Allocation Flat DFA Engine</strong>: Trie memory footprint reduced to ~500KB and peak RAM down to ~11MB.</li>
<li><strong>100% Core Test Coverage</strong> achieved for reporter, git, commands, and updater packages.</li>
<li><strong>Heuristics &amp; Suppressions</strong>: Added support for Mailgun/Hex letters-only findings and fixed updater comparison logic.</li>
<li><strong>Dedicated Output Argument</strong>: Added the <code>-o</code> / <code>--output</code> flag to Sentinel scan, enabling silent SARIF/JSON generation in CI while keeping pretty CLI logs.</li>
<li><strong>CI/CD Integration</strong>: Reusable GitHub Action with native SARIF output, officially published to the Marketplace as <strong>Sentinel Git Secrets Scanner</strong>.</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sentinel-cli/sentinel/compare/v2.0.4...v2.0.5">https://github.com/sentinel-cli/sentinel/compare/v2.0.4...v2.0.5</a></p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sentinel-cli/sentinel/compare/v2.0.4...v2.0.5">https://github.com/sentinel-cli/sentinel/compare/v2.0.4...v2.0.5</a></p>
]]></content:encoded></item><item><title>pi GitHub Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/pi-github-action/</link><pubDate>Tue, 07 Jul 2026 15:18:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/pi-github-action/</guid><description>Version updated for https://github.com/shaftoe/pi-coding-agent-action to version v2.25.1.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 2.25.1 - 2026-07-07 Changed deps-dev: bump fallow-rs/fallow from 2 to 3 (#363) deps-dev: update dependencies (#359) deps-dev: update dependencies (#360) deps-dev: update dependencies (#367) deps-dev: update dependencies (#370) deps-dev: update dependencies (#371) deps: update dependencies, Pi to v0.80.3 (#358) Fixed improve create_pull_request Forgejo compatibility with API URL fix and compare-URL fallback (#362) make system prompt dynamic based on platform input (#366) platform-github: treat HTTP 404 from pulls.create as a permission error on Forgejo (#369)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/shaftoe/pi-coding-agent-action">https://github.com/shaftoe/pi-coding-agent-action</a></strong> to version <strong>v2.25.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pi-github-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="2251---2026-07-07"><a href="https://github.com/shaftoe/pi-coding-agent-action/compare/v2.25.0...v2.25.1">2.25.1</a> - 2026-07-07</h2>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>deps-dev</strong>: bump fallow-rs/fallow from 2 to 3 (#363)</li>
<li><strong>deps-dev</strong>: update dependencies (#359)</li>
<li><strong>deps-dev</strong>: update dependencies (#360)</li>
<li><strong>deps-dev</strong>: update dependencies (#367)</li>
<li><strong>deps-dev</strong>: update dependencies (#370)</li>
<li><strong>deps-dev</strong>: update dependencies (#371)</li>
<li><strong>deps</strong>: update dependencies, Pi to v0.80.3 (#358)</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>improve create_pull_request Forgejo compatibility with API URL fix and compare-URL fallback (#362)</li>
<li>make system prompt dynamic based on platform input (#366)</li>
<li><strong>platform-github</strong>: treat HTTP 404 from pulls.create as a permission error on Forgejo (#369)</li>
</ul>
]]></content:encoded></item><item><title>Setup DepVault CLI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/setup-depvault-cli/</link><pubDate>Tue, 07 Jul 2026 15:17:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/setup-depvault-cli/</guid><description>Version updated for https://github.com/suxrobGM/depvault to version cli/v1.9.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Zero-knowledge CI tokens: DEPVAULT_TOKEN now has the form dvci_&amp;lt;auth&amp;gt;.&amp;lt;key&amp;gt; — the CLI sends only the auth part to the server and derives the decryption key from the key part locally, so the server can never unwrap your project key. Existing CI tokens must be regenerated in the web dashboard Add a doctor command that checks server reachability, login, vault setup, active project, and encryption key, printing the exact next command for anything not ready project info now accepts a positional [id] argument (e.g. depvault project info &amp;lt;id&amp;gt;) in addition to --project Clearer guidance: point to the dashboard vault-setup URL when the vault isn’t initialized, and make the encryption-key error honest that the CLI attempts creation automatically Support Windows and Linux ARM64 CI runners: the GitHub Action installs on Windows runners, and linux-arm64 binaries are now published</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/suxrobGM/depvault">https://github.com/suxrobGM/depvault</a></strong> to version <strong>cli/v1.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-depvault-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Zero-knowledge CI tokens: <code>DEPVAULT_TOKEN</code> now has the form <code>dvci_&lt;auth&gt;.&lt;key&gt;</code> — the CLI sends only the auth part to the server and derives the decryption key from the key part locally, so the server can never unwrap your project key. <strong>Existing CI tokens must be regenerated</strong> in the web dashboard</li>
<li>Add a <code>doctor</code> command that checks server reachability, login, vault setup, active project, and encryption key, printing the exact next command for anything not ready</li>
<li><code>project info</code> now accepts a positional <code>[id]</code> argument (e.g. <code>depvault project info &lt;id&gt;</code>) in addition to <code>--project</code></li>
<li>Clearer guidance: point to the dashboard vault-setup URL when the vault isn&rsquo;t initialized, and make the encryption-key error honest that the CLI attempts creation automatically</li>
<li>Support Windows and Linux ARM64 CI runners: the GitHub Action installs on Windows runners, and <code>linux-arm64</code> binaries are now published</li>
</ul>
]]></content:encoded></item><item><title>SFDX Code Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/sfdx-code-review/</link><pubDate>Tue, 07 Jul 2026 15:17:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/sfdx-code-review/</guid><description>Version updated for https://github.com/svierk/sfdx-code-review to version v1.0.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed add documentation and usage instructions Full Changelog: https://github.com/svierk/sfdx-code-review/compare/v0.0.2...v1.0.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/svierk/sfdx-code-review">https://github.com/svierk/sfdx-code-review</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sfdx-code-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>add documentation and usage instructions</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/svierk/sfdx-code-review/compare/v0.0.2...v1.0.0">https://github.com/svierk/sfdx-code-review/compare/v0.0.2...v1.0.0</a></p>
]]></content:encoded></item><item><title>SFDX Deploy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/sfdx-deploy/</link><pubDate>Tue, 07 Jul 2026 15:16:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/sfdx-deploy/</guid><description>Version updated for https://github.com/svierk/sfdx-deploy to version v1.1.4.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed suppress sfdx-git-delta output for cleaner deploy logs Full Changelog: https://github.com/svierk/sfdx-deploy/compare/v1.1.3...v1.1.4</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/svierk/sfdx-deploy">https://github.com/svierk/sfdx-deploy</a></strong> to version <strong>v1.1.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sfdx-deploy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>suppress sfdx-git-delta output for cleaner deploy logs</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/svierk/sfdx-deploy/compare/v1.1.3...v1.1.4">https://github.com/svierk/sfdx-deploy/compare/v1.1.3...v1.1.4</a></p>
]]></content:encoded></item><item><title>Polder Drift — Design System Drift Alerts</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/polder-drift-design-system-drift-alerts/</link><pubDate>Tue, 07 Jul 2026 15:15:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/polder-drift-design-system-drift-alerts/</guid><description>Version updated for https://github.com/usepolder/drift to version v1.1.2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Hardening release (PR #14).
Security
Drift-table cells are sanitized: backticks, pipes, and newlines in import paths or filenames can no longer break the comment table or inject markdown rendered as authored by the bot (fork-PR comment spoofing). Correctness</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/usepolder/drift">https://github.com/usepolder/drift</a></strong> to version <strong>v1.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/polder-drift-design-system-drift-alerts">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Hardening release (PR #14).</p>
<p><strong>Security</strong></p>
<ul>
<li>Drift-table cells are sanitized: backticks, pipes, and newlines in import paths or filenames can no longer break the comment table or inject markdown rendered as authored by the bot (fork-PR comment spoofing).</li>
</ul>
<p><strong>Correctness</strong></p>
<ul>
<li>Allowlist entries match whole path segments: <code>#ds</code> no longer silently allowlists <code>#dsx/Button</code>; trailing-slash entries keep prefix semantics.</li>
<li>Packages declaring types only under the <code>exports</code> map (root or nested <code>import</code>/<code>require</code>/<code>default</code> conditions) now resolve their barrel <code>.d.ts</code>.</li>
</ul>
<p><strong>Visibility</strong></p>
<ul>
<li>Unparseable changed files warn instead of silently reporting zero drift, on both the head and base versions (a base parse failure now warns that drift may be reported as new).</li>
<li>On GitHub, fork PRs (read-only token) get the drift report written to the workflow step summary when the comment post 403s; the failure still surfaces loudly.</li>
</ul>
<p>No changes to detection rules, severity, suppression, or adoption math. 289 tests.</p>
]]></content:encoded></item><item><title>Upkeep Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/upkeep-audit/</link><pubDate>Tue, 07 Jul 2026 15:15:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/upkeep-audit/</guid><description>Version updated for https://github.com/wei18/Upkeep to version v2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Upkeep is now installable as a Claude Code plugin (/plugin marketplace add wei18/upkeep + /plugin install upkeep@upkeep) or via npx skills add wei18/upkeep --skill upkeep-audit. The GHA reusable workflow is unchanged — @v1 callers keep working but v1 is now frozen; switch to @v2 (identical interface). From now on fixes move the v2 tag only.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wei18/Upkeep">https://github.com/wei18/Upkeep</a></strong> to version <strong>v2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/upkeep-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Upkeep is now installable as a Claude Code plugin (<code>/plugin marketplace add wei18/upkeep</code> + <code>/plugin install upkeep@upkeep</code>) or via <code>npx skills add wei18/upkeep --skill upkeep-audit</code>. The GHA reusable workflow is unchanged — <code>@v1</code> callers keep working but <code>v1</code> is now frozen; switch to <code>@v2</code> (identical interface). From now on fixes move the <code>v2</code> tag only.</p>
]]></content:encoded></item><item><title>AGENTS.md Lint (Schliff)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/agents.md-lint-schliff/</link><pubDate>Tue, 07 Jul 2026 15:14:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/agents.md-lint-schliff/</guid><description>Version updated for https://github.com/Zandereins/schliff to version v8.5.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed verify scores under the detected format profile (#102, closes #101): schliff verify AGENTS.md no longer fails spuriously (was 27.7/F under the SKILL profile on a file score grades 91.6/A). SKILL.md verdicts unchanged. Positional negation in operational_coverage (#96): contrastive sentences (“run X, never Y directly”) keep the recommended command. Dead-marker detector matches marker tokens, not English prose (#97, closes #93). Corpus goldens re-derived. Security Runtime scorer prompt nonce-hardened (#99) — defense-in-depth, dimension remains opt-in. Added Theme-aware README hero + social-preview asset (#106); star-notify workflow (#98); grouped Dependabot action bumps (#107). Docs README redesigned (#100): AGENTS.md-first, every number ground-truthed against the released engine, honesty-hardened. Full changelog: https://github.com/Zandereins/schliff/blob/main/CHANGELOG.md</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Zandereins/schliff">https://github.com/Zandereins/schliff</a></strong> to version <strong>v8.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agents-md-lint-schliff">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="fixed">Fixed</h2>
<ul>
<li><strong><code>verify</code> scores under the detected format profile</strong> (#102, closes #101): <code>schliff verify AGENTS.md</code> no longer fails spuriously (was 27.7/F under the SKILL profile on a file <code>score</code> grades 91.6/A). SKILL.md verdicts unchanged.</li>
<li><strong>Positional negation in <code>operational_coverage</code></strong> (#96): contrastive sentences (&ldquo;run X, never Y directly&rdquo;) keep the recommended command.</li>
<li><strong>Dead-marker detector matches marker tokens, not English prose</strong> (#97, closes #93). Corpus goldens re-derived.</li>
</ul>
<h2 id="security">Security</h2>
<ul>
<li>Runtime scorer prompt nonce-hardened (#99) — defense-in-depth, dimension remains opt-in.</li>
</ul>
<h2 id="added">Added</h2>
<ul>
<li>Theme-aware README hero + social-preview asset (#106); star-notify workflow (#98); grouped Dependabot action bumps (#107).</li>
</ul>
<h2 id="docs">Docs</h2>
<ul>
<li>README redesigned (#100): AGENTS.md-first, every number ground-truthed against the released engine, honesty-hardened.</li>
</ul>
<p>Full changelog: <a href="https://github.com/Zandereins/schliff/blob/main/CHANGELOG.md">https://github.com/Zandereins/schliff/blob/main/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>XcodeReady Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/xcodeready-scan/</link><pubDate>Tue, 07 Jul 2026 05:23:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/xcodeready-scan/</guid><description>Version updated for https://github.com/gautam00010/xcodeready-action to version Error loading version from page [https://github.com/marketplace/actions/xcodeready-scan], unable to determine latest release.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/gautam00010/xcodeready-action">https://github.com/gautam00010/xcodeready-action</a></strong> to version <strong>Error loading version from page [https://github.com/marketplace/actions/xcodeready-scan], unable to determine latest release</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/xcodeready-scan">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/ai-plugin-scanner/</link><pubDate>Tue, 07 Jul 2026 05:22:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.397.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/2e9f06f4562accd2c70e006e3b10ada68c0d91be with plugin-scanner 2.0.997.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.396...v1.2.397</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.397</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>18</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/2e9f06f4562accd2c70e006e3b10ada68c0d91be">https://github.com/hashgraph-online/hol-guard/tree/2e9f06f4562accd2c70e006e3b10ada68c0d91be</a> with plugin-scanner 2.0.997.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.396...v1.2.397">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.396...v1.2.397</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/hol-codex-plugin-scanner/</link><pubDate>Tue, 07 Jul 2026 05:22:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.397.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.397</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.397</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.397">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.397</a></p>
]]></content:encoded></item><item><title>Hyperlocalise CI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/hyperlocalise-ci/</link><pubDate>Tue, 07 Jul 2026 05:21:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/hyperlocalise-ci/</guid><description>Version updated for https://github.com/hyperlocalise/hyperlocalise to version v1.8.18.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix(web): redirect /dashboard via route handler by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1118 test(web): cover Contentful no-writeback failures by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1120 ⚡ Bolt: optimize XCStrings parser and marshaler by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1121 🧪 Scout: escape line feeds in CSV formula neutralization by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1123 fix(web): preserve workspace automation output summary on orchestrator finish by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1122 fix(crowdin): add missing DateFrom to EnterpriseVendorTaskCreateForm and fix typos by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1124 feat(web): add per-file translation import for native TMS by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1125 update deps by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1126 🧪 Scout: fix PO parser continuation leakage by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1129 fix(crowdin): add URL field to Screenshot model for API parity by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1130 fix(web): rename billing AI usage label to AI Credit by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1131 fix(web): parse target locale when importing xcstrings translations by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1128 chore: update deps by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1132 ⚡ Bolt: optimize ICU parser via low-copy literal tracking by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1127 ⚡ Bolt: Optimize CSV parser and marshaler with capacity hints by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1133 🧪 Scout: add regression tests for ICU pound summation in sibling blocks by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1135 fix(web): fail Contentful idempotent retry when prior run wrote no drafts by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1134 ⚡ Bolt: optimize ICU simple style parsing by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1136 🧪 Scout: Improve ICU placeholder name validation and test coverage by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1138 ⚡ Bolt: optimize ARB parser and marshaler by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1139 🧪 Scout: improve locale normalization unit tests by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1141 fix(crowdin): improve Screenshot and Distribution model parity by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1142 fix(web): parse CSV target locale column on translation import by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1137 feat(cat): isolate panel runtime errors with react-error-boundary by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1143 fix(cat): improve queue status a11y and cross-platform shortcuts by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1144 feat(cat): support Crowdin issue comments in CAT workspace by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1145 fix(cat): include maxLength in native CAT segment payload by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1147 fix(cat): pass approve flag for native translation saves by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1146 Correct Distribution validation for branch and directory IDs by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1152 🧪 Scout: improve ICU parser invariant test coverage by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1153 ⚡ Bolt: optimize Java properties comment formatting by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1151 fix(cat): render segment tags in queue rows by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1149 feat(cat): add native project comment support in CAT workspace by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1150 fix(web): enforce org job budget in agent translation tools by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1154 🧪 Scout: fix leading slash in CLI pathresolver by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1157 fix(crowdin): improve task list parity for creatorId and projectId by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1158 test(web): cover CSV import parsing edge cases by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1155 ⚡ Bolt: optimize placeholder and segment key generation by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1156 fix(web): route invitees to dashboard after accept, not onboarding by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1159 fix(web): unblock users stuck on invitation pending after WorkOS acceptance by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1160 feat(web): Crowdin PAT mode and fix WorkOS invite membership sync by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1161 feat(web): list projects and jobs from live TMS API with native/TMS sections by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1162 refactor(web): remove WORKOS_ENABLED env flag by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1163 feat(hyperlocalise-web): add Crowdin progress skill and agent tool by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1164 fix(web): pass Crowdin credential base URL to comment pusher client by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1165 fix(web): load native and TMS projects/jobs in parallel by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1166 fix(agent): use skill registry for Crowdin TMS queries in Slack by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1167 fix(crowdin): use per-user OAuth credentials for progress checks by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1169 fix(web): remove stale sync labels and fix external TMS open job count by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1170 feat(blog): add TMS-agnostic AI translation post for July 2026 by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1172 test(web): cover Crowdin progress file and string scopes by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1173 fix(web): use per-user Crowdin credentials for CAT concordance by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1175 feat(web): unify inbox chat with Slack agent skills by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1171 fix(integrations): show skeleton loader for action buttons while loading by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1177 ⚡ Bolt: optimize NormalizeList capacity hinting by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1174 fix(crowdin): fix Enterprise PAT flow and remove legacy org api_token by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1178 refactor(providers): replace providerSafeFetch with fetch by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1179 feat(agent): disambiguate multi-repo GitHub context in Hyperlocalise agent by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1176 perf(web): speed up external TMS project list and split overview data loading by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1180 perf(web): reduce TMS job fan-out and speed up jobs/files loading by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1181 perf(web): split CAT file load from per-segment detail fetching by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1182 fix(web): show only job files in CAT source file picker by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1184 feat(web): lazy-load TMS job detail tabs and projects section by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1183 test(web): cover project job loading helper by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1185 🧪 Scout: Capture ICU styles in message invariants by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1189 perf(crowdin): reduce TMS jobs list API fan-out by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1190 refactor(web): remove provider background sync pipeline by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1191 feat(web): rebuild workspace dashboard overview layout by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1192 update deps by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1193 fix(crowdin): fetch source strings by numeric id via Get String endpoint by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1194 feat(web): split CAT queue API and polish skeleton loading by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1195 perf(cat): split segment detail from comments and paginate queue by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1196 refactor(cat): reorganize into feature slices by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1197 refactor(cat): split cat-editor-panel into isolated sub-components by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1198 test(web): cover CAT queue and Crowdin progress gaps by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1199 fix(phrase): restore has_issues CAT queue filtering after lazy comment load by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1201 ⚡ Bolt: optimize default strategy initialization by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1200 feat(cat): MobX workspace store for CAT editor state by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1203 🧪 Scout: add unit tests for usage context helpers by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1202 fix(agents): stabilize due Contentful automation list test by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1205 feat(web): add MobX app shell store with substores by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1204 test(cat): add comprehensive CAT tool tests with API mocks by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1206 fix(deps): update go dependencies by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1208 chore(deps): update actions/checkout action to v7 by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1213 chore(deps): update actions/setup-go digest to 924ae3a by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1210 chore(deps): update goreleaser/goreleaser-action digest to f06c13b by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1211 chore(deps): update voidzero-dev/setup-vp digest to 13e7afb by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1212 feat(web): replace files preview with View strings action by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1207 fix(deps): update web dependencies by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1209 feat(cat): lazy load agent context by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1214 feat(web): migrate to Geist design system color tokens by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1215 fix(web): rename visual context label by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1216 refactor(app-shell): wire MobX shell hooks by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1217 fix(deps): update web dependencies by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1219 fix(cat): improve ICU highlight contrast with theme-aware color tokens by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1220 fix(cat): faster segment queue with lazy panel loading by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1218 ci(web): cache Next.js builds and add Vercel ignore by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1221 feat(automations): expand Storybook coverage for editor and templates by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1222 feat(blog): announce Slator Language AI 50 Under 50 selection by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1223 ci(web): ignore MSW handler files in Vercel uploads by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1226 fix(cat): restore lazy-loaded translations and Crowdin concordance locale by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1225 fix(cat): keep editor drafts out of queue pagination hydration by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1227 refactor(cat): separate concordance lookup from segment review by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1228 refactor(web): show source files as tree only by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1229 test(web): cover provider file branch routes by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1231 fix(crowdin): add internalCode to Language model for API parity by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1234 fix(cat): preserve unsaved edits across filter changes and target refetch by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1233 🧪 Scout: add TestParseASTSelectOrdinalWithOffset by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1235 feat(cat-validate): add segment validation service and profile rules by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1230 ⚡ Bolt: optimize Android XML parser and marshaler by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1232 feat(cat): validate segments with Go service by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1236 refactor(cat): compose MobX workspace domains by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1237 fix(web): set explicit height on Pierre file tree by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1239 test(app-shell): expand unit test coverage and edge cases by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1238 chore(deps): update actions/cache action to v6 by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1240 fix(deps): update module github.com/workos/workos-go/v7 to v9 by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1241 fix(web): restore job source file actions and CAT context lookup by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1242 feat(web): default job CAT to untranslated queue filter by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1244 fix(web): auto-open first job file in CAT workspace by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1245 feat(web): add fixture-auth e2e test foundation by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1243 feat(dashboard): improve workspace overview by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1246 feat(web): add projects UX utilities for avatars and recent tracking by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1247 fix(web): guard live TMS memory and glossary IDs from DB lookups by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1248 feat(web): select GitHub repo for chat context by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1249 fix(dashboard): color automation run status badges by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1252 feat(web): improve CAT header selectors by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1250 fix(web): track chat agent usage by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1251 feat(web): add zoomable lightbox for visual context screenshots by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1253 feat(web): localise integrations page components by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1254 feat(api): support TMS source file uploads via public files API by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1255 ⚡ Bolt: Optimize HTML tag parity checks by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1257 test(web): cover live provider resource access guards by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1256 feat(web): add Storybook stories for glossaries and translation memories pages by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1260 🧪 Scout: robustly extract related tokens with spaces by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1259 chore(deps): update golang docker tag to v1.26.4 by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1262 chore(deps): update voidzero-dev/setup-vp digest to 250f29c by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1261 feat(lokalise): add CAT workspace and live TMS APIs by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1258 fix(deps): update web dependencies by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1264 feat(web): add Storybook stories for integrations page by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1263 fix(web): fix github repo refresh + context for external tms by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1265 fix(deps): update go dependencies by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1266 chore(deps): update dependency typescript to v6 by @renovate[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1269 feat(cat): structure agent context output and chain AI recommendation by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1270 fix(web): improve project file browser capacity by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1271 feat(web): Smartling live CAT and Crowdin parity for web by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1274 refactor: tms oop classes by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1275 feat(marketing): replace changelog with recent blog posts on homepage by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1276 ⚡ Bolt: optimize segment profile validation by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1278 test(web): cover Smartling review pull by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1277 fix(cat): hide unsupported Smartling queue status filters by @cursor[bot] in https://github.com/hyperlocalise/hyperlocalise/pull/1279 🧪 Scout: improve newline parity and fix CRLF literal width by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1280 Improve Task and Source String upload parity by @cungminh2710 in https://github.com/hyperlocalise/hyperlocalise/pull/1281 Full Changelog: https://github.com/hyperlocalise/hyperlocalise/compare/v1...v1.8.18</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hyperlocalise/hyperlocalise">https://github.com/hyperlocalise/hyperlocalise</a></strong> to version <strong>v1.8.18</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hyperlocalise-ci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(web): redirect /dashboard via route handler by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1118">https://github.com/hyperlocalise/hyperlocalise/pull/1118</a></li>
<li>test(web): cover Contentful no-writeback failures by @cursor[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1120">https://github.com/hyperlocalise/hyperlocalise/pull/1120</a></li>
<li>⚡ Bolt: optimize XCStrings parser and marshaler by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1121">https://github.com/hyperlocalise/hyperlocalise/pull/1121</a></li>
<li>🧪 Scout: escape line feeds in CSV formula neutralization by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1123">https://github.com/hyperlocalise/hyperlocalise/pull/1123</a></li>
<li>fix(web): preserve workspace automation output summary on orchestrator finish by @cursor[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1122">https://github.com/hyperlocalise/hyperlocalise/pull/1122</a></li>
<li>fix(crowdin): add missing DateFrom to EnterpriseVendorTaskCreateForm and fix typos by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1124">https://github.com/hyperlocalise/hyperlocalise/pull/1124</a></li>
<li>feat(web): add per-file translation import for native TMS by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1125">https://github.com/hyperlocalise/hyperlocalise/pull/1125</a></li>
<li>update deps by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1126">https://github.com/hyperlocalise/hyperlocalise/pull/1126</a></li>
<li>🧪 Scout: fix PO parser continuation leakage by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1129">https://github.com/hyperlocalise/hyperlocalise/pull/1129</a></li>
<li>fix(crowdin): add URL field to Screenshot model for API parity by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1130">https://github.com/hyperlocalise/hyperlocalise/pull/1130</a></li>
<li>fix(web): rename billing AI usage label to AI Credit by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1131">https://github.com/hyperlocalise/hyperlocalise/pull/1131</a></li>
<li>fix(web): parse target locale when importing xcstrings translations by @cursor[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1128">https://github.com/hyperlocalise/hyperlocalise/pull/1128</a></li>
<li>chore: update deps by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1132">https://github.com/hyperlocalise/hyperlocalise/pull/1132</a></li>
<li>⚡ Bolt: optimize ICU parser via low-copy literal tracking by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1127">https://github.com/hyperlocalise/hyperlocalise/pull/1127</a></li>
<li>⚡ Bolt: Optimize CSV parser and marshaler with capacity hints by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1133">https://github.com/hyperlocalise/hyperlocalise/pull/1133</a></li>
<li>🧪 Scout: add regression tests for ICU pound summation in sibling blocks by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1135">https://github.com/hyperlocalise/hyperlocalise/pull/1135</a></li>
<li>fix(web): fail Contentful idempotent retry when prior run wrote no drafts by @cursor[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1134">https://github.com/hyperlocalise/hyperlocalise/pull/1134</a></li>
<li>⚡ Bolt: optimize ICU simple style parsing by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1136">https://github.com/hyperlocalise/hyperlocalise/pull/1136</a></li>
<li>🧪 Scout: Improve ICU placeholder name validation and test coverage by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1138">https://github.com/hyperlocalise/hyperlocalise/pull/1138</a></li>
<li>⚡ Bolt: optimize ARB parser and marshaler by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1139">https://github.com/hyperlocalise/hyperlocalise/pull/1139</a></li>
<li>🧪 Scout: improve locale normalization unit tests by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1141">https://github.com/hyperlocalise/hyperlocalise/pull/1141</a></li>
<li>fix(crowdin): improve Screenshot and Distribution model parity by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1142">https://github.com/hyperlocalise/hyperlocalise/pull/1142</a></li>
<li>fix(web): parse CSV target locale column on translation import by @cursor[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1137">https://github.com/hyperlocalise/hyperlocalise/pull/1137</a></li>
<li>feat(cat): isolate panel runtime errors with react-error-boundary by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1143">https://github.com/hyperlocalise/hyperlocalise/pull/1143</a></li>
<li>fix(cat): improve queue status a11y and cross-platform shortcuts by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1144">https://github.com/hyperlocalise/hyperlocalise/pull/1144</a></li>
<li>feat(cat): support Crowdin issue comments in CAT workspace by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1145">https://github.com/hyperlocalise/hyperlocalise/pull/1145</a></li>
<li>fix(cat): include maxLength in native CAT segment payload by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1147">https://github.com/hyperlocalise/hyperlocalise/pull/1147</a></li>
<li>fix(cat): pass approve flag for native translation saves by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1146">https://github.com/hyperlocalise/hyperlocalise/pull/1146</a></li>
<li>Correct Distribution validation for branch and directory IDs by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1152">https://github.com/hyperlocalise/hyperlocalise/pull/1152</a></li>
<li>🧪 Scout: improve ICU parser invariant test coverage by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1153">https://github.com/hyperlocalise/hyperlocalise/pull/1153</a></li>
<li>⚡ Bolt: optimize Java properties comment formatting by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1151">https://github.com/hyperlocalise/hyperlocalise/pull/1151</a></li>
<li>fix(cat): render segment tags in queue rows by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1149">https://github.com/hyperlocalise/hyperlocalise/pull/1149</a></li>
<li>feat(cat): add native project comment support in CAT workspace by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1150">https://github.com/hyperlocalise/hyperlocalise/pull/1150</a></li>
<li>fix(web): enforce org job budget in agent translation tools by @cursor[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1154">https://github.com/hyperlocalise/hyperlocalise/pull/1154</a></li>
<li>🧪 Scout: fix leading slash in CLI pathresolver by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1157">https://github.com/hyperlocalise/hyperlocalise/pull/1157</a></li>
<li>fix(crowdin): improve task list parity for creatorId and projectId by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1158">https://github.com/hyperlocalise/hyperlocalise/pull/1158</a></li>
<li>test(web): cover CSV import parsing edge cases by @cursor[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1155">https://github.com/hyperlocalise/hyperlocalise/pull/1155</a></li>
<li>⚡ Bolt: optimize placeholder and segment key generation by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1156">https://github.com/hyperlocalise/hyperlocalise/pull/1156</a></li>
<li>fix(web): route invitees to dashboard after accept, not onboarding by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1159">https://github.com/hyperlocalise/hyperlocalise/pull/1159</a></li>
<li>fix(web): unblock users stuck on invitation pending after WorkOS acceptance by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1160">https://github.com/hyperlocalise/hyperlocalise/pull/1160</a></li>
<li>feat(web): Crowdin PAT mode and fix WorkOS invite membership sync by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1161">https://github.com/hyperlocalise/hyperlocalise/pull/1161</a></li>
<li>feat(web): list projects and jobs from live TMS API with native/TMS sections by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1162">https://github.com/hyperlocalise/hyperlocalise/pull/1162</a></li>
<li>refactor(web): remove WORKOS_ENABLED env flag by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1163">https://github.com/hyperlocalise/hyperlocalise/pull/1163</a></li>
<li>feat(hyperlocalise-web): add Crowdin progress skill and agent tool by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1164">https://github.com/hyperlocalise/hyperlocalise/pull/1164</a></li>
<li>fix(web): pass Crowdin credential base URL to comment pusher client by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1165">https://github.com/hyperlocalise/hyperlocalise/pull/1165</a></li>
<li>fix(web): load native and TMS projects/jobs in parallel by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1166">https://github.com/hyperlocalise/hyperlocalise/pull/1166</a></li>
<li>fix(agent): use skill registry for Crowdin TMS queries in Slack by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1167">https://github.com/hyperlocalise/hyperlocalise/pull/1167</a></li>
<li>fix(crowdin): use per-user OAuth credentials for progress checks by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1169">https://github.com/hyperlocalise/hyperlocalise/pull/1169</a></li>
<li>fix(web): remove stale sync labels and fix external TMS open job count by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1170">https://github.com/hyperlocalise/hyperlocalise/pull/1170</a></li>
<li>feat(blog): add TMS-agnostic AI translation post for July 2026 by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1172">https://github.com/hyperlocalise/hyperlocalise/pull/1172</a></li>
<li>test(web): cover Crowdin progress file and string scopes by @cursor[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1173">https://github.com/hyperlocalise/hyperlocalise/pull/1173</a></li>
<li>fix(web): use per-user Crowdin credentials for CAT concordance by @cursor[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1175">https://github.com/hyperlocalise/hyperlocalise/pull/1175</a></li>
<li>feat(web): unify inbox chat with Slack agent skills by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1171">https://github.com/hyperlocalise/hyperlocalise/pull/1171</a></li>
<li>fix(integrations): show skeleton loader for action buttons while loading by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1177">https://github.com/hyperlocalise/hyperlocalise/pull/1177</a></li>
<li>⚡ Bolt: optimize NormalizeList capacity hinting by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1174">https://github.com/hyperlocalise/hyperlocalise/pull/1174</a></li>
<li>fix(crowdin): fix Enterprise PAT flow and remove legacy org api_token by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1178">https://github.com/hyperlocalise/hyperlocalise/pull/1178</a></li>
<li>refactor(providers): replace providerSafeFetch with fetch by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1179">https://github.com/hyperlocalise/hyperlocalise/pull/1179</a></li>
<li>feat(agent): disambiguate multi-repo GitHub context in Hyperlocalise agent by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1176">https://github.com/hyperlocalise/hyperlocalise/pull/1176</a></li>
<li>perf(web): speed up external TMS project list and split overview data loading by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1180">https://github.com/hyperlocalise/hyperlocalise/pull/1180</a></li>
<li>perf(web): reduce TMS job fan-out and speed up jobs/files loading by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1181">https://github.com/hyperlocalise/hyperlocalise/pull/1181</a></li>
<li>perf(web): split CAT file load from per-segment detail fetching by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1182">https://github.com/hyperlocalise/hyperlocalise/pull/1182</a></li>
<li>fix(web): show only job files in CAT source file picker by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1184">https://github.com/hyperlocalise/hyperlocalise/pull/1184</a></li>
<li>feat(web): lazy-load TMS job detail tabs and projects section by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1183">https://github.com/hyperlocalise/hyperlocalise/pull/1183</a></li>
<li>test(web): cover project job loading helper by @cursor[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1185">https://github.com/hyperlocalise/hyperlocalise/pull/1185</a></li>
<li>🧪 Scout: Capture ICU styles in message invariants by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1189">https://github.com/hyperlocalise/hyperlocalise/pull/1189</a></li>
<li>perf(crowdin): reduce TMS jobs list API fan-out by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1190">https://github.com/hyperlocalise/hyperlocalise/pull/1190</a></li>
<li>refactor(web): remove provider background sync pipeline by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1191">https://github.com/hyperlocalise/hyperlocalise/pull/1191</a></li>
<li>feat(web): rebuild workspace dashboard overview layout by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1192">https://github.com/hyperlocalise/hyperlocalise/pull/1192</a></li>
<li>update deps by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1193">https://github.com/hyperlocalise/hyperlocalise/pull/1193</a></li>
<li>fix(crowdin): fetch source strings by numeric id via Get String endpoint by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1194">https://github.com/hyperlocalise/hyperlocalise/pull/1194</a></li>
<li>feat(web): split CAT queue API and polish skeleton loading by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1195">https://github.com/hyperlocalise/hyperlocalise/pull/1195</a></li>
<li>perf(cat): split segment detail from comments and paginate queue by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1196">https://github.com/hyperlocalise/hyperlocalise/pull/1196</a></li>
<li>refactor(cat): reorganize into feature slices by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1197">https://github.com/hyperlocalise/hyperlocalise/pull/1197</a></li>
<li>refactor(cat): split cat-editor-panel into isolated sub-components by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1198">https://github.com/hyperlocalise/hyperlocalise/pull/1198</a></li>
<li>test(web): cover CAT queue and Crowdin progress gaps by @cursor[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1199">https://github.com/hyperlocalise/hyperlocalise/pull/1199</a></li>
<li>fix(phrase): restore has_issues CAT queue filtering after lazy comment load by @cursor[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1201">https://github.com/hyperlocalise/hyperlocalise/pull/1201</a></li>
<li>⚡ Bolt: optimize default strategy initialization by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1200">https://github.com/hyperlocalise/hyperlocalise/pull/1200</a></li>
<li>feat(cat): MobX workspace store for CAT editor state by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1203">https://github.com/hyperlocalise/hyperlocalise/pull/1203</a></li>
<li>🧪 Scout: add unit tests for usage context helpers by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1202">https://github.com/hyperlocalise/hyperlocalise/pull/1202</a></li>
<li>fix(agents): stabilize due Contentful automation list test by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1205">https://github.com/hyperlocalise/hyperlocalise/pull/1205</a></li>
<li>feat(web): add MobX app shell store with substores by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1204">https://github.com/hyperlocalise/hyperlocalise/pull/1204</a></li>
<li>test(cat): add comprehensive CAT tool tests with API mocks by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1206">https://github.com/hyperlocalise/hyperlocalise/pull/1206</a></li>
<li>fix(deps): update go dependencies by @renovate[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1208">https://github.com/hyperlocalise/hyperlocalise/pull/1208</a></li>
<li>chore(deps): update actions/checkout action to v7 by @renovate[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1213">https://github.com/hyperlocalise/hyperlocalise/pull/1213</a></li>
<li>chore(deps): update actions/setup-go digest to 924ae3a by @renovate[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1210">https://github.com/hyperlocalise/hyperlocalise/pull/1210</a></li>
<li>chore(deps): update goreleaser/goreleaser-action digest to f06c13b by @renovate[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1211">https://github.com/hyperlocalise/hyperlocalise/pull/1211</a></li>
<li>chore(deps): update voidzero-dev/setup-vp digest to 13e7afb by @renovate[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1212">https://github.com/hyperlocalise/hyperlocalise/pull/1212</a></li>
<li>feat(web): replace files preview with View strings action by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1207">https://github.com/hyperlocalise/hyperlocalise/pull/1207</a></li>
<li>fix(deps): update web dependencies by @renovate[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1209">https://github.com/hyperlocalise/hyperlocalise/pull/1209</a></li>
<li>feat(cat): lazy load agent context by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1214">https://github.com/hyperlocalise/hyperlocalise/pull/1214</a></li>
<li>feat(web): migrate to Geist design system color tokens by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1215">https://github.com/hyperlocalise/hyperlocalise/pull/1215</a></li>
<li>fix(web): rename visual context label by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1216">https://github.com/hyperlocalise/hyperlocalise/pull/1216</a></li>
<li>refactor(app-shell): wire MobX shell hooks by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1217">https://github.com/hyperlocalise/hyperlocalise/pull/1217</a></li>
<li>fix(deps): update web dependencies by @renovate[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1219">https://github.com/hyperlocalise/hyperlocalise/pull/1219</a></li>
<li>fix(cat): improve ICU highlight contrast with theme-aware color tokens by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1220">https://github.com/hyperlocalise/hyperlocalise/pull/1220</a></li>
<li>fix(cat): faster segment queue with lazy panel loading by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1218">https://github.com/hyperlocalise/hyperlocalise/pull/1218</a></li>
<li>ci(web): cache Next.js builds and add Vercel ignore by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1221">https://github.com/hyperlocalise/hyperlocalise/pull/1221</a></li>
<li>feat(automations): expand Storybook coverage for editor and templates by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1222">https://github.com/hyperlocalise/hyperlocalise/pull/1222</a></li>
<li>feat(blog): announce Slator Language AI 50 Under 50 selection by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1223">https://github.com/hyperlocalise/hyperlocalise/pull/1223</a></li>
<li>ci(web): ignore MSW handler files in Vercel uploads by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1226">https://github.com/hyperlocalise/hyperlocalise/pull/1226</a></li>
<li>fix(cat): restore lazy-loaded translations and Crowdin concordance locale by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1225">https://github.com/hyperlocalise/hyperlocalise/pull/1225</a></li>
<li>fix(cat): keep editor drafts out of queue pagination hydration by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1227">https://github.com/hyperlocalise/hyperlocalise/pull/1227</a></li>
<li>refactor(cat): separate concordance lookup from segment review by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1228">https://github.com/hyperlocalise/hyperlocalise/pull/1228</a></li>
<li>refactor(web): show source files as tree only by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1229">https://github.com/hyperlocalise/hyperlocalise/pull/1229</a></li>
<li>test(web): cover provider file branch routes by @cursor[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1231">https://github.com/hyperlocalise/hyperlocalise/pull/1231</a></li>
<li>fix(crowdin): add internalCode to Language model for API parity by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1234">https://github.com/hyperlocalise/hyperlocalise/pull/1234</a></li>
<li>fix(cat): preserve unsaved edits across filter changes and target refetch by @cursor[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1233">https://github.com/hyperlocalise/hyperlocalise/pull/1233</a></li>
<li>🧪 Scout: add TestParseASTSelectOrdinalWithOffset by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1235">https://github.com/hyperlocalise/hyperlocalise/pull/1235</a></li>
<li>feat(cat-validate): add segment validation service and profile rules by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1230">https://github.com/hyperlocalise/hyperlocalise/pull/1230</a></li>
<li>⚡ Bolt: optimize Android XML parser and marshaler by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1232">https://github.com/hyperlocalise/hyperlocalise/pull/1232</a></li>
<li>feat(cat): validate segments with Go service by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1236">https://github.com/hyperlocalise/hyperlocalise/pull/1236</a></li>
<li>refactor(cat): compose MobX workspace domains by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1237">https://github.com/hyperlocalise/hyperlocalise/pull/1237</a></li>
<li>fix(web): set explicit height on Pierre file tree by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1239">https://github.com/hyperlocalise/hyperlocalise/pull/1239</a></li>
<li>test(app-shell): expand unit test coverage and edge cases by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1238">https://github.com/hyperlocalise/hyperlocalise/pull/1238</a></li>
<li>chore(deps): update actions/cache action to v6 by @renovate[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1240">https://github.com/hyperlocalise/hyperlocalise/pull/1240</a></li>
<li>fix(deps): update module github.com/workos/workos-go/v7 to v9 by @renovate[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1241">https://github.com/hyperlocalise/hyperlocalise/pull/1241</a></li>
<li>fix(web): restore job source file actions and CAT context lookup by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1242">https://github.com/hyperlocalise/hyperlocalise/pull/1242</a></li>
<li>feat(web): default job CAT to untranslated queue filter by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1244">https://github.com/hyperlocalise/hyperlocalise/pull/1244</a></li>
<li>fix(web): auto-open first job file in CAT workspace by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1245">https://github.com/hyperlocalise/hyperlocalise/pull/1245</a></li>
<li>feat(web): add fixture-auth e2e test foundation by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1243">https://github.com/hyperlocalise/hyperlocalise/pull/1243</a></li>
<li>feat(dashboard): improve workspace overview by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1246">https://github.com/hyperlocalise/hyperlocalise/pull/1246</a></li>
<li>feat(web): add projects UX utilities for avatars and recent tracking by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1247">https://github.com/hyperlocalise/hyperlocalise/pull/1247</a></li>
<li>fix(web): guard live TMS memory and glossary IDs from DB lookups by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1248">https://github.com/hyperlocalise/hyperlocalise/pull/1248</a></li>
<li>feat(web): select GitHub repo for chat context by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1249">https://github.com/hyperlocalise/hyperlocalise/pull/1249</a></li>
<li>fix(dashboard): color automation run status badges by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1252">https://github.com/hyperlocalise/hyperlocalise/pull/1252</a></li>
<li>feat(web): improve CAT header selectors by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1250">https://github.com/hyperlocalise/hyperlocalise/pull/1250</a></li>
<li>fix(web): track chat agent usage by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1251">https://github.com/hyperlocalise/hyperlocalise/pull/1251</a></li>
<li>feat(web): add zoomable lightbox for visual context screenshots by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1253">https://github.com/hyperlocalise/hyperlocalise/pull/1253</a></li>
<li>feat(web): localise integrations page components by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1254">https://github.com/hyperlocalise/hyperlocalise/pull/1254</a></li>
<li>feat(api): support TMS source file uploads via public files API by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1255">https://github.com/hyperlocalise/hyperlocalise/pull/1255</a></li>
<li>⚡ Bolt: Optimize HTML tag parity checks by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1257">https://github.com/hyperlocalise/hyperlocalise/pull/1257</a></li>
<li>test(web): cover live provider resource access guards by @cursor[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1256">https://github.com/hyperlocalise/hyperlocalise/pull/1256</a></li>
<li>feat(web): add Storybook stories for glossaries and translation memories pages by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1260">https://github.com/hyperlocalise/hyperlocalise/pull/1260</a></li>
<li>🧪 Scout: robustly extract related tokens with spaces by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1259">https://github.com/hyperlocalise/hyperlocalise/pull/1259</a></li>
<li>chore(deps): update golang docker tag to v1.26.4 by @renovate[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1262">https://github.com/hyperlocalise/hyperlocalise/pull/1262</a></li>
<li>chore(deps): update voidzero-dev/setup-vp digest to 250f29c by @renovate[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1261">https://github.com/hyperlocalise/hyperlocalise/pull/1261</a></li>
<li>feat(lokalise): add CAT workspace and live TMS APIs by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1258">https://github.com/hyperlocalise/hyperlocalise/pull/1258</a></li>
<li>fix(deps): update web dependencies by @renovate[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1264">https://github.com/hyperlocalise/hyperlocalise/pull/1264</a></li>
<li>feat(web): add Storybook stories for integrations page by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1263">https://github.com/hyperlocalise/hyperlocalise/pull/1263</a></li>
<li>fix(web): fix github repo refresh + context for external tms by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1265">https://github.com/hyperlocalise/hyperlocalise/pull/1265</a></li>
<li>fix(deps): update go dependencies by @renovate[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1266">https://github.com/hyperlocalise/hyperlocalise/pull/1266</a></li>
<li>chore(deps): update dependency typescript to v6 by @renovate[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1269">https://github.com/hyperlocalise/hyperlocalise/pull/1269</a></li>
<li>feat(cat): structure agent context output and chain AI recommendation by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1270">https://github.com/hyperlocalise/hyperlocalise/pull/1270</a></li>
<li>fix(web): improve project file browser capacity by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1271">https://github.com/hyperlocalise/hyperlocalise/pull/1271</a></li>
<li>feat(web): Smartling live CAT and Crowdin parity for web by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1274">https://github.com/hyperlocalise/hyperlocalise/pull/1274</a></li>
<li>refactor: tms oop classes by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1275">https://github.com/hyperlocalise/hyperlocalise/pull/1275</a></li>
<li>feat(marketing): replace changelog with recent blog posts on homepage by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1276">https://github.com/hyperlocalise/hyperlocalise/pull/1276</a></li>
<li>⚡ Bolt: optimize segment profile validation by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1278">https://github.com/hyperlocalise/hyperlocalise/pull/1278</a></li>
<li>test(web): cover Smartling review pull by @cursor[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1277">https://github.com/hyperlocalise/hyperlocalise/pull/1277</a></li>
<li>fix(cat): hide unsupported Smartling queue status filters by @cursor[bot] in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1279">https://github.com/hyperlocalise/hyperlocalise/pull/1279</a></li>
<li>🧪 Scout: improve newline parity and fix CRLF literal width by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1280">https://github.com/hyperlocalise/hyperlocalise/pull/1280</a></li>
<li>Improve Task and Source String upload parity by @cungminh2710 in <a href="https://github.com/hyperlocalise/hyperlocalise/pull/1281">https://github.com/hyperlocalise/hyperlocalise/pull/1281</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hyperlocalise/hyperlocalise/compare/v1...v1.8.18">https://github.com/hyperlocalise/hyperlocalise/compare/v1...v1.8.18</a></p>
]]></content:encoded></item><item><title>JFrog Boost</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/jfrog-boost/</link><pubDate>Tue, 07 Jul 2026 05:20:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/jfrog-boost/</guid><description>Version updated for https://github.com/jfrog/boost to version v0.8.6.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 2 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Release v0.7.23 by @yahav-ohana in https://github.com/jfrog/boost/pull/41 Release v0.7.25 by @menachemm-byte in https://github.com/jfrog/boost/pull/44 New Contributors @menachemm-byte made their first contribution in https://github.com/jfrog/boost/pull/44 Full Changelog: https://github.com/jfrog/boost/compare/v0.7.23...v0.8.6</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jfrog/boost">https://github.com/jfrog/boost</a></strong> to version <strong>v0.8.6</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>2</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jfrog-boost">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Release v0.7.23 by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/41">https://github.com/jfrog/boost/pull/41</a></li>
<li>Release v0.7.25 by @menachemm-byte in <a href="https://github.com/jfrog/boost/pull/44">https://github.com/jfrog/boost/pull/44</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@menachemm-byte made their first contribution in <a href="https://github.com/jfrog/boost/pull/44">https://github.com/jfrog/boost/pull/44</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jfrog/boost/compare/v0.7.23...v0.8.6">https://github.com/jfrog/boost/compare/v0.7.23...v0.8.6</a></p>
]]></content:encoded></item><item><title>Suricata Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/suricata-check/</link><pubDate>Tue, 07 Jul 2026 05:20:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/suricata-check/</guid><description>Version updated for https://github.com/Koen1999/suricata-check-action to version v1.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/Koen1999/suricata-check-action/compare/v1.0...v1.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Koen1999/suricata-check-action">https://github.com/Koen1999/suricata-check-action</a></strong> to version <strong>v1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/suricata-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Koen1999/suricata-check-action/compare/v1.0...v1.1">https://github.com/Koen1999/suricata-check-action/compare/v1.0...v1.1</a></p>
]]></content:encoded></item><item><title>Relivio Deploy Monitor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/relivio-deploy-monitor/</link><pubDate>Tue, 07 Jul 2026 05:19:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/relivio-deploy-monitor/</guid><description>Version updated for https://github.com/lazypl82/deploy-monitor-action to version v1.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Marketplace description updated to reflect the post-deploy verdict flow: tell Relivio a deploy went out, it watches the next 15 minutes and returns a STABLE / WATCH / RISK verdict. No change to action inputs or runtime behavior.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lazypl82/deploy-monitor-action">https://github.com/lazypl82/deploy-monitor-action</a></strong> to version <strong>v1.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/relivio-deploy-monitor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Marketplace description updated to reflect the post-deploy verdict flow: tell Relivio a deploy went out, it watches the next 15 minutes and returns a STABLE / WATCH / RISK verdict. No change to action inputs or runtime behavior.</p>
]]></content:encoded></item><item><title>EIS — Upload Signals</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/eis-upload-signals/</link><pubDate>Tue, 07 Jul 2026 05:19:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/eis-upload-signals/</guid><description>Version updated for https://github.com/machuz/eis to version v2.27.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog 6a7c9734bbbd83d4d1dbc6fd54858197c216d638 feat(analyze): threshold-gated streaming log ingest for giant repos (#344) eecb83e7b84ef79c42925a4fa58ef11b9e70fbc8 fix(debt): honor file-exclusion patterns (#350) 6fa00de5a585d84e3258155c5f8edf303d617aac fix(timeline): deterministic, cache-independent blame assembly (#349) 765f8a40e344317e6b7c278c014e7ca2c8a2da02 perf(analyze): memoize file-exclusion glob matching (#346) 616a28e61896723a48d88504321fe33b9641b936 perf(analyze): parallelize debt blames and auto-scale workers (~2.3x) (#345) 68096926c408c0e849a296215a68811c5f24cb78 perf(timeline): auto period-concurrency when unset (#348) eb8a0c31cba4ef67e856f2ad0e599c9ec20c9cd9 perf(timeline): enable blame cache + auto-workers; make output deterministic (#347)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/machuz/eis">https://github.com/machuz/eis</a></strong> to version <strong>v2.27.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/eis-upload-signals">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>6a7c9734bbbd83d4d1dbc6fd54858197c216d638 feat(analyze): threshold-gated streaming log ingest for giant repos (#344)</li>
<li>eecb83e7b84ef79c42925a4fa58ef11b9e70fbc8 fix(debt): honor file-exclusion patterns (#350)</li>
<li>6fa00de5a585d84e3258155c5f8edf303d617aac fix(timeline): deterministic, cache-independent blame assembly (#349)</li>
<li>765f8a40e344317e6b7c278c014e7ca2c8a2da02 perf(analyze): memoize file-exclusion glob matching (#346)</li>
<li>616a28e61896723a48d88504321fe33b9641b936 perf(analyze): parallelize debt blames and auto-scale workers (~2.3x) (#345)</li>
<li>68096926c408c0e849a296215a68811c5f24cb78 perf(timeline): auto period-concurrency when unset (#348)</li>
<li>eb8a0c31cba4ef67e856f2ad0e599c9ec20c9cd9 perf(timeline): enable blame cache + auto-workers; make output deterministic (#347)</li>
</ul>
]]></content:encoded></item><item><title>Sentrik Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/sentrik-gate/</link><pubDate>Tue, 07 Jul 2026 05:18:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/sentrik-gate/</guid><description>Version updated for https://github.com/maxgerhardson/sentrik-community to version v1.7.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v1.7.0 sentrik deadlines — regulatory enforcement countdown for your enabled packs: EU AI Act (post-omnibus timeline), EU Cyber Resilience Act, CMMC 2.0, PCI DSS, ISO 27001, FDA §524B (--all, --past, --json) Anonymous usage telemetry (opt-out) — one daily ping: random id, version, OS, Python version, command name. Nothing else, ever. First-run notice, full disclosure at https://docs.sentrik.dev/telemetry/ — disable with SENTRIK_TELEMETRY=0 or telemetry_enabled: false Complete binary data files — sentrik dashboard, the auditor portal, and CVE function-level reachability now work from the standalone binary (previously wheel-only) First-run output fixes — severity labels render correctly; findings table no longer collapses in narrow/CI terminals Includes all v1.6.0 fixes (working Linux binary, npm wrapper error handling) Install: npm install -g sentrik or pip install sentrik</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/maxgerhardson/sentrik-community">https://github.com/maxgerhardson/sentrik-community</a></strong> to version <strong>v1.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sentrik-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v170">v1.7.0</h2>
<ul>
<li><strong><code>sentrik deadlines</code></strong> — regulatory enforcement countdown for your enabled packs: EU AI Act (post-omnibus timeline), EU Cyber Resilience Act, CMMC 2.0, PCI DSS, ISO 27001, FDA §524B (<code>--all</code>, <code>--past</code>, <code>--json</code>)</li>
<li><strong>Anonymous usage telemetry</strong> (opt-out) — one daily ping: random id, version, OS, Python version, command name. Nothing else, ever. First-run notice, full disclosure at <a href="https://docs.sentrik.dev/telemetry/">https://docs.sentrik.dev/telemetry/</a> — disable with <code>SENTRIK_TELEMETRY=0</code> or <code>telemetry_enabled: false</code></li>
<li><strong>Complete binary data files</strong> — <code>sentrik dashboard</code>, the auditor portal, and CVE function-level reachability now work from the standalone binary (previously wheel-only)</li>
<li><strong>First-run output fixes</strong> — severity labels render correctly; findings table no longer collapses in narrow/CI terminals</li>
<li>Includes all v1.6.0 fixes (working Linux binary, npm wrapper error handling)</li>
</ul>
<p>Install: <code>npm install -g sentrik</code> or <code>pip install sentrik</code></p>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/totem-shield/</link><pubDate>Tue, 07 Jul 2026 05:18:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.90.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Cohort-link bump (no direct package changes). See .changeset/config.json for the fixed-cohort definition.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.90.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>Falsifying Swarm Orchestrator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/falsifying-swarm-orchestrator/</link><pubDate>Tue, 07 Jul 2026 05:17:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/falsifying-swarm-orchestrator/</guid><description>Version updated for https://github.com/moonrunnerkc/swarm-orchestrator to version v12.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v12.1.0: autonomous-merge trust layer (built, not yet lit) This release adds the two-sided merge-trust layer and its evidence and measurement machinery on top of the v12.0.0 proof tier. It is additive and backward-compatible: no public API was removed, no existing flag changed behavior. Nothing auto-merges yet. The honest state is a gate that is built, measured, and deliberately dark until the numbers earn it.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/moonrunnerkc/swarm-orchestrator">https://github.com/moonrunnerkc/swarm-orchestrator</a></strong> to version <strong>v12.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/falsifying-swarm-orchestrator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v1210-autonomous-merge-trust-layer-built-not-yet-lit">v12.1.0: autonomous-merge trust layer (built, not yet lit)</h2>
<p>This release adds the two-sided merge-trust layer and its evidence and
measurement machinery on top of the v12.0.0 proof tier. It is additive and
backward-compatible: no public API was removed, no existing flag changed
behavior. Nothing auto-merges yet. The honest state is a gate that is built,
measured, and deliberately dark until the numbers earn it.</p>
<h3 id="positive-merge-safety-gate-phase-1">Positive merge-safety gate (Phase 1)</h3>
<p><code>swarm audit --pr &lt;ref&gt; --merge-gate</code> provisions the merged tree and runs a
positive gate over the existing <code>verifyObligation</code> path (build, test, declared
obligations, and a falsifier control when adapters are configured), then composes
a two-sided verdict: <code>AUTO-MERGE</code> only when the negative cheat gate is clean AND
the positive gate is all-green with no null controls AND the PR is on an
execution-groundable language. Everything else routes to <code>HUMAN</code> with a recorded
reason. Fail-closed by construction: a control that could not run is
<code>unavailable</code> (not proven), never a pass. The flag surfaces the verdict; it does
not itself merge and does not change the audit exit code.</p>
<h3 id="pytest-and-go-execution-grounded-runners-phase-2">pytest and Go execution-grounded runners (Phase 2)</h3>
<p>The execution-grounded sandbox now recognizes pytest and Go behind the
<code>TestRunner</code> seam. Re-measured EG-viability over the 197-PR outcome-labeled
corpus went from 12/197 to <strong>78/197</strong> (12 Node, 52 Python, 14 Go). The runners
are proven end to end on committed fixtures and real <code>python3 -m pytest</code> /
<code>go test</code> runs. Honest boundary: screen-viable is not yet proof-tier
provisionable. The sandbox dependency-install path is still Node package
managers only, so the 66 new pytest/Go PRs are recognized but not yet
provisioned; <code>provisionableCount</code> (12) is recorded distinctly from <code>viableCount</code>
(78).</p>
<h3 id="evidence-packs-phase-3">Evidence packs (Phase 3)</h3>
<p><code>swarm audit --pr &lt;ref&gt; --evidence-pack &lt;dir&gt;</code> writes a self-contained,
re-verifiable directory: two AIBOMs (CycloneDX 1.6 ML-BOM, SPDX 3.0 AI-Profile),
the raw execution-grounded evidence content-addressed by sha256, a <code>MANIFEST.json</code>
integrity index, and the per-run ledger. The AIBOMs are replay-identical: a
version-5 serialNumber derived from the run inputs and a <code>SOURCE_DATE_EPOCH</code>
-honoring timestamp (no fabricated wall-clock), so two audits of the same PR head
produce byte-identical attestations. The new <code>pr-audit-work-verified</code> ledger kind
records the positive-gate verdict. Honest boundary: the run ledger has real
timestamps and a random runId, so it is not claimed as reproducible and is
excluded from the MANIFEST; its integrity is its own hash chain and its sha is
pinned in a <code>run-record.json</code> sidecar. Cryptographic signing (DSSE, in-toto,
sigstore) is flagged as an out-of-scope follow-on: the pack is integrity-pinned
but not signed.</p>
<h3 id="corroborated-gate-measurement-loop-phase-4">Corroborated-gate measurement loop (Phase 4)</h3>
<p>The corroborated structural gate (a structural cheat finding backed by a
surviving mutant, coverage gap, or still-failing repro on the same line) now has
a readiness measurement over real merged-PR outcomes. It lights up only when the
Wilson-95 lower bound of its precision clears 0.90 with at least 5 true
positives, and is fail-closed on undefined n: a slice with no outcome-bad PR has
no positive class and can never be reported ready. Measured result on the current
corpus: <strong>undefined-n</strong>. The 12 provisionable PRs are all outcome-clean, and the
8 outcome-bad EG-viable PRs are all pytest (no install path yet), so the gate
stays advisory. A CI guard recomputes the artifact and refuses any <code>ready</code>
verdict on undefined n or below the floor.</p>
<h3 id="baseline-and-honesty-gates-phase-0">Baseline and honesty gates (Phase 0)</h3>
<p>The v12 ground truth (oracle recall 301/325, real-corpus precision 0.217 with a
Wilson lower bound of 0.097, EG-viable 78/197) is frozen as code constants with a
committed reference mirror, and a CI guard fails any change that regresses a floor
or hand-edits the floors out of step with the constants.</p>
<h3 id="verification">Verification</h3>
<ul>
<li>Full suite 2064 passing, 0 failing.</li>
<li>Four CI policy guards hold: baseline, promotions (gate-eligible 0), block
eligibility (block-eligible 8), corroborated-gate (undefined-n).</li>
<li>No breaking changes since v12.0.0.</li>
</ul>
<p><strong>Full changelog:</strong> <a href="https://github.com/moonrunnerkc/swarm-orchestrator/compare/v12.0.0...v12.1.0">https://github.com/moonrunnerkc/swarm-orchestrator/compare/v12.0.0...v12.1.0</a></p>
]]></content:encoded></item><item><title>Suppress Ratchet</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/suppress-ratchet/</link><pubDate>Tue, 07 Jul 2026 05:17:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/suppress-ratchet/</guid><description>Version updated for https://github.com/motchalini-llc/suppress-ratchet to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Docs-only release — no behavior change (gate.sh untouched).
README: embed demo GIF + link the live demo PR (motchalini-llc/ratchet-demo#1, one “quick fix” that trips all three gates) Refreshes the Marketplace listing with the new README</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/motchalini-llc/suppress-ratchet">https://github.com/motchalini-llc/suppress-ratchet</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/suppress-ratchet">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Docs-only release — no behavior change (gate.sh untouched).</p>
<ul>
<li>README: embed demo GIF + link the live demo PR (motchalini-llc/ratchet-demo#1, one &ldquo;quick fix&rdquo; that trips all three gates)</li>
<li>Refreshes the Marketplace listing with the new README</li>
</ul>
]]></content:encoded></item><item><title>Test Ratchet</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/test-ratchet/</link><pubDate>Tue, 07 Jul 2026 05:16:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/test-ratchet/</guid><description>Version updated for https://github.com/motchalini-llc/test-ratchet to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Docs-only release — no behavior change (gate.sh untouched).
README: embed demo GIF + link the live demo PR (motchalini-llc/ratchet-demo#1, one “quick fix” that trips all three gates) Refreshes the Marketplace listing with the new README</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/motchalini-llc/test-ratchet">https://github.com/motchalini-llc/test-ratchet</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/test-ratchet">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Docs-only release — no behavior change (gate.sh untouched).</p>
<ul>
<li>README: embed demo GIF + link the live demo PR (motchalini-llc/ratchet-demo#1, one &ldquo;quick fix&rdquo; that trips all three gates)</li>
<li>Refreshes the Marketplace listing with the new README</li>
</ul>
]]></content:encoded></item><item><title>Type Ratchet</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/type-ratchet/</link><pubDate>Tue, 07 Jul 2026 05:15:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/type-ratchet/</guid><description>Version updated for https://github.com/motchalini-llc/type-ratchet to version v1.1.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Docs-only release — no behavior change (gate.sh untouched).
README: embed demo GIF + link the live demo PR (motchalini-llc/ratchet-demo#1, one “quick fix” that trips all three gates) Refreshes the Marketplace listing with the new README</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/motchalini-llc/type-ratchet">https://github.com/motchalini-llc/type-ratchet</a></strong> to version <strong>v1.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/type-ratchet">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Docs-only release — no behavior change (gate.sh untouched).</p>
<ul>
<li>README: embed demo GIF + link the live demo PR (motchalini-llc/ratchet-demo#1, one &ldquo;quick fix&rdquo; that trips all three gates)</li>
<li>Refreshes the Marketplace listing with the new README</li>
</ul>
]]></content:encoded></item><item><title>lacuna-cli</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/lacuna-cli/</link><pubDate>Tue, 07 Jul 2026 05:15:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/lacuna-cli/</guid><description>Version updated for https://github.com/Octagon-simon/lacuna to version v0.3.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/Octagon-simon/lacuna/compare/v0.3.1...v0.3.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Octagon-simon/lacuna">https://github.com/Octagon-simon/lacuna</a></strong> to version <strong>v0.3.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lacuna-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Octagon-simon/lacuna/compare/v0.3.1...v0.3.2">https://github.com/Octagon-simon/lacuna/compare/v0.3.1...v0.3.2</a></p>
]]></content:encoded></item><item><title>Setup Omnistrate CTL</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/setup-omnistrate-ctl/</link><pubDate>Tue, 07 Jul 2026 05:14:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/setup-omnistrate-ctl/</guid><description>Version updated for https://github.com/omnistrate-oss/setup-omnistrate-ctl to version v1.1.0.
This action is used across all versions by 3 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump the npm-development group with 6 updates by @dependabot[bot] in https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/196 Fix CodeQL badge link in README by @pberton in https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/197 Fix CodeQL workflow filename in README by @pberton in https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/198 Bump the npm-development group with 5 updates by @dependabot[bot] in https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/199 Bump the npm-development group with 5 updates by @dependabot[bot] in https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/200 Bump actions/checkout from 6.0.2 to 6.0.3 in the actions-minor group by @dependabot[bot] in https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/201 Bump the npm-development group across 1 directory with 7 updates by @dependabot[bot] in https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/203 Update Node.js runtime to 24 by @pberton in https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/212 Full Changelog: https://github.com/omnistrate-oss/setup-omnistrate-ctl/compare/v1...v1.1.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/omnistrate-oss/setup-omnistrate-ctl">https://github.com/omnistrate-oss/setup-omnistrate-ctl</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-omnistrate-ctl">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump the npm-development group with 6 updates by @dependabot[bot] in <a href="https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/196">https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/196</a></li>
<li>Fix CodeQL badge link in README by @pberton in <a href="https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/197">https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/197</a></li>
<li>Fix CodeQL workflow filename in README by @pberton in <a href="https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/198">https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/198</a></li>
<li>Bump the npm-development group with 5 updates by @dependabot[bot] in <a href="https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/199">https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/199</a></li>
<li>Bump the npm-development group with 5 updates by @dependabot[bot] in <a href="https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/200">https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/200</a></li>
<li>Bump actions/checkout from 6.0.2 to 6.0.3 in the actions-minor group by @dependabot[bot] in <a href="https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/201">https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/201</a></li>
<li>Bump the npm-development group across 1 directory with 7 updates by @dependabot[bot] in <a href="https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/203">https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/203</a></li>
<li>Update Node.js runtime to 24 by @pberton in <a href="https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/212">https://github.com/omnistrate-oss/setup-omnistrate-ctl/pull/212</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/omnistrate-oss/setup-omnistrate-ctl/compare/v1...v1.1.0">https://github.com/omnistrate-oss/setup-omnistrate-ctl/compare/v1...v1.1.0</a></p>
]]></content:encoded></item><item><title>OSSystems Nix Actions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/ossystems-nix-actions/</link><pubDate>Tue, 07 Jul 2026 05:14:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/ossystems-nix-actions/</guid><description>Version updated for https://github.com/OSSystems/nix-actions to version v1.0.5.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Add post-run to the update-flake action.
post-run — command run after nix flake update, before the PR is created, so its file changes (e.g. a regenerated Cargo.nix) land in the update PR commit. export-devshell — &amp;#34;true&amp;#34; loads a dev shell into the environment before post-run (env-export via nicknovitski/nix-develop); &amp;#34;false&amp;#34; runs in plain bash. devshell — which dev shell to export when export-devshell is &amp;#34;true&amp;#34;; empty uses the flake’s default. Token safety: when post-run is set with token-owner, the GitHub App token is automatically re-minted after post-run — so a long-running post-run can’t expire the token before the PR is opened. Correct by default, with no flag to remember.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/OSSystems/nix-actions">https://github.com/OSSystems/nix-actions</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ossystems-nix-actions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Add <code>post-run</code> to the <code>update-flake</code> action.</p>
<ul>
<li><code>post-run</code> — command run after <code>nix flake update</code>, before the PR is created, so its file changes (e.g. a regenerated <code>Cargo.nix</code>) land in the update PR commit.</li>
<li><code>export-devshell</code> — <code>&quot;true&quot;</code> loads a dev shell into the environment before <code>post-run</code> (env-export via nicknovitski/nix-develop); <code>&quot;false&quot;</code> runs in plain bash.</li>
<li><code>devshell</code> — which dev shell to export when <code>export-devshell</code> is <code>&quot;true&quot;</code>; empty uses the flake&rsquo;s default.</li>
</ul>
<p><strong>Token safety:</strong> when <code>post-run</code> is set with <code>token-owner</code>, the GitHub App token is automatically re-minted after <code>post-run</code> — so a long-running <code>post-run</code> can&rsquo;t expire the token before the PR is opened. Correct by default, with no flag to remember.</p>
]]></content:encoded></item><item><title>Create Verified Commit and Tag</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/create-verified-commit-and-tag/</link><pubDate>Tue, 07 Jul 2026 05:13:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/create-verified-commit-and-tag/</guid><description>Version updated for https://github.com/oWretch/create-verified-commits to version v1.0.2.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.0.2 (2026-07-06) Bug Fixes deps: update @commitlint/cli to 21.2.0 to fix ESM-only package resolution (6124f06)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/oWretch/create-verified-commits">https://github.com/oWretch/create-verified-commits</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/create-verified-commit-and-tag">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="102-2026-07-06"><a href="https://github.com/oWretch/create-verified-commits/compare/v1.0.1...v1.0.2">1.0.2</a> (2026-07-06)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> update @commitlint/cli to 21.2.0 to fix ESM-only package resolution (<a href="https://github.com/oWretch/create-verified-commits/commit/6124f062d4480c58c51b1270f232a87e0ce22110">6124f06</a>)</li>
</ul>
]]></content:encoded></item><item><title>Quick OCP</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/quick-ocp/</link><pubDate>Tue, 07 Jul 2026 05:13:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/quick-ocp/</guid><description>Version updated for https://github.com/palmsoftware/quick-ocp to version v0.0.37.
This action is used across all versions by 14 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Add OCP 4.22 support (CRC v2.62.0) Fix oc tools download by stripping patch version to use latest-4.X channel Full Changelog: https://github.com/palmsoftware/quick-ocp/compare/v0.0.36...v0.0.37</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/palmsoftware/quick-ocp">https://github.com/palmsoftware/quick-ocp</a></strong> to version <strong>v0.0.37</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>14</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/quick-ocp">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add OCP 4.22 support (CRC v2.62.0)</li>
<li>Fix oc tools download by stripping patch version to use latest-4.X channel</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/palmsoftware/quick-ocp/compare/v0.0.36...v0.0.37">https://github.com/palmsoftware/quick-ocp/compare/v0.0.36...v0.0.37</a></p>
]]></content:encoded></item><item><title>SkillTotal AI Component Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/skilltotal-ai-component-security-scan/</link><pubDate>Tue, 07 Jul 2026 05:12:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/skilltotal-ai-component-security-scan/</guid><description>Version updated for https://github.com/pezhik/skilltotal to version v0.33.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed Ruleset 31 — installed-app Google OAuth client secret false positive (see RULES_CHANGELOG.md): a GOCSPX- client secret in a file with installed-app flow markers (loopback redirect, device code, PKCE, oob) is routed to needs_review instead of scored — for native/CLI apps Google documents this value as not confidential (gcloud ships one), so it must not synthesize a critical exfiltration verdict. A GOCSPX- secret without those markers (a leaked web-app secret) and all other secret shapes stay fully scored. Found on gemini-cli: critical/100 → high/50.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pezhik/skilltotal">https://github.com/pezhik/skilltotal</a></strong> to version <strong>v0.33.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skilltotal-ai-component-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>Ruleset 31 — installed-app Google OAuth client secret false positive</strong> (see
<code>RULES_CHANGELOG.md</code>): a <code>GOCSPX-</code> client secret in a file with installed-app flow markers
(loopback redirect, device code, PKCE, oob) is routed to <code>needs_review</code> instead of scored —
for native/CLI apps Google documents this value as not confidential (gcloud ships one), so
it must not synthesize a critical exfiltration verdict. A <code>GOCSPX-</code> secret without those
markers (a leaked web-app secret) and all other secret shapes stay fully scored. Found on
gemini-cli: critical/100 → high/50.</li>
</ul>
]]></content:encoded></item><item><title>MaintainerOps AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/maintainerops-ai/</link><pubDate>Tue, 07 Jul 2026 05:11:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/maintainerops-ai/</guid><description>Version updated for https://github.com/rtonf/maintainerops-ai to version v0.1.14.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v0.1.14 Marketplace Snapshot and Package Metadata Consistency MaintainerOps AI v0.1.14 is a small consistency release for public package and Marketplace evidence.
Changes Updated npm package repository metadata to the canonical git+https://github.com/rtonf/maintainerops-ai.git URL. Corrected the README GitHub Action example from the stale v0.1.12 tag to the currently verified Marketplace latest tag before release. Added an API-free security diff review for the metadata and Marketplace snapshot cleanup. Tracked the release workflow in Issue #85. Verification npm run verify git diff --check npm view maintainerops-ai version dist-tags --json GitHub Marketplace public listing check Notes This release does not change runtime behavior, model prompts, GitHub permissions, authorization boundaries, or package execution logic. It exists to keep Marketplace-facing documentation and package metadata aligned with the public release process.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rtonf/maintainerops-ai">https://github.com/rtonf/maintainerops-ai</a></strong> to version <strong>v0.1.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/maintainerops-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v0114-marketplace-snapshot-and-package-metadata-consistency">v0.1.14 Marketplace Snapshot and Package Metadata Consistency</h1>
<p>MaintainerOps AI <code>v0.1.14</code> is a small consistency release for public package and Marketplace evidence.</p>
<h2 id="changes">Changes</h2>
<ul>
<li>Updated npm package repository metadata to the canonical <code>git+https://github.com/rtonf/maintainerops-ai.git</code> URL.</li>
<li>Corrected the README GitHub Action example from the stale <code>v0.1.12</code> tag to the currently verified Marketplace latest tag before release.</li>
<li>Added an API-free security diff review for the metadata and Marketplace snapshot cleanup.</li>
<li>Tracked the release workflow in Issue #85.</li>
</ul>
<h2 id="verification">Verification</h2>
<ul>
<li><code>npm run verify</code></li>
<li><code>git diff --check</code></li>
<li><code>npm view maintainerops-ai version dist-tags --json</code></li>
<li>GitHub Marketplace public listing check</li>
</ul>
<h2 id="notes">Notes</h2>
<p>This release does not change runtime behavior, model prompts, GitHub permissions, authorization boundaries, or package execution logic. It exists to keep Marketplace-facing documentation and package metadata aligned with the public release process.</p>
]]></content:encoded></item><item><title>js Giphy PR Comment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/js-giphy-pr-comment/</link><pubDate>Tue, 07 Jul 2026 05:11:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/js-giphy-pr-comment/</guid><description>Version updated for https://github.com/sanketddev/js-action-pr-giphy-comment to version v1.0.0-alpha.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed This is a demo action for PR GIF comments.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sanketddev/js-action-pr-giphy-comment">https://github.com/sanketddev/js-action-pr-giphy-comment</a></strong> to version <strong>v1.0.0-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/js-giphy-pr-comment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This is a demo action for PR GIF comments.</p>
]]></content:encoded></item><item><title>Pipr Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/pipr-review/</link><pubDate>Tue, 07 Jul 2026 05:10:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/pipr-review/</guid><description>Version updated for https://github.com/somus/pipr to version v0.2.2.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.2.2 (2026-07-06) Features harden review prompts and evals (#22) (7415e3b) This PR was generated with Release Please. See documentation.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somus/pipr">https://github.com/somus/pipr</a></strong> to version <strong>v0.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pipr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="022-2026-07-06"><a href="https://github.com/somus/pipr/compare/v0.2.1...v0.2.2">0.2.2</a> (2026-07-06)</h2>
<h3 id="features">Features</h3>
<ul>
<li>harden review prompts and evals (<a href="https://github.com/somus/pipr/issues/22">#22</a>) (<a href="https://github.com/somus/pipr/commit/7415e3b932e925b3c41315f275706c0e373e9d96">7415e3b</a>)</li>
</ul>
<hr>
<p>This PR was generated with <a href="https://github.com/googleapis/release-please">Release Please</a>. See <a href="https://github.com/googleapis/release-please#release-please">documentation</a>.</p>
<!-- stage-review-badge-begin -->
]]></content:encoded></item><item><title>SFDX Run Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/sfdx-run-tests/</link><pubDate>Tue, 07 Jul 2026 05:10:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/sfdx-run-tests/</guid><description>Version updated for https://github.com/svierk/sfdx-run-tests to version v1.0.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed add documentation and usage instructions Full Changelog: https://github.com/svierk/sfdx-run-tests/compare/v0.0.4...v1.0.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/svierk/sfdx-run-tests">https://github.com/svierk/sfdx-run-tests</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sfdx-run-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>add documentation and usage instructions</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/svierk/sfdx-run-tests/compare/v0.0.4...v1.0.0">https://github.com/svierk/sfdx-run-tests/compare/v0.0.4...v1.0.0</a></p>
]]></content:encoded></item><item><title>Expand AWS IAM Wildcards</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/expand-aws-iam-wildcards/</link><pubDate>Tue, 07 Jul 2026 05:09:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/expand-aws-iam-wildcards/</guid><description>Version updated for https://github.com/thekbb/expand-aws-iam-wildcards to version v1.3.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix release verification by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/122 Release continue by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/123 release script prepts changelog for release by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/124 ci: bump zizmorcore/zizmor-action from 0.5.6 to 0.5.7 by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/127 ci: bump actions/attest from 4.1.0 to 4.1.1 by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/125 deps: bump the npm-dependencies group with 6 updates by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/126 Update IAM action data by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/128 Prepare v1.3.0 release by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/129 Full Changelog: https://github.com/thekbb/expand-aws-iam-wildcards/compare/v1...v1.3.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/thekbb/expand-aws-iam-wildcards">https://github.com/thekbb/expand-aws-iam-wildcards</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/expand-aws-iam-wildcards">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix release verification by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/122">https://github.com/thekbb/expand-aws-iam-wildcards/pull/122</a></li>
<li>Release continue by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/123">https://github.com/thekbb/expand-aws-iam-wildcards/pull/123</a></li>
<li>release script prepts changelog for release by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/124">https://github.com/thekbb/expand-aws-iam-wildcards/pull/124</a></li>
<li>ci: bump zizmorcore/zizmor-action from 0.5.6 to 0.5.7 by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/127">https://github.com/thekbb/expand-aws-iam-wildcards/pull/127</a></li>
<li>ci: bump actions/attest from 4.1.0 to 4.1.1 by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/125">https://github.com/thekbb/expand-aws-iam-wildcards/pull/125</a></li>
<li>deps: bump the npm-dependencies group with 6 updates by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/126">https://github.com/thekbb/expand-aws-iam-wildcards/pull/126</a></li>
<li>Update IAM action data by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/128">https://github.com/thekbb/expand-aws-iam-wildcards/pull/128</a></li>
<li>Prepare v1.3.0 release by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/129">https://github.com/thekbb/expand-aws-iam-wildcards/pull/129</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/thekbb/expand-aws-iam-wildcards/compare/v1...v1.3.0">https://github.com/thekbb/expand-aws-iam-wildcards/compare/v1...v1.3.0</a></p>
]]></content:encoded></item><item><title>Setup Modern C++ Development Environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/setup-modern-c-development-environment/</link><pubDate>Tue, 07 Jul 2026 05:09:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/07/setup-modern-c-development-environment/</guid><description>Version updated for https://github.com/wx257osn2/cxx_environment to version v3.5.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed now pull.bash can be called with no argument when you don’t pass image version, most recent one will be chosen fix msvc debug build</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wx257osn2/cxx_environment">https://github.com/wx257osn2/cxx_environment</a></strong> to version <strong>v3.5.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-modern-c-development-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>now <code>pull.bash</code> can be called with no argument
<ul>
<li>when you don&rsquo;t pass image version, most recent one will be chosen</li>
</ul>
</li>
<li>fix msvc debug build</li>
</ul>
]]></content:encoded></item><item><title>Forgejo Kaniko</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/forgejo-kaniko/</link><pubDate>Mon, 06 Jul 2026 23:09:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/forgejo-kaniko/</guid><description>Version updated for https://github.com/leandro-costa-oliveira/forgejo-kaniko-action to version v4.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/leandro-costa-oliveira/forgejo-kaniko-action/compare/v3...v4</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/leandro-costa-oliveira/forgejo-kaniko-action">https://github.com/leandro-costa-oliveira/forgejo-kaniko-action</a></strong> to version <strong>v4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/forgejo-kaniko">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/leandro-costa-oliveira/forgejo-kaniko-action/compare/v3...v4">https://github.com/leandro-costa-oliveira/forgejo-kaniko-action/compare/v3...v4</a></p>
]]></content:encoded></item><item><title>vcpkg GitHub Packages cache</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/vcpkg-github-packages-cache/</link><pubDate>Mon, 06 Jul 2026 23:08:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/vcpkg-github-packages-cache/</guid><description>Version updated for https://github.com/LegalizeAdulthood/vcpkg-github-cache to version v1.5.0.
This action is used across all versions by 4 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Improved BSD setup compatibility for current vcpkg on FreeBSD, OpenBSD, and NetBSD. Made BSD vcpkg-tool package caching repository-scoped to avoid cross-repo collisions. Fixed FreeBSD warm-cache restores caused by stale NuGet HTTP cache data. Added setup-log analysis for setup-side vcpkg-tool publish failures. Kept package summary links available when GitHub omits package settings metadata. Full Changelog: https://github.com/LegalizeAdulthood/vcpkg-github-cache/compare/v1.4.0...v1.5.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/LegalizeAdulthood/vcpkg-github-cache">https://github.com/LegalizeAdulthood/vcpkg-github-cache</a></strong> to version <strong>v1.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vcpkg-github-packages-cache">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Improved BSD setup compatibility for current vcpkg on FreeBSD, OpenBSD, and NetBSD.</li>
<li>Made BSD vcpkg-tool package caching repository-scoped to avoid cross-repo collisions.</li>
<li>Fixed FreeBSD warm-cache restores caused by stale NuGet HTTP cache data.</li>
<li>Added setup-log analysis for setup-side vcpkg-tool publish failures.</li>
<li>Kept package summary links available when GitHub omits package settings metadata.</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/LegalizeAdulthood/vcpkg-github-cache/compare/v1.4.0...v1.5.0">https://github.com/LegalizeAdulthood/vcpkg-github-cache/compare/v1.4.0...v1.5.0</a></p>
]]></content:encoded></item><item><title>Lingo.Dev AI Localization</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/lingo.dev-ai-localization/</link><pubDate>Mon, 06 Jul 2026 23:07:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/lingo.dev-ai-localization/</guid><description>Version updated for https://github.com/lingodotdev/lingo.dev to version lingo.dev@0.138.0.
This action is used across all versions by 104 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Minor Changes #2162 62c00b4 Thanks @AndreyHirsa! - Remove the ./compiler and ./react* subpath exports, the @lingo.dev/_compiler and @lingo.dev/_react dependencies, and the optional react peer dependency from the CLI package.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lingodotdev/lingo.dev">https://github.com/lingodotdev/lingo.dev</a></strong> to version <strong><a href="mailto:lingo.dev@0.138.0">lingo.dev@0.138.0</a></strong>.</p>
<ul>
<li>This action is used across all versions by <strong>104</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lingo-dev-ai-localization">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="minor-changes">Minor Changes</h3>
<ul>
<li><a href="https://github.com/lingodotdev/lingo.dev/pull/2162">#2162</a> <a href="https://github.com/lingodotdev/lingo.dev/commit/62c00b43bfcc3cd8fd65d7d3d3a69d69ed396f1e"><code>62c00b4</code></a> Thanks <a href="https://github.com/AndreyHirsa">@AndreyHirsa</a>! - Remove the <code>./compiler</code> and <code>./react*</code> subpath exports, the <code>@lingo.dev/_compiler</code> and <code>@lingo.dev/_react</code> dependencies, and the optional <code>react</code> peer dependency from the CLI package.</li>
</ul>
]]></content:encoded></item><item><title>crabd</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/crabd/</link><pubDate>Mon, 06 Jul 2026 23:07:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/crabd/</guid><description>Version updated for https://github.com/louisescher/crabd to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: Support for AGENTS.md, CLAUDE.md, skills by @louisescher in https://github.com/louisescher/crabd/pull/9 feat: Whitelabling for comments by @louisescher in https://github.com/louisescher/crabd/pull/11 feat: Pretty errors, scoped environment by @louisescher in https://github.com/louisescher/crabd/pull/12 feat: Cross-Repo read access &amp;amp; private NPM registries by @louisescher in https://github.com/louisescher/crabd/pull/13 chore: version packages by @github-actions[bot] in https://github.com/louisescher/crabd/pull/10 Full Changelog: https://github.com/louisescher/crabd/compare/v0...v0.3.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/louisescher/crabd">https://github.com/louisescher/crabd</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/crab-d">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: Support for AGENTS.md, CLAUDE.md, skills by @louisescher in <a href="https://github.com/louisescher/crabd/pull/9">https://github.com/louisescher/crabd/pull/9</a></li>
<li>feat: Whitelabling for comments by @louisescher in <a href="https://github.com/louisescher/crabd/pull/11">https://github.com/louisescher/crabd/pull/11</a></li>
<li>feat: Pretty errors, scoped environment by @louisescher in <a href="https://github.com/louisescher/crabd/pull/12">https://github.com/louisescher/crabd/pull/12</a></li>
<li>feat: Cross-Repo read access &amp; private NPM registries by @louisescher in <a href="https://github.com/louisescher/crabd/pull/13">https://github.com/louisescher/crabd/pull/13</a></li>
<li>chore: version packages by @github-actions[bot] in <a href="https://github.com/louisescher/crabd/pull/10">https://github.com/louisescher/crabd/pull/10</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/louisescher/crabd/compare/v0...v0.3.0">https://github.com/louisescher/crabd/compare/v0...v0.3.0</a></p>
]]></content:encoded></item><item><title>EIS — Upload Signals</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/eis-upload-signals/</link><pubDate>Mon, 06 Jul 2026 23:06:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/eis-upload-signals/</guid><description>Version updated for https://github.com/machuz/eis to version v2.26.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog 6c7fc4d74fa5122634f66ee96adfa38056237966 fix(output): make scores/rankings deterministic with tie-breaks (#343) 809e78242e07d15ccacdf5c48d0fa18db97b8574 perf(log): streaming-ingest Phase A — intern filenames + release chunks (repairs main build) (#342)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/machuz/eis">https://github.com/machuz/eis</a></strong> to version <strong>v2.26.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/eis-upload-signals">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>6c7fc4d74fa5122634f66ee96adfa38056237966 fix(output): make scores/rankings deterministic with tie-breaks (#343)</li>
<li>809e78242e07d15ccacdf5c48d0fa18db97b8574 perf(log): streaming-ingest Phase A — intern filenames + release chunks (repairs main build) (#342)</li>
</ul>
]]></content:encoded></item><item><title>lgtmaybe</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/lgtmaybe/</link><pubDate>Mon, 06 Jul 2026 23:06:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/lgtmaybe/</guid><description>Version updated for https://github.com/MattJColes/lgtmaybe to version lgtmaybe-v0.11.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.11.0 (2026-07-06) Features cli: add help command with usage examples (#177) (beac277) Bug Fixes evals: disable the review deadline in eval runs + one-command preset A/B (#175) (934b309)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MattJColes/lgtmaybe">https://github.com/MattJColes/lgtmaybe</a></strong> to version <strong>lgtmaybe-v0.11.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lgtmaybe">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="0110-2026-07-06"><a href="https://github.com/MattJColes/lgtmaybe/compare/lgtmaybe-v0.10.0...lgtmaybe-v0.11.0">0.11.0</a> (2026-07-06)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>cli:</strong> add help command with usage examples (<a href="https://github.com/MattJColes/lgtmaybe/issues/177">#177</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/beac277149225a0f9170109bf7e494bed0635d50">beac277</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>evals:</strong> disable the review deadline in eval runs + one-command preset A/B (<a href="https://github.com/MattJColes/lgtmaybe/issues/175">#175</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/934b309ed338fa3ddea152c19299bdffbe1707bf">934b309</a>)</li>
</ul>
]]></content:encoded></item><item><title>nix-magic-setup</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/nix-magic-setup/</link><pubDate>Mon, 06 Jul 2026 23:05:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/nix-magic-setup/</guid><description>Version updated for https://github.com/mdarocha/nix-magic-setup to version v1.3.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed The action now runs nothing-but-nix to help free up some space in the runner for Nix. The severity of the cleanup is controlled by a new config flag, and by default it only allocates free runner space to /nix, without removing anything (holster config) Automatically read nixConfig, and set NIX_CONFIG, so that all future steps use the flake’s config properly If devenv is detected, automatically set devenv caches (devenv.cachix.org and pre-commit.cachix.org) Full Changelog: https://github.com/mdarocha/nix-magic-setup/compare/v1.2.0...v1.3.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mdarocha/nix-magic-setup">https://github.com/mdarocha/nix-magic-setup</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nix-magic-setup">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>The action now runs <a href="https://github.com/marketplace/actions/nothing-but-nix">nothing-but-nix</a> to help free up some space in the runner for Nix. The severity of the cleanup is controlled by a new config flag, and by default it only allocates free runner space to <code>/nix</code>, without removing anything (<code>holster</code> config)</li>
<li>Automatically read <code>nixConfig</code>, and set <code>NIX_CONFIG</code>, so that all future steps use the flake&rsquo;s config properly</li>
<li>If <code>devenv</code> is detected, automatically set devenv caches (devenv.cachix.org and pre-commit.cachix.org)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mdarocha/nix-magic-setup/compare/v1.2.0...v1.3.0">https://github.com/mdarocha/nix-magic-setup/compare/v1.2.0...v1.3.0</a></p>
]]></content:encoded></item><item><title>Suppress Ratchet</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/suppress-ratchet/</link><pubDate>Mon, 06 Jul 2026 23:05:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/suppress-ratchet/</guid><description>Version updated for https://github.com/motchalini-llc/suppress-ratchet to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Docs-only release — no behavior change (gate.sh untouched).
README: Ratchet family cross-links; new “Why now” intro (guardrail for AI-written code); launch-article links (dev.to EN / Zenn JA) action.yml: sharpened description (Marketplace listing/search text)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/motchalini-llc/suppress-ratchet">https://github.com/motchalini-llc/suppress-ratchet</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/suppress-ratchet">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Docs-only release — no behavior change (gate.sh untouched).</p>
<ul>
<li>README: Ratchet family cross-links; new &ldquo;Why now&rdquo; intro (guardrail for AI-written code); launch-article links (dev.to EN / Zenn JA)</li>
<li>action.yml: sharpened <code>description</code> (Marketplace listing/search text)</li>
</ul>
]]></content:encoded></item><item><title>Test Ratchet</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/test-ratchet/</link><pubDate>Mon, 06 Jul 2026 23:04:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/test-ratchet/</guid><description>Version updated for https://github.com/motchalini-llc/test-ratchet to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Docs-only release — no behavior change (gate.sh untouched).
README: Ratchet family cross-links; new “Why now” intro (guardrail for AI-written code); launch-article links (dev.to EN / Zenn JA) action.yml: sharpened description (Marketplace listing/search text)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/motchalini-llc/test-ratchet">https://github.com/motchalini-llc/test-ratchet</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/test-ratchet">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Docs-only release — no behavior change (gate.sh untouched).</p>
<ul>
<li>README: Ratchet family cross-links; new &ldquo;Why now&rdquo; intro (guardrail for AI-written code); launch-article links (dev.to EN / Zenn JA)</li>
<li>action.yml: sharpened <code>description</code> (Marketplace listing/search text)</li>
</ul>
]]></content:encoded></item><item><title>Star History Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/star-history-action/</link><pubDate>Mon, 06 Jul 2026 23:04:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/star-history-action/</guid><description>Version updated for https://github.com/narayann7/star-history-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First release.
An unofficial GitHub Action that renders a star history chart for your own repositories and commits it into your repo, so your README embeds a static SVG that stays fresh. It is meant for repos you own or collaborate on, and works after GitHub’s June 2026 stargazers API restriction.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/narayann7/star-history-action">https://github.com/narayann7/star-history-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/star-history-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release.</p>
<p>An unofficial GitHub Action that renders a star history chart for your own repositories and commits it into your repo, so your README embeds a static SVG that stays fresh. It is meant for repos you own or collaborate on, and works after GitHub&rsquo;s June 2026 stargazers API restriction.</p>
<p>Highlights:</p>
<ul>
<li>Renders with star-history&rsquo;s own chart code (vendored, MIT, credited). No headless browser, no third-party CLI.</li>
<li>Light and dark SVGs, embedded via a <code>&lt;picture&gt;</code> block between README markers.</li>
<li>Commits only when the chart actually changes (data-signature detection).</li>
<li>Timestamped filenames bust GitHub&rsquo;s image cache; old files are cleaned up.</li>
<li>Logos inlined as base64 so GitHub renders them; embedded font stripped to keep files small.</li>
</ul>
<p>Usage: <code>uses: narayann7/star-history-action@v1</code>. See the README for the workflow and README markers.</p>
<p>Not affiliated with star-history.com.</p>
]]></content:encoded></item><item><title>Run AER Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/run-aer-tests/</link><pubDate>Mon, 06 Jul 2026 23:03:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/run-aer-tests/</guid><description>Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.9.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Version v1.2.9
Fix DmlException Thrown For For User-Mode DML Field Access Failures
Give SetupEntityAccess.SetupEntityId Its Polymorphic Target List
Resolve Feature Parameter Names Against The Executing Namespace
Group Bulkified Multi-Row Lookups By Key Instead Of Keeping First Row</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/octoberswimmer/aer-dist">https://github.com/octoberswimmer/aer-dist</a></strong> to version <strong>v1.2.9</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-aer-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Version v1.2.9</p>
<ul>
<li>
<p>Fix DmlException Thrown For For User-Mode DML Field Access Failures</p>
</li>
<li>
<p>Give SetupEntityAccess.SetupEntityId Its Polymorphic Target List</p>
</li>
<li>
<p>Resolve Feature Parameter Names Against The Executing Namespace</p>
</li>
<li>
<p>Group Bulkified Multi-Row Lookups By Key Instead Of Keeping First Row</p>
</li>
<li>
<p>Null Empty Flow Get Records Results And Append Null On Collection Add</p>
</li>
<li>
<p>Fall Back To The Master Record Type When A Profile Has No Default</p>
</li>
<li>
<p>Skip Rolled-Back Async Jobs And Keep Aborted AsyncApexJob Rows</p>
</li>
<li>
<p>Pause Flow Interviews At Wait Elements</p>
</li>
<li>
<p>Keep Per-Record Queries With Loop-Variable Binds Beyond The Rewritten Equality</p>
</li>
</ul>
]]></content:encoded></item><item><title>Polygraph MCP gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/polygraph-mcp-gate/</link><pubDate>Mon, 06 Jul 2026 23:02:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/polygraph-mcp-gate/</guid><description>Version updated for https://github.com/polygraphso/litmus to version litmus-v0.30.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Ships litmus-v14: a C-04 probe 3.2 false-positive fix (#104). A server that safely rejects a jailbreak-as-argument and echoes it back inside its own error frame (Invalid label &amp;#34;…&amp;#34;, Error: … not found: …), including char-stripped or truncated echoes, is no longer mis-flagged as amplification. Some safe-rejecting servers move D→A. server.json bumped in lockstep.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/polygraphso/litmus">https://github.com/polygraphso/litmus</a></strong> to version <strong>litmus-v0.30.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/polygraph-mcp-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Ships <strong>litmus-v14</strong>: a C-04 probe 3.2 false-positive fix (#104). A server that safely rejects a jailbreak-as-argument and echoes it back inside its own error frame (<code>Invalid label &quot;…&quot;</code>, <code>Error: … not found: …</code>), including char-stripped or truncated echoes, is no longer mis-flagged as amplification. Some safe-rejecting servers move D→A. <code>server.json</code> bumped in lockstep.</p>
]]></content:encoded></item><item><title>Prowler Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/prowler-security-scan/</link><pubDate>Mon, 06 Jul 2026 23:02:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/prowler-security-scan/</guid><description>Version updated for https://github.com/prowler-cloud/prowler to version 5.32.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed UI 🐞 Fixed Invitation callback paths are now preserved when invited users continue with Google, GitHub, or SAML authentication (#11752) API 🐞 Fixed Attack Paths: Scan rows now have database defaults for is_migrated and sink_backend so scan-perform-scheduled inserts survive deploy skew (#11826) Invited users now keep their invitation context when completing authentication with Google, GitHub, or SAML, so the invitation is accepted during login (#11752) 🔐 Security User profile updates now allow users to update their own account while requiring user-management permissions to update other users in the same tenant (#11792) SDK 🐞 Fixed KeyError: &amp;#39;MANUAL&amp;#39; crash while rendering the compliance summary table (e.g. CIS Microsoft 365) when a framework has manual, checks-less requirements with a Level 1/Level 2 profile; MANUAL findings are now skipped in the PASS/FAIL section tally instead of raising (#11822)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/prowler-cloud/prowler">https://github.com/prowler-cloud/prowler</a></strong> to version <strong>5.32.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/prowler-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="ui">UI</h2>
<h3 id="-fixed">🐞 Fixed</h3>
<ul>
<li>Invitation callback paths are now preserved when invited users continue with Google, GitHub, or SAML authentication <a href="https://github.com/prowler-cloud/prowler/pull/11752">(#11752)</a></li>
</ul>
<h2 id="api">API</h2>
<h3 id="-fixed-1">🐞 Fixed</h3>
<ul>
<li>Attack Paths: Scan rows now have database defaults for <code>is_migrated</code> and <code>sink_backend</code> so <code>scan-perform-scheduled</code> inserts survive deploy skew <a href="https://github.com/prowler-cloud/prowler/pull/11826">(#11826)</a></li>
<li>Invited users now keep their invitation context when completing authentication with Google, GitHub, or SAML, so the invitation is accepted during login <a href="https://github.com/prowler-cloud/prowler/pull/11752">(#11752)</a></li>
</ul>
<h3 id="-security">🔐 Security</h3>
<ul>
<li>User profile updates now allow users to update their own account while requiring user-management permissions to update other users in the same tenant <a href="https://github.com/prowler-cloud/prowler/pull/11792">(#11792)</a></li>
</ul>
<h2 id="sdk">SDK</h2>
<h3 id="-fixed-2">🐞 Fixed</h3>
<ul>
<li><code>KeyError: 'MANUAL'</code> crash while rendering the compliance summary table (e.g. CIS Microsoft 365) when a framework has manual, checks-less requirements with a Level 1/Level 2 profile; <code>MANUAL</code> findings are now skipped in the PASS/FAIL section tally instead of raising <a href="https://github.com/prowler-cloud/prowler/issues/11822">(#11822)</a></li>
</ul>
]]></content:encoded></item><item><title>No Deploy Fridays</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/no-deploy-fridays/</link><pubDate>Mon, 06 Jul 2026 23:01:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/no-deploy-fridays/</guid><description>Version updated for https://github.com/rorycaraher/no-deploy-fridays to version v0.1.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/rorycaraher/no-deploy-fridays/compare/v0...v0.1.4</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rorycaraher/no-deploy-fridays">https://github.com/rorycaraher/no-deploy-fridays</a></strong> to version <strong>v0.1.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/no-deploy-fridays">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/rorycaraher/no-deploy-fridays/compare/v0...v0.1.4">https://github.com/rorycaraher/no-deploy-fridays/compare/v0...v0.1.4</a></p>
]]></content:encoded></item><item><title>Vibe Index</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/vibe-index/</link><pubDate>Mon, 06 Jul 2026 23:00:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/vibe-index/</guid><description>Version updated for https://github.com/roxblnfk/action-vibe-index to version v1.3.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.3.1 (2026-07-06) Bug Fixes push the badge commit to the checked-out branch (f98e946)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/roxblnfk/action-vibe-index">https://github.com/roxblnfk/action-vibe-index</a></strong> to version <strong>v1.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibe-index">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="131-2026-07-06"><a href="https://github.com/roxblnfk/action-vibe-index/compare/v1.3.0...v1.3.1">1.3.1</a> (2026-07-06)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>push the badge commit to the checked-out branch (<a href="https://github.com/roxblnfk/action-vibe-index/commit/f98e946aa405a9aa698aed3c149ebdda466a54f0">f98e946</a>)</li>
</ul>
]]></content:encoded></item><item><title>Scanbox Security Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/scanbox-security-audit/</link><pubDate>Mon, 06 Jul 2026 23:00:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/scanbox-security-audit/</guid><description>Version updated for https://github.com/Savvii/scanbox to version v1.0.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Tweak prompt to remove /app dependency, makes it easier to override the dir for other pipelines.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Savvii/scanbox">https://github.com/Savvii/scanbox</a></strong> to version <strong>v1.0.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/scanbox-security-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Tweak prompt to remove <code>/app</code> dependency, makes it easier to override the dir for other pipelines.</p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/bernstein-multi-agent-orchestration/</link><pubDate>Mon, 06 Jul 2026 22:59:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v3.0.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v3.0.0 Released 2026-07-06.
A verifiability release. Every major surface in this line ships its primary artifact as a proof: a signed lineage receipt, an HMAC-chained journal entry, a content-addressed record, or a deterministic projection that two operators can recompute to the same bytes. The features are not “capability plus an audit log” bolted together; the audit substrate is the shape of the capability. Strip the chain and the feature loses its meaning, not just its logging.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v3.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v300">v3.0.0</h1>
<p>Released 2026-07-06.</p>
<p>A verifiability release. Every major surface in this line ships its primary
artifact as a proof: a signed lineage receipt, an HMAC-chained journal entry, a
content-addressed record, or a deterministic projection that two operators can
recompute to the same bytes. The features are not &ldquo;capability plus an audit
log&rdquo; bolted together; the audit substrate is the shape of the capability. Strip
the chain and the feature loses its meaning, not just its logging.</p>
<h2 id="substrate">Substrate</h2>
<ul>
<li>Lineage is now a single, always-on chained record. Every artifact-producing
step folds into one Ed25519-signed lineage spine instead of the previous
optional per-subsystem records; <code>bernstein lineage verify &lt;run_id&gt;</code> walks the
whole chain. (#2292)</li>
<li>Deterministic replay records by default. The step journal is a Merkle chain
where each entry hashes its predecessor, inputs, model, prompt, tool call, and
tool result, so non-determinism surfaces as hash divergence rather than a
flaky rerun. <code>bernstein replay --from-step N</code> rebuilds state by walking it.
(#2293)</li>
</ul>
<h2 id="governance-and-review">Governance and review</h2>
<ul>
<li>Maker-checker and judge-panel gates whose verdict is an adjudication receipt
anchored to the audit chain; the decision, its inputs, and the panel identity
are all recoverable after the fact. (#2294)</li>
<li>Attested pull-request review and autofix: the PR carries a receipt linking the
originating issue, the plan, every tool call, and the diff, so a reviewer can
verify the change was generated from the ticket without operator override.
(#2296)</li>
<li>RBAC, budgets, and seat attribution as verifiable projections: an authorization
or spend decision is a governance-decision journal entry, not a mutable
in-memory grant. (#2309)</li>
<li>Verifiable spending mandates recorded as journal-anchored records, so a spend
limit and its consumption are independently auditable. (#2306)</li>
</ul>
<h2 id="interoperability">Interoperability</h2>
<ul>
<li>Stateless MCP protocol core with owned cross-request identity, so a session
spanning stateless calls stays attributable. (#2307)</li>
<li>Bernstein exposed as an audited execution node with signed webhook receipts:
every inbound trigger is a receipt in the chain. (#2310)</li>
<li>Outbound agent HTTP requests are signed and each signature chains to the audit
log, so a receiver can prove which install identity issued a call. (#2305)</li>
<li>Native subagent delegation for fan-out execution, each delegation recorded as
a chain entry. (#2308)</li>
</ul>
<h2 id="modality-and-observability">Modality and observability</h2>
<ul>
<li>Skill installs produce lineage receipts and catalog provenance, so a skill&rsquo;s
usage history is attested rather than asserted by a registry. (#2301)</li>
<li>Fork-from-step using git worktree commits as the snapshot boundary: a fork is
a real commit, isolated per worktree, not a soft copy. (#2295)</li>
<li>OpenTelemetry GenAI spans emitted as a signed projection of the audit chain,
so an exported trace and the executed actions verify against each other.
(#2300)</li>
<li>C2PA content credentials emitted as a deterministic projection: attached and
produced media carry content-address-anchored provenance. (#2303)</li>
<li>Cross-session memory rebuilt as a tamper-evident, content-addressed store;
a memory write is a chained receipt keyed by content hash. (#2298)</li>
<li>TUI reads the existing event stream instead of polling, so the interface is a
projection of the same journal the run records. (#2297)</li>
<li>Recurring goals as deterministic projections onto a canonical task graph: two
operators with identical state fire the byte-identical graph at time T. (#2302)</li>
<li>Stuck-worker escalation as a signed, forensically-reconstructable receipt
carrying the last audit entries and a deterministic recommended action, so a
stall can be handed to a postmortem with cryptographic certainty about the
failure window. (#2299)</li>
</ul>
<h2 id="federation-and-activity-model">Federation and activity model</h2>
<ul>
<li>A2A federation where every inbound and outbound message is a signed lineage
receipt anchored to the install identity, so a peer can verify a received
message chains back to us. (#2304)</li>
<li>A typed activity boundary so any agent modality, not only coding CLIs, runs
under the deterministic scheduler and is journaled identically, letting replay
verify across modalities. (#2311)</li>
</ul>
]]></content:encoded></item><item><title>cvesse CVE gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/cvesse-cve-gate/</link><pubDate>Mon, 06 Jul 2026 22:59:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/cvesse-cve-gate/</guid><description>Version updated for https://github.com/srknzl/cvesse-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First release of cvesse CVE gate — a zero-dependency GitHub Action that takes the CVE IDs your scanner already produces (Trivy, Grype, osv-scanner, Dependabot), enriches them against cvesse, and fails CI on CISA KEV, severity, or EPSS thresholds.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/srknzl/cvesse-action">https://github.com/srknzl/cvesse-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cvesse-cve-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release of <strong>cvesse CVE gate</strong> — a zero-dependency GitHub Action that takes the CVE IDs your scanner already produces (Trivy, Grype, osv-scanner, Dependabot), enriches them against <a href="https://cvesse.com">cvesse</a>, and <strong>fails CI</strong> on CISA KEV, severity, or EPSS thresholds.</p>
<p>Why not just use the scanner&rsquo;s own severity? cvesse&rsquo;s <code>calculated_severity</code> promotes anything in <strong>CISA KEV</strong> or with <strong>EPSS &gt; 0.36</strong> to CRITICAL — so this catches <em>&ldquo;your scanner said HIGH but it&rsquo;s being actively exploited.&rdquo;</em></p>
<h2 id="features">Features</h2>
<ul>
<li><strong>Any scanner</strong> — regex-extracts <code>CVE-YYYY-NNNN</code> from any SARIF/JSON/text output; point <code>input</code> at one or more files.</li>
<li><strong>Dependabot mode</strong> — <code>dependabot: true</code> reads your open Dependabot alerts directly. Fails loudly (never silently passes) if the token can&rsquo;t read them, and reports GHSA-only alerts it can&rsquo;t check.</li>
<li><strong>Independent gates</strong> — <code>fail-on-kev</code>, <code>fail-on-severity</code>, <code>fail-on-epss</code>, <code>fail-on-unknown</code>; set any to <code>&quot;&quot;</code>/<code>false</code> to disable.</li>
<li><strong>PR feedback</strong> — writes a results table to the job summary and, with <code>comment: true</code>, a sticky PR comment.</li>
<li><strong>Zero dependencies</strong> — single <code>index.js</code> on Node 20. Nothing to audit but the code you can read.</li>
</ul>
]]></content:encoded></item><item><title>Node Semantic Release</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/node-semantic-release/</link><pubDate>Mon, 06 Jul 2026 22:58:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/node-semantic-release/</guid><description>Version updated for https://github.com/stairwaytowonderland/node-semantic-release to version v1.195.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed chore(release): 1.195.0
1.195.0 (2026-07-06) ✨ Features updates (16fcf9d)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stairwaytowonderland/node-semantic-release">https://github.com/stairwaytowonderland/node-semantic-release</a></strong> to version <strong>v1.195.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/node-semantic-release">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>chore(release): 1.195.0</p>
<h2 id="11950-2026-07-06"><a href="https://github.com/stairwaytowonderland/node-semantic-release/compare/v1.194.0...v1.195.0">1.195.0</a> (2026-07-06)</h2>
<h3 id="-features">✨ Features</h3>
<ul>
<li>updates (<a href="https://github.com/stairwaytowonderland/node-semantic-release/commit/16fcf9dbe0cf9f974773c6343e4ae930a679bc14">16fcf9d</a>)</li>
</ul>
]]></content:encoded></item><item><title>Trigv</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/trigv/</link><pubDate>Mon, 06 Jul 2026 22:58:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/trigv/</guid><description>Version updated for https://github.com/Trigv/trigv-github-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixes Default channel input is now general (Trigv workspace default), not ci. README examples omit channel unless you need a custom slug. Pin workflows to @v1.0.1 or newer.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Trigv/trigv-github-action">https://github.com/Trigv/trigv-github-action</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/trigv">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="fixes">Fixes</h2>
<ul>
<li>Default <code>channel</code> input is now <code>general</code> (Trigv workspace default), not <code>ci</code>.</li>
<li>README examples omit <code>channel</code> unless you need a custom slug.</li>
</ul>
<p>Pin workflows to <code>@v1.0.1</code> or newer.</p>
]]></content:encoded></item><item><title>HumaneProxy Safety Benchmark</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/humaneproxy-safety-benchmark/</link><pubDate>Mon, 06 Jul 2026 22:57:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/humaneproxy-safety-benchmark/</guid><description>Version updated for https://github.com/Vishisht16/Humane-Proxy to version v0.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed This release is about doing the same work faster and scaling it across workers—three independent performance wins, each behind an opt-in extra with a clean fallback.
Added ONNX Runtime Stage-2 backend (stage2.backend, env HUMANE_PROXY_STAGE2_BACKEND): Stage 2 can now run the embedding model on its pre-exported ONNX graph via a new onnx extra (onnxruntime + tokenizers + huggingface_hub)—no PyTorch, roughly 2 GB lighter to install, and faster on CPU. The default &amp;#34;auto&amp;#34; prefers ONNX when installed and falls back to sentence-transformers; both produce numerically equivalent embeddings, verified by an equivalence test suite (including long-input truncation parity). Model, anchor, and result caches are keyed per backend.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Vishisht16/Humane-Proxy">https://github.com/Vishisht16/Humane-Proxy</a></strong> to version <strong>v0.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/humaneproxy-safety-benchmark">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This release is about doing the same work faster and scaling it across workers—three independent performance wins, each behind an opt-in extra with a clean fallback.</p>
<h3 id="added">Added</h3>
<ul>
<li>
<p><strong>ONNX Runtime Stage-2 backend</strong> (<code>stage2.backend</code>, env <code>HUMANE_PROXY_STAGE2_BACKEND</code>): Stage 2 can now run the embedding model on its pre-exported ONNX graph via a new <code>onnx</code> extra (<code>onnxruntime</code> + <code>tokenizers</code> + <code>huggingface_hub</code>)—<strong>no PyTorch</strong>, roughly 2 GB lighter to install, and faster on CPU. The default <code>&quot;auto&quot;</code> prefers ONNX when installed and falls back to <code>sentence-transformers</code>; both produce numerically equivalent embeddings, verified by an equivalence test suite (including long-input truncation parity). Model, anchor, and result caches are keyed per backend.</p>
</li>
<li>
<p><strong>Redis-backed trajectory analysis</strong> (<code>trajectory.backend: redis</code>, env <code>HUMANE_PROXY_TRAJECTORY_BACKEND</code>): Session risk windows move into Redis sorted sets with an atomic Lua read-append-trim, so every uvicorn worker shares one consistent view of a session&rsquo;s trajectory (the in-memory default tracks per process). Reuses <code>storage.redis.url</code> unless <code>trajectory.redis.url</code> is set. Sessions auto-expire via TTL (default 2× the decay half-life), fall back to in-memory tracking with a logged warning when Redis is unavailable, and <code>DELETE /admin/sessions/{id}</code> now erases the Redis trajectory keys as well.</p>
</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>orjson JSON fast path</strong> (new optional <code>perf</code> extra): When installed, the proxy serializes every <code>/chat</code> response through an orjson-backed response class. Storage trigger serialization, Stage-3 response parsing, and integration tool output also route through an internal shim. Without the extra, everything falls back to the standard library <code>json</code> module with identical behavior.</li>
</ul>
<h3 id="install">Install</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install humane-proxy<span style="color:#f92672">[</span>onnx<span style="color:#f92672">]</span>     <span style="color:#75715e"># Stage 2 without PyTorch</span>
</span></span><span style="display:flex;"><span>pip install humane-proxy<span style="color:#f92672">[</span>perf<span style="color:#f92672">]</span>     <span style="color:#75715e"># orjson fast path</span>
</span></span><span style="display:flex;"><span>pip install humane-proxy<span style="color:#f92672">[</span>redis<span style="color:#f92672">]</span>    <span style="color:#75715e"># shared trajectory + storage</span>
</span></span><span style="display:flex;"><span>pip install humane-proxy<span style="color:#f92672">[</span>all<span style="color:#f92672">]</span>      <span style="color:#75715e"># everything</span>
</span></span></code></pre></div><p><strong>Full Changelog:</strong> <a href="https://github.com/Vishisht16/Humane-Proxy/compare/v0.5.6...v0.6.0">https://github.com/Vishisht16/Humane-Proxy/compare/v0.5.6...v0.6.0</a></p>
]]></content:encoded></item><item><title>PR Ripple</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/pr-ripple/</link><pubDate>Mon, 06 Jul 2026 22:56:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/pr-ripple/</guid><description>Version updated for https://github.com/vivek5071/ripple to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s new dry-run input — run the full analysis pipeline with zero side effects: the report is logged instead of posted, reviewers are logged instead of requested, AI review is skipped. Trial Ripple on any repo without spamming your team: - uses: vivek5071/ripple@v1 with: dry-run: true Test suite — 8 unit tests covering symbol extraction and owner resolution CI — typecheck + tests on every push and PR</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vivek5071/ripple">https://github.com/vivek5071/ripple</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pr-ripple">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new">What&rsquo;s new</h2>
<ul>
<li><strong><code>dry-run</code> input</strong> — run the full analysis pipeline with zero side effects: the report is logged instead of posted, reviewers are logged instead of requested, AI review is skipped. Trial Ripple on any repo without spamming your team:
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">vivek5071/ripple@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">dry-run</span>: <span style="color:#66d9ef">true</span>
</span></span></code></pre></div></li>
<li><strong>Test suite</strong> — 8 unit tests covering symbol extraction and owner resolution</li>
<li><strong>CI</strong> — typecheck + tests on every push and PR</li>
</ul>
]]></content:encoded></item><item><title>Upkeep Audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/upkeep-audit/</link><pubDate>Mon, 06 Jul 2026 22:56:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/upkeep-audit/</guid><description>Version updated for https://github.com/wei18/Upkeep to version v2.1.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Patch release for GitHub Marketplace publishing.
action.yml description shortened under the Marketplace 125-character limit (#22). Plugin version bumped to 2.1.1. v2.1.0 highlights (composite action.yml for Marketplace, README usage section, docs updates) are in the v2.1.0 notes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wei18/Upkeep">https://github.com/wei18/Upkeep</a></strong> to version <strong>v2.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/upkeep-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Patch release for GitHub Marketplace publishing.</p>
<ul>
<li><code>action.yml</code> description shortened under the Marketplace 125-character limit (#22).</li>
<li>Plugin version bumped to 2.1.1.</li>
</ul>
<p>v2.1.0 highlights (composite <code>action.yml</code> for Marketplace, README usage section, docs updates) are in the <a href="https://github.com/Wei18/Upkeep/releases/tag/v2.1.0">v2.1.0 notes</a>.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Wei18/Upkeep/compare/v2.1.0...v2.1.1">https://github.com/Wei18/Upkeep/compare/v2.1.0...v2.1.1</a></p>
<p>🤖 Generated with <a href="https://claude.com/claude-code">Claude Code</a></p>
]]></content:encoded></item><item><title>install spaces</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/install-spaces/</link><pubDate>Mon, 06 Jul 2026 22:55:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/install-spaces/</guid><description>Version updated for https://github.com/work-spaces/install-spaces to version v0.17.3.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump version to v0.17.3 by @tyler-gilbert in https://github.com/work-spaces/install-spaces/pull/34 Full Changelog: https://github.com/work-spaces/install-spaces/compare/v0.17.2...v0.17.3</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/work-spaces/install-spaces">https://github.com/work-spaces/install-spaces</a></strong> to version <strong>v0.17.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-spaces">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump version to v0.17.3 by @tyler-gilbert in <a href="https://github.com/work-spaces/install-spaces/pull/34">https://github.com/work-spaces/install-spaces/pull/34</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/work-spaces/install-spaces/compare/v0.17.2...v0.17.3">https://github.com/work-spaces/install-spaces/compare/v0.17.2...v0.17.3</a></p>
]]></content:encoded></item><item><title>spaces checkout run</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/spaces-checkout-run/</link><pubDate>Mon, 06 Jul 2026 22:55:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/spaces-checkout-run/</guid><description>Version updated for https://github.com/work-spaces/spaces-checkout-run to version v0.17.3.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump version to v0.17.3 by @tyler-gilbert in https://github.com/work-spaces/spaces-checkout-run/pull/28 Full Changelog: https://github.com/work-spaces/spaces-checkout-run/compare/v0.17.2...v0.17.3</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/work-spaces/spaces-checkout-run">https://github.com/work-spaces/spaces-checkout-run</a></strong> to version <strong>v0.17.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spaces-checkout-run">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump version to v0.17.3 by @tyler-gilbert in <a href="https://github.com/work-spaces/spaces-checkout-run/pull/28">https://github.com/work-spaces/spaces-checkout-run/pull/28</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/work-spaces/spaces-checkout-run/compare/v0.17.2...v0.17.3">https://github.com/work-spaces/spaces-checkout-run/compare/v0.17.2...v0.17.3</a></p>
]]></content:encoded></item><item><title>Type Ratchet</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/type-ratchet/</link><pubDate>Mon, 06 Jul 2026 15:31:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/type-ratchet/</guid><description>Version updated for https://github.com/motchalini-llc/type-ratchet to version v1.1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Docs-only release — no behavior change (gate.sh untouched).
README: Ratchet family cross-links; new “Why now” intro (guardrail for AI-written code); launch-article links (dev.to EN / Zenn JA) action.yml: sharpened description (Marketplace listing/search text)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/motchalini-llc/type-ratchet">https://github.com/motchalini-llc/type-ratchet</a></strong> to version <strong>v1.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/type-ratchet">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Docs-only release — no behavior change (gate.sh untouched).</p>
<ul>
<li>README: Ratchet family cross-links; new &ldquo;Why now&rdquo; intro (guardrail for AI-written code); launch-article links (dev.to EN / Zenn JA)</li>
<li>action.yml: sharpened <code>description</code> (Marketplace listing/search text)</li>
</ul>
]]></content:encoded></item><item><title>moult-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/moult-action/</link><pubDate>Mon, 06 Jul 2026 15:30:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/moult-action/</guid><description>Version updated for https://github.com/moult-rb/moult-rb to version v0.4.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Add moult cycles, hotspot coupling columns, and hierarchy-aware deadcode confidence by @GoodPie in https://github.com/moult-rb/moult-rb/pull/9 Full Changelog: https://github.com/moult-rb/moult-rb/compare/v0.4.1...v0.4.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/moult-rb/moult-rb">https://github.com/moult-rb/moult-rb</a></strong> to version <strong>v0.4.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/moult-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add moult cycles, hotspot coupling columns, and hierarchy-aware deadcode confidence by @GoodPie in <a href="https://github.com/moult-rb/moult-rb/pull/9">https://github.com/moult-rb/moult-rb/pull/9</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/moult-rb/moult-rb/compare/v0.4.1...v0.4.2">https://github.com/moult-rb/moult-rb/compare/v0.4.1...v0.4.2</a></p>
]]></content:encoded></item><item><title>agent-bom Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/agent-bom-scan/</link><pubDate>Mon, 06 Jul 2026 15:30:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/agent-bom-scan/</guid><description>Version updated for https://github.com/msaad00/agent-bom to version v0.93.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix(docs): keep extension contract link mkdocs-strict safe by @msaad00 in https://github.com/msaad00/agent-bom/pull/3429 docs(readme): refresh personas and terminal demo for 0.92.0 CLI by @msaad00 in https://github.com/msaad00/agent-bom/pull/3430 fix(ci): unblock Sigma WebGL E2E dynamic import by @msaad00 in https://github.com/msaad00/agent-bom/pull/3432 chore(perf): findings read bench and 2k CI regression by @msaad00 in https://github.com/msaad00/agent-bom/pull/3440 feat(retention): enforce graph snapshot purge and history cap (PR1) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3441 feat(api): server-side compliance hub findings pagination (PR1) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3442 fix(scan): skip unreachable Go checksum lookups by @msaad00 in https://github.com/msaad00/agent-bom/pull/3443 fix(compliance): normalize pci-dss slug alias and SAML install hint (#3439) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3444 feat(helm): Alembic pre-upgrade hook; chore(sdks): bump Python SDK (#3433, #3438) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3445 fix(scan): reduce secret FP on OAuth token minting assignments (#3437) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3447 refactor(output): migrate compact and console formatters to Finding (#2918) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3448 feat(skills): CI exit code and wider skill file discovery (#3434) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3449 fix(hardening): Role enum, Grafana creds, ecosystem claims, HOSTS rollup (#3242) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3450 feat(release): SBOM release asset, image scan gate, air-gap vuln-DB docs (#3436) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3451 fix(hardening): severity unification and cosign/MCP audit fixes (#3242) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3452 feat(retention): per-tenant graph retention and analytics cap (PR2) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3453 feat(api): findings read PR2 — approximate counts and UI pagination (#3192) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3454 chore(deps): combine dependency updates (2026-07-03) by @andres-linero in https://github.com/msaad00/agent-bom/pull/3460 feat(api): expression-indexed severity/cvss finding sorts (#3192) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3461 fix(api): idempotent finding ingest (P0) (#3242) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3462 fix(reliability): tenant fail-closed, cloud retry, health rate-exempt, batch cap by @msaad00 in https://github.com/msaad00/agent-bom/pull/3464 feat(enrich): bundle KEV and EPSS into offline vuln-DB layer by @msaad00 in https://github.com/msaad00/agent-bom/pull/3466 feat(ui): labeled demo estate and surface lock states (PR1) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3467 feat(api): finding lifecycle L1 — monotone current-state merge (#3465) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3470 fix(api): batch cap returns 422 and index filtered severity+cvss reads (#3474) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3477 chore(repo): hygiene + session cookie Secure default (#3475) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3479 fix(auth): cluster-safe SAML RelayState nonce store (#3476) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3478 feat(api): finding lifecycle L2 — occurrence log keyed on scan_id (#3465) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3480 feat(sdk): expose finding lifecycle ingest on control-plane clients by @msaad00 in https://github.com/msaad00/agent-bom/pull/3483 feat(api): finding lifecycle L3+L4 — resolve reconcile and current-state reads (#3465) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3481 docs(audit): add sanitized 2026-07-03 ledger with issue mapping by @msaad00 in https://github.com/msaad00/agent-bom/pull/3500 fix(api): harden OCSF ingest — cap/offload (A) + deterministic event IDs &amp;amp; ClickHouse dedup (J) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3501 feat(ui): interactive blast-radius overlay on the lineage graph by @msaad00 in https://github.com/msaad00/agent-bom/pull/3502 fix(ui): dock graph lens switcher — stop overlaying the canvas by @msaad00 in https://github.com/msaad00/agent-bom/pull/3505 docs(deploy): auto-migration hook, finding encryption prereq, ClickHouse OSS+Cloud by @msaad00 in https://github.com/msaad00/agent-bom/pull/3504 feat(ui): wire estate roll-up navigation for large graphs by @msaad00 in https://github.com/msaad00/agent-bom/pull/3507 fix(api,http): bound ScanRequest list elements and jitter sync retries by @msaad00 in https://github.com/msaad00/agent-bom/pull/3508 fix(api): gate external compliance frameworks and lock OCSF product attribution by @msaad00 in https://github.com/msaad00/agent-bom/pull/3509 fix(api): restore overview tiles from compact scans and add current-state sort indexes by @msaad00 in https://github.com/msaad00/agent-bom/pull/3515 refactor(api): deduplicate current-state hub payloads via ledger refs by @msaad00 in https://github.com/msaad00/agent-bom/pull/3517 feat(api): keyset cursor pagination for hub current-state findings by @msaad00 in https://github.com/msaad00/agent-bom/pull/3518 perf(api): gzip JSON responses and zstd-compress hub payloads at rest by @msaad00 in https://github.com/msaad00/agent-bom/pull/3516 feat(helm): enterprise-demo profile with AWS estate inventory cron by @msaad00 in https://github.com/msaad00/agent-bom/pull/3519 feat(api,ui): overview graph drill and estate correlation API by @msaad00 in https://github.com/msaad00/agent-bom/pull/3520 fix(cloud,helm): http_client GPU connectors + scoped API NetworkPolicy by @msaad00 in https://github.com/msaad00/agent-bom/pull/3522 feat(scanners): runtime-enforce driver run() and failure_mode by @msaad00 in https://github.com/msaad00/agent-bom/pull/3524 fix(api): Postgres rate-limit sliding window matches docstring by @msaad00 in https://github.com/msaad00/agent-bom/pull/3523 docs: compact session/enforcement flow diagrams by @andres-linero in https://github.com/msaad00/agent-bom/pull/3525 feat(api): async findings report export jobs by @msaad00 in https://github.com/msaad00/agent-bom/pull/3526 perf(analytics): ClickHouse sink dedup for canonical rows by @msaad00 in https://github.com/msaad00/agent-bom/pull/3527 fix(api): CVSS keyset pagination and report export truncation by @msaad00 in https://github.com/msaad00/agent-bom/pull/3530 refactor(api): hub reference-table normalization by @msaad00 in https://github.com/msaad00/agent-bom/pull/3528 docs(deploy): audit Alembic, encryption prerequisite, ClickHouse positioning by @msaad00 in https://github.com/msaad00/agent-bom/pull/3532 fix(api/scim): group PATCH, deprovision keys, SCIM error envelopes by @msaad00 in https://github.com/msaad00/agent-bom/pull/3540 feat(export): delta-stream connector for SIEM and data-lake sinks by @msaad00 in https://github.com/msaad00/agent-bom/pull/3531 test(api): lock in hub current-state payload dedup by @msaad00 in https://github.com/msaad00/agent-bom/pull/3541 feat(api): S3 report export artifacts with presigned URLs by @msaad00 in https://github.com/msaad00/agent-bom/pull/3542 fix(api/scim): PUT full replace and schema discovery by id by @msaad00 in https://github.com/msaad00/agent-bom/pull/3543 fix(api): gate bulk-ingest O(n) snapshot walk (#3544) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3545 fix(fleet): local discovery push for fleet sync by @msaad00 in https://github.com/msaad00/agent-bom/pull/3546 chore(glama): pin release ref and verify Dockerfile on publish by @msaad00 in https://github.com/msaad00/agent-bom/pull/3547 docs(audit): sync AUDIT-2026-07-03 ledger with shipped main by @msaad00 in https://github.com/msaad00/agent-bom/pull/3550 docs(readme): lead with personas, Start Here, and demo proof by @msaad00 in https://github.com/msaad00/agent-bom/pull/3548 feat(headless): wire findings push CLI and hub current-state list (#3482) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3549 feat(ui): show findings lifecycle status and timestamps in queue by @msaad00 in https://github.com/msaad00/agent-bom/pull/3551 fix(cli): skip PyPI update check in offline and air-gap mode (#3242) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3552 fix(deploy): mount ~/.agent-bom for abom user in compose profiles (#3242) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3553 fix(cli): reject reserved tenant ids on CLI and MCP resolvers (#3242) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3554 docs(audit): headless ingest docs and audit ledger sync by @msaad00 in https://github.com/msaad00/agent-bom/pull/3555 fix(cli): honor –offline for PyPI check and loopback fleet push by @msaad00 in https://github.com/msaad00/agent-bom/pull/3556 fix(headless): offline push, MCP check version, token-derived auth by @msaad00 in https://github.com/msaad00/agent-bom/pull/3557 chore(ci): reject LLM co-author trailers in commit messages by @msaad00 in https://github.com/msaad00/agent-bom/pull/3558 refactor(output): use canonical severity_rank in remediation plan by @msaad00 in https://github.com/msaad00/agent-bom/pull/3559 docs(audit): sync ledger for headless hardening #3556-#3558 by @msaad00 in https://github.com/msaad00/agent-bom/pull/3560 fix(auth): reject replayed OIDC JWTs via jti one-time store by @msaad00 in https://github.com/msaad00/agent-bom/pull/3561 refactor(trust): derive CVE weights from canonical severity_rank by @msaad00 in https://github.com/msaad00/agent-bom/pull/3562 docs(audit): sync ledger post #3561 OIDC jti replay by @msaad00 in https://github.com/msaad00/agent-bom/pull/3563 feat(plugins): runtime activation for opt-in plugin entry points by @andres-linero in https://github.com/msaad00/agent-bom/pull/3564 refactor(severity): unify API scan and compact CIS sort ranks by @msaad00 in https://github.com/msaad00/agent-bom/pull/3565 refactor(severity): canonical CIS sort ranks in HTML report by @msaad00 in https://github.com/msaad00/agent-bom/pull/3566 refactor(severity): canonical package severity rank in Mermaid output by @msaad00 in https://github.com/msaad00/agent-bom/pull/3567 refactor(severity): canonical CIS sort ranks in console renderer by @msaad00 in https://github.com/msaad00/agent-bom/pull/3568 refactor(severity): canonical sort ranks in skills, license, extensions by @msaad00 in https://github.com/msaad00/agent-bom/pull/3569 feat(reachability): export Python symbol reachability in findings by @msaad00 in https://github.com/msaad00/agent-bom/pull/3571 refactor(output): migrate markdown CVE sections to unified Finding by @msaad00 in https://github.com/msaad00/agent-bom/pull/3570 perf(db): partition hub observations with retention rollover by @msaad00 in https://github.com/msaad00/agent-bom/pull/3572 feat(reachability): include symbol reachability in delta-stream snapshots by @msaad00 in https://github.com/msaad00/agent-bom/pull/3573 refactor(output): migrate PDF CVE sections to unified Finding by @msaad00 in https://github.com/msaad00/agent-bom/pull/3574 feat(reachability): multilang symbol join + CWE/CVE/CPE advisory context by @msaad00 in https://github.com/msaad00/agent-bom/pull/3576 feat(reachability): wire symbol reach into triage scoring and VEX by @msaad00 in https://github.com/msaad00/agent-bom/pull/3577 refactor(output): migrate SARIF CVE loop to unified Finding stream by @msaad00 in https://github.com/msaad00/agent-bom/pull/3578 feat(reachability): Java/Rust AST symbol join for Maven and Cargo by @msaad00 in https://github.com/msaad00/agent-bom/pull/3579 docs(readme): product-first flow, compact persona band, plain-language taglines by @msaad00 in https://github.com/msaad00/agent-bom/pull/3580 feat(reachability): NuGet/C# AST symbol join for .NET MCP backends by @msaad00 in https://github.com/msaad00/agent-bom/pull/3581 feat(reachability): RubyGems AST symbol join for Rails MCP backends by @msaad00 in https://github.com/msaad00/agent-bom/pull/3582 feat(reachability): Gradle-only Java symbol join via build.gradle coords by @msaad00 in https://github.com/msaad00/agent-bom/pull/3584 docs(roadmap): validated quick-wins queue for evidence and discovery by @msaad00 in https://github.com/msaad00/agent-bom/pull/3583 feat(ingest): wire SARIF into external scanner detect_and_parse path by @msaad00 in https://github.com/msaad00/agent-bom/pull/3585 feat(vex): ingest CSAF and CycloneDX VEX documents by @msaad00 in https://github.com/msaad00/agent-bom/pull/3586 feat(output): registry verified badge and evidence ingest docs by @msaad00 in https://github.com/msaad00/agent-bom/pull/3587 refactor(output): migrate json and html CVE tables to Finding stream by @msaad00 in https://github.com/msaad00/agent-bom/pull/3588 feat(alignment): VEX on Finding stream and API scan field parity by @msaad00 in https://github.com/msaad00/agent-bom/pull/3589 chore(release): prepare v0.93.0 by @msaad00 in https://github.com/msaad00/agent-bom/pull/3590 feat(gap): pre-tag slice — Finding topology, lock cards, close #3242 by @msaad00 in https://github.com/msaad00/agent-bom/pull/3592 Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.92.0...v0.93.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/msaad00/agent-bom">https://github.com/msaad00/agent-bom</a></strong> to version <strong>v0.93.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-bom-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(docs): keep extension contract link mkdocs-strict safe by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3429">https://github.com/msaad00/agent-bom/pull/3429</a></li>
<li>docs(readme): refresh personas and terminal demo for 0.92.0 CLI by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3430">https://github.com/msaad00/agent-bom/pull/3430</a></li>
<li>fix(ci): unblock Sigma WebGL E2E dynamic import by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3432">https://github.com/msaad00/agent-bom/pull/3432</a></li>
<li>chore(perf): findings read bench and 2k CI regression by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3440">https://github.com/msaad00/agent-bom/pull/3440</a></li>
<li>feat(retention): enforce graph snapshot purge and history cap (PR1) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3441">https://github.com/msaad00/agent-bom/pull/3441</a></li>
<li>feat(api): server-side compliance hub findings pagination (PR1) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3442">https://github.com/msaad00/agent-bom/pull/3442</a></li>
<li>fix(scan): skip unreachable Go checksum lookups by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3443">https://github.com/msaad00/agent-bom/pull/3443</a></li>
<li>fix(compliance): normalize pci-dss slug alias and SAML install hint (#3439) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3444">https://github.com/msaad00/agent-bom/pull/3444</a></li>
<li>feat(helm): Alembic pre-upgrade hook; chore(sdks): bump Python SDK (#3433, #3438) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3445">https://github.com/msaad00/agent-bom/pull/3445</a></li>
<li>fix(scan): reduce secret FP on OAuth token minting assignments (#3437) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3447">https://github.com/msaad00/agent-bom/pull/3447</a></li>
<li>refactor(output): migrate compact and console formatters to Finding (#2918) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3448">https://github.com/msaad00/agent-bom/pull/3448</a></li>
<li>feat(skills): CI exit code and wider skill file discovery (#3434) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3449">https://github.com/msaad00/agent-bom/pull/3449</a></li>
<li>fix(hardening): Role enum, Grafana creds, ecosystem claims, HOSTS rollup (#3242) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3450">https://github.com/msaad00/agent-bom/pull/3450</a></li>
<li>feat(release): SBOM release asset, image scan gate, air-gap vuln-DB docs (#3436) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3451">https://github.com/msaad00/agent-bom/pull/3451</a></li>
<li>fix(hardening): severity unification and cosign/MCP audit fixes (#3242) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3452">https://github.com/msaad00/agent-bom/pull/3452</a></li>
<li>feat(retention): per-tenant graph retention and analytics cap (PR2) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3453">https://github.com/msaad00/agent-bom/pull/3453</a></li>
<li>feat(api): findings read PR2 — approximate counts and UI pagination (#3192) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3454">https://github.com/msaad00/agent-bom/pull/3454</a></li>
<li>chore(deps): combine dependency updates (2026-07-03) by @andres-linero in <a href="https://github.com/msaad00/agent-bom/pull/3460">https://github.com/msaad00/agent-bom/pull/3460</a></li>
<li>feat(api): expression-indexed severity/cvss finding sorts (#3192) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3461">https://github.com/msaad00/agent-bom/pull/3461</a></li>
<li>fix(api): idempotent finding ingest (P0) (#3242) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3462">https://github.com/msaad00/agent-bom/pull/3462</a></li>
<li>fix(reliability): tenant fail-closed, cloud retry, health rate-exempt, batch cap by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3464">https://github.com/msaad00/agent-bom/pull/3464</a></li>
<li>feat(enrich): bundle KEV and EPSS into offline vuln-DB layer by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3466">https://github.com/msaad00/agent-bom/pull/3466</a></li>
<li>feat(ui): labeled demo estate and surface lock states (PR1) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3467">https://github.com/msaad00/agent-bom/pull/3467</a></li>
<li>feat(api): finding lifecycle L1 — monotone current-state merge (#3465) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3470">https://github.com/msaad00/agent-bom/pull/3470</a></li>
<li>fix(api): batch cap returns 422 and index filtered severity+cvss reads (#3474) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3477">https://github.com/msaad00/agent-bom/pull/3477</a></li>
<li>chore(repo): hygiene + session cookie Secure default (#3475) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3479">https://github.com/msaad00/agent-bom/pull/3479</a></li>
<li>fix(auth): cluster-safe SAML RelayState nonce store (#3476) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3478">https://github.com/msaad00/agent-bom/pull/3478</a></li>
<li>feat(api): finding lifecycle L2 — occurrence log keyed on scan_id (#3465) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3480">https://github.com/msaad00/agent-bom/pull/3480</a></li>
<li>feat(sdk): expose finding lifecycle ingest on control-plane clients by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3483">https://github.com/msaad00/agent-bom/pull/3483</a></li>
<li>feat(api): finding lifecycle L3+L4 — resolve reconcile and current-state reads (#3465) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3481">https://github.com/msaad00/agent-bom/pull/3481</a></li>
<li>docs(audit): add sanitized 2026-07-03 ledger with issue mapping by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3500">https://github.com/msaad00/agent-bom/pull/3500</a></li>
<li>fix(api): harden OCSF ingest — cap/offload (A) + deterministic event IDs &amp; ClickHouse dedup (J) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3501">https://github.com/msaad00/agent-bom/pull/3501</a></li>
<li>feat(ui): interactive blast-radius overlay on the lineage graph by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3502">https://github.com/msaad00/agent-bom/pull/3502</a></li>
<li>fix(ui): dock graph lens switcher — stop overlaying the canvas by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3505">https://github.com/msaad00/agent-bom/pull/3505</a></li>
<li>docs(deploy): auto-migration hook, finding encryption prereq, ClickHouse OSS+Cloud by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3504">https://github.com/msaad00/agent-bom/pull/3504</a></li>
<li>feat(ui): wire estate roll-up navigation for large graphs by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3507">https://github.com/msaad00/agent-bom/pull/3507</a></li>
<li>fix(api,http): bound ScanRequest list elements and jitter sync retries by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3508">https://github.com/msaad00/agent-bom/pull/3508</a></li>
<li>fix(api): gate external compliance frameworks and lock OCSF product attribution by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3509">https://github.com/msaad00/agent-bom/pull/3509</a></li>
<li>fix(api): restore overview tiles from compact scans and add current-state sort indexes by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3515">https://github.com/msaad00/agent-bom/pull/3515</a></li>
<li>refactor(api): deduplicate current-state hub payloads via ledger refs by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3517">https://github.com/msaad00/agent-bom/pull/3517</a></li>
<li>feat(api): keyset cursor pagination for hub current-state findings by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3518">https://github.com/msaad00/agent-bom/pull/3518</a></li>
<li>perf(api): gzip JSON responses and zstd-compress hub payloads at rest by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3516">https://github.com/msaad00/agent-bom/pull/3516</a></li>
<li>feat(helm): enterprise-demo profile with AWS estate inventory cron by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3519">https://github.com/msaad00/agent-bom/pull/3519</a></li>
<li>feat(api,ui): overview graph drill and estate correlation API by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3520">https://github.com/msaad00/agent-bom/pull/3520</a></li>
<li>fix(cloud,helm): http_client GPU connectors + scoped API NetworkPolicy by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3522">https://github.com/msaad00/agent-bom/pull/3522</a></li>
<li>feat(scanners): runtime-enforce driver run() and failure_mode by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3524">https://github.com/msaad00/agent-bom/pull/3524</a></li>
<li>fix(api): Postgres rate-limit sliding window matches docstring by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3523">https://github.com/msaad00/agent-bom/pull/3523</a></li>
<li>docs: compact session/enforcement flow diagrams by @andres-linero in <a href="https://github.com/msaad00/agent-bom/pull/3525">https://github.com/msaad00/agent-bom/pull/3525</a></li>
<li>feat(api): async findings report export jobs by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3526">https://github.com/msaad00/agent-bom/pull/3526</a></li>
<li>perf(analytics): ClickHouse sink dedup for canonical rows by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3527">https://github.com/msaad00/agent-bom/pull/3527</a></li>
<li>fix(api): CVSS keyset pagination and report export truncation by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3530">https://github.com/msaad00/agent-bom/pull/3530</a></li>
<li>refactor(api): hub reference-table normalization by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3528">https://github.com/msaad00/agent-bom/pull/3528</a></li>
<li>docs(deploy): audit Alembic, encryption prerequisite, ClickHouse positioning by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3532">https://github.com/msaad00/agent-bom/pull/3532</a></li>
<li>fix(api/scim): group PATCH, deprovision keys, SCIM error envelopes by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3540">https://github.com/msaad00/agent-bom/pull/3540</a></li>
<li>feat(export): delta-stream connector for SIEM and data-lake sinks by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3531">https://github.com/msaad00/agent-bom/pull/3531</a></li>
<li>test(api): lock in hub current-state payload dedup by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3541">https://github.com/msaad00/agent-bom/pull/3541</a></li>
<li>feat(api): S3 report export artifacts with presigned URLs by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3542">https://github.com/msaad00/agent-bom/pull/3542</a></li>
<li>fix(api/scim): PUT full replace and schema discovery by id by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3543">https://github.com/msaad00/agent-bom/pull/3543</a></li>
<li>fix(api): gate bulk-ingest O(n) snapshot walk (#3544) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3545">https://github.com/msaad00/agent-bom/pull/3545</a></li>
<li>fix(fleet): local discovery push for fleet sync by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3546">https://github.com/msaad00/agent-bom/pull/3546</a></li>
<li>chore(glama): pin release ref and verify Dockerfile on publish by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3547">https://github.com/msaad00/agent-bom/pull/3547</a></li>
<li>docs(audit): sync AUDIT-2026-07-03 ledger with shipped main by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3550">https://github.com/msaad00/agent-bom/pull/3550</a></li>
<li>docs(readme): lead with personas, Start Here, and demo proof by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3548">https://github.com/msaad00/agent-bom/pull/3548</a></li>
<li>feat(headless): wire findings push CLI and hub current-state list (#3482) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3549">https://github.com/msaad00/agent-bom/pull/3549</a></li>
<li>feat(ui): show findings lifecycle status and timestamps in queue by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3551">https://github.com/msaad00/agent-bom/pull/3551</a></li>
<li>fix(cli): skip PyPI update check in offline and air-gap mode (#3242) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3552">https://github.com/msaad00/agent-bom/pull/3552</a></li>
<li>fix(deploy): mount ~/.agent-bom for abom user in compose profiles (#3242) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3553">https://github.com/msaad00/agent-bom/pull/3553</a></li>
<li>fix(cli): reject reserved tenant ids on CLI and MCP resolvers (#3242) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3554">https://github.com/msaad00/agent-bom/pull/3554</a></li>
<li>docs(audit): headless ingest docs and audit ledger sync by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3555">https://github.com/msaad00/agent-bom/pull/3555</a></li>
<li>fix(cli): honor &ndash;offline for PyPI check and loopback fleet push by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3556">https://github.com/msaad00/agent-bom/pull/3556</a></li>
<li>fix(headless): offline push, MCP check version, token-derived auth by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3557">https://github.com/msaad00/agent-bom/pull/3557</a></li>
<li>chore(ci): reject LLM co-author trailers in commit messages by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3558">https://github.com/msaad00/agent-bom/pull/3558</a></li>
<li>refactor(output): use canonical severity_rank in remediation plan by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3559">https://github.com/msaad00/agent-bom/pull/3559</a></li>
<li>docs(audit): sync ledger for headless hardening #3556-#3558 by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3560">https://github.com/msaad00/agent-bom/pull/3560</a></li>
<li>fix(auth): reject replayed OIDC JWTs via jti one-time store by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3561">https://github.com/msaad00/agent-bom/pull/3561</a></li>
<li>refactor(trust): derive CVE weights from canonical severity_rank by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3562">https://github.com/msaad00/agent-bom/pull/3562</a></li>
<li>docs(audit): sync ledger post #3561 OIDC jti replay by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3563">https://github.com/msaad00/agent-bom/pull/3563</a></li>
<li>feat(plugins): runtime activation for opt-in plugin entry points by @andres-linero in <a href="https://github.com/msaad00/agent-bom/pull/3564">https://github.com/msaad00/agent-bom/pull/3564</a></li>
<li>refactor(severity): unify API scan and compact CIS sort ranks by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3565">https://github.com/msaad00/agent-bom/pull/3565</a></li>
<li>refactor(severity): canonical CIS sort ranks in HTML report by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3566">https://github.com/msaad00/agent-bom/pull/3566</a></li>
<li>refactor(severity): canonical package severity rank in Mermaid output by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3567">https://github.com/msaad00/agent-bom/pull/3567</a></li>
<li>refactor(severity): canonical CIS sort ranks in console renderer by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3568">https://github.com/msaad00/agent-bom/pull/3568</a></li>
<li>refactor(severity): canonical sort ranks in skills, license, extensions by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3569">https://github.com/msaad00/agent-bom/pull/3569</a></li>
<li>feat(reachability): export Python symbol reachability in findings by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3571">https://github.com/msaad00/agent-bom/pull/3571</a></li>
<li>refactor(output): migrate markdown CVE sections to unified Finding by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3570">https://github.com/msaad00/agent-bom/pull/3570</a></li>
<li>perf(db): partition hub observations with retention rollover by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3572">https://github.com/msaad00/agent-bom/pull/3572</a></li>
<li>feat(reachability): include symbol reachability in delta-stream snapshots by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3573">https://github.com/msaad00/agent-bom/pull/3573</a></li>
<li>refactor(output): migrate PDF CVE sections to unified Finding by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3574">https://github.com/msaad00/agent-bom/pull/3574</a></li>
<li>feat(reachability): multilang symbol join + CWE/CVE/CPE advisory context by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3576">https://github.com/msaad00/agent-bom/pull/3576</a></li>
<li>feat(reachability): wire symbol reach into triage scoring and VEX by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3577">https://github.com/msaad00/agent-bom/pull/3577</a></li>
<li>refactor(output): migrate SARIF CVE loop to unified Finding stream by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3578">https://github.com/msaad00/agent-bom/pull/3578</a></li>
<li>feat(reachability): Java/Rust AST symbol join for Maven and Cargo by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3579">https://github.com/msaad00/agent-bom/pull/3579</a></li>
<li>docs(readme): product-first flow, compact persona band, plain-language taglines by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3580">https://github.com/msaad00/agent-bom/pull/3580</a></li>
<li>feat(reachability): NuGet/C# AST symbol join for .NET MCP backends by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3581">https://github.com/msaad00/agent-bom/pull/3581</a></li>
<li>feat(reachability): RubyGems AST symbol join for Rails MCP backends by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3582">https://github.com/msaad00/agent-bom/pull/3582</a></li>
<li>feat(reachability): Gradle-only Java symbol join via build.gradle coords by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3584">https://github.com/msaad00/agent-bom/pull/3584</a></li>
<li>docs(roadmap): validated quick-wins queue for evidence and discovery by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3583">https://github.com/msaad00/agent-bom/pull/3583</a></li>
<li>feat(ingest): wire SARIF into external scanner detect_and_parse path by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3585">https://github.com/msaad00/agent-bom/pull/3585</a></li>
<li>feat(vex): ingest CSAF and CycloneDX VEX documents by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3586">https://github.com/msaad00/agent-bom/pull/3586</a></li>
<li>feat(output): registry verified badge and evidence ingest docs by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3587">https://github.com/msaad00/agent-bom/pull/3587</a></li>
<li>refactor(output): migrate json and html CVE tables to Finding stream by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3588">https://github.com/msaad00/agent-bom/pull/3588</a></li>
<li>feat(alignment): VEX on Finding stream and API scan field parity by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3589">https://github.com/msaad00/agent-bom/pull/3589</a></li>
<li>chore(release): prepare v0.93.0 by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3590">https://github.com/msaad00/agent-bom/pull/3590</a></li>
<li>feat(gap): pre-tag slice — Finding topology, lock cards, close #3242 by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3592">https://github.com/msaad00/agent-bom/pull/3592</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/msaad00/agent-bom/compare/v0.92.0...v0.93.0">https://github.com/msaad00/agent-bom/compare/v0.92.0...v0.93.0</a></p>
]]></content:encoded></item><item><title>vimanam-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/vimanam-action/</link><pubDate>Mon, 06 Jul 2026 15:29:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/vimanam-action/</guid><description>Version updated for https://github.com/noemaforge/vimanam-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Vimanam is a high-performance OpenAPI/Swagger (JSON or YAML) to Markdown documentation generator. It supports OpenAPI 2.0 (Swagger) and OpenAPI 3.0 specifications.
While useful for human documentation, Vimanam is uniquely optimized for feeding API specifications to LLMs by condensing large multi-megabyte specs into token-budget-friendly Markdown representations.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/noemaforge/vimanam-action">https://github.com/noemaforge/vimanam-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vimanam-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Vimanam is a high-performance OpenAPI/Swagger (JSON or YAML) to Markdown documentation generator. It supports OpenAPI 2.0 (Swagger) and OpenAPI 3.0 specifications.</p>
<p>While useful for human documentation, Vimanam is uniquely optimized for feeding API specifications to LLMs by condensing large multi-megabyte specs into token-budget-friendly Markdown representations.</p>
<h2 id="what-it-is">What it is</h2>
<p>Vimanam translates complex API specs into clean, structured Markdown. Key features include:</p>
<ul>
<li>Multiple Detail Levels: Choose from summary, basic, standard, or full levels depending on how deep you want to go.</li>
<li>Token-Budget-Aware Rendering (&ndash;max-tokens): Input a maximum token budget, and Vimanam will automatically step down the detail level of the documentation until it fits, outputting what was trimmed to stderr.</li>
<li>Deterministic, Byte-Identical Output: Guaranteed stable output across identical runs, which maximizes LLM prompt-caching efficiency.</li>
<li>Compact Schema Expansion: Component schemas reached through $ref are expanded once in a trailing &ldquo;Schema Definitions&rdquo; section to keep output size compact, with an option (&ndash;inline-schemas) to inline them directly.</li>
<li>Beautiful Grouping: Group endpoints by service (tags), HTTP methods, path, or leave them flat.</li>
</ul>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">noemaforge/vimanam-action@4599a14c84d9d7bce1ec34ed9f12f3036f06b518</span> <span style="color:#75715e"># v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">spec</span>: <span style="color:#ae81ff">openapi.json</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">output</span>: <span style="color:#ae81ff">docs/api.md</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">detail</span>: <span style="color:#ae81ff">full</span>
</span></span></code></pre></div><blockquote>
<p><strong>Pin to a commit SHA, not a tag.</strong> See <a href="#pinning">Pinning</a> below — it matters for security.</p>
</blockquote>
<h2 id="keep-docs-in-sync-staleness-gate">Keep docs in sync (staleness gate)</h2>
<p>vimanam&rsquo;s output is deterministic, so you can fail CI whenever the committed docs drift from
the spec:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">noemaforge/vimanam-action@4599a14c84d9d7bce1ec34ed9f12f3036f06b518</span> <span style="color:#75715e"># v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">spec</span>: <span style="color:#ae81ff">openapi.json</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">output</span>: <span style="color:#ae81ff">docs/api-map.md</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">detail</span>: <span style="color:#ae81ff">summary</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">name</span>: <span style="color:#ae81ff">Fail if docs are stale</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">run</span>: <span style="color:#ae81ff">git diff --exit-code -- docs/api-map.md</span>
</span></span><span style="display:flex;"><span>    <span style="color:#ae81ff">|| { echo &#34;::error::docs/api-map.md is out of date — regenerate and commit&#34;; exit 1; }</span>
</span></span></code></pre></div><p>See <a href="examples/"><code>examples/</code></a> for complete workflows.</p>
<h2 id="pinning">Pinning</h2>
<p><strong>Always pin GitHub Actions — including this one — to a full 40-character commit SHA, not a
tag.</strong> Tags like <code>@v1</code> are <em>mutable</em>: whoever controls the action&rsquo;s repo can move them to point
at new code at any time. If an action (or one of its maintainers&rsquo; accounts) is ever compromised,
an attacker can repoint the tag and your workflow silently runs their code — with access to your
repo token and secrets. This is a real, recurring supply-chain attack vector.</p>
<p>A commit SHA is <strong>immutable</strong>: it always resolves to the exact code you reviewed. It is currently
the only way to use an action as an immutable release.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#75715e"># ✅ pinned — immutable, audit once and trust</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">noemaforge/vimanam-action@4599a14c84d9d7bce1ec34ed9f12f3036f06b518</span> <span style="color:#75715e"># v1</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># ❌ mutable — the tag can be repointed at any time</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">noemaforge/vimanam-action@v1</span>
</span></span></code></pre></div><p>Keep the <code># v1</code> trailing comment so the version stays human-readable.
<a href="https://docs.github.com/code-security/dependabot">Dependabot</a> and
<a href="https://docs.renovatebot.com/">Renovate</a> both understand SHA-pinned actions and will open PRs
to bump the SHA (and the comment) when a new release lands — so pinning costs you nothing in
maintenance. Many orgs now <a href="https://github.blog/changelog/2025-08-15-github-actions-policy-now-supports-blocking-and-sha-pinning-actions/">enforce SHA pinning by policy</a>.</p>
<p>Find the SHA for any tag on the <a href="https://github.com/noemaforge/vimanam-action/releases">releases page</a>
or with:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>gh api repos/noemaforge/vimanam-action/commits/v1 --jq .sha
</span></span></code></pre></div><h2 id="inputs">Inputs</h2>
<table>
  <thead>
      <tr>
          <th>Input</th>
          <th>Required</th>
          <th>Default</th>
          <th>Description</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>spec</code></td>
          <td>yes</td>
          <td>—</td>
          <td>Path to the OpenAPI/Swagger JSON spec</td>
      </tr>
      <tr>
          <td><code>output</code></td>
          <td>no</td>
          <td>stdout</td>
          <td>Output Markdown file path</td>
      </tr>
      <tr>
          <td><code>detail</code></td>
          <td>no</td>
          <td>vimanam default</td>
          <td><code>summary</code> | <code>basic</code> | <code>standard</code> | <code>full</code></td>
      </tr>
      <tr>
          <td><code>group-by</code></td>
          <td>no</td>
          <td>vimanam default</td>
          <td><code>service</code> | <code>method</code> | <code>path</code></td>
      </tr>
      <tr>
          <td><code>args</code></td>
          <td>no</td>
          <td>—</td>
          <td>Extra raw CLI args appended verbatim (e.g. <code>--service-filter Auth --include-auth</code>)</td>
      </tr>
      <tr>
          <td><code>version</code></td>
          <td>no</td>
          <td><code>v0.6.0</code></td>
          <td>vimanam release tag to install</td>
      </tr>
      <tr>
          <td><code>token</code></td>
          <td>no</td>
          <td><code>${{ github.token }}</code></td>
          <td>Token used to download release assets</td>
      </tr>
  </tbody>
</table>
<h2 id="supported-runners">Supported runners</h2>
<table>
  <thead>
      <tr>
          <th>OS</th>
          <th>Arch</th>
          <th></th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Linux</td>
          <td>x86_64, aarch64</td>
          <td>✓</td>
      </tr>
      <tr>
          <td>macOS</td>
          <td>Intel, Apple Silicon</td>
          <td>✓</td>
      </tr>
      <tr>
          <td>Windows</td>
          <td>x86_64</td>
          <td>✓</td>
      </tr>
  </tbody>
</table>
<p>Other combinations (e.g. Windows ARM) have no prebuilt binary; the action fails with a clear message.</p>
<h2 id="license">License</h2>
<p><a href="LICENSE">Apache-2.0</a></p>
]]></content:encoded></item><item><title>Nox Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/nox-security-scanner/</link><pubDate>Mon, 06 Jul 2026 15:29:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/nox-security-scanner/</guid><description>Version updated for https://github.com/Nox-HQ/nox to version v1.7.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Nox v1.7.1 (2026-07-06T11:16:23Z) Language-agnostic security scanner with first-class AI application security.
Installation macOS/Linux (Homebrew) brew tap felixgeelhaar/tap brew install nox Direct Download Download the appropriate archive for your platform from the assets below.
What’s Changed Changelog Bug Fixes 8082b46b7debac25261e0b069ede57ec682a864f fix(scan): restore –baseline override flag + friendly unknown-flag error (#224) Others f432fad83ab0d0a783509f8aba7c3d31a569158e chore(release): 1.7.1 — restore –baseline override flag (#226) Full Changelog: https://github.com/nox-hq/nox/compare/v1.7.0...v1.7.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Nox-HQ/nox">https://github.com/Nox-HQ/nox</a></strong> to version <strong>v1.7.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nox-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="nox-v171-2026-07-06t111623z">Nox v1.7.1 (2026-07-06T11:16:23Z)</h2>
<p>Language-agnostic security scanner with first-class AI application security.</p>
<h3 id="installation">Installation</h3>
<h4 id="macoslinux-homebrew">macOS/Linux (Homebrew)</h4>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>brew tap felixgeelhaar/tap
</span></span><span style="display:flex;"><span>brew install nox
</span></span></code></pre></div><h4 id="direct-download">Direct Download</h4>
<p>Download the appropriate archive for your platform from the assets below.</p>
<h3 id="whats-changed-1">What&rsquo;s Changed</h3>
<h2 id="changelog">Changelog</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>8082b46b7debac25261e0b069ede57ec682a864f fix(scan): restore &ndash;baseline override flag + friendly unknown-flag error (#224)</li>
</ul>
<h3 id="others">Others</h3>
<ul>
<li>f432fad83ab0d0a783509f8aba7c3d31a569158e chore(release): 1.7.1 — restore &ndash;baseline override flag (#226)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nox-hq/nox/compare/v1.7.0...v1.7.1">https://github.com/nox-hq/nox/compare/v1.7.0...v1.7.1</a></p>
]]></content:encoded></item><item><title>Open Delivery Spec</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/open-delivery-spec/</link><pubDate>Mon, 06 Jul 2026 15:28:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/open-delivery-spec/</guid><description>Version updated for https://github.com/open-delivery-spec/validate-action to version v0.2.2.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed 🚀 Features feat: surface and act on the policy review_tier verdict by @shenxianpeng in #46 🐛 Bug fixes fix: add manual repair path to the existing Move Major Tag workflow by @shenxianpeng in #49 📝 Documentation docs: document the kernel Assisted-by trailer in the attribution table by @shenxianpeng in #48 👻 Maintenance chore: bump default cli-ref to v0.4.0 by @shenxianpeng in #47 Full Changelog: https://github.com/open-delivery-spec/validate-action/compare/v0.2.1...v0.2.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/open-delivery-spec/validate-action">https://github.com/open-delivery-spec/validate-action</a></strong> to version <strong>v0.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/open-delivery-spec">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h2 id="-features">🚀 Features</h2>
<ul>
<li>feat: surface and act on the policy review_tier verdict by @shenxianpeng in #46</li>
</ul>
<h2 id="-bug-fixes">🐛 Bug fixes</h2>
<ul>
<li>fix: add manual repair path to the existing Move Major Tag workflow by @shenxianpeng in #49</li>
</ul>
<h2 id="-documentation">📝 Documentation</h2>
<ul>
<li>docs: document the kernel Assisted-by trailer in the attribution table by @shenxianpeng in #48</li>
</ul>
<h2 id="-maintenance">👻 Maintenance</h2>
<ul>
<li>chore: bump default cli-ref to v0.4.0 by @shenxianpeng in #47</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/open-delivery-spec/validate-action/compare/v0.2.1...v0.2.2">https://github.com/open-delivery-spec/validate-action/compare/v0.2.1...v0.2.2</a></p>
]]></content:encoded></item><item><title>Download a Build Artifact (oro)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/download-a-build-artifact-oro/</link><pubDate>Mon, 06 Jul 2026 15:28:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/download-a-build-artifact-oro/</guid><description>Version updated for https://github.com/orochibraru/download-artifact to version v8.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed fix: readme name [skip ci] (f4f9265) fix: fuck check dist (95c65d2) fix: version (5540036) fix: immutable action version (95d8c95) fix: action name (ce57196) chore: removed unused packages (048b6bd) fix: bun cfg (681facc) fix: biome lint (ca0a98c) chore: my stuff + disable ghes warns (8bb719c) fix: isghes (d32f35d)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/orochibraru/download-artifact">https://github.com/orochibraru/download-artifact</a></strong> to version <strong>v8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/download-a-build-artifact-oro">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: readme name [skip ci] (f4f9265)</li>
<li>fix: fuck check dist (95c65d2)</li>
<li>fix: version (5540036)</li>
<li>fix: immutable action version (95d8c95)</li>
<li>fix: action name (ce57196)</li>
<li>chore: removed unused packages (048b6bd)</li>
<li>fix: bun cfg (681facc)</li>
<li>fix: biome lint (ca0a98c)</li>
<li>chore: my stuff + disable ghes warns (8bb719c)</li>
<li>fix: isghes (d32f35d)</li>
</ul>
]]></content:encoded></item><item><title>Upload a Build Artifact (oro)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/upload-a-build-artifact-oro/</link><pubDate>Mon, 06 Jul 2026 15:27:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/upload-a-build-artifact-oro/</guid><description>Version updated for https://github.com/orochibraru/upload-artifact to version v8.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed fix: missing patch on ghes (aeca548) fix: ghes (fc8717e) fix: action name [skip ci] (f897267) fix: fuck check dist (6ab8cd6) fix: version (486bd7f) fix: immutable action version (4bb427a) fix: rebuilt assets (52f6ae9) fix: lockfile (11b092a) fix: action name (164535d) chore: trigger ci (dc9c7e9)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/orochibraru/upload-artifact">https://github.com/orochibraru/upload-artifact</a></strong> to version <strong>v8.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/upload-a-build-artifact-oro">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: missing patch on ghes (aeca548)</li>
<li>fix: ghes (fc8717e)</li>
<li>fix: action name [skip ci] (f897267)</li>
<li>fix: fuck check dist (6ab8cd6)</li>
<li>fix: version (486bd7f)</li>
<li>fix: immutable action version (4bb427a)</li>
<li>fix: rebuilt assets (52f6ae9)</li>
<li>fix: lockfile (11b092a)</li>
<li>fix: action name (164535d)</li>
<li>chore: trigger ci (dc9c7e9)</li>
</ul>
]]></content:encoded></item><item><title>Polygraph MCP gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/polygraph-mcp-gate/</link><pubDate>Mon, 06 Jul 2026 15:26:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/polygraph-mcp-gate/</guid><description>Version updated for https://github.com/polygraphso/litmus to version litmus-v0.29.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed litmus-v13 — C-01 tool-output-injection false-positive recalibration.
Honest servers no longer flip to F on benign patterns that merely resemble injection. The C-01 static/output text scan now distinguishes real hijack attempts from ordinary documentation:
angle-bracket placeholders in usage text (&amp;lt;tool&amp;gt;, &amp;lt;system|...&amp;gt;) data: / format examples (data:image/*;base64,…, XML/JSX samples) benign second-person prose in tool descriptions and returned docs U+200B zero-width doc artifacts — regraded MEDIUM, with keyword-evasion still caught HIGH via normalize-then-scan (ins&amp;lt;ZW&amp;gt;tructions de-obfuscates before the keyword pass) Skills keep every invisible character HIGH (S-01 strict). True-positive detection is preserved — the evil / injecting / second-order fixtures still grade F.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/polygraphso/litmus">https://github.com/polygraphso/litmus</a></strong> to version <strong>litmus-v0.29.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/polygraph-mcp-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>litmus-v13 — C-01 tool-output-injection false-positive recalibration.</strong></p>
<p>Honest servers no longer flip to <strong>F</strong> on benign patterns that merely resemble injection. The C-01 static/output text scan now distinguishes real hijack attempts from ordinary documentation:</p>
<ul>
<li>angle-bracket <strong>placeholders</strong> in usage text (<code>&lt;tool&gt;</code>, <code>&lt;system|...&gt;</code>)</li>
<li><code>data:</code> / format <strong>examples</strong> (<code>data:image/*;base64,…</code>, XML/JSX samples)</li>
<li>benign second-person <strong>prose</strong> in tool descriptions and returned docs</li>
<li><code>U+200B</code> <strong>zero-width</strong> doc artifacts — regraded MEDIUM, with keyword-evasion still caught HIGH via normalize-then-scan (<code>ins&lt;ZW&gt;tructions</code> de-obfuscates before the keyword pass)</li>
</ul>
<p>Skills keep every invisible character HIGH (S-01 strict). True-positive detection is preserved — the evil / injecting / second-order fixtures still grade <strong>F</strong>.</p>
<p><code>methodologyVersion</code> → <strong>litmus-v13</strong> (grades can move, so older attestations coexist by string).</p>
<p>Ships #101 (fix) + #102 (release bump).</p>
]]></content:encoded></item><item><title>Agent PR Police</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/agent-pr-police/</link><pubDate>Mon, 06 Jul 2026 15:26:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/agent-pr-police/</guid><description>Version updated for https://github.com/Pradumnasaraf/agent-pr-police to version v1.3.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Features expand and verify the agent detection registry (#3) (c043745)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Pradumnasaraf/agent-pr-police">https://github.com/Pradumnasaraf/agent-pr-police</a></strong> to version <strong>v1.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-pr-police">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="features">Features</h3>
<ul>
<li>expand and verify the agent detection registry (<a href="https://github.com/Pradumnasaraf/agent-pr-police/issues/3">#3</a>) (<a href="https://github.com/Pradumnasaraf/agent-pr-police/commit/c043745a32dbe705409a4c502e08f316eb664b73">c043745</a>)</li>
</ul>
]]></content:encoded></item><item><title>Python Semantic Release - Publish</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/python-semantic-release-publish/</link><pubDate>Mon, 06 Jul 2026 15:25:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/python-semantic-release-publish/</guid><description>Version updated for https://github.com/python-semantic-release/publish-action to version v10.6.1.
This action is used across all versions by 662 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v10.6.1 (2026-07-06) Build System deps: Bump python-semantic-release@v10.6.0 to v10.6.1 (#104, 5a5718c) Detailed Changes: v10.6.0…v10.6.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/python-semantic-release/publish-action">https://github.com/python-semantic-release/publish-action</a></strong> to version <strong>v10.6.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>662</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/python-semantic-release-publish">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v1061-2026-07-06">v10.6.1 (2026-07-06)</h2>
<h3 id="build-system">Build System</h3>
<ul>
<li><strong>deps</strong>: Bump <code>python-semantic-release@v10.6.0</code> to <code>v10.6.1</code> (<a href="https://github.com/python-semantic-release/publish-action/pull/104">#104</a>, <a href="https://github.com/python-semantic-release/publish-action/commit/5a5718ce47b892ef699f2972dae122297771d641"><code>5a5718c</code></a>)</li>
</ul>
<hr>
<p><strong>Detailed Changes</strong>: <a href="https://github.com/python-semantic-release/publish-action/compare/v10.6.0...v10.6.1">v10.6.0&hellip;v10.6.1</a></p>
]]></content:encoded></item><item><title>release-please-oss-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/release-please-oss-action/</link><pubDate>Mon, 06 Jul 2026 15:25:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/release-please-oss-action/</guid><description>Version updated for https://github.com/release-please-oss/release-please-action to version v6.0.3.
This action is used across all versions by 13 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 6.0.3 (2026-07-06) Bug Fixes ESM globals shims (5329246) Miscellaneous Chores automated dist build (#55) (db21fb4) deps: update github-actions (#53) (31e2a33) deps: update github-actions (#56) (77c4f32) deps: update github-actions to v7 (#57) (8b506ac) deps: update npm dependencies (#52) (42d21e3) deps: update npm dependencies (#58) (6e29bd8)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/release-please-oss/release-please-action">https://github.com/release-please-oss/release-please-action</a></strong> to version <strong>v6.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>13</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/release-please-oss-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="603-2026-07-06"><a href="https://github.com/release-please-oss/release-please-action/compare/v6.0.2...v6.0.3">6.0.3</a> (2026-07-06)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>ESM globals shims (<a href="https://github.com/release-please-oss/release-please-action/commit/532924610d8d4c8c80335e219bbee311d21954a6">5329246</a>)</li>
</ul>
<h3 id="miscellaneous-chores">Miscellaneous Chores</h3>
<ul>
<li>automated dist build (<a href="https://github.com/release-please-oss/release-please-action/issues/55">#55</a>) (<a href="https://github.com/release-please-oss/release-please-action/commit/db21fb486d75a624030b8678b5c4cb7c1ff6d359">db21fb4</a>)</li>
<li><strong>deps:</strong> update github-actions (<a href="https://github.com/release-please-oss/release-please-action/issues/53">#53</a>) (<a href="https://github.com/release-please-oss/release-please-action/commit/31e2a33337faeb45403592514152951d3368d10f">31e2a33</a>)</li>
<li><strong>deps:</strong> update github-actions (<a href="https://github.com/release-please-oss/release-please-action/issues/56">#56</a>) (<a href="https://github.com/release-please-oss/release-please-action/commit/77c4f32a9573dd1fbcc226ca1eb30c4983470455">77c4f32</a>)</li>
<li><strong>deps:</strong> update github-actions to v7 (<a href="https://github.com/release-please-oss/release-please-action/issues/57">#57</a>) (<a href="https://github.com/release-please-oss/release-please-action/commit/8b506ac4b824eb8d43c118054357eba676f6a592">8b506ac</a>)</li>
<li><strong>deps:</strong> update npm dependencies (<a href="https://github.com/release-please-oss/release-please-action/issues/52">#52</a>) (<a href="https://github.com/release-please-oss/release-please-action/commit/42d21e3deb8bad37fe9f36bf59a40d89b4c137e7">42d21e3</a>)</li>
<li><strong>deps:</strong> update npm dependencies (<a href="https://github.com/release-please-oss/release-please-action/issues/58">#58</a>) (<a href="https://github.com/release-please-oss/release-please-action/commit/6e29bd8ade048df804f028acfe6b15a27bbcb14b">6e29bd8</a>)</li>
</ul>
]]></content:encoded></item><item><title>AgentAuditKit MCP Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/agentauditkit-mcp-security-scan/</link><pubDate>Mon, 06 Jul 2026 15:24:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/agentauditkit-mcp-security-scan/</guid><description>Version updated for https://github.com/sattyamjjain/agent-audit-kit to version v0.3.46.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Installation pip:
pip install agent-audit-kit==v0.3.46 Docker:
docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.46 GitHub Action:
- uses: sattyamjjain/agent-audit-kit@v0.3.46 with: fail-on: high Supply chain rules.json — deterministic rule bundle rules.json.sha256 — trusted digest sbom.cdx.json / sbom.spdx.json — CycloneDX + SPDX SBOM *.sigstore — Sigstore keyless signatures (verify with agent-audit-kit verify-bundle) What’s Changed feat: State of MCP Security 2026 data-report harness by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/373 docs: kill public rule-count drift (221-&amp;gt;225) + promote MCP-security data-report by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/382 chore(deps): Bump actions/setup-python from 6.2.0 to 6.3.0 by @dependabot[bot] in https://github.com/sattyamjjain/agent-audit-kit/pull/377 chore(deps): Bump click from 8.1.8 to 8.4.2 by @dependabot[bot] in https://github.com/sattyamjjain/agent-audit-kit/pull/376 chore(deps): bump github/codeql-action to v4.36.2 (all steps together) by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/383 docs: finish State of MCP Security 2026 report (launch-ready) + v0.3.42 by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/392 feat: MCP prevalence scan (664 configs) + score calibration (#23) by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/393 feat(rules): pin CVE-2026-52830 bearer-token path-traversal (AAK-MCP-AUTH-PATHTRAVERSAL-001, #394) by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/396 feat: MCP Server Card (SEP-1649) static scanner + prevalence crawler by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/397 feat: public OWASP coverage leaderboard (#67) + Kong Konnect MCP CVE-2026-13341 by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/405 feat(bench): reproducibility head-to-head — 20-run byte-identical finding set by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/406 fix(rules): AAK-FLOWISE-001 pin 3.1.2→3.1.3 for CVE-2026-58057 (closes #372) by @sattyamjjain in https://github.com/sattyamjjain/agent-audit-kit/pull/407 Full Changelog: https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.41...v0.3.46</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sattyamjjain/agent-audit-kit">https://github.com/sattyamjjain/agent-audit-kit</a></strong> to version <strong>v0.3.46</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentauditkit-mcp-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="installation">Installation</h2>
<p><strong>pip:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install agent-audit-kit<span style="color:#f92672">==</span>v0.3.46
</span></span></code></pre></div><p><strong>Docker:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>docker pull ghcr.io/sattyamjjain/agent-audit-kit:v0.3.46
</span></span></code></pre></div><p><strong>GitHub Action:</strong></p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sattyamjjain/agent-audit-kit@v0.3.46</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fail-on</span>: <span style="color:#ae81ff">high</span>
</span></span></code></pre></div><h2 id="supply-chain">Supply chain</h2>
<ul>
<li><code>rules.json</code> — deterministic rule bundle</li>
<li><code>rules.json.sha256</code> — trusted digest</li>
<li><code>sbom.cdx.json</code> / <code>sbom.spdx.json</code> — CycloneDX + SPDX SBOM</li>
<li><code>*.sigstore</code> — Sigstore keyless signatures (verify with <code>agent-audit-kit verify-bundle</code>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: State of MCP Security 2026 data-report harness by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/373">https://github.com/sattyamjjain/agent-audit-kit/pull/373</a></li>
<li>docs: kill public rule-count drift (221-&gt;225) + promote MCP-security data-report by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/382">https://github.com/sattyamjjain/agent-audit-kit/pull/382</a></li>
<li>chore(deps): Bump actions/setup-python from 6.2.0 to 6.3.0 by @dependabot[bot] in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/377">https://github.com/sattyamjjain/agent-audit-kit/pull/377</a></li>
<li>chore(deps): Bump click from 8.1.8 to 8.4.2 by @dependabot[bot] in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/376">https://github.com/sattyamjjain/agent-audit-kit/pull/376</a></li>
<li>chore(deps): bump github/codeql-action to v4.36.2 (all steps together) by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/383">https://github.com/sattyamjjain/agent-audit-kit/pull/383</a></li>
<li>docs: finish State of MCP Security 2026 report (launch-ready) + v0.3.42 by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/392">https://github.com/sattyamjjain/agent-audit-kit/pull/392</a></li>
<li>feat: MCP prevalence scan (664 configs) + score calibration (#23) by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/393">https://github.com/sattyamjjain/agent-audit-kit/pull/393</a></li>
<li>feat(rules): pin CVE-2026-52830 bearer-token path-traversal (AAK-MCP-AUTH-PATHTRAVERSAL-001, #394) by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/396">https://github.com/sattyamjjain/agent-audit-kit/pull/396</a></li>
<li>feat: MCP Server Card (SEP-1649) static scanner + prevalence crawler by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/397">https://github.com/sattyamjjain/agent-audit-kit/pull/397</a></li>
<li>feat: public OWASP coverage leaderboard (#67) + Kong Konnect MCP CVE-2026-13341 by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/405">https://github.com/sattyamjjain/agent-audit-kit/pull/405</a></li>
<li>feat(bench): reproducibility head-to-head — 20-run byte-identical finding set by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/406">https://github.com/sattyamjjain/agent-audit-kit/pull/406</a></li>
<li>fix(rules): AAK-FLOWISE-001 pin 3.1.2→3.1.3 for CVE-2026-58057 (closes #372) by @sattyamjjain in <a href="https://github.com/sattyamjjain/agent-audit-kit/pull/407">https://github.com/sattyamjjain/agent-audit-kit/pull/407</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.41...v0.3.46">https://github.com/sattyamjjain/agent-audit-kit/compare/v0.3.41...v0.3.46</a></p>
]]></content:encoded></item><item><title>Snapshot auto-fix PR</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/snapshot-auto-fix-pr/</link><pubDate>Mon, 06 Jul 2026 15:24:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/snapshot-auto-fix-pr/</guid><description>Version updated for https://github.com/sedlukha/snapshot-autofix-pr to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial public release.
Composite GitHub Action that runs a visual-snapshot command which updates baselines, then opens, updates, or closes a single auto-fix pull request carrying only the changed snapshot files. Capture-agnostic — works with Playwright, Storybook, or your own script.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sedlukha/snapshot-autofix-pr">https://github.com/sedlukha/snapshot-autofix-pr</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/snapshot-auto-fix-pr">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial public release.</p>
<p>Composite GitHub Action that runs a visual-snapshot command which updates baselines, then opens, updates, or closes <strong>a single auto-fix pull request</strong> carrying only the changed snapshot files. Capture-agnostic — works with Playwright, Storybook, or your own script.</p>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">sedlukha/snapshot-autofix-pr@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">token</span>: <span style="color:#ae81ff">${{ secrets.PAT_TOKEN }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">run-command</span>: <span style="color:#ae81ff">npx playwright test --update-snapshots</span>
</span></span></code></pre></div><p>See the <a href="https://github.com/sedlukha/snapshot-autofix-pr#readme">README</a> for all inputs/outputs and examples.</p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/bernstein-multi-agent-orchestration/</link><pubDate>Mon, 06 Jul 2026 15:23:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v2.16.1.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.16.1 Released 2026-07-06.
Fixes Windows: adapter binaries installed as .cmd/.bat shims (for example Codex via nvm-windows) now spawn correctly. The worker resolves the adapter binary to its absolute path before spawning and routes resolved shims through the command interpreter on Windows, and PATHEXT is passed through the worker environment. Real executables and all POSIX spawns are unchanged. (#2287, #2290; thanks @ViteaVlaikov for the report and diagnostics)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v2.16.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v2161">v2.16.1</h1>
<p>Released 2026-07-06.</p>
<h2 id="fixes">Fixes</h2>
<ul>
<li>Windows: adapter binaries installed as <code>.cmd</code>/<code>.bat</code> shims (for example Codex via nvm-windows) now spawn correctly. The worker resolves the adapter binary to its absolute path before spawning and routes resolved shims through the command interpreter on Windows, and <code>PATHEXT</code> is passed through the worker environment. Real executables and all POSIX spawns are unchanged. (#2287, #2290; thanks @ViteaVlaikov for the report and diagnostics)</li>
</ul>
]]></content:encoded></item><item><title>Pipr Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/pipr-review/</link><pubDate>Mon, 06 Jul 2026 15:22:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/pipr-review/</guid><description>Version updated for https://github.com/somus/pipr to version v0.2.1.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.2.1 (2026-07-06) Features cli: bundle pipr setup skill (#18) (801957d) make review runs retry-safe (#21) (98dc50f)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somus/pipr">https://github.com/somus/pipr</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pipr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="021-2026-07-06"><a href="https://github.com/somus/pipr/compare/v0.2.0...v0.2.1">0.2.1</a> (2026-07-06)</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>cli:</strong> bundle pipr setup skill (<a href="https://github.com/somus/pipr/issues/18">#18</a>) (<a href="https://github.com/somus/pipr/commit/801957d8ea8ed5d04ddeaf8efa8d122c174e7c83">801957d</a>)</li>
<li>make review runs retry-safe (<a href="https://github.com/somus/pipr/issues/21">#21</a>) (<a href="https://github.com/somus/pipr/commit/98dc50f10d24e0f4c00d49fc2df951d4b90f953a">98dc50f</a>)</li>
</ul>
]]></content:encoded></item><item><title>Trigv</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/trigv/</link><pubDate>Mon, 06 Jul 2026 15:22:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/trigv/</guid><description>Version updated for https://github.com/Trigv/trigv-github-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First public release of the official Trigv GitHub Action.
Send a native push notification when a workflow succeeds or fails — one step, no curl.
Requirements: Trigv account, API key, Trigv for iOS on your phone.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Trigv/trigv-github-action">https://github.com/Trigv/trigv-github-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/trigv">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release of the official Trigv GitHub Action.</p>
<p>Send a native push notification when a workflow succeeds or fails — one step, no curl.</p>
<p>Requirements: Trigv account, API key, Trigv for iOS on your phone.</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Trigv/trigv-github-action@v1.0.0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.TRIGV_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">channel</span>: <span style="color:#ae81ff">ci</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">title</span>: <span style="color:#ae81ff">Workflow failed</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">level</span>: <span style="color:#ae81ff">error</span>
</span></span></code></pre></div><p>Docs: <a href="https://trigv.com/docs/learn/github-actions/">https://trigv.com/docs/learn/github-actions/</a></p>
]]></content:encoded></item><item><title>setup-hcloud</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/setup-hcloud/</link><pubDate>Mon, 06 Jul 2026 15:21:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/setup-hcloud/</guid><description>Version updated for https://github.com/vbem/setup-hcloud to version v1.0.5.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/vbem/setup-hcloud/compare/v1.0.4...v1.0.5</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vbem/setup-hcloud">https://github.com/vbem/setup-hcloud</a></strong> to version <strong>v1.0.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-hcloud">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vbem/setup-hcloud/compare/v1.0.4...v1.0.5">https://github.com/vbem/setup-hcloud/compare/v1.0.4...v1.0.5</a></p>
]]></content:encoded></item><item><title>vilancer-bugbit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/vilancer-bugbit/</link><pubDate>Mon, 06 Jul 2026 15:21:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/vilancer-bugbit/</guid><description>Version updated for https://github.com/Vilancer/bugbit to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed action.yml load failure — Removed invalid workflow expression from action metadata that caused Failed to load action.yml on all consumers. workflow_dispatch runtime — resolveEvent uses fetch for GitHub API instead of an unbundled @actions/github import. @v1 updated to this release.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Vilancer/bugbit">https://github.com/Vilancer/bugbit</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vilancer-bugbit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="fixed">Fixed</h2>
<ul>
<li><strong>action.yml load failure</strong> — Removed invalid workflow expression from action metadata that caused <code>Failed to load action.yml</code> on all consumers.</li>
<li><strong>workflow_dispatch runtime</strong> — <code>resolveEvent</code> uses <code>fetch</code> for GitHub API instead of an unbundled <code>@actions/github</code> import.</li>
</ul>
<p><code>@v1</code> updated to this release.</p>
]]></content:encoded></item><item><title>HumaneProxy Safety Benchmark</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/humaneproxy-safety-benchmark/</link><pubDate>Mon, 06 Jul 2026 15:20:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/humaneproxy-safety-benchmark/</guid><description>Version updated for https://github.com/Vishisht16/Humane-Proxy to version v0.5.6.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed This release rolls up the 0.5.x bug-fix series (0.5.1-0.5.6) — the result of a full audit of the codebase against its documentation. Every fix ships with regression tests: the suite grew from 298 to 353 tests, with zero skips and zero expected failures.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Vishisht16/Humane-Proxy">https://github.com/Vishisht16/Humane-Proxy</a></strong> to version <strong>v0.5.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/humaneproxy-safety-benchmark">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This release rolls up the 0.5.x bug-fix series (0.5.1-0.5.6) — the result of a full audit of the codebase against its documentation. Every fix ships with regression tests: the suite grew from 298 to 353 tests, with zero skips and zero expected failures.</p>
<h3 id="critical-fixes">Critical fixes</h3>
<ul>
<li><strong>Email-only alert configs never dispatched</strong> — the webhook gate checked a key that does not exist in the config schema. If SMTP was your only alert channel, you received nothing. (0.5.1)</li>
<li><strong>Redis rate limiting never triggered</strong> — the per-session counter was set once and never incremented, allowing unlimited alerts. Replaced with an atomic Lua <code>INCR</code>+<code>EXPIRE</code> script that also removes the multi-worker race from #5. (0.5.1)</li>
<li><strong>LlamaGuard category mapping</strong> — S9 (Indiscriminate Weapons) was mapped to <code>safe</code> and S10 (Hate) to <code>self_harm</code>, so weapons queries passed Stage 3 unflagged while hate speech received a suicide-crisis care response. (0.5.1)</li>
<li><strong>User configuration finally reaches the classifiers</strong> — <code>heuristics:</code> and <code>trajectory:</code> overrides in <code>humane_proxy.yaml</code>, and the documented <code>HUMANE_PROXY_DECAY_HALF_LIFE</code> env var, were silently ignored because two modules read config through a legacy package-only loader at import time. (0.5.2)</li>
<li><strong>HTTP MCP auth crashed with real fastmcp</strong> — the server imported a <code>BearerTokenAuth</code> class no fastmcp release exports, so setting <code>HUMANE_PROXY_ADMIN_KEY</code> (exactly as the README instructs) killed <code>mcp-serve</code> at import. Rebuilt on <code>StaticTokenVerifier</code>; the <code>[mcp]</code> extra now requires <code>fastmcp&gt;=2.11</code>. (0.5.3)</li>
</ul>
<h3 id="behavior-improvements">Behavior improvements</h3>
<ul>
<li><strong>Span-aware context reducers</strong> — a keyword and an intent pattern firing on the same phrase now count as one signal, so &ldquo;how to make a bomb in minecraft&rdquo; is correctly reduced to safe, while separate harmful expressions in one message still disable reduction entirely. (0.5.5)</li>
<li><strong>The audit log is exempt from the alert rate limit</strong> — every escalation is now persisted; the quota only caps operator notifications. Previously, events past the quota were dropped entirely, blinding the audit trail for exactly the sessions escalating hardest. <code>escalate()</code> results gained an <code>alerted</code> field. (0.5.5)</li>
<li><strong>Right to erasure is now complete</strong> — <code>DELETE /admin/sessions/{id}</code> clears live in-memory trajectory state, and the Redis backend cleans its category indexes on session deletion. (0.5.1)</li>
<li><strong>Malformed pipeline config no longer crashes classification</strong> — invalid <code>enabled_stages</code> values fall back to <code>[1]</code> and non-numeric thresholds coerce to safe defaults, with logged warnings. (0.5.5)</li>
</ul>
<h3 id="security">Security</h3>
<ul>
<li>Webhook logs show only the scheme and host of webhook URLs — Slack/Discord/Teams routing tokens live in the URL path and were previously logged.</li>
<li>Webhook error logs record HTTP status and response length only; bodies moved to DEBUG.</li>
<li>The reverse proxy no longer echoes raw upstream response bodies to clients.</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li><strong>Shared HTTP connection pool</strong> — the proxy, all webhook dispatchers, and all three Stage-3 classifiers reuse one <code>httpx.AsyncClient</code> instead of a fresh TCP+TLS handshake per call. (0.5.4)</li>
<li><strong>Embedding caches</strong> — Stage-2 anchor sentences are encoded once per process, and a bounded 5-minute TTL cache serves repeated identical messages without re-encoding. (0.5.4)</li>
<li><strong>Singleton pipelines</strong> — MCP tools and the LlamaIndex/CrewAI/AutoGen integrations no longer rebuild the full pipeline (including Stage-2 setup) on every call. (0.5.4)</li>
</ul>
<h3 id="repository--tooling">Repository &amp; tooling</h3>
<ul>
<li><strong>No-emoji policy</strong> — all emojis removed from source, output, and docs; severity markers are now bracketed ASCII tags (<code>[SELF-HARM]</code>, <code>[ALERT]</code>, <code>[FLAGGED]</code>, &hellip;). CI-enforced by a new repository-wide scan test. Also fixes <code>humane-proxy init</code> crashing with <code>UnicodeEncodeError</code> on default Windows (cp1252) consoles. (0.5.6)</li>
<li><strong>Decluttered layout</strong> — compliance and launch docs under <code>docs/</code>, community files under <code>.github/</code>, the Glama marketplace Dockerfile under <code>deploy/glama/</code>; <code>requirements.txt</code> removed (<code>pyproject.toml</code> is the single dependency source). (0.5.6)</li>
<li><strong>GitHub Action fixed</strong> — defaults to the <code>ml</code> extra so the benchmark no longer fails its own sample dataset in <code>--ci</code> mode. (0.5.2)</li>
<li><code>.env.example</code> now includes all documented secrets (<code>OPENAI_API_KEY</code>, <code>GROQ_API_KEY</code>, <code>HUMANE_PROXY_ADMIN_KEY</code>) with purpose comments (#63), and the docs correctly explain that <code>.env</code> files are not auto-loaded. (0.5.3, 0.5.5)</li>
<li>Documented OTel spans now all exist (<code>stage1.heuristics</code>, <code>session_id</code> attribute), and test isolation was hardened (per-test storage reset; the MCP auth test now runs against real fastmcp instead of a mock that masked the crash). (0.5.3, 0.5.4)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Vishisht16/Humane-Proxy/compare/v0.5.0...v0.5.6">https://github.com/Vishisht16/Humane-Proxy/compare/v0.5.0...v0.5.6</a></p>
]]></content:encoded></item><item><title>Build Flow Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/build-flow-action/</link><pubDate>Mon, 06 Jul 2026 15:20:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/build-flow-action/</guid><description>Version updated for https://github.com/wgtechlabs/build-flow-action to version v0.1.9.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [0.1.9] - 2026-07-06 Changed address review feedback in docs update readme and architecture for full primitive input passthrough clarify architecture principle for passthrough vs silent defaults (#38) expose all package-build-flow-action inputs (#35) expose all release-build-flow-action inputs (#34) expose all container-build-flow-action inputs (#33) Security fix ghcr-token fallback to github.token when unset (#37)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wgtechlabs/build-flow-action">https://github.com/wgtechlabs/build-flow-action</a></strong> to version <strong>v0.1.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/build-flow-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="019---2026-07-06">[0.1.9] - 2026-07-06</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>address review feedback in docs</li>
<li>update readme and architecture for full primitive input passthrough</li>
<li>clarify architecture principle for passthrough vs silent defaults (#38)</li>
<li>expose all package-build-flow-action inputs (#35)</li>
<li>expose all release-build-flow-action inputs (#34)</li>
<li>expose all container-build-flow-action inputs (#33)</li>
</ul>
<h3 id="security">Security</h3>
<ul>
<li>fix ghcr-token fallback to github.token when unset (#37)</li>
</ul>
]]></content:encoded></item><item><title>Setup Backlog CLI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/setup-backlog-cli/</link><pubDate>Mon, 06 Jul 2026 15:19:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/setup-backlog-cli/</guid><description>Version updated for https://github.com/yacchi/backlog-cli to version v0.29.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog 74cc75852815ae5feb5c373f2192e1736f272ab9 feat(action): 認証情報の入力を追加しCI設定を集約 (#32)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yacchi/backlog-cli">https://github.com/yacchi/backlog-cli</a></strong> to version <strong>v0.29.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-backlog-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>74cc75852815ae5feb5c373f2192e1736f272ab9 feat(action): 認証情報の入力を追加しCI設定を集約 (#32)</li>
</ul>
]]></content:encoded></item><item><title>Kover Report Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/kover-report-action/</link><pubDate>Mon, 06 Jul 2026 15:19:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/kover-report-action/</guid><description>Version updated for https://github.com/yshrsmz/kover-report-action to version v2.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.1.0: PR #132 - chore(deps): lock file maintenance</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yshrsmz/kover-report-action">https://github.com/yshrsmz/kover-report-action</a></strong> to version <strong>v2.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/kover-report-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>v2.1.0: PR #132 - chore(deps): lock file maintenance</p>
]]></content:encoded></item><item><title>vibecheck-ai-slop</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/vibecheck-ai-slop/</link><pubDate>Mon, 06 Jul 2026 15:17:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/vibecheck-ai-slop/</guid><description>Version updated for https://github.com/yuvrajangadsingh/vibecheck to version v1.10.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/yuvrajangadsingh/vibecheck/compare/v1.9.1...v1.10.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yuvrajangadsingh/vibecheck">https://github.com/yuvrajangadsingh/vibecheck</a></strong> to version <strong>v1.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibecheck-ai-slop">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yuvrajangadsingh/vibecheck/compare/v1.9.1...v1.10.0">https://github.com/yuvrajangadsingh/vibecheck/compare/v1.9.1...v1.10.0</a></p>
]]></content:encoded></item><item><title>AI TestGen — Generate &amp; Review Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/ai-testgen-generate-review-tests/</link><pubDate>Mon, 06 Jul 2026 15:17:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/ai-testgen-generate-review-tests/</guid><description>Version updated for https://github.com/zer0dayf/ai-testgen to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First-class Rust support.
New rust preset: Cargo.toml auto-detection, src/**/*.rs, integration tests in top-level tests/, run with cargo test --test {stem}, public-API-only guidance. New {stem} placeholder for run_cmd (needed by compiled-language runners like cargo). Optional per-language extra_rules injected into the generation prompt. Consumers on @v1 get this automatically; pin @v1.1.0 for an immutable version.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zer0dayf/ai-testgen">https://github.com/zer0dayf/ai-testgen</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-testgen-generate-review-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First-class <strong>Rust</strong> support.</p>
<ul>
<li>New <code>rust</code> preset: Cargo.toml auto-detection, <code>src/**/*.rs</code>, integration tests in top-level <code>tests/</code>, run with <code>cargo test --test {stem}</code>, public-API-only guidance.</li>
<li>New <code>{stem}</code> placeholder for <code>run_cmd</code> (needed by compiled-language runners like cargo).</li>
<li>Optional per-language <code>extra_rules</code> injected into the generation prompt.</li>
</ul>
<p>Consumers on <code>@v1</code> get this automatically; pin <code>@v1.1.0</code> for an immutable version.</p>
]]></content:encoded></item><item><title>Localize Pipeline</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/localize-pipeline/</link><pubDate>Mon, 06 Jul 2026 06:35:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/localize-pipeline/</guid><description>Version updated for https://github.com/bisq-network/localize-pipeline to version v0.1.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Production release for the 2026-07-04 full-repo pre-merge review hardening.
Highlights:
Docker runtime secrets replace build-layer SSH/GPG private key persistence. Core translation retry, ledger, validation, queue, and reporting paths are hardened. Quality gate, semantic review, remediation, placeholder, and validator checks are stricter. Config, CLI, provider, shell, Docker, and GitHub Action behavior is aligned for safer production runs. Parser, adapter, translation-memory, connector, bootstrap, layout, and docs edge cases are fixed. Verification:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/bisq-network/localize-pipeline">https://github.com/bisq-network/localize-pipeline</a></strong> to version <strong>v0.1.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/localize-pipeline">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Production release for the 2026-07-04 full-repo pre-merge review hardening.</p>
<p>Highlights:</p>
<ul>
<li>Docker runtime secrets replace build-layer SSH/GPG private key persistence.</li>
<li>Core translation retry, ledger, validation, queue, and reporting paths are hardened.</li>
<li>Quality gate, semantic review, remediation, placeholder, and validator checks are stricter.</li>
<li>Config, CLI, provider, shell, Docker, and GitHub Action behavior is aligned for safer production runs.</li>
<li>Parser, adapter, translation-memory, connector, bootstrap, layout, and docs edge cases are fixed.</li>
</ul>
<p>Verification:</p>
<ul>
<li>venv/bin/pytest passed locally: 620 passed.</li>
<li>PR checks passed for #112 through #119, including build-and-verify, CodeQL, and CodeRabbit status where available.</li>
</ul>
<p>Human action required:</p>
<ul>
<li>Rotate the SSH deploy key and GPG bot key used by production deployments. The old keys were present in previously built image layers before the Phase 1 fix.</li>
</ul>
]]></content:encoded></item><item><title>GitHub Space Shooter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/github-space-shooter/</link><pubDate>Mon, 06 Jul 2026 06:34:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/github-space-shooter/</guid><description>Version updated for https://github.com/czl9707/gh-space-shooter to version v2.0.4.
This action is used across all versions by 144 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Automated release of pypi version v2.0.4
What’s Changed perf: enable GIF optimization to reduce file size by @HmonWutt in https://github.com/czl9707/gh-space-shooter/pull/43 perf: use lossy WebP encoding for dramatically smaller files by @HmonWutt in https://github.com/czl9707/gh-space-shooter/pull/45 New Contributors @HmonWutt made their first contribution in https://github.com/czl9707/gh-space-shooter/pull/43 Full Changelog: https://github.com/czl9707/gh-space-shooter/compare/v2.0.3...v2.0.4</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/czl9707/gh-space-shooter">https://github.com/czl9707/gh-space-shooter</a></strong> to version <strong>v2.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>144</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-space-shooter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Automated release of pypi version v2.0.4</p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>perf: enable GIF optimization to reduce file size by @HmonWutt in <a href="https://github.com/czl9707/gh-space-shooter/pull/43">https://github.com/czl9707/gh-space-shooter/pull/43</a></li>
<li>perf: use lossy WebP encoding for dramatically smaller files by @HmonWutt in <a href="https://github.com/czl9707/gh-space-shooter/pull/45">https://github.com/czl9707/gh-space-shooter/pull/45</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@HmonWutt made their first contribution in <a href="https://github.com/czl9707/gh-space-shooter/pull/43">https://github.com/czl9707/gh-space-shooter/pull/43</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/czl9707/gh-space-shooter/compare/v2.0.3...v2.0.4">https://github.com/czl9707/gh-space-shooter/compare/v2.0.3...v2.0.4</a></p>
]]></content:encoded></item><item><title>Assign Reviewers when Dependencies Change</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/assign-reviewers-when-dependencies-change/</link><pubDate>Mon, 06 Jul 2026 06:34:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/assign-reviewers-when-dependencies-change/</guid><description>Version updated for https://github.com/dependency-owners/assign to version v2.0.24.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 2.0.24 (2026-07-05) Bug Fixes deps: lock file maintenance (#121) (ac1fd95)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/dependency-owners/assign">https://github.com/dependency-owners/assign</a></strong> to version <strong>v2.0.24</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/assign-reviewers-when-dependencies-change">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="2024-2026-07-05"><a href="https://github.com/dependency-owners/assign/compare/v2.0.23...v2.0.24">2.0.24</a> (2026-07-05)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> lock file maintenance (<a href="https://github.com/dependency-owners/assign/issues/121">#121</a>) (<a href="https://github.com/dependency-owners/assign/commit/ac1fd950a2356ec64fe9dc92f21cd51f05aba420">ac1fd95</a>)</li>
</ul>
]]></content:encoded></item><item><title>Check Unowned Dependencies</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/check-unowned-dependencies/</link><pubDate>Mon, 06 Jul 2026 06:33:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/check-unowned-dependencies/</guid><description>Version updated for https://github.com/dependency-owners/check to version v2.0.17.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 2.0.17 (2026-07-05) Bug Fixes deps: lock file maintenance (#130) (873d9df)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/dependency-owners/check">https://github.com/dependency-owners/check</a></strong> to version <strong>v2.0.17</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/check-unowned-dependencies">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="2017-2026-07-05"><a href="https://github.com/dependency-owners/check/compare/v2.0.16...v2.0.17">2.0.17</a> (2026-07-05)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> lock file maintenance (<a href="https://github.com/dependency-owners/check/issues/130">#130</a>) (<a href="https://github.com/dependency-owners/check/commit/873d9df42ed1eaa620e6def42d0756cc3008540c">873d9df</a>)</li>
</ul>
]]></content:encoded></item><item><title>AgentGuard Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/agentguard-security-scan/</link><pubDate>Mon, 06 Jul 2026 06:32:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/agentguard-security-scan/</guid><description>Version updated for https://github.com/dockfixlabs/agentguard to version v0.6.10.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed docker run ghcr.io/dockfixlabs/agentguard . Run AgentGuard anywhere. Fixed publish skip-existing masking.
Full Changelog: https://github.com/dockfixlabs/agentguard/compare/v0.6.9...v0.6.10</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/dockfixlabs/agentguard">https://github.com/dockfixlabs/agentguard</a></strong> to version <strong>v0.6.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentguard-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>docker run ghcr.io/dockfixlabs/agentguard . Run AgentGuard anywhere. Fixed publish skip-existing masking.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/dockfixlabs/agentguard/compare/v0.6.9...v0.6.10">https://github.com/dockfixlabs/agentguard/compare/v0.6.9...v0.6.10</a></p>
]]></content:encoded></item><item><title>Setup Piet</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/setup-piet/</link><pubDate>Mon, 06 Jul 2026 06:32:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/setup-piet/</guid><description>Version updated for https://github.com/fabasoad/setup-piet-action to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps): bump actions/checkout from 4 to 5 by @dependabot[bot] in https://github.com/fabasoad/setup-piet-action/pull/15 chore(deps): bump actionlint from 1.7.8 to 1.7.9 by @fabasoad in https://github.com/fabasoad/setup-piet-action/pull/16 Update license copyright year to 2026 by @github-actions[bot] in https://github.com/fabasoad/setup-piet-action/pull/17 chore(deps): bump gitleaks from 8.30.0 to 8.30.1 by @fabasoad in https://github.com/fabasoad/setup-piet-action/pull/18 Full Changelog: https://github.com/fabasoad/setup-piet-action/compare/v0.2.0...v0.3.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/fabasoad/setup-piet-action">https://github.com/fabasoad/setup-piet-action</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-piet">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): bump actions/checkout from 4 to 5 by @dependabot[bot] in <a href="https://github.com/fabasoad/setup-piet-action/pull/15">https://github.com/fabasoad/setup-piet-action/pull/15</a></li>
<li>chore(deps): bump actionlint from 1.7.8 to 1.7.9 by @fabasoad in <a href="https://github.com/fabasoad/setup-piet-action/pull/16">https://github.com/fabasoad/setup-piet-action/pull/16</a></li>
<li>Update license copyright year to 2026 by @github-actions[bot] in <a href="https://github.com/fabasoad/setup-piet-action/pull/17">https://github.com/fabasoad/setup-piet-action/pull/17</a></li>
<li>chore(deps): bump gitleaks from 8.30.0 to 8.30.1 by @fabasoad in <a href="https://github.com/fabasoad/setup-piet-action/pull/18">https://github.com/fabasoad/setup-piet-action/pull/18</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/fabasoad/setup-piet-action/compare/v0.2.0...v0.3.0">https://github.com/fabasoad/setup-piet-action/compare/v0.2.0...v0.3.0</a></p>
]]></content:encoded></item><item><title>Fallow - Codebase Intelligence</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/fallow-codebase-intelligence/</link><pubDate>Mon, 06 Jul 2026 06:31:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/fallow-codebase-intelligence/</guid><description>Version updated for https://github.com/fallow-rs/fallow to version v3.2.0.
This action is used across all versions by 252 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Health: a configurable “function too big” threshold, surfaced in the summary This release makes the unit-size (large-function) check configurable and reports the effective ceiling in the health output.
health.maxUnitSize: raise the large-function bar instead of switching it off The line count at which a function is reported as an oversized “large function” was hardcoded to 60 LOC. That made test suites noisy: a describe() callback spans hundreds of lines, and each large it() body trips the threshold too. The only escape was health.ignore, which drops every health signal (complexity, CRAP, hotspots) for those files, so you lost complexity checking on your test code as well.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/fallow-rs/fallow">https://github.com/fallow-rs/fallow</a></strong> to version <strong>v3.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>252</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/fallow-codebase-intelligence">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="health-a-configurable-function-too-big-threshold-surfaced-in-the-summary">Health: a configurable &ldquo;function too big&rdquo; threshold, surfaced in the summary</h2>
<p>This release makes the unit-size (large-function) check configurable and reports the effective ceiling in the health output.</p>
<h3 id="healthmaxunitsize-raise-the-large-function-bar-instead-of-switching-it-off"><code>health.maxUnitSize</code>: raise the large-function bar instead of switching it off</h3>
<p>The line count at which a function is reported as an oversized &ldquo;large function&rdquo; was hardcoded to 60 LOC. That made test suites noisy: a <code>describe()</code> callback spans hundreds of lines, and each large <code>it()</code> body trips the threshold too. The only escape was <code>health.ignore</code>, which drops every health signal (complexity, CRAP, hotspots) for those files, so you lost complexity checking on your test code as well.</p>
<p>You can now raise the bar rather than turning it off:</p>
<ul>
<li>Set a global <code>health.maxUnitSize</code> (default 60).</li>
<li>Or scope it to a glob with a per-file <code>thresholdOverrides</code> entry, for example <code>{ &quot;files&quot;: [&quot;**/*.test.*&quot;], &quot;maxUnitSize&quot;: 500 }</code>. Leave <code>functions</code> empty so the override covers both the <code>describe()</code> wrapper and the individual <code>it()</code> blocks.</li>
</ul>
<p>Complexity, cognitive, and CRAP findings on those files are unchanged. Like the existing <code>maxCyclomatic</code> / <code>maxCognitive</code> / <code>maxCrap</code> overrides, this filters the reported &ldquo;large functions&rdquo; list; the descriptive unit-size profile and the health score still reflect raw sizes (use <code>health.ignore</code> to remove a file from the score entirely). Resolved thresholds are inspectable via <code>fallow config</code>. Thanks @digulla for the request. (Closes #1731)</p>
<h3 id="the-health-json-summary-reports-the-effective-unit-size-threshold">The health JSON summary reports the effective unit-size threshold</h3>
<p>The <code>summary</code> block on <code>fallow health --format json</code> already carried <code>max_cyclomatic_threshold</code>, <code>max_cognitive_threshold</code>, and <code>max_crap_threshold</code>, but not a unit-size sibling, so a consumer reading the summary to learn which thresholds a run uses saw only three of the four. It now also carries <code>max_unit_size_threshold</code> (the effective global <code>health.maxUnitSize</code>, default 60). The human report&rsquo;s &ldquo;Large functions&rdquo; section reflects the configured global instead of a static &ldquo;60&rdquo; when <code>health.maxUnitSize</code> is raised project-wide. This is an additive-required field matching the existing <code>max*Threshold</code> siblings; no change to the unit-size check itself. (Closes #1750)</p>
<h3 id="other-changes">Other changes</h3>
<ul>
<li>Reuse the audit analysis context in the programmatic API path for less redundant work per run.</li>
<li>Benchmark-harness coverage and CI sharding improvements (internal).</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/fallow-rs/fallow/compare/v3.1.0...v3.2.0">https://github.com/fallow-rs/fallow/compare/v3.1.0...v3.2.0</a></p>
]]></content:encoded></item><item><title>TrustCheck Package Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/trustcheck-package-scanner/</link><pubDate>Mon, 06 Jul 2026 06:31:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/trustcheck-package-scanner/</guid><description>Version updated for https://github.com/Halfblood-Prince/trustcheck to version v2.2.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published from immutable commit 80ba32f691b15f39c26df081b8d7865ae7561750. The release workflow publishes PyPI, GitHub Action, Snap Store, Homebrew tap pins, and GHCR Docker distributions after shared tag verification, QA, matrix, and coverage builds.
Release artifacts:
dist/* dist/SHA256SUMS.txt dist/*.cdx.json standalone trustcheck-*-windows-x86_64.exe with checksum unsigned trustcheck-*-store.msix for Microsoft Store submission GHCR Docker images for linux/amd64, linux/arm64, and linux/arm/v7 Verify the direct Windows executable before use:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Halfblood-Prince/trustcheck">https://github.com/Halfblood-Prince/trustcheck</a></strong> to version <strong>v2.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/trustcheck-package-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published from immutable commit <code>80ba32f691b15f39c26df081b8d7865ae7561750</code>.
The release workflow publishes PyPI, GitHub Action, Snap Store,
Homebrew tap pins, and GHCR Docker distributions after shared tag
verification, QA, matrix, and coverage builds.</p>
<p>Release artifacts:</p>
<ul>
<li><code>dist/*</code></li>
<li><code>dist/SHA256SUMS.txt</code></li>
<li><code>dist/*.cdx.json</code></li>
<li>standalone <code>trustcheck-*-windows-x86_64.exe</code> with checksum</li>
<li>unsigned <code>trustcheck-*-store.msix</code> for Microsoft Store submission</li>
<li>GHCR Docker images for <code>linux/amd64</code>, <code>linux/arm64</code>, and <code>linux/arm/v7</code></li>
</ul>
<p>Verify the direct Windows executable before use:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-powershell" data-lang="powershell"><span style="display:flex;"><span>Get-AuthenticodeSignature .\trustcheck-*-windows-x86_64.exe | Format-List
</span></span><span style="display:flex;"><span>Get-FileHash .\trustcheck-*-windows-x86_64.exe -Algorithm SHA256
</span></span></code></pre></div><p>The Authenticode status must be <code>Valid</code>, include a timestamp
certificate, and match the adjacent <code>.sha256</code> file. The Store signs
the MSIX during submission; the workflow tests its execution alias
with a disposable certificate before upload.</p>
<p>GitHub Action:</p>
<ul>
<li>Immutable: <code>uses: Halfblood-Prince/trustcheck@v2.2.2</code></li>
<li>Compatible major: <code>uses: Halfblood-Prince/trustcheck@v2</code></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Halfblood-Prince/trustcheck/compare/v2.2.1...v2.2.2">https://github.com/Halfblood-Prince/trustcheck/compare/v2.2.1...v2.2.2</a></p>
]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/ai-plugin-scanner/</link><pubDate>Mon, 06 Jul 2026 06:30:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.391.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/94bc5f097f380f55261291070e6913bd7ad528e0 with plugin-scanner 2.0.991.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.390...v1.2.391</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.391</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>18</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/94bc5f097f380f55261291070e6913bd7ad528e0">https://github.com/hashgraph-online/hol-guard/tree/94bc5f097f380f55261291070e6913bd7ad528e0</a> with plugin-scanner 2.0.991.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.390...v1.2.391">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.390...v1.2.391</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/hol-codex-plugin-scanner/</link><pubDate>Mon, 06 Jul 2026 06:30:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.391.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.391</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.391</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.391">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.391</a></p>
]]></content:encoded></item><item><title>Git Submodules Upgrade</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/git-submodules-upgrade/</link><pubDate>Mon, 06 Jul 2026 06:29:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/git-submodules-upgrade/</guid><description>Version updated for https://github.com/itsapinhulk/git-submodules-upgrade to version v3.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore: update vendored upgrade-git-submodules by @github-actions[bot] in https://github.com/itsapinhulk/git-submodules-upgrade/pull/13 chore: update vendored upgrade-git-submodules by @github-actions[bot] in https://github.com/itsapinhulk/git-submodules-upgrade/pull/14 Full Changelog: https://github.com/itsapinhulk/git-submodules-upgrade/compare/v3.0...v3.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/itsapinhulk/git-submodules-upgrade">https://github.com/itsapinhulk/git-submodules-upgrade</a></strong> to version <strong>v3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/git-submodules-upgrade">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: update vendored upgrade-git-submodules by @github-actions[bot] in <a href="https://github.com/itsapinhulk/git-submodules-upgrade/pull/13">https://github.com/itsapinhulk/git-submodules-upgrade/pull/13</a></li>
<li>chore: update vendored upgrade-git-submodules by @github-actions[bot] in <a href="https://github.com/itsapinhulk/git-submodules-upgrade/pull/14">https://github.com/itsapinhulk/git-submodules-upgrade/pull/14</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/itsapinhulk/git-submodules-upgrade/compare/v3.0...v3.1">https://github.com/itsapinhulk/git-submodules-upgrade/compare/v3.0...v3.1</a></p>
]]></content:encoded></item><item><title>L10n.dev AI Localization Automation</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/l10n.dev-ai-localization-automation/</link><pubDate>Mon, 06 Jul 2026 06:29:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/l10n.dev-ai-localization-automation/</guid><description>Version updated for https://github.com/l10n-dev/ai-l10n to version v1.9.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: Add MCP server and tools for localization management by @AntonovAnton in https://github.com/l10n-dev/ai-l10n/pull/49 Added “mcp” to the root workspaces by @AntonovAnton in https://github.com/l10n-dev/ai-l10n/pull/50 feat: Update build process to include SDK dependencies by @AntonovAnton in https://github.com/l10n-dev/ai-l10n/pull/51 feat: Add test script and trigger by @AntonovAnton in https://github.com/l10n-dev/ai-l10n/pull/52 Full Changelog: https://github.com/l10n-dev/ai-l10n/compare/v1.9.0...v1.9.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/l10n-dev/ai-l10n">https://github.com/l10n-dev/ai-l10n</a></strong> to version <strong>v1.9.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/l10n-dev-ai-localization-automation">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: Add MCP server and tools for localization management by @AntonovAnton in <a href="https://github.com/l10n-dev/ai-l10n/pull/49">https://github.com/l10n-dev/ai-l10n/pull/49</a></li>
<li>Added &ldquo;mcp&rdquo; to the root workspaces by @AntonovAnton in <a href="https://github.com/l10n-dev/ai-l10n/pull/50">https://github.com/l10n-dev/ai-l10n/pull/50</a></li>
<li>feat: Update build process to include SDK dependencies by @AntonovAnton in <a href="https://github.com/l10n-dev/ai-l10n/pull/51">https://github.com/l10n-dev/ai-l10n/pull/51</a></li>
<li>feat: Add test script and trigger by @AntonovAnton in <a href="https://github.com/l10n-dev/ai-l10n/pull/52">https://github.com/l10n-dev/ai-l10n/pull/52</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/l10n-dev/ai-l10n/compare/v1.9.0...v1.9.1">https://github.com/l10n-dev/ai-l10n/compare/v1.9.0...v1.9.1</a></p>
]]></content:encoded></item><item><title>EIS — Upload Signals</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/eis-upload-signals/</link><pubDate>Mon, 06 Jul 2026 06:28:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/eis-upload-signals/</guid><description>Version updated for https://github.com/machuz/eis to version v2.22.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog 1bb1e10897d9d8e5f844b082c8241d84f784d9fe feat(git): suppress gravity for git subtree –squash imports (#334)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/machuz/eis">https://github.com/machuz/eis</a></strong> to version <strong>v2.22.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/eis-upload-signals">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>1bb1e10897d9d8e5f844b082c8241d84f784d9fe feat(git): suppress gravity for git subtree &ndash;squash imports (#334)</li>
</ul>
]]></content:encoded></item><item><title>lgtmaybe</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/lgtmaybe/</link><pubDate>Mon, 06 Jul 2026 06:27:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/lgtmaybe/</guid><description>Version updated for https://github.com/MattJColes/lgtmaybe to version lgtmaybe-v0.10.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.10.0 (2026-07-06) ⚠ BREAKING CHANGES engine: reviews now run the fast preset by default — all nine lenses covered in four grouped model calls (~half the calls and wall time), trading some recall on the softer lenses (performance, complexity, ponytail, deprecation, tests, documentation). Set preset: full (or –preset full / the Action’s preset input) to restore the previous one-call-per-lens behaviour. Features engine: first-class structured describe + opt-in auto-describe (#171) (35f1b08) engine: function-boundary context, per-tool lint floors, eval A/B coverage (#173) (684acf1) engine: review-effort/risk labels + declarative finding rules (#172) (1414322) engine: static-analysis fusion — deterministic linters ground the review (#169) (48d6ecf) engine: two-stage triage routing behind a security floor (#170) (00966fe) github: commit-scoped incremental review on synchronize pushes (#168) (f16f915) prompt caching + audit-driven review improvements (#166) (95acc2b) Performance Improvements engine: cut review wall time — global fan-out pool, cached diff prefix, fast preset, deadlines (#174) (853917a) Dependencies bump the python-dependencies group across 1 directory with 3 updates (#164) (bb83a4f)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MattJColes/lgtmaybe">https://github.com/MattJColes/lgtmaybe</a></strong> to version <strong>lgtmaybe-v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lgtmaybe">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="0100-2026-07-06"><a href="https://github.com/MattJColes/lgtmaybe/compare/lgtmaybe-v0.9.2...lgtmaybe-v0.10.0">0.10.0</a> (2026-07-06)</h2>
<h3 id="-breaking-changes">⚠ BREAKING CHANGES</h3>
<ul>
<li><strong>engine:</strong> reviews now run the fast preset by default — all nine lenses covered in four grouped model calls (~half the calls and wall time), trading some recall on the softer lenses (performance, complexity, ponytail, deprecation, tests, documentation). Set preset: full (or &ndash;preset full / the Action&rsquo;s preset input) to restore the previous one-call-per-lens behaviour.</li>
</ul>
<h3 id="features">Features</h3>
<ul>
<li><strong>engine:</strong> first-class structured describe + opt-in auto-describe (<a href="https://github.com/MattJColes/lgtmaybe/issues/171">#171</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/35f1b0872bada212232a69dd32e85d44e7b5de20">35f1b08</a>)</li>
<li><strong>engine:</strong> function-boundary context, per-tool lint floors, eval A/B coverage (<a href="https://github.com/MattJColes/lgtmaybe/issues/173">#173</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/684acf1e2307c926a743f3a2ca53a4031011744b">684acf1</a>)</li>
<li><strong>engine:</strong> review-effort/risk labels + declarative finding rules (<a href="https://github.com/MattJColes/lgtmaybe/issues/172">#172</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/14143221e8cec7037617902e154fa96d04e77769">1414322</a>)</li>
<li><strong>engine:</strong> static-analysis fusion — deterministic linters ground the review (<a href="https://github.com/MattJColes/lgtmaybe/issues/169">#169</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/48d6ecff8bd5195752ad0b9267ee25db8d6403a7">48d6ecf</a>)</li>
<li><strong>engine:</strong> two-stage triage routing behind a security floor (<a href="https://github.com/MattJColes/lgtmaybe/issues/170">#170</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/00966feb9052dffcd6091303bbd91693cd424d71">00966fe</a>)</li>
<li><strong>github:</strong> commit-scoped incremental review on synchronize pushes (<a href="https://github.com/MattJColes/lgtmaybe/issues/168">#168</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/f16f91579d6aac9dbe8b4556a133a3126b8210c0">f16f915</a>)</li>
<li>prompt caching + audit-driven review improvements (<a href="https://github.com/MattJColes/lgtmaybe/issues/166">#166</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/95acc2b63aaa8062acaca603023492ad75bec90c">95acc2b</a>)</li>
</ul>
<h3 id="performance-improvements">Performance Improvements</h3>
<ul>
<li><strong>engine:</strong> cut review wall time — global fan-out pool, cached diff prefix, fast preset, deadlines (<a href="https://github.com/MattJColes/lgtmaybe/issues/174">#174</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/853917a7c45c4450e379ede033cfd04ddfdf490b">853917a</a>)</li>
</ul>
<h3 id="dependencies">Dependencies</h3>
<ul>
<li>bump the python-dependencies group across 1 directory with 3 updates (<a href="https://github.com/MattJColes/lgtmaybe/issues/164">#164</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/bb83a4f2973791d3cdb5c04ee5a87431e7b7ef9f">bb83a4f</a>)</li>
</ul>
]]></content:encoded></item><item><title>Go - Test Suites</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/go-test-suites/</link><pubDate>Mon, 06 Jul 2026 06:27:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/go-test-suites/</guid><description>Version updated for https://github.com/mvrahden/go-test to version v1.24.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed CI-friendly test failure summaries with GitHub Action by @mvrahden in https://github.com/mvrahden/go-test/pull/80 Use gotest action for CI test execution by @mvrahden in https://github.com/mvrahden/go-test/pull/81 ci: update major version tag on release by @mvrahden in https://github.com/mvrahden/go-test/pull/82 Lint rule to simplify assertion usage by @mvrahden in https://github.com/mvrahden/go-test/pull/83 Detect and report unnecessary T escapes in test suites by @mvrahden in https://github.com/mvrahden/go-test/pull/84 Full Changelog: https://github.com/mvrahden/go-test/compare/v1.23.1...v1.24.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mvrahden/go-test">https://github.com/mvrahden/go-test</a></strong> to version <strong>v1.24.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-test-suites">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>CI-friendly test failure summaries with GitHub Action by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/80">https://github.com/mvrahden/go-test/pull/80</a></li>
<li>Use gotest action for CI test execution by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/81">https://github.com/mvrahden/go-test/pull/81</a></li>
<li>ci: update major version tag on release by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/82">https://github.com/mvrahden/go-test/pull/82</a></li>
<li>Lint rule to simplify assertion usage by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/83">https://github.com/mvrahden/go-test/pull/83</a></li>
<li>Detect and report unnecessary T escapes in test suites by @mvrahden in <a href="https://github.com/mvrahden/go-test/pull/84">https://github.com/mvrahden/go-test/pull/84</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/mvrahden/go-test/compare/v1.23.1...v1.24.0">https://github.com/mvrahden/go-test/compare/v1.23.1...v1.24.0</a></p>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/go-proxy-cache-updater/</link><pubDate>Mon, 06 Jul 2026 06:26:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.15.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.1.15 (2026-07-06)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.15</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1115-2026-07-06"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.14...v1.1.15">1.1.15</a> (2026-07-06)</h2>
]]></content:encoded></item><item><title>lacuna-cli</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/lacuna-cli/</link><pubDate>Mon, 06 Jul 2026 06:26:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/lacuna-cli/</guid><description>Version updated for https://github.com/Octagon-simon/lacuna to version v0.3.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/Octagon-simon/lacuna/compare/v0.3.0...v0.3.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Octagon-simon/lacuna">https://github.com/Octagon-simon/lacuna</a></strong> to version <strong>v0.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lacuna-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Octagon-simon/lacuna/compare/v0.3.0...v0.3.1">https://github.com/Octagon-simon/lacuna/compare/v0.3.0...v0.3.1</a></p>
]]></content:encoded></item><item><title>SkillTotal AI Component Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/skilltotal-ai-component-security-scan/</link><pubDate>Mon, 06 Jul 2026 06:25:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/skilltotal-ai-component-security-scan/</guid><description>Version updated for https://github.com/pezhik/skilltotal to version v0.32.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed Ruleset 30 — CI-config and vendored-tree false positives (see RULES_CHANGELOG.md), found when numpy scored critical/90 on its own infrastructure files: CI/CD pipeline configuration (.circleci/, .github/workflows/, .gitlab-ci.yml, Jenkinsfile, …) is demoted to needs_review — a CI job runs on the project’s build service, never on the consumer’s machine, so numpy’s docs-deploy SSH setup is not component behavior and can no longer feed ST-COMBO-EXFIL. Install-time hooks (setup.py, npm postinstall) are unaffected and stay fully scored. vendored-* directories (numpy’s vendored-meson/, which bundles the meson build system with meson’s own CI docker scripts) are now skipped like vendor/ and node_modules. Effect: numpy critical/90 → low/20; recall floors unchanged.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pezhik/skilltotal">https://github.com/pezhik/skilltotal</a></strong> to version <strong>v0.32.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skilltotal-ai-component-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>Ruleset 30 — CI-config and vendored-tree false positives</strong> (see <code>RULES_CHANGELOG.md</code>),
found when numpy scored critical/90 on its own infrastructure files:
<ul>
<li><strong>CI/CD pipeline configuration</strong> (<code>.circleci/</code>, <code>.github/workflows/</code>, <code>.gitlab-ci.yml</code>,
<code>Jenkinsfile</code>, …) is demoted to <code>needs_review</code> — a CI job runs on the project&rsquo;s build
service, never on the consumer&rsquo;s machine, so numpy&rsquo;s docs-deploy SSH setup is not
component behavior and can no longer feed <code>ST-COMBO-EXFIL</code>. Install-time hooks
(<code>setup.py</code>, npm <code>postinstall</code>) are unaffected and stay fully scored.</li>
<li><strong><code>vendored-*</code> directories</strong> (numpy&rsquo;s <code>vendored-meson/</code>, which bundles the meson build
system with meson&rsquo;s own CI docker scripts) are now skipped like <code>vendor/</code> and
<code>node_modules</code>. Effect: numpy critical/90 → low/20; recall floors unchanged.</li>
</ul>
</li>
</ul>
]]></content:encoded></item><item><title>OpenTelemetry for GitHub Workflows, Jobs and Steps</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/opentelemetry-for-github-workflows-jobs-and-steps/</link><pubDate>Mon, 06 Jul 2026 06:25:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/opentelemetry-for-github-workflows-jobs-and-steps/</guid><description>Version updated for https://github.com/plengauer/Thoth to version v5.59.0.
This action is used across all versions by 14 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Stop masking super-linter failures and harden OTel super-linter patching by @plengauer with @Copilot in https://github.com/plengauer/Thoth/pull/3507 Update opentelemetry-js-contrib monorepo by @plengauer in https://github.com/plengauer/Thoth/pull/3627 Update actions/checkout action to v7 by @plengauer in https://github.com/plengauer/Thoth/pull/3663 Update actions/setup-java action to v5.4.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3677 Pin dependencies by @plengauer in https://github.com/plengauer/Thoth/pull/3670 Update otel/opentelemetry-collector-contrib Docker tag to v0.155.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3681 Update Gradle to v9.6.1 by @plengauer in https://github.com/plengauer/Thoth/pull/3674 Update actions/cache action to v5.1.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3675 Update actions/setup-python action to v6.3.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3678 Update github/gh-aw-actions action to v0.81.6 by @plengauer in https://github.com/plengauer/Thoth/pull/3680 Update actions/attest-build-provenance action to v4.1.1 by @plengauer in https://github.com/plengauer/Thoth/pull/3672 Update ghcr.io/plengauer/opentelemetry-github-workflow-instrumentation-runner Docker tag to v5.58.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3679 Update plengauer/opentelemetry-github action to v5.58.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3682 Fix renovate of copilot instrumentation by @plengauer in https://github.com/plengauer/Thoth/pull/3684 Update actions/setup-dotnet action to v5.4.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3676 Update Demo injection_deep_java by @plengauer in https://github.com/plengauer/Thoth/pull/3686 Update Demo _complex_download_github_releases by @plengauer in https://github.com/plengauer/Thoth/pull/3687 Update Demo injection_deep_node by @plengauer in https://github.com/plengauer/Thoth/pull/3688 Update Demo injection_inner_xargs_parallel by @plengauer in https://github.com/plengauer/Thoth/pull/3689 Update Demo observe_subprocesses by @plengauer in https://github.com/plengauer/Thoth/pull/3690 Update Demo injection_deep_python by @plengauer in https://github.com/plengauer/Thoth/pull/3691 Update Demo injection_docker_renovate by @plengauer in https://github.com/plengauer/Thoth/pull/3692 Deploy OpenTelemetry by @plengauer in https://github.com/plengauer/Thoth/pull/3685 Update opentelemetry-js-contrib monorepo by @plengauer in https://github.com/plengauer/Thoth/pull/3709 Update dependency net.bytebuddy:byte-buddy to v1.18.11-jdk5 by @plengauer in https://github.com/plengauer/Thoth/pull/3705 Update docker/setup-buildx-action action to v4.2.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3707 Update github/codeql-action action to v4.36.3 by @plengauer in https://github.com/plengauer/Thoth/pull/3706 Update github/gh-aw-actions action to v0.82.2 by @plengauer in https://github.com/plengauer/Thoth/pull/3697 Unbreak agentic workflow recompilation with current gh-aw schema by @plengauer with @Copilot in https://github.com/plengauer/Thoth/pull/3704 Re-disable slim images by @plengauer in https://github.com/plengauer/Thoth/pull/3703 Update plengauer/autorerun action to v0.38.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3702 Update docker/build-push-action action to v7.3.0 by @plengauer in https://github.com/plengauer/Thoth/pull/3700 Update actions/cache action to v6 by @plengauer in https://github.com/plengauer/Thoth/pull/3683 Update dependency traceloop-sdk to v0.62.1 by @plengauer in https://github.com/plengauer/Thoth/pull/3695 Update renovatebot/github-action action to v46.1.17 by @plengauer in https://github.com/plengauer/Thoth/pull/3694 Update dependency org.junit.jupiter:junit-jupiter to v6.1.1 by @plengauer in https://github.com/plengauer/Thoth/pull/3693 Rename quality job by @plengauer in https://github.com/plengauer/Thoth/pull/3696 Automatic Version Bump by @plengauer in https://github.com/plengauer/Thoth/pull/3698 Full Changelog: https://github.com/plengauer/Thoth/compare/v5...v5.59.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/plengauer/Thoth">https://github.com/plengauer/Thoth</a></strong> to version <strong>v5.59.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>14</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/opentelemetry-for-github-workflows-jobs-and-steps">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Stop masking super-linter failures and harden OTel super-linter patching by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3507">https://github.com/plengauer/Thoth/pull/3507</a></li>
<li>Update opentelemetry-js-contrib monorepo by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3627">https://github.com/plengauer/Thoth/pull/3627</a></li>
<li>Update actions/checkout action to v7 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3663">https://github.com/plengauer/Thoth/pull/3663</a></li>
<li>Update actions/setup-java action to v5.4.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3677">https://github.com/plengauer/Thoth/pull/3677</a></li>
<li>Pin dependencies by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3670">https://github.com/plengauer/Thoth/pull/3670</a></li>
<li>Update otel/opentelemetry-collector-contrib Docker tag to v0.155.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3681">https://github.com/plengauer/Thoth/pull/3681</a></li>
<li>Update Gradle to v9.6.1 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3674">https://github.com/plengauer/Thoth/pull/3674</a></li>
<li>Update actions/cache action to v5.1.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3675">https://github.com/plengauer/Thoth/pull/3675</a></li>
<li>Update actions/setup-python action to v6.3.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3678">https://github.com/plengauer/Thoth/pull/3678</a></li>
<li>Update github/gh-aw-actions action to v0.81.6 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3680">https://github.com/plengauer/Thoth/pull/3680</a></li>
<li>Update actions/attest-build-provenance action to v4.1.1 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3672">https://github.com/plengauer/Thoth/pull/3672</a></li>
<li>Update ghcr.io/plengauer/opentelemetry-github-workflow-instrumentation-runner Docker tag to v5.58.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3679">https://github.com/plengauer/Thoth/pull/3679</a></li>
<li>Update plengauer/opentelemetry-github action to v5.58.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3682">https://github.com/plengauer/Thoth/pull/3682</a></li>
<li>Fix renovate of copilot instrumentation by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3684">https://github.com/plengauer/Thoth/pull/3684</a></li>
<li>Update actions/setup-dotnet action to v5.4.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3676">https://github.com/plengauer/Thoth/pull/3676</a></li>
<li>Update Demo injection_deep_java by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3686">https://github.com/plengauer/Thoth/pull/3686</a></li>
<li>Update Demo _complex_download_github_releases by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3687">https://github.com/plengauer/Thoth/pull/3687</a></li>
<li>Update Demo injection_deep_node by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3688">https://github.com/plengauer/Thoth/pull/3688</a></li>
<li>Update Demo injection_inner_xargs_parallel by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3689">https://github.com/plengauer/Thoth/pull/3689</a></li>
<li>Update Demo observe_subprocesses by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3690">https://github.com/plengauer/Thoth/pull/3690</a></li>
<li>Update Demo injection_deep_python by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3691">https://github.com/plengauer/Thoth/pull/3691</a></li>
<li>Update Demo injection_docker_renovate by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3692">https://github.com/plengauer/Thoth/pull/3692</a></li>
<li>Deploy OpenTelemetry by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3685">https://github.com/plengauer/Thoth/pull/3685</a></li>
<li>Update opentelemetry-js-contrib monorepo by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3709">https://github.com/plengauer/Thoth/pull/3709</a></li>
<li>Update dependency net.bytebuddy:byte-buddy to v1.18.11-jdk5 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3705">https://github.com/plengauer/Thoth/pull/3705</a></li>
<li>Update docker/setup-buildx-action action to v4.2.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3707">https://github.com/plengauer/Thoth/pull/3707</a></li>
<li>Update github/codeql-action action to v4.36.3 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3706">https://github.com/plengauer/Thoth/pull/3706</a></li>
<li>Update github/gh-aw-actions action to v0.82.2 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3697">https://github.com/plengauer/Thoth/pull/3697</a></li>
<li>Unbreak agentic workflow recompilation with current gh-aw schema by @plengauer with @Copilot in <a href="https://github.com/plengauer/Thoth/pull/3704">https://github.com/plengauer/Thoth/pull/3704</a></li>
<li>Re-disable slim images by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3703">https://github.com/plengauer/Thoth/pull/3703</a></li>
<li>Update plengauer/autorerun action to v0.38.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3702">https://github.com/plengauer/Thoth/pull/3702</a></li>
<li>Update docker/build-push-action action to v7.3.0 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3700">https://github.com/plengauer/Thoth/pull/3700</a></li>
<li>Update actions/cache action to v6 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3683">https://github.com/plengauer/Thoth/pull/3683</a></li>
<li>Update dependency traceloop-sdk to v0.62.1 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3695">https://github.com/plengauer/Thoth/pull/3695</a></li>
<li>Update renovatebot/github-action action to v46.1.17 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3694">https://github.com/plengauer/Thoth/pull/3694</a></li>
<li>Update dependency org.junit.jupiter:junit-jupiter to v6.1.1 by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3693">https://github.com/plengauer/Thoth/pull/3693</a></li>
<li>Rename quality job by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3696">https://github.com/plengauer/Thoth/pull/3696</a></li>
<li>Automatic Version Bump by @plengauer in <a href="https://github.com/plengauer/Thoth/pull/3698">https://github.com/plengauer/Thoth/pull/3698</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/plengauer/Thoth/compare/v5...v5.59.0">https://github.com/plengauer/Thoth/compare/v5...v5.59.0</a></p>
]]></content:encoded></item><item><title>Multi-Style Contribution Snake</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/multi-style-contribution-snake/</link><pubDate>Mon, 06 Jul 2026 06:24:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/multi-style-contribution-snake/</guid><description>Version updated for https://github.com/Pro-Bandey/multi-style-snake-contribution-grid to version v06.07.26.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 🐍 Multi-Style Snake Daily Update Automated daily release to the GitHub Marketplace.
Version Details:
Tag: v06.07.26 Release Date: $(date +’%A, %B %d, 20%y&amp;#39;) Included Features:
5 Unique Snake Styles (Blocks, Rounds, Triangles, Stars, Diamonds) Automated Month Labels above grids Dynamic Username Detection Auto-generated Asset Gallery</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Pro-Bandey/multi-style-snake-contribution-grid">https://github.com/Pro-Bandey/multi-style-snake-contribution-grid</a></strong> to version <strong>v06.07.26</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/multi-style-contribution-snake">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-multi-style-snake-daily-update">🐍 Multi-Style Snake Daily Update</h2>
<p>Automated daily release to the GitHub Marketplace.</p>
<p><strong>Version Details:</strong></p>
<ul>
<li><strong>Tag:</strong> <code>v06.07.26</code></li>
<li><strong>Release Date:</strong> $(date +&rsquo;%A, %B %d, 20%y')</li>
</ul>
<p><strong>Included Features:</strong></p>
<ul>
<li>5 Unique Snake Styles (Blocks, Rounds, Triangles, Stars, Diamonds)</li>
<li>Automated Month Labels above grids</li>
<li>Dynamic Username Detection</li>
<li>Auto-generated Asset Gallery</li>
</ul>
]]></content:encoded></item><item><title>websec-validator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/websec-validator/</link><pubDate>Mon, 06 Jul 2026 06:24:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/websec-validator/</guid><description>Version updated for https://github.com/raccioly/websec-validator to version v0.10.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Minor: the browser-vuln trio (XSS / clickjacking / CSRF) closes the classic-web-vuln gap, and a new enterprise / CI integration surface turns websec from a CLI-a-human-runs into a truth source a pipeline, dashboard, or any MCP agent can consume — SARIF, a --fail-on gate, git-diff baselining, a GitHub Action, an MCP server, and versioned output schemas. All stdlib, zero new runtime deps.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/raccioly/websec-validator">https://github.com/raccioly/websec-validator</a></strong> to version <strong>v0.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/websec-validator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Minor: the <strong>browser-vuln trio</strong> (XSS / clickjacking / CSRF) closes the classic-web-vuln gap, and a
new <strong>enterprise / CI integration surface</strong> turns websec from a CLI-a-human-runs into a truth source a
pipeline, dashboard, or any MCP agent can consume — SARIF, a <code>--fail-on</code> gate, git-diff baselining, a
GitHub Action, an MCP server, and versioned output schemas. All stdlib, zero new runtime deps.</p>
<h3 id="added">Added</h3>
<ul>
<li><strong>SARIF 2.1.0 output</strong> (<code>formats.py</code>) — every <code>run</code> writes <code>results.sarif</code> (one <code>rule</code> per attack
class carrying its CWE/ASVS/OWASP citation; severity → error/warning/note; stable
<code>partialFingerprints</code>). Drops into GitHub Code Scanning (inline PR annotations + Security tab),
GitLab, Azure DevOps, VS Code, DefectDojo. <code>--format sarif</code> also emits it to stdout for piping.</li>
<li><strong>CI gate</strong> — <code>--fail-on {critical,high,medium,low}</code> exits 1 when a finding at/above that severity
remains (report-only by default).</li>
<li><strong>Baseline / diff</strong> (<code>baseline.py</code>) — <code>--baseline &lt;prior findings-ledger.json&gt;</code> marks findings
<code>new</code>/<code>unchanged</code>/<code>fixed</code> via a stable per-finding fingerprint (surfaced as SARIF <code>baselineState</code>);
<code>--fail-on</code> then gates on <strong>only the new</strong> findings, so a legacy backlog doesn&rsquo;t block every PR.</li>
<li><strong>Reusable GitHub Action</strong> (<code>action.yml</code>) — composite action: install → run → upload SARIF, with
<code>fail-on</code> / <code>baseline</code> / <code>scan</code> inputs.</li>
<li><strong>MCP server</strong> (<code>mcp_server.py</code>, <code>websec mcp</code> + a <code>websec-mcp</code> entry point) — Model Context Protocol
over stdio (raw JSON-RPC 2.0, stdlib only) exposing <code>websec_recon</code> / <code>websec_findings</code> /
<code>websec_sarif</code> / <code>websec_briefing</code> so Cursor/Cline/Windsurf/Zed can call recon as typed tools.</li>
<li><strong>Versioned output contract</strong> — <code>schema_version</code> on FACTS/ledger/envelope + published JSON Schemas
(<code>schemas/facts.schema.json</code>, <code>schemas/ledger.schema.json</code>); a <code>findings.envelope.json</code> artifact.</li>
<li><strong>JSON envelope output</strong> (<code>--format json</code>) — a self-describing wrapper around the ledger for
non-GitHub CI / dashboards.</li>
<li><strong>Reflected / DOM / template XSS sink class</strong> (<code>surface.py</code>, 16th sink class) — the classic
browser-rendered vuln the recon layer previously deferred entirely to optional Semgrep. Detects
DOM sinks (<code>innerHTML</code>/<code>outerHTML</code>/<code>insertAdjacentHTML</code>/<code>document.write</code>/jQuery <code>.html()</code>), React
<code>dangerouslySetInnerHTML</code>, Vue <code>v-html</code>, and server template-escape-off (Jinja <code>|safe</code>, <code>mark_safe</code>,
<code>Markup(</code>, <code>{% autoescape false %}</code>, interpolated <code>res.send</code>/<code>res.write</code> HTML). A per-file sanitizer
guard (DOMPurify / sanitize-html / bleach / <code>escapeHtml</code>) suppresses the lead so a sanitized render
doesn&rsquo;t false-fire; kept LOW-confidence like every surface signal (<code>xss</code> → CWE-79/CWE-116, ASVS V5.3.3).</li>
<li><strong>Framework-agnostic clickjacking baseline</strong> (<code>transport_security.py</code>) — a web surface that sets
neither <code>X-Frame-Options</code> nor a CSP <code>frame-ancestors</code> directive is framable (UI-redress). Previously
clickjacking was only checked inside Next.js configs; now it parallels the CSP/HSTS baseline for
Express/Flask/Django/any surface (<code>clickjacking</code> → CWE-1021/CWE-451, ASVS V14.4.7).</li>
<li><strong>CSRF baseline</strong> (<code>transport_security.py</code>) — a cookie/session-authenticated app with HTTP routes
but no anti-CSRF token library/middleware (csurf/csrf-csrf/@fastify/csrf/Django/Rails) and no
<code>SameSite</code> cookie attribute. Derived from the auth extractor so a Bearer-token-only API is exempt —
low-FP by design (<code>csrf</code> → CWE-352, ASVS V4.2.2).</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>Metrics: 15 → <strong>16 sink classes</strong>, 238 → <strong>285 tests</strong>. New modules: <code>formats.py</code>, <code>baseline.py</code>,
<code>mcp_server.py</code>, <code>schemas/</code>. New CLI: <code>--format</code>, <code>--fail-on</code>, <code>--baseline</code>, <code>websec mcp</code>.</li>
</ul>
<h3 id="added-coverage--false-negatives-the-fpfn-audit-surfaced">Added (coverage — false negatives the FP/FN audit surfaced)</h3>
<ul>
<li><strong>AWS SAM / serverless route modeling</strong> (<code>routes.py</code>) — a <code>template.yaml</code>&rsquo;s <code>AWS::Serverless::Function</code>
Api/HttpApi events and Function URLs are now mapped to routes (handler resolved to the source file,
build-dir <code>dist/</code>→<code>src/</code> aware), so a serverless backend is no longer 0-routes/unprobed. A Function URL
with <code>AuthType: NONE</code> emits an <strong>unauthenticated-serverless-endpoint</strong> finding (a public dashboard
serving account/P&amp;L/PII data is the risk). Stdlib-only line/regex parse — no YAML dependency. On the
audit corpus this surfaced a public P&amp;L dashboard and a 19-route backend that were previously invisible.</li>
<li><strong>Broken-auth backdoor detector</strong> (<code>auth.py</code>) — the total-auth-bypass bugs the route/guard model can&rsquo;t
see because the endpoint <em>is</em> &ldquo;guarded&rdquo;, just by something forgeable. Flags a <strong>dev-token backdoor</strong>
(<code>token.startsWith('dev-')</code> deriving a principal), an <strong>accept-any-credential</strong> login (explicit
accept-any/MVP intent, or a password-length-only check with no hash compare), and a <strong>fail-open
signature/secret verification</strong> (<code>if(env.*_SECRET){ verify }</code> that silently skips when the secret is
unset). New classes <code>auth-backdoor</code> (CRITICAL, CWE-288/798/287) and <code>fail-open-auth</code> (HIGH, CWE-636/325).
On the audit corpus it caught a treasury API&rsquo;s <code>dev-*</code> bearer bypass, an accept-any-password login that
self-elevates to admin, and a fail-open Stripe webhook verify — all previously missed.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<p>Real-repo false-positive audit (ran recon against a diverse set of real GitHub repos — TS/Python
frontends, backends, CLIs, static sites):</p>
<ul>
<li><strong>Path-scoped standalone guard mounts</strong> (<code>authz.py</code>) — <code>app.use('/api', requireAuth)</code> on its own
line, with routers mounted on <code>/api</code> in later statements, is now recognized (resolving each router
instance&rsquo;s import and respecting Express source order, so a router mounted <em>before</em> the guard — e.g.
a public login route — stays unguarded). Cut a real backend&rsquo;s guarded-route false positives 63→5.</li>
<li><strong>Frontend API-client files no longer parsed as server routes</strong> (<code>routes.py</code>) — in a combined
frontend+backend monorepo, a React axios client (<code>import {api} from './client'; api.get('/x')</code>) and
static hosting config (<code>public/_redirects</code>) were emitted as endpoints and flagged missing-auth. Now
dropped via a client-vs-handler discriminator that still keeps serverless handlers (Cloudflare Pages
<code>onRequest*</code>, Lambda <code>handler</code>) even when they call axios/fetch. Cut a monorepo&rsquo;s missing-auth 185→3.</li>
<li><strong>Python test files</strong> (<code>test_*.py</code> / <code>*_test.py</code> / <code>conftest.py</code>) are now classified as tests
(<code>base.py</code>), so a <code>test_curl.py</code> doing <code>requests.get()</code> no longer false-fires SSRF.</li>
<li><strong>Browser-hardening findings gated on a served-web surface</strong> (<code>transport_security.py</code>) — CSP / HSTS /
clickjacking no longer fire on a non-web Python/CLI tool that merely builds an HTML string (a report
generator); they require an HTTP-serving construct (<code>new Response</code> / <code>res.send</code> / a framework).</li>
</ul>
<p>Second FP audit — a 15-agent adversarial workflow verified every finding across the corpus against the
real code and clustered the false positives; the dominant patterns are now fixed (corpus findings
308 → 191, −37%, with zero true-positive loss):</p>
<ul>
<li><strong>App-specific auth-wrapper recognition</strong> (<code>authz.py</code>) — a handler wrapped in an application HOF that
composes a known guard (<code>withDealAuth = withAuth(...)</code>, <code>withSuperAdmin</code>, <code>requireUserRecord</code>) is now
credited (dynamic guard-alias resolver, generic-aware <code>withDealAuth&lt;{…}&gt;(</code>). Also recognizes Fastify
<code>addHook('onRequest', auth)</code> / per-route <code>{preHandler: auth}</code> and a secret-bearer guard
(<code>Bearer ${CRON_SECRET}</code>). Cut one real app&rsquo;s missing-auth 94→3 (total 111→18).</li>
<li><strong>Request-driven sinks gated on a web surface</strong> (<code>surface.py</code>) — SSRF / path-traversal /
command-injection / open-redirect are suppressed on a repo with no HTTP listener (a CLI / library /
data tool: <code>languages</code> analyzed, no routes, no framework) and in more script/CLI file classes
(research/, tools/, notebooks/, a Python <code>__main__</code>/argparse module).</li>
<li><strong>PKCE is not password hashing</strong> (<code>crypto_usage.py</code>) — a <code>createHash('sha256')</code> over an OAuth PKCE
<code>code_verifier</code> (RFC 7636) no longer false-fires weak-password-hash.</li>
<li><strong>webhook-forgery requires receiver evidence</strong> (<code>integrations.py</code>) — an OAuth authorization-code
callback, a webhook-subscription-management CRUD route, or a GET stub at a webhook-ish path is no
longer flagged unsigned; a weak path (<code>/callback</code>) now needs raw-body/event/signature evidence, and
verification via an imported helper (<code>constructEvent</code>) counts. Cleared ~16 FPs; kept real leads.</li>
<li><strong>CSRF credits framework defaults</strong> (<code>transport_security.py</code>) — NextAuth/Auth.js (SameSite=Lax by
default) and Next.js Server Actions (built-in Origin check) no longer trigger the no-SameSite CSRF lead.</li>
</ul>
]]></content:encoded></item><item><title>SpecGuard CI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/specguard-ci/</link><pubDate>Mon, 06 Jul 2026 06:23:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/specguard-ci/</guid><description>Version updated for https://github.com/Sawaiz-zip/spec-guard to version v0.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed SpecGuard v0.4.0 Semantic governance gate for spec files — classifies PR changes against a locked project goal/scope and blocks unauthorized drift.
Highlights since v0.3.0 GitHub App — native check runs, fork-PR governance, and agent-identity handling for PRs that don’t come through the classic CI workflow (specs/006-github-app/) Advanced governance — section-level locking (govern just part of a file), monorepo multi-scope support (independent verdicts per package), and audit-trail JSON export (specs/007-advanced/) Approval commands — /specguard approve comment command and MCP containment for agent-driven approvals (specs/005-approval-commands/) Version metadata now consistent across pyproject.toml, __init__.py, and action.yml (all 0.4.0) Using this release - uses: Sawaiz-zip/spec-guard@v0 with: anthropic-api-key: ${{ secrets.ANTHROPIC_API_KEY }} specguard-ci==0.4.0 is published on PyPI; the composite action pins to it directly.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Sawaiz-zip/spec-guard">https://github.com/Sawaiz-zip/spec-guard</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/specguard-ci">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="specguard-v040">SpecGuard v0.4.0</h2>
<p>Semantic governance gate for spec files — classifies PR changes against a locked project goal/scope and blocks unauthorized drift.</p>
<h3 id="highlights-since-v030">Highlights since v0.3.0</h3>
<ul>
<li><strong>GitHub App</strong> — native check runs, fork-PR governance, and agent-identity handling for PRs that don&rsquo;t come through the classic CI workflow (<code>specs/006-github-app/</code>)</li>
<li><strong>Advanced governance</strong> — section-level locking (govern just part of a file), monorepo multi-scope support (independent verdicts per package), and audit-trail JSON export (<code>specs/007-advanced/</code>)</li>
<li><strong>Approval commands</strong> — <code>/specguard approve</code> comment command and MCP containment for agent-driven approvals (<code>specs/005-approval-commands/</code>)</li>
<li>Version metadata now consistent across <code>pyproject.toml</code>, <code>__init__.py</code>, and <code>action.yml</code> (all <code>0.4.0</code>)</li>
</ul>
<h3 id="using-this-release">Using this release</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Sawaiz-zip/spec-guard@v0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">anthropic-api-key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span></code></pre></div><p><code>specguard-ci==0.4.0</code> is published on PyPI; the composite action pins to it directly.</p>
<h3 id="full-history">Full history</h3>
<p>001 CI gate → 002 local tools → 003 provider-agnostic classifier → 004 framework adapters → 005 approval commands → 006 GitHub App → 007 advanced governance. See <code>specs/</code> for individual feature specs.</p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/bernstein-multi-agent-orchestration/</link><pubDate>Mon, 06 Jul 2026 06:22:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v2.16.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.16.0 Released 2026-07-05.
An output-economy and worker-reliability release: response-style profiles wired end to end, ledger-attributed savings you can recompute, a three-arm cost-and-quality A/B harness, proactive context compaction with signed receipts, schema-enforced worker outcomes, and pinned team manifests. Plus a batch of contributor reliability fixes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v2.16.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v2160">v2.16.0</h1>
<p>Released 2026-07-05.</p>
<p>An output-economy and worker-reliability release: response-style profiles wired end to end, ledger-attributed savings you can recompute, a three-arm cost-and-quality A/B harness, proactive context compaction with signed receipts, schema-enforced worker outcomes, and pinned team manifests. Plus a batch of contributor reliability fixes.</p>
<h2 id="output-economy">Output economy</h2>
<ul>
<li>Response-style profiles are now resolved deterministically per role or per task and rendered into the worker spawn prompt; the profile hash is folded into task identity and recorded in the cost ledger. (#2251)</li>
<li>Per-profile cost attribution: <code>bernstein cost --by profile</code> and a content-addressed, audit-chain-anchored <code>bernstein cost profile-report</code> whose every figure recomputes from ledger entries; mid-run profile changes are excluded rather than guessed. (#2255)</li>
<li>Three-arm profile A/B harness (<code>bernstein eval ab --suite ... --arms 3</code>): baseline, minimal-control, and candidate arms, cost and quality in one canonical-JSON comparison artifact with every cost figure referenced to a ledger line. (#2264)</li>
<li>Operator-gated role-template compression (<code>bernstein templates compress|restore</code>): mechanical invariant validators, out-of-tree hash-verified backups, byte-identical restore, and chained receipts; savings are only ever reported from real ledger deltas. (#2272)</li>
</ul>
<h2 id="worker-reliability-and-safety">Worker reliability and safety</h2>
<ul>
<li>Proactive context compaction: long-running workers compact at a configurable pressure threshold instead of waiting for an overflow failure; each event is validated by zero-LLM invariant checks (code blocks and error text must survive) and recorded as an HMAC-chained receipt. <code>bernstein compaction log --task &lt;id&gt;</code>. (#2263)</li>
<li>Credential-shaped content is refused before any compaction or summary request reaches a model API; redactions and refusals are audit-logged by span hash, never by content. Reactive-path refusals now fail fast with a typed reason instead of burning retries. (#2250, #2270)</li>
<li>Schema-enforced worker completion payloads with typed refusal outcomes; an invalid payload is a typed <code>contract_violation</code> failure, and blocked workers report a closed set of refusal kinds the orchestrator can route deterministically. (#2252)</li>
<li>Named, sha256-pinned team manifests with drift detection and lineage-recorded digests: <code>bernstein team list|show|drift</code>. (#2256)</li>
</ul>
<h2 id="contributor-fixes">Contributor fixes</h2>
<p>Thanks to @shanemmattner for a deep reliability batch, all merged with authorship preserved:</p>
<ul>
<li>Tasks now transition to failed on <code>MaxTurnsExceeded</code> instead of hanging in <code>claimed</code>; the previously dead timeout / auth-error / api-error fast-fail paths are activated. (#2259)</li>
<li>Static budget-aware prompt nudge for turn-limited models, composing with the response-style addendum. (#2260)</li>
<li>A batch of ten independent bugfixes across the run-id override, seed-path resolution, model-alias matching, auto-commit deny list, merge safety, and secret-log hygiene. (#2261)</li>
<li>Instrumentation capture for content, tool results, and batched-task fan-out; JSONL parser resilience; a single documented max_turns validation story across the API, adapter, and resolution layers. (#2262)</li>
</ul>
<h2 id="internal">Internal</h2>
<ul>
<li>Fixed a per-request <code>/api/v1</code> router mutation that grew route tables quadratically and could crash the test harness with recursion; app factories now build a fresh router each call. (#2266)</li>
<li>Migrated the remaining str-Enum classes to <code>StrEnum</code>. (#2267)</li>
<li>Refreshed the deferred-adapter review stamps and resolved outstanding scanner findings. (#2258)</li>
</ul>
]]></content:encoded></item><item><title>Jekyll Redirects for Cloudflare</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/jekyll-redirects-for-cloudflare/</link><pubDate>Mon, 06 Jul 2026 06:22:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/jekyll-redirects-for-cloudflare/</guid><description>Version updated for https://github.com/SocksTheWolf/jekyll-cloudflare-redirects to version v1.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Just some minor logging changes, nothing major. Should be the final release for awhile.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SocksTheWolf/jekyll-cloudflare-redirects">https://github.com/SocksTheWolf/jekyll-cloudflare-redirects</a></strong> to version <strong>v1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jekyll-redirects-for-cloudflare">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Just some minor logging changes, nothing major. Should be the final release for awhile.</p>
]]></content:encoded></item><item><title>Papyrus Markdown Export</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/papyrus-markdown-export/</link><pubDate>Mon, 06 Jul 2026 06:21:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/papyrus-markdown-export/</guid><description>Version updated for https://github.com/thomas-worm/papyrus-export-markdown to version v1.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by ? repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed papyrus-export-markdown This initial release provides a GitHub action that can export documentation from Papyrus projects in Markdown format. It iterates over a package tree and exports documentation and diagrams.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/thomas-worm/papyrus-export-markdown">https://github.com/thomas-worm/papyrus-export-markdown</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>?</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/papyrus-markdown-export">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="papyrus-export-markdown">papyrus-export-markdown</h1>
<p>This initial release provides a GitHub action that can export documentation from Papyrus projects in Markdown format. It iterates over a package tree and exports documentation and diagrams.</p>
<h2 id="prerequisites">Prerequisites</h2>
<p>You need to run <code>thomas-worm/setup-papyrus</code> before this action in your workflow or have pre-rendered diagram images available.</p>
<h2 id="sample-workflow">Sample workflow</h2>
<p>This workflow would export all documentation to an model_docs folder:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">Export documentation</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">on</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">push</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">paths</span>: [<span style="color:#e6db74">&#39;model/**&#39;</span>]
</span></span><span style="display:flex;"><span><span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">export</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v6</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">id</span>: <span style="color:#ae81ff">papyrus</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">thomas-worm/setup-papyrus@v1</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">thomas-worm/papyrus-export-markdown@v1</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">papyrus-home</span>:     <span style="color:#ae81ff">${{ steps.papyrus.outputs.papyrus-home }}</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">papyrus-launcher</span>: <span style="color:#ae81ff">${{ steps.papyrus.outputs.papyrus-launcher }}</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">model-dir</span>:        <span style="color:#ae81ff">model</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">output-dir</span>:       <span style="color:#ae81ff">model_docs</span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">run</span>: |<span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">          git config user.name  &#34;github-actions[bot]&#34;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">          git config user.email &#34;github-actions[bot]@users.noreply.github.com&#34;
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">          git add docs
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">          git diff --staged --quiet || \
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">            (git commit -m &#34;docs: re-export documentation [skip ci]&#34; &amp;&amp; \
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">             git push origin HEAD:${GITHUB_REF#refs/heads/})</span>
</span></span></code></pre></div><h2 id="inputs">Inputs</h2>
<table>
  <thead>
      <tr>
          <th>Input</th>
          <th>Default</th>
          <th>Description</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>model-dir</code></td>
          <td><code>model</code></td>
          <td>Scanned recursively for <code>*.uml</code>, <code>*.di</code>/<code>*.notation</code> and <code>*.aird</code> files. GMF diagrams need their <code>.di</code> file (same rule as <code>papyrus-export-diagrams</code>).</td>
      </tr>
      <tr>
          <td><code>start-package</code></td>
          <td>model root</td>
          <td>Package to start from: qualified name (<code>Documentation::arc42</code>, with or without the root model name) or <code>xmi:id</code>.</td>
      </tr>
      <tr>
          <td><code>output-dir</code></td>
          <td>—</td>
          <td>Root of the generated markdown tree. Created if missing.</td>
      </tr>
      <tr>
          <td><code>include-diagrams</code></td>
          <td><code>true</code></td>
          <td>Embed diagrams placed directly inside a package into that package&rsquo;s file (see ordering rules below).</td>
      </tr>
      <tr>
          <td><code>diagram-format</code></td>
          <td><code>SVG</code></td>
          <td>One of <code>SVG</code>, <code>PNG</code>, <code>JPEG</code>, <code>BMP</code>, <code>GIF</code>.</td>
      </tr>
      <tr>
          <td><code>images-subdir</code></td>
          <td><code>images</code></td>
          <td>Directory below <code>output-dir</code> holding the diagram images.</td>
      </tr>
      <tr>
          <td><code>images-dir</code></td>
          <td>—</td>
          <td>Pre-exported diagram images (<code>naming: xmiId</code>). Skips the internal diagram export.</td>
      </tr>
      <tr>
          <td><code>index-file</code></td>
          <td><code>README.md</code></td>
          <td>Per-package file name; use <code>index.md</code> for MkDocs-style sites.</td>
      </tr>
      <tr>
          <td><code>add-title</code></td>
          <td><code>true</code></td>
          <td>Start every file with a <code># &lt;package name&gt;</code> heading.</td>
      </tr>
      <tr>
          <td><code>papyrus-home</code></td>
          <td>—</td>
          <td>From <code>setup-papyrus</code>. Required unless <code>images-dir</code> is set.</td>
      </tr>
      <tr>
          <td><code>papyrus-launcher</code></td>
          <td>—</td>
          <td>From <code>setup-papyrus</code>. Optional.</td>
      </tr>
      <tr>
          <td><code>fail-on-error</code></td>
          <td><code>true</code></td>
          <td>Fail on export errors and unresolvable <code>uml:#</code> references. Set to <code>false</code> to get partial output with warnings.</td>
      </tr>
  </tbody>
</table>
<h2 id="outputs">Outputs</h2>
<table>
  <thead>
      <tr>
          <th>Output</th>
          <th>Description</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>package-count</code></td>
          <td>Number of markdown files generated (one per package).</td>
      </tr>
      <tr>
          <td><code>diagram-count</code></td>
          <td>Number of distinct diagram images embedded or referenced.</td>
      </tr>
  </tbody>
</table>
<h2 id="how-the-documentation-is-modelled">How the documentation is modelled</h2>
<p>The text shown in Papyrus Desktop&rsquo;s <em>Documentation</em> view of a package is
stored as a <code>Comment</code> owned by the package that <em>annotates</em> the package.
Exactly those comments become the package&rsquo;s markdown content, in model
order, emitted verbatim — write markdown in the Documentation textarea
and it ends up 1:1 in the generated file.</p>
<p>The package tree becomes the folder tree: every package is a directory
with one <code>index-file</code> inside; the starting package&rsquo;s file sits directly
in <code>output-dir</code>. Directory names are the package names with unsafe
characters replaced by <code>_</code>.</p>
<p>Diagrams placed inside a package are appended after the package&rsquo;s
comments (with <code>include-diagrams: true</code>). Papyrus does not persist an
ordering between comments and diagrams, so to place a diagram at an
exact position — for example between two paragraphs — reference it
explicitly with a <code>uml:#</code> image link; explicitly referenced diagrams
are not appended a second time.</p>
<h2 id="referencing-model-content-from-comments">Referencing model content from comments</h2>
<p>Inside comment bodies the following link forms are rewritten:</p>
<ul>
<li><code>![Alt text](uml:#_DjtpcGsBEfGhz_JEWM1XrA)</code> — a diagram by its unique
id (the <code>xmi:id</code> of the diagram in the <code>.notation</code> file, or the
descriptor <code>uid</code> in the <code>.aird</code> file).</li>
<li><code>![Alt text](&lt;uml:#Documentation::Building Block View::BuildingBlockView&gt;)</code>
— a diagram by qualified name: the owning packages&rsquo; names plus the
diagram name, <code>::</code>-separated. The root model name may be omitted.
Wrap the URI in <code>&lt;…&gt;</code> when names contain spaces (or <code>%20</code>-encode).</li>
<li><code>![Alt text](&lt;uml:#Documentation::Building Block View&gt;)</code> — when the
reference resolves to a <em>package</em> instead of a diagram, an image link
embeds all diagrams placed directly in that package.</li>
<li><code>[Link text](&lt;uml:#Documentation::Glossary&gt;)</code> — a plain (non-image)
link to a package becomes a link to that package&rsquo;s generated file.</li>
<li><code>![Alt text](images/photo.png)</code> — plain relative references are
resolved against the folder of the model file that contains the
comment; the referenced files are copied into the output tree and the
paths adjusted automatically.</li>
</ul>
<h2 id="table-of-contents">Table of contents</h2>
<p>Put a TOC directive into any documentation comment:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-markdown" data-lang="markdown"><span style="display:flex;"><span>&lt;!-- toc --&gt;
</span></span></code></pre></div><p>It expands to a nested bullet list of all sub-packages of the current
package, linking their generated files. An optional
<code>&lt;!-- toc --maxdepth=2 --&gt;</code> limits the nesting depth. The generated list
is wrapped in <code>&lt;!-- toc --&gt;</code> … <code>&lt;!-- tocstop --&gt;</code> markers, so the
directive stays invisible in unprocessed markdown and re-exports are
idempotent. <code>[[_TOC_]]</code> and <code>[TOC]</code> (alone on a line) are accepted as
aliases.</p>
]]></content:encoded></item><item><title>Auto Version</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/auto-version/</link><pubDate>Mon, 06 Jul 2026 06:21:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/06/auto-version/</guid><description>Version updated for https://github.com/twopow/auto-version-action to version v1.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/twopow/auto-version-action/compare/v1...v1.4</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/twopow/auto-version-action">https://github.com/twopow/auto-version-action</a></strong> to version <strong>v1.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/auto-version">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/twopow/auto-version-action/compare/v1...v1.4">https://github.com/twopow/auto-version-action/compare/v1...v1.4</a></p>
]]></content:encoded></item><item><title>cibuild-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/cibuild-action/</link><pubDate>Sun, 05 Jul 2026 22:08:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/cibuild-action/</guid><description>Version updated for https://github.com/invarnhq/cibuild to version v2.3.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v2.3.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/invarnhq/cibuild">https://github.com/invarnhq/cibuild</a></strong> to version <strong>v2.3.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cibuild-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release v2.3.2</p>
]]></content:encoded></item><item><title>IsReadyAI — readiness audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/isreadyai-readiness-audit/</link><pubDate>Sun, 05 Jul 2026 22:08:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/isreadyai-readiness-audit/</guid><description>Version updated for https://github.com/isreadyai/audit-action to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed bump actions to node24 versions (de249af) fix: marketplace-compliant description (fd40855) feat: initial action release tree (63ef75c)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/isreadyai/audit-action">https://github.com/isreadyai/audit-action</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/isreadyai-readiness-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>bump actions to node24 versions (de249af)</li>
<li>fix: marketplace-compliant description (fd40855)</li>
<li>feat: initial action release tree (63ef75c)</li>
</ul>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/neurolink-ai/</link><pubDate>Sun, 05 Jul 2026 22:07:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v9.81.2.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 9.81.2 (2026-07-05) Bug Fixes (mcp): do not cache error tool results (BZ-664 follow-up) (8f876dc)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v9.81.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="9812-2026-07-05"><a href="https://github.com/juspay/neurolink/compare/v9.81.1...v9.81.2">9.81.2</a> (2026-07-05)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(mcp):</strong>  do not cache error tool results (BZ-664 follow-up) (<a href="https://github.com/juspay/neurolink/commit/8f876dc55fff4410b4a78cafd2de3f4146a875d1">8f876dc</a>)</li>
</ul>
]]></content:encoded></item><item><title>Setup runner cli</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/setup-runner-cli/</link><pubDate>Sun, 05 Jul 2026 22:06:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/setup-runner-cli/</guid><description>Version updated for https://github.com/kjanat/runner to version v0.19.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added runner lsp completes [tasks.overrides] entry keys with the project’s own task names (discovered from the document’s directory, same detection as the CLI), each carrying its source and description. Works both under the [tasks.overrides] header and as a dotted overrides.&amp;lt;task&amp;gt; key in [tasks]; names that aren’t bare TOML keys (e.g. build:web) insert quoted. Dotted overrides.&amp;lt;task&amp;gt; = values now complete the source-label vocabulary like their [tasks.overrides] equivalents. runner lsp key completions scaffold the value shape the field’s schema type calls for, when the client supports snippets: array fields insert pms = [&amp;#34;|&amp;#34;], string fields node = &amp;#34;|&amp;#34;, others a bare tab stop; table fields continue the dotted key path (overrides.), which re-triggers completion. Clients without snippet support keep the plain name = insert. Fixed runner lsp no longer offers field completions after a dotted key (group_output. suggested the section’s whole field list; TOML reads the dot as a key path, and no section has enumerable sub-keys). Key completions also now carry an explicit text edit replacing the typed token, so a completion accepted from a stale list (e.g. left open across a backspace) substitutes the token instead of pasting after it (group_outputgroup_output =). runner lsp value completions inside an open string literal (prefer = [&amp;#34;ba) insert the bare word instead of a quoted one — the quotes are already typed (and auto-paired), so accepting previously produced &amp;#34;&amp;#34;bacon&amp;#34;&amp;#34;. runner lsp is now comment-aware: no completions or hover at or after a # (whole-line or trailing); a # inside a string literal still isn’t treated as a comment. What’s Changed fix(lsp): dotted-key completion fixes + complete [tasks.overrides] keys with project task names by @kjanat in https://github.com/kjanat/runner/pull/85 Full Changelog: https://github.com/kjanat/runner/compare/v0.19.0...v0.19.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kjanat/runner">https://github.com/kjanat/runner</a></strong> to version <strong>v0.19.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-runner-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><code>runner lsp</code> completes <code>[tasks.overrides]</code> entry keys with the
project&rsquo;s own task names (discovered from the document&rsquo;s directory,
same detection as the CLI), each carrying its source and description.
Works both under the <code>[tasks.overrides]</code> header and as a dotted
<code>overrides.&lt;task&gt;</code> key in <code>[tasks]</code>; names that aren&rsquo;t bare TOML keys
(e.g. <code>build:web</code>) insert quoted. Dotted <code>overrides.&lt;task&gt; =</code> values
now complete the source-label vocabulary like their
<code>[tasks.overrides]</code> equivalents.</li>
<li><code>runner lsp</code> key completions scaffold the value shape the field&rsquo;s
schema type calls for, when the client supports snippets: array fields
insert <code>pms = [&quot;|&quot;]</code>, string fields <code>node = &quot;|&quot;</code>, others a bare tab
stop; table fields continue the dotted key path (<code>overrides.</code>), which
re-triggers completion. Clients without snippet support keep the plain
<code>name =</code> insert.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><code>runner lsp</code> no longer offers field completions after a dotted key
(<code>group_output.</code> suggested the section&rsquo;s whole field list; TOML reads
the dot as a key path, and no section has enumerable sub-keys). Key
completions also now carry an explicit text edit replacing the typed
token, so a completion accepted from a stale list (e.g. left open
across a backspace) substitutes the token instead of pasting after it
(<code>group_outputgroup_output =</code>).</li>
<li><code>runner lsp</code> value completions inside an open string literal
(<code>prefer = [&quot;ba</code>) insert the bare word instead of a quoted one — the
quotes are already typed (and auto-paired), so accepting previously
produced <code>&quot;&quot;bacon&quot;&quot;</code>.</li>
<li><code>runner lsp</code> is now comment-aware: no completions or hover at or after
a <code>#</code> (whole-line or trailing); a <code>#</code> inside a string literal still
isn&rsquo;t treated as a comment.</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(lsp): dotted-key completion fixes + complete [tasks.overrides] keys with project task names by @kjanat in <a href="https://github.com/kjanat/runner/pull/85">https://github.com/kjanat/runner/pull/85</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/kjanat/runner/compare/v0.19.0...v0.19.1">https://github.com/kjanat/runner/compare/v0.19.0...v0.19.1</a></p>
]]></content:encoded></item><item><title>conventional-semver</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/conventional-semver/</link><pubDate>Sun, 05 Jul 2026 22:06:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/conventional-semver/</guid><description>Version updated for https://github.com/logi-camp/conventional-semver to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v1.1.0 — Prerelease Support New Features Prerelease versioning — New prerelease input to generate tags like v1.3.0-rc.1 or v1.3.0-rc.a1b2c3d. Prerelease identifier modes — numbered (auto-incrementing rc.1, rc.2, …) or sha (commit hash-based). SHA suffix control — include_sha input: auto (prerelease only), true, or false. New Outputs base_version — Base version without prerelease suffix (e.g. 1.3.0) base_version_tag — Base version tag with prefix (e.g. v1.3.0) rc_number — The prerelease identifier number or SHA Improvements Expanded test suite with dedicated prerelease test cases Improved test output formatting and helper utilities Usage - uses: Logiconamp/conventional-semver@v1.1.0 with: prerelease: rc prerelease_identifier: numbered # or sha</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/logi-camp/conventional-semver">https://github.com/logi-camp/conventional-semver</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/conventional-semver">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v110--prerelease-support">v1.1.0 — Prerelease Support</h2>
<h3 id="new-features">New Features</h3>
<ul>
<li><strong>Prerelease versioning</strong> — New <code>prerelease</code> input to generate tags like <code>v1.3.0-rc.1</code> or <code>v1.3.0-rc.a1b2c3d</code>.</li>
<li><strong>Prerelease identifier modes</strong> — <code>numbered</code> (auto-incrementing <code>rc.1</code>, <code>rc.2</code>, &hellip;) or <code>sha</code> (commit hash-based).</li>
<li><strong>SHA suffix control</strong> — <code>include_sha</code> input: <code>auto</code> (prerelease only), <code>true</code>, or <code>false</code>.</li>
</ul>
<h3 id="new-outputs">New Outputs</h3>
<ul>
<li><code>base_version</code> — Base version without prerelease suffix (e.g. <code>1.3.0</code>)</li>
<li><code>base_version_tag</code> — Base version tag with prefix (e.g. <code>v1.3.0</code>)</li>
<li><code>rc_number</code> — The prerelease identifier number or SHA</li>
</ul>
<h3 id="improvements">Improvements</h3>
<ul>
<li>Expanded test suite with dedicated prerelease test cases</li>
<li>Improved test output formatting and helper utilities</li>
</ul>
<h3 id="usage">Usage</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Logiconamp/conventional-semver@v1.1.0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">prerelease</span>: <span style="color:#ae81ff">rc</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">prerelease_identifier</span>: <span style="color:#ae81ff">numbered </span> <span style="color:#75715e"># or sha</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>ReviewGate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/reviewgate/</link><pubDate>Sun, 05 Jul 2026 22:05:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/reviewgate/</guid><description>Version updated for https://github.com/LVTD-LLC/reviewgate to version v0.1.12.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed [Docs] Add ReviewGate Agent Skills by @rasulkireev in https://github.com/LVTD-LLC/reviewgate/pull/31 Highlights Added public check-reviewgate and reviewgate-loop agent skills. Documented npx skills add LVTD-LLC/reviewgate installation. Added comment-before-resolve guidance for agent repair loops. Added CI validation for public skill frontmatter, fenced Markdown, and shell snippets. Full Changelog: https://github.com/LVTD-LLC/reviewgate/compare/v0.1.11...v0.1.12</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/LVTD-LLC/reviewgate">https://github.com/LVTD-LLC/reviewgate</a></strong> to version <strong>v0.1.12</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/reviewgate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>[Docs] Add ReviewGate Agent Skills by @rasulkireev in <a href="https://github.com/LVTD-LLC/reviewgate/pull/31">https://github.com/LVTD-LLC/reviewgate/pull/31</a></li>
</ul>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Added public <code>check-reviewgate</code> and <code>reviewgate-loop</code> agent skills.</li>
<li>Documented <code>npx skills add LVTD-LLC/reviewgate</code> installation.</li>
<li>Added comment-before-resolve guidance for agent repair loops.</li>
<li>Added CI validation for public skill frontmatter, fenced Markdown, and shell snippets.</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/LVTD-LLC/reviewgate/compare/v0.1.11...v0.1.12">https://github.com/LVTD-LLC/reviewgate/compare/v0.1.11...v0.1.12</a></p>
]]></content:encoded></item><item><title>EIS — Upload Signals</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/eis-upload-signals/</link><pubDate>Sun, 05 Jul 2026 22:05:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/eis-upload-signals/</guid><description>Version updated for https://github.com/machuz/eis to version v2.20.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog 12b8647cfb0faefd02757e3e2df9f56591ccf8b8 feat(attribution): expand + configure bot/AI co-author exclusion (#330) dc19e28d53502e089ce3cd4093238cfaca7eb2f7 feat(oss-map): monthly ingest + git/git (Linus) + identity pin + per-window streaming (#328)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/machuz/eis">https://github.com/machuz/eis</a></strong> to version <strong>v2.20.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/eis-upload-signals">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>12b8647cfb0faefd02757e3e2df9f56591ccf8b8 feat(attribution): expand + configure bot/AI co-author exclusion (#330)</li>
<li>dc19e28d53502e089ce3cd4093238cfaca7eb2f7 feat(oss-map): monthly ingest + git/git (Linus) + identity pin + per-window streaming (#328)</li>
</ul>
]]></content:encoded></item><item><title>Sentrik Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/sentrik-gate/</link><pubDate>Sun, 05 Jul 2026 22:04:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/sentrik-gate/</guid><description>Version updated for https://github.com/maxgerhardson/sentrik-community to version v1.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v1.6.0 Fixes the silent Linux binary. The v1.4.0 Linux binary produced no output and exited 0 due to a missing CLI entry-point invocation in the frozen build. All platform binaries in this release are built from a dedicated entry point and verified to produce output in CI before upload.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/maxgerhardson/sentrik-community">https://github.com/maxgerhardson/sentrik-community</a></strong> to version <strong>v1.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sentrik-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v160">v1.6.0</h2>
<p><strong>Fixes the silent Linux binary.</strong> The v1.4.0 Linux binary produced no output and exited 0 due to a missing CLI entry-point invocation in the frozen build. All platform binaries in this release are built from a dedicated entry point and verified to produce output in CI before upload.</p>
<p>Also in this release:</p>
<ul>
<li>npm wrapper now reports launch failures (wrong architecture, missing exec permission) instead of silently exiting 0</li>
<li>npm installer verifies the downloaded binary runs on your machine at install time</li>
<li>linux-arm64 is no longer incorrectly served the x64 binary — use <code>pip install sentrik</code> on ARM64 Linux</li>
</ul>
<p>Install: <code>npm install -g sentrik</code> or <code>pip install sentrik</code></p>
]]></content:encoded></item><item><title>FHIR Validator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/fhir-validator/</link><pubDate>Sun, 05 Jul 2026 22:04:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/fhir-validator/</guid><description>Version updated for https://github.com/medvertical/records-fhir-validator to version validator-v0.4.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed npm tarball release for @records-fhir/validator@0.4.2. Synced from medvertical/records monorepo.
Install npm install @records-fhir/validator@0.4.2 What’s new in 0.4.2 Patch release for validator architecture boundaries, evidence policy, and maintainability after the 0.4.1 evidence release.
Added Added stable host and conformance package surfaces for embedding and evidence tooling, keeping repository consumers off deprecated implementation subpaths. Added dedupeIssuesWithTrace() so duplicate-suppression decisions expose the named policy rule that removed an issue. Added an explicit FHIR Schema runtime policy export that keeps the graph path evidence-only until Java/reference and dual-path gates justify promotion. Changed Hardened public-export and mirror-import architecture guards so new internal validator exports or repository imports fail fast. Split terminology remote CodeSystem budget handling out of the API client and kept the fail-open budget reason traceable. Split remote CodeSystem budget aggregation tests into focused coverage. Documentation Documented validator fallback, fail-open, fail-closed, legacy compatibility, and release-gate guardrails. Verification Verified with merged PR #252 CI, main CI, validator build, OSS boundary audit, OSS package smoke, architecture guards, focused Vitest suites, and npm publish dry-run. Matched npm tarballs @records-fhir/validator@0.4.2 — also tagged validator-v0.4.2 @records-fhir/validation-types@0.1.5 The matching GitHub Action release (if any) is published separately under tag v0.4.2 and is not auto-synced; this release covers the npm package only.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/medvertical/records-fhir-validator">https://github.com/medvertical/records-fhir-validator</a></strong> to version <strong>validator-v0.4.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/fhir-validator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>npm tarball release for <code>@records-fhir/validator@0.4.2</code>. Synced from medvertical/records monorepo.</p>
<h2 id="install">Install</h2>
<pre tabindex="0"><code>npm install @records-fhir/validator@0.4.2
</code></pre><h2 id="whats-new-in-042">What&rsquo;s new in 0.4.2</h2>
<p>Patch release for validator architecture boundaries, evidence policy, and
maintainability after the 0.4.1 evidence release.</p>
<h3 id="added">Added</h3>
<ul>
<li>Added stable <code>host</code> and <code>conformance</code> package surfaces for embedding and
evidence tooling, keeping repository consumers off deprecated implementation
subpaths.</li>
<li>Added <code>dedupeIssuesWithTrace()</code> so duplicate-suppression decisions expose the
named policy rule that removed an issue.</li>
<li>Added an explicit FHIR Schema runtime policy export that keeps the graph path
evidence-only until Java/reference and dual-path gates justify promotion.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>Hardened public-export and mirror-import architecture guards so new internal
validator exports or repository imports fail fast.</li>
<li>Split terminology remote CodeSystem budget handling out of the API client and
kept the fail-open budget reason traceable.</li>
<li>Split remote CodeSystem budget aggregation tests into focused coverage.</li>
</ul>
<h3 id="documentation">Documentation</h3>
<ul>
<li>Documented validator fallback, fail-open, fail-closed, legacy compatibility,
and release-gate guardrails.</li>
</ul>
<h3 id="verification">Verification</h3>
<ul>
<li>Verified with merged PR #252 CI, main CI, validator build, OSS boundary audit,
OSS package smoke, architecture guards, focused Vitest suites, and npm publish
dry-run.</li>
</ul>
<h2 id="matched-npm-tarballs">Matched npm tarballs</h2>
<ul>
<li><code>@records-fhir/validator@0.4.2</code> — also tagged <code>validator-v0.4.2</code></li>
<li><code>@records-fhir/validation-types@0.1.5</code></li>
</ul>
<p>The matching GitHub Action release (if any) is published separately under tag <code>v0.4.2</code> and is not auto-synced; this release covers the npm package only.</p>
]]></content:encoded></item><item><title>moult-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/moult-action/</link><pubDate>Sun, 05 Jul 2026 22:03:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/moult-action/</guid><description>Version updated for https://github.com/moult-rb/moult-rb to version v0.4.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Add clone_group fingerprints to duplication findings and gate contributions by @GoodPie in https://github.com/moult-rb/moult-rb/pull/8 Full Changelog: https://github.com/moult-rb/moult-rb/compare/v0.3.0...v0.4.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/moult-rb/moult-rb">https://github.com/moult-rb/moult-rb</a></strong> to version <strong>v0.4.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/moult-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add clone_group fingerprints to duplication findings and gate contributions by @GoodPie in <a href="https://github.com/moult-rb/moult-rb/pull/8">https://github.com/moult-rb/moult-rb/pull/8</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/moult-rb/moult-rb/compare/v0.3.0...v0.4.0">https://github.com/moult-rb/moult-rb/compare/v0.3.0...v0.4.0</a></p>
]]></content:encoded></item><item><title>Agent Security Harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/agent-security-harness/</link><pubDate>Sun, 05 Jul 2026 22:03:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/agent-security-harness/</guid><description>Version updated for https://github.com/msaleme/red-team-blue-team-agent-fabric to version v4.9.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Closes the honest gap flagged in Discussion #231 and named by the ACM SIGOPS ATC ‘26 analysis Free-Riding the Agentic Web (arXiv:2605.30998).
Three of that paper’s four x402 attack primitives were already covered. The fourth — denial of settlement (consume the resource while withholding or delaying finality) — is a liveness attack with a different shape than a tamper→reject differential, so it was an untested gap. This release closes it: 3-of-4 → 4-of-4.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/msaleme/red-team-blue-team-agent-fabric">https://github.com/msaleme/red-team-blue-team-agent-fabric</a></strong> to version <strong>v4.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-security-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Closes the honest gap flagged in <a href="https://github.com/msaleme/red-team-blue-team-agent-fabric/discussions/231">Discussion #231</a> and named by the ACM SIGOPS <strong>ATC &lsquo;26</strong> analysis <em>Free-Riding the Agentic Web</em> (arXiv:2605.30998).</p>
<p>Three of that paper&rsquo;s four x402 attack primitives were already covered. The fourth — <strong>denial of settlement</strong> (consume the resource while withholding or delaying finality) — is a <strong>liveness</strong> attack with a different shape than a tamper→reject differential, so it was an untested gap. This release closes it: 3-of-4 → <strong>4-of-4</strong>.</p>
<h2 id="new-settlement_finality_harnesspy--8-tests-dset-001008">New: <code>settlement_finality_harness.py</code> — 8 tests (DSET-001..008)</h2>
<p>Stdlib-only, deterministic settlement state machine, every check fails closed:
release-before-finality (broadcast ≠ final), insufficient confirmations, reorg/reverted revocation, finality-deadline (withheld settlement), self-asserted finality vs an authentic receipt, escrow atomicity, grant idempotency (double-consume), and post-grant revocation.</p>
<p>The question under test: <strong>what is the authoritative finality point before the resource is released?</strong></p>
<p><strong>532 → 540 tests, 37 → 38 modules.</strong> Verified by <code>scripts/count_tests.py</code>.</p>
]]></content:encoded></item><item><title>SkillTotal AI Component Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/skilltotal-ai-component-security-scan/</link><pubDate>Sun, 05 Jul 2026 22:02:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/skilltotal-ai-component-security-scan/</guid><description>Version updated for https://github.com/pezhik/skilltotal to version v0.31.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed Ruleset 29 — four architectural false-positive fixes from a full audit of production reports (see RULES_CHANGELOG.md). The tandem “critical exfil” verdict was a symptom of broader engine gaps in where evidence is trusted; each class is fixed at the demotion layer so recall is preserved (efficacy + FP floors stay at 0): Example/demo/benchmark scaffolding (examples/, demo/, samples/, .env.example templates) is demoted to needs_review — it ships as illustration, not the component’s own runtime behavior. Also blocks such scaffolding from feeding ST-COMBO-EXFIL. Prompt-injection phrases inside structured-data values (.json / .yaml / .toml fixtures, scenario/eval data) are demoted — a string in a data blob is not an agent-facing instruction. MCP manifests are excluded (a tool description there is an instruction surface), so injection in mcp.json still scores. Over-broad MCP scope (ST-MCP-OVERBROAD-SCOPE) now only applies in an MCP context and ignores file-path globs (**/*.ts, .github/**) — a build-tool angular.json / greptile.json scope key is no longer misread as a permission wildcard. Net effect on audited projects: nopua high→low, ECC low/0, browser-use scaffold FP removed (real findings kept), and the tandem false “critical/malicious” collapses to medium/not-malicious.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pezhik/skilltotal">https://github.com/pezhik/skilltotal</a></strong> to version <strong>v0.31.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skilltotal-ai-component-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>Ruleset 29 — four architectural false-positive fixes from a full audit of production
reports</strong> (see <code>RULES_CHANGELOG.md</code>). The tandem &ldquo;critical exfil&rdquo; verdict was a symptom of
broader engine gaps in <em>where</em> evidence is trusted; each class is fixed at the demotion layer
so recall is preserved (efficacy + FP floors stay at 0):
<ul>
<li><strong>Example/demo/benchmark scaffolding</strong> (<code>examples/</code>, <code>demo/</code>, <code>samples/</code>, <code>.env.example</code>
templates) is demoted to <code>needs_review</code> — it ships as illustration, not the component&rsquo;s own
runtime behavior. Also blocks such scaffolding from feeding <code>ST-COMBO-EXFIL</code>.</li>
<li><strong>Prompt-injection phrases inside structured-data values</strong> (<code>.json</code> / <code>.yaml</code> / <code>.toml</code>
fixtures, scenario/eval data) are demoted — a string in a data blob is not an agent-facing
instruction. <strong>MCP manifests are excluded</strong> (a tool description there <em>is</em> an instruction
surface), so injection in <code>mcp.json</code> still scores.</li>
<li><strong>Over-broad MCP scope</strong> (<code>ST-MCP-OVERBROAD-SCOPE</code>) now only applies in an MCP context and
ignores file-path globs (<code>**/*.ts</code>, <code>.github/**</code>) — a build-tool <code>angular.json</code> / <code>greptile.json</code>
<code>scope</code> key is no longer misread as a permission wildcard.</li>
<li>Net effect on audited projects: <code>nopua</code> high→low, <code>ECC</code> low/0, <code>browser-use</code> scaffold FP
removed (real findings kept), and the <code>tandem</code> false &ldquo;critical/malicious&rdquo; collapses to
<code>medium</code>/not-malicious.</li>
</ul>
</li>
</ul>
]]></content:encoded></item><item><title>pipewell-confluence-publisher</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/pipewell-confluence-publisher/</link><pubDate>Sun, 05 Jul 2026 22:02:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/pipewell-confluence-publisher/</guid><description>Version updated for https://github.com/pipewell/confluence-publisher to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What changed Manifest write-back now handled by the action itself.
Previously, the consuming repo’s workflow was responsible for committing updated page IDs back to confluence-manifest.yaml after new pages were created. This required a direct push to main, which broke when branch protection was enabled.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pipewell/confluence-publisher">https://github.com/pipewell/confluence-publisher</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pipewell-confluence-publisher">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="what-changed">What changed</h2>
<p><strong>Manifest write-back now handled by the action itself.</strong></p>
<p>Previously, the consuming repo&rsquo;s workflow was responsible for committing updated page IDs back to <code>confluence-manifest.yaml</code> after new pages were created. This required a direct push to <code>main</code>, which broke when branch protection was enabled.</p>
<p>The action now handles write-back automatically:</p>
<ol>
<li>After a sync run, if new page IDs were assigned, the action commits the manifest via the GitHub Contents API.</li>
<li>If branch protection blocks the direct commit, the action opens a PR automatically. Merge it promptly &ndash; until merged, the next publish run will not have the new page IDs.</li>
</ol>
<p>To avoid the PR fallback, grant <code>github-actions[bot]</code> bypass permission on the branch protection rule for <code>main</code> in your repository settings.</p>
<h2 id="required-workflow-permissions">Required workflow permissions</h2>
<p>Add these to your publish workflow:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span></code></pre></div><h2 id="new-input">New input</h2>
<table>
  <thead>
      <tr>
          <th>Input</th>
          <th>Default</th>
          <th>Description</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>github-token</code></td>
          <td><code>GITHUB_TOKEN</code></td>
          <td>Override the token used for manifest write-back; useful when a PAT with elevated permissions is needed</td>
      </tr>
  </tbody>
</table>
<p>See <a href="https://github.com/pipewell/confluence-publisher/blob/main/docs/ONBOARDING.md">ONBOARDING.md</a> for full details.</p>
]]></content:encoded></item><item><title>Drawio Export Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/drawio-export-action/</link><pubDate>Sun, 05 Jul 2026 22:00:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/drawio-export-action/</guid><description>Version updated for https://github.com/rlespinasse/drawio-export-action to version v2.52.0.
This action is used across all versions by 124 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 2.52.0 (2026-07-05) Features bump actions/checkout from 6 to 7 in the dependencies group (#104) (05de7b5)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rlespinasse/drawio-export-action">https://github.com/rlespinasse/drawio-export-action</a></strong> to version <strong>v2.52.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>124</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/drawio-export-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="2520-2026-07-05"><a href="https://github.com/rlespinasse/drawio-export-action/compare/v2.51.0...v2.52.0">2.52.0</a> (2026-07-05)</h1>
<h3 id="features">Features</h3>
<ul>
<li>bump actions/checkout from 6 to 7 in the dependencies group (<a href="https://github.com/rlespinasse/drawio-export-action/issues/104">#104</a>) (<a href="https://github.com/rlespinasse/drawio-export-action/commit/05de7b518a649f6f7a5284d9576241ec271eb471">05de7b5</a>)</li>
</ul>
]]></content:encoded></item><item><title>Overleaf Resume Syncer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/overleaf-resume-syncer/</link><pubDate>Sun, 05 Jul 2026 22:00:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/overleaf-resume-syncer/</guid><description>Version updated for https://github.com/sahitya1903/resume-syncer to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Refactor Overleaf parser, rename portfolio variables to external, and update docs
What’s Changed Refactor Overleaf parser, rename portfolio variables to external, and update docs by @sahitya1903 in https://github.com/sahitya1903/resume-syncer/pull/1 New Contributors @sahitya1903 made their first contribution in https://github.com/sahitya1903/resume-syncer/pull/1 Full Changelog: https://github.com/sahitya1903/resume-syncer/compare/v1...v1.0.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sahitya1903/resume-syncer">https://github.com/sahitya1903/resume-syncer</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/overleaf-resume-syncer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Refactor Overleaf parser, rename portfolio variables to external, and update docs</p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Refactor Overleaf parser, rename portfolio variables to external, and update docs by @sahitya1903 in <a href="https://github.com/sahitya1903/resume-syncer/pull/1">https://github.com/sahitya1903/resume-syncer/pull/1</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@sahitya1903 made their first contribution in <a href="https://github.com/sahitya1903/resume-syncer/pull/1">https://github.com/sahitya1903/resume-syncer/pull/1</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sahitya1903/resume-syncer/compare/v1...v1.0.1">https://github.com/sahitya1903/resume-syncer/compare/v1...v1.0.1</a></p>
]]></content:encoded></item><item><title>Docker Compose Cache</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/docker-compose-cache/</link><pubDate>Sun, 05 Jul 2026 21:59:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/docker-compose-cache/</guid><description>Version updated for https://github.com/seijikohara/docker-compose-cache-action to version v1.8.16.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps): lock file maintenance by @renovate[bot] in https://github.com/seijikohara/docker-compose-cache-action/pull/303 Full Changelog: https://github.com/seijikohara/docker-compose-cache-action/compare/v1.8.15...v1.8.16</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/seijikohara/docker-compose-cache-action">https://github.com/seijikohara/docker-compose-cache-action</a></strong> to version <strong>v1.8.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/docker-compose-cache">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/303">https://github.com/seijikohara/docker-compose-cache-action/pull/303</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/seijikohara/docker-compose-cache-action/compare/v1.8.15...v1.8.16">https://github.com/seijikohara/docker-compose-cache-action/compare/v1.8.15...v1.8.16</a></p>
]]></content:encoded></item><item><title>Vulnerability Spoiler Alert</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/vulnerability-spoiler-alert/</link><pubDate>Sun, 05 Jul 2026 21:59:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/vulnerability-spoiler-alert/</guid><description>Version updated for https://github.com/spaceraccoon/vulnerability-spoiler-alert-action to version v1.6.0.
This action is used across all versions by 3 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed refactor: diff truncation by @spaceraccoon in https://github.com/spaceraccoon/vulnerability-spoiler-alert-action/pull/21 Full Changelog: https://github.com/spaceraccoon/vulnerability-spoiler-alert-action/compare/v1.5.0...v1.6.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spaceraccoon/vulnerability-spoiler-alert-action">https://github.com/spaceraccoon/vulnerability-spoiler-alert-action</a></strong> to version <strong>v1.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vulnerability-spoiler-alert">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>refactor: diff truncation by @spaceraccoon in <a href="https://github.com/spaceraccoon/vulnerability-spoiler-alert-action/pull/21">https://github.com/spaceraccoon/vulnerability-spoiler-alert-action/pull/21</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spaceraccoon/vulnerability-spoiler-alert-action/compare/v1.5.0...v1.6.0">https://github.com/spaceraccoon/vulnerability-spoiler-alert-action/compare/v1.5.0...v1.6.0</a></p>
]]></content:encoded></item><item><title>GitGalaxy Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/gitgalaxy-scanner/</link><pubDate>Sun, 05 Jul 2026 21:58:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/gitgalaxy-scanner/</guid><description>Version updated for https://github.com/squid-protocol/gitgalaxy to version v2.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed This release represents a massive architectural maturation for GitGalaxy. The primary focus of v2.3.0 is the total alignment of the core parsing engine with formal, enterprise-grade DevSecOps terminology, alongside a complete overhaul of the CI/CD ingestion pipelines for air-gapped resilience and absolute data provenance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/squid-protocol/gitgalaxy">https://github.com/squid-protocol/gitgalaxy</a></strong> to version <strong>v2.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gitgalaxy-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This release represents a massive architectural maturation for GitGalaxy. The primary focus of <code>v2.3.0</code> is the total alignment of the core parsing engine with formal, enterprise-grade DevSecOps terminology, alongside a complete overhaul of the CI/CD ingestion pipelines for air-gapped resilience and absolute data provenance.</p>
<p>Furthermore, we have upgraded key risk exposures from flat heuristics to N-Dimensional physics equations, vastly improving the precision of the engine. All structural changes in this release were subjected to a Full Differential Scan against our 80-repo calibrated baseline to mathematically guarantee zero regressions in accuracy or speed.</p>
<h2 id="-major-features--architectural-upgrades">🚀 Major Features &amp; Architectural Upgrades</h2>
<ul>
<li><strong>The DevSecOps Terminology Overhaul:</strong> The entire core engine, including the 5-tier optical extraction pipelines (<code>prism.py</code>) and security sensors (<code>ai_appsec_sensor.py</code>, <code>security_lens.py</code>), has been refactored to use formal industry terminology (e.g., SAST, RCE Funnels, Taint Tracking). Legacy Sci-Fi terminology has been deprecated in favor of explicit architectural mapping.</li>
<li><strong>Zero-Trust Licensing &amp; Environmental Friction:</strong> Deployed aggressive Commercial Licensing guardrails (PolyForm Noncommercial 1.0.0). Unverified pipelines now face environmental friction traps and RSA validation checks, ensuring the engine cannot be silently deployed in unauthorized enterprise environments.</li>
<li><strong>The Muninn Security Gauntlet:</strong> Integrated <code>Muninn</code> (v0.3.4) and <code>Poutine</code> for rigorous internal AppSec scanning. Sealed multiple O(N^2) ReDoS vulnerabilities discovered in our C/C++ regex definitions, uploaded SARIF reports for strict vulnerability gating, and suppressed CI log-scraping vectors to protect output telemetry.</li>
</ul>
<h2 id="-mathematical-upgrades-the-physics-engine">🧮 Mathematical Upgrades (The Physics Engine)</h2>
<ul>
<li><strong>Algorithmic DoS Vector (Big-O Detection):</strong> Upgraded algorithmic complexity scanning. We abandoned flat heuristics and introduced an N-Dimensional physics equation that correlates the mathematical depth of a loop (e.g., O(N^3)) with its &ldquo;Data Gravity&rdquo; (DB complexity) and &ldquo;Choke Points&rdquo; (Public APIs) to detect weaponizable performance bottlenecks.</li>
<li><strong>N-Dimensional Verification Risk (Test Coverage):</strong> Integrated the Asymptotic Dampener and Opacity Tax. The engine now applies structural cross-file test tethers to prove that defensive mass accurately shields vulnerable execution paths.</li>
<li><strong>GuideStar Documentation Umbrellas:</strong> Upgraded the Documentation Risk equation to project &ldquo;GuideStar Umbrellas,&rdquo; factoring in markdown instructional density and instructional multipliers, rather than just counting docstrings.</li>
</ul>
<h2 id="-cicd--pipeline-resilience">🛡️ CI/CD &amp; Pipeline Resilience</h2>
<ul>
<li><strong>The Dynamic Golden Crucible:</strong> Completely rebuilt the test architecture. Deprecated static fixtures in favor of a dynamic <code>language-crucible</code> ingestion pipeline. The workflow now strictly enforces a Golden Master baseline file against a locked matrix of test targets.</li>
<li><strong>Deep GitHub Actions Hardening:</strong> Pinned all third-party actions to strict commit SHAs, established explicit workflow permissions, fixed template injection vectors in <code>action.yml</code>, and resolved <code>zizmor</code> cache-poisoning flags. Upgraded core workflow environments to <code>actions/checkout@v7.0.0</code> and <code>actions/setup-python@v6.2.0</code>.</li>
<li><strong>Native Air-Gapped Checkout:</strong> Replaced <code>actions/checkout</code> with native, scope-stripped <code>git clone</code> protocols to bypass scoped token auth bugs, eliminate credential persistence, and ensure perfect execution on underpowered or restricted GitHub Runners.</li>
<li><strong>Supply Chain RAM-Firewall:</strong> Upgraded the Supply Chain firewall to a RAM-exclusive architecture and deployed the formal <code>ManifestParser</code> for deep dependency-spoofing detection.</li>
</ul>
<h2 id="-chore--dependency-management">🧹 Chore &amp; Dependency Management</h2>
<ul>
<li><strong>Visual Observatory Validation:</strong> Verified that all JSON payload updates successfully render within the Airgap Observatory and GitGalaxy.io without breaking flexbox constraints or 3D WebGL rendering.</li>
<li><strong>Stable Documentation:</strong> Pinned <code>mkdocs</code> to <code>&lt;2.0</code> to protect the newly deployed topological web architecture from upstream material theme breakages.</li>
<li><strong>Dependency Bumps:</strong> Massive, repo-wide dependency resolution via Dependabot, bringing <code>flask</code>, <code>cryptography</code>, <code>werkzeug</code>, and data-science libraries (<code>xgboost</code>, <code>plotly</code>, <code>umap-learn</code>, <code>matplotlib-inline</code>, <code>tqdm</code>) to their latest secure versions.</li>
</ul>
<hr>
<h2 id="-community-shoutouts">🏆 Community Shoutouts</h2>
<p>A massive thank you to our first community contributor, <strong><a href="https://github.com/sg0nzalez">@sg0nzalez</a></strong> (Santiago González), for architecting and deploying the Muninn security scanning gauntlet across the GitGalaxy pipeline. Your work on PRs #71 and #95 fundamentally hardened our CI/CD workflows and helped seal critical ReDoS vulnerabilities. Thank you for elevating the security posture of the blAST engine!</p>
]]></content:encoded></item><item><title>DiffGate Review Triage</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/diffgate-review-triage/</link><pubDate>Sun, 05 Jul 2026 21:58:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/diffgate-review-triage/</guid><description>Version updated for https://github.com/srbsa/diffgate to version v0.7.11.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed release: 0.7.11 — finding-led positioning + PR-trail study post (9f9b019) release: 0.7.10 — fix mcpb/Smithery bundle crash, MCP tool metadata (6eb9373) fix: mcpb/Smithery bundle crashed with no node_modules; add MCP tool metadata (8ed0ea0) release: 0.7.9 — per-rule path scoping + docs-prose carve-out (Backstage eval fixes) (54110d9) release: 0.7.8 — dependency-manifest goes section-aware (version bumps no longer flagged) (2f992bc) release: 0.7.7 — fix GH Marketplace action.yml rejection + MCP registry description cap (87b8fdf) fix: action.yml name collision + description over Marketplace’s 125-char cap (05227d2) fix: shorten server.json description under the MCP registry’s 100-char cap (2a4ada1) release: 0.7.6 — distribution plumbing (MCP registry, Docker/GHCR, pre-commit, GH Action, Claude plugin) (56fc4a6) release: 0.7.5, republish with updated README after 0.7.4 publish (3c778dd)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/srbsa/diffgate">https://github.com/srbsa/diffgate</a></strong> to version <strong>v0.7.11</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/diffgate-review-triage">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>release: 0.7.11 — finding-led positioning + PR-trail study post (9f9b019)</li>
<li>release: 0.7.10 — fix mcpb/Smithery bundle crash, MCP tool metadata (6eb9373)</li>
<li>fix: mcpb/Smithery bundle crashed with no node_modules; add MCP tool metadata (8ed0ea0)</li>
<li>release: 0.7.9 — per-rule path scoping + docs-prose carve-out (Backstage eval fixes) (54110d9)</li>
<li>release: 0.7.8 — dependency-manifest goes section-aware (version bumps no longer flagged) (2f992bc)</li>
<li>release: 0.7.7 — fix GH Marketplace action.yml rejection + MCP registry description cap (87b8fdf)</li>
<li>fix: action.yml name collision + description over Marketplace&rsquo;s 125-char cap (05227d2)</li>
<li>fix: shorten server.json description under the MCP registry&rsquo;s 100-char cap (2a4ada1)</li>
<li>release: 0.7.6 — distribution plumbing (MCP registry, Docker/GHCR, pre-commit, GH Action, Claude plugin) (56fc4a6)</li>
<li>release: 0.7.5, republish with updated README after 0.7.4 publish (3c778dd)</li>
</ul>
]]></content:encoded></item><item><title>pinprick-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/pinprick-action/</link><pubDate>Sun, 05 Jul 2026 21:57:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/pinprick-action/</guid><description>Version updated for https://github.com/starhaven-io/pinprick-action to version v0.4.1.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Updates the pinned pinprick version.
Defaults to pinprick 0.20.1 (was 0.20.0 in v0.4.0), pinned for deterministic runs. pinprick 0.20.1 restores the documented checksum-verification suppression for saved shell fetches that 0.20.0 dropped: an unversioned-URL download verified against a pinned digest within the three-line window is recorded as an allowed match again, including the piped manifest form. Pipe-to-shell and latest-URL findings remain exempt. The action’s behavior, inputs, and permissions are unchanged. See the README for usage.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/starhaven-io/pinprick-action">https://github.com/starhaven-io/pinprick-action</a></strong> to version <strong>v0.4.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pinprick-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Updates the pinned pinprick version.</p>
<p>Defaults to pinprick 0.20.1 (was 0.20.0 in v0.4.0), pinned for deterministic runs. pinprick 0.20.1 restores the documented checksum-verification suppression for saved shell fetches that 0.20.0 dropped: an unversioned-URL download verified against a pinned digest within the three-line window is recorded as an allowed match again, including the piped manifest form. Pipe-to-shell and latest-URL findings remain exempt. The action&rsquo;s behavior, inputs, and permissions are unchanged. See the README for usage.</p>
]]></content:encoded></item><item><title>Pi Review Agent</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/pi-review-agent/</link><pubDate>Sun, 05 Jul 2026 21:57:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/pi-review-agent/</guid><description>Version updated for https://github.com/sun-praise/pi-review-agent to version v1.3.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Fixed Team mode now respects the model input (#16). Previously the model was registered into the LiteLLM provider but never forwarded to runReview, so every persona and the coordinator fell back to the hardcoded default deepseek-v4-flash and failed for any non-default model such as mimo-v2.5. Single mode model input also fixed: it had the same omission and would fail for non-default models because the provider only registers the user-selected model. Verification Tested end-to-end in PR #18 with team: quality:1,security:1,performance:1 and model: mimo-v2.5: all three personas plus the coordinator completed successfully and posted a review comment. New Contributors None.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sun-praise/pi-review-agent">https://github.com/sun-praise/pi-review-agent</a></strong> to version <strong>v1.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pi-review-agent">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>Team mode now respects the <code>model</code> input</strong> (#16). Previously the model was registered into the LiteLLM provider but never forwarded to <code>runReview</code>, so every persona and the coordinator fell back to the hardcoded default <code>deepseek-v4-flash</code> and failed for any non-default model such as <code>mimo-v2.5</code>.</li>
<li><strong>Single mode <code>model</code> input</strong> also fixed: it had the same omission and would fail for non-default models because the provider only registers the user-selected model.</li>
</ul>
<h2 id="verification">Verification</h2>
<ul>
<li>Tested end-to-end in PR #18 with <code>team: quality:1,security:1,performance:1</code> and <code>model: mimo-v2.5</code>: all three personas plus the coordinator completed successfully and posted a review comment.</li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<p>None.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sun-praise/pi-review-agent/compare/v1.3.0...v1.3.1">https://github.com/sun-praise/pi-review-agent/compare/v1.3.0...v1.3.1</a></p>
]]></content:encoded></item><item><title>Setup Tombi</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/setup-tombi/</link><pubDate>Sun, 05 Jul 2026 21:56:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/setup-tombi/</guid><description>Version updated for https://github.com/tombi-toml/setup-tombi to version v1.2.0.
This action is used across all versions by 131 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed This setup-tombi release matches tombi v1.2.0.
Full Changelog: https://github.com/tombi-toml/setup-tombi/compare/v1...v1.2.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tombi-toml/setup-tombi">https://github.com/tombi-toml/setup-tombi</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>131</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-tombi">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This setup-tombi release matches <a href="https://github.com/tombi-toml/tombi/releases/tag/v1.2.0">tombi v1.2.0</a>.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/tombi-toml/setup-tombi/compare/v1...v1.2.0">https://github.com/tombi-toml/setup-tombi/compare/v1...v1.2.0</a></p>
]]></content:encoded></item><item><title>configure-huawei-cloud-credentials</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/configure-huawei-cloud-credentials/</link><pubDate>Sun, 05 Jul 2026 21:55:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/configure-huawei-cloud-credentials/</guid><description>Version updated for https://github.com/vbem/configure-huawei-cloud-credentials to version v1.0.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/vbem/configure-huawei-cloud-credentials/compare/v1.0.0...v1.0.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vbem/configure-huawei-cloud-credentials">https://github.com/vbem/configure-huawei-cloud-credentials</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/configure-huawei-cloud-credentials">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vbem/configure-huawei-cloud-credentials/compare/v1.0.0...v1.0.1">https://github.com/vbem/configure-huawei-cloud-credentials/compare/v1.0.0...v1.0.1</a></p>
]]></content:encoded></item><item><title>HumaneProxy Safety Benchmark</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/humaneproxy-safety-benchmark/</link><pubDate>Sun, 05 Jul 2026 21:55:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/humaneproxy-safety-benchmark/</guid><description>Version updated for https://github.com/Vishisht16/Humane-Proxy to version v0.5.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Highlights 🔭 OpenTelemetry distributed tracing (#7) — export pipeline traces to Jaeger, Grafana Tempo, or Datadog via the new [telemetry] extra. Every request produces a pipeline.classify span with privacy-safe attributes (category, score, stage reached, message hash — never raw text). Zero overhead when disabled. 🌍 Region-aware care response — set safety.categories.self_harm.region: &amp;#34;IN&amp;#34; (any ISO country code) to surface that country’s crisis resources first, while always keeping the full international list. ☎️ Crisis helplines for new countries (#26) — Japan, South Korea, Spain, Italy, Mexico, New Zealand and more join the existing US/IN/GB/AU/CA/DE/FR/BR/ZA resources. 🗄️ Storage-backend consistency (#37) — the admin API, CLI, and MCP tools now route through the storage factory instead of raw SQLite, so Redis and PostgreSQL deployments see the same data everywhere. 📊 Query upgrades — escalation queries support date filtering (date_from/date_to) and sorting across all three backends. Fixed Multimodal content arrays: /chat extracts text from OpenAI-style content parts and no longer errors on string or malformed message content (#44, #45, #48). Empty /chat request bodies return a clean 400 (#41). CodeQL SQL-injection alerts resolved with statically generated SQL templates; timezone conversion and CSV triggers serialization fixed in escalation export. Security Admin Bearer-token comparison hardened against timing attacks with hmac.compare_digest (#18, #21). HTTP MCP hardened: binds to 127.0.0.1 by default, warns on public binds without a token, supports Bearer auth via HUMANE_PROXY_ADMIN_KEY, and bounds audit-log queries (#17). Docs &amp;amp; Tests Mermaid.js architecture diagram, README table of contents, corrected Stage-1 transition labels. New test coverage: Unicode/leet-speak heuristic edge cases, pipeline config validation, malformed payloads, decay-weighted-mean edge cases. Full Changelog: https://github.com/Vishisht16/Humane-Proxy/compare/v0.4.0...v0.5.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Vishisht16/Humane-Proxy">https://github.com/Vishisht16/Humane-Proxy</a></strong> to version <strong>v0.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/humaneproxy-safety-benchmark">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="highlights">Highlights</h3>
<ul>
<li>🔭 <strong>OpenTelemetry distributed tracing</strong> (#7) — export pipeline traces to Jaeger, Grafana Tempo, or Datadog via the new <code>[telemetry]</code> extra. Every request produces a <code>pipeline.classify</code> span with privacy-safe attributes (category, score, stage reached, message hash — never raw text). Zero overhead when disabled.</li>
<li>🌍 <strong>Region-aware care response</strong> — set <code>safety.categories.self_harm.region: &quot;IN&quot;</code> (any ISO country code) to surface that country&rsquo;s crisis resources first, while always keeping the full international list.</li>
<li>☎️ <strong>Crisis helplines for new countries</strong> (#26) — Japan, South Korea, Spain, Italy, Mexico, New Zealand and more join the existing US/IN/GB/AU/CA/DE/FR/BR/ZA resources.</li>
<li>🗄️ <strong>Storage-backend consistency</strong> (#37) — the admin API, CLI, and MCP tools now route through the storage factory instead of raw SQLite, so Redis and PostgreSQL deployments see the same data everywhere.</li>
<li>📊 <strong>Query upgrades</strong> — escalation queries support date filtering (<code>date_from</code>/<code>date_to</code>) and sorting across all three backends.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Multimodal content arrays: <code>/chat</code> extracts text from OpenAI-style content parts and no longer errors on string or malformed message content (#44, #45, #48).</li>
<li>Empty <code>/chat</code> request bodies return a clean 400 (#41).</li>
<li>CodeQL SQL-injection alerts resolved with statically generated SQL templates; timezone conversion and CSV <code>triggers</code> serialization fixed in escalation export.</li>
</ul>
<h3 id="security">Security</h3>
<ul>
<li>Admin Bearer-token comparison hardened against timing attacks with <code>hmac.compare_digest</code> (#18, #21).</li>
<li>HTTP MCP hardened: binds to <code>127.0.0.1</code> by default, warns on public binds without a token, supports Bearer auth via <code>HUMANE_PROXY_ADMIN_KEY</code>, and bounds audit-log queries (#17).</li>
</ul>
<h3 id="docs--tests">Docs &amp; Tests</h3>
<ul>
<li>Mermaid.js architecture diagram, README table of contents, corrected Stage-1 transition labels.</li>
<li>New test coverage: Unicode/leet-speak heuristic edge cases, pipeline config validation, malformed payloads, decay-weighted-mean edge cases.</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Vishisht16/Humane-Proxy/compare/v0.4.0...v0.5.0">https://github.com/Vishisht16/Humane-Proxy/compare/v0.4.0...v0.5.0</a></p>
]]></content:encoded></item><item><title>Setup vp</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/setup-vp/</link><pubDate>Sun, 05 Jul 2026 21:54:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/setup-vp/</guid><description>Version updated for https://github.com/voidzero-dev/setup-vp to version v1.15.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps): update dependency vite-plus to v0.2.2 by @renovate[bot] in https://github.com/voidzero-dev/setup-vp/pull/104 feat: add GitLab CI/CD integration for setup-vp by @naokihaba in https://github.com/voidzero-dev/setup-vp/pull/97 New Contributors @naokihaba made their first contribution in https://github.com/voidzero-dev/setup-vp/pull/97 Full Changelog: https://github.com/voidzero-dev/setup-vp/compare/v1.14.0...v1.15.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/voidzero-dev/setup-vp">https://github.com/voidzero-dev/setup-vp</a></strong> to version <strong>v1.15.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-vp">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): update dependency vite-plus to v0.2.2 by @renovate[bot] in <a href="https://github.com/voidzero-dev/setup-vp/pull/104">https://github.com/voidzero-dev/setup-vp/pull/104</a></li>
<li>feat: add GitLab CI/CD integration for setup-vp by @naokihaba in <a href="https://github.com/voidzero-dev/setup-vp/pull/97">https://github.com/voidzero-dev/setup-vp/pull/97</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@naokihaba made their first contribution in <a href="https://github.com/voidzero-dev/setup-vp/pull/97">https://github.com/voidzero-dev/setup-vp/pull/97</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/voidzero-dev/setup-vp/compare/v1.14.0...v1.15.0">https://github.com/voidzero-dev/setup-vp/compare/v1.14.0...v1.15.0</a></p>
]]></content:encoded></item><item><title>Decionis Action Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/decionis-action-gate/</link><pubDate>Sun, 05 Jul 2026 15:03:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/decionis-action-gate/</guid><description>Version updated for https://github.com/decionis/govern to version v1.9.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ⚡ Performance Local policy engine: the committed ```decionis rules block in DECIONIS_POLICY.md is evaluated in-process in microseconds, faithfully mirroring the platform evaluator. Deterministic allow/block verdicts act immediately; the API call becomes an async notarization off the critical path (signed dossiers, verify URLs, and badges still arrive). New local-eval input: auto (default) / strict (fully offline) / off (v1.8 behavior). Speculative shadow mode: run commands start immediately while the verdict resolves in the background — the gate adds ~zero latency. The step’s exit code is always the command’s; evaluation failures are notices. Shadow can no longer fail a build for any reason, and unconfigured gates (no secrets yet) are inert. Every run logs a Decionis timing — line so the speedups are visible. 🔧 Correctness API outcome normalization (APPROVE→allow, REJECT→block, REQUIRE_REVIEW→review) — enforce-mode run gating and fail-on now work against the live API vocabulary. New outputs: decision-source (local/api) and verdict-mismatch (local verdict vs notarizing API verdict, with a ::warning::). Example policies and the installer template set explicit rule priority and &amp;#34;domain&amp;#34;: &amp;#34;*&amp;#34; so committed policies actually fire. 🚀 Onboarding install.sh ships in the repo: curl -fsSL https://decionis.com/govern/install.sh | sh -s -- --pr --inject writes a shadow workflow + starter policy, injects observe-only (continue-on-error) gate steps into existing workflows, and opens the onboarding PR. Badge/verify URLs pin the policy revision: &amp;amp;policy=sha256:&amp;lt;hash&amp;gt;. ✅ Compatibility All existing inputs/outputs unchanged; repos without a rules block see no decision-flow change. 143 tests, including end-to-end timing proofs against a mock API.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/decionis/govern">https://github.com/decionis/govern</a></strong> to version <strong>v1.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/decionis-action-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-performance">⚡ Performance</h2>
<ul>
<li><strong>Local policy engine</strong>: the committed ```decionis rules block in DECIONIS_POLICY.md is evaluated in-process in microseconds, faithfully mirroring the platform evaluator. Deterministic allow/block verdicts act immediately; the API call becomes an async notarization off the critical path (signed dossiers, verify URLs, and badges still arrive). New <code>local-eval</code> input: <code>auto</code> (default) / <code>strict</code> (fully offline) / <code>off</code> (v1.8 behavior).</li>
<li><strong>Speculative shadow mode</strong>: <code>run</code> commands start immediately while the verdict resolves in the background — the gate adds ~zero latency. The step&rsquo;s exit code is always the command&rsquo;s; evaluation failures are notices. Shadow can no longer fail a build for any reason, and unconfigured gates (no secrets yet) are inert.</li>
<li>Every run logs a <code>Decionis timing —</code> line so the speedups are visible.</li>
</ul>
<h2 id="-correctness">🔧 Correctness</h2>
<ul>
<li><strong>API outcome normalization</strong> (<code>APPROVE</code>→<code>allow</code>, <code>REJECT</code>→<code>block</code>, <code>REQUIRE_REVIEW</code>→<code>review</code>) — enforce-mode <code>run</code> gating and <code>fail-on</code> now work against the live API vocabulary.</li>
<li>New outputs: <code>decision-source</code> (<code>local</code>/<code>api</code>) and <code>verdict-mismatch</code> (local verdict vs notarizing API verdict, with a <code>::warning::</code>).</li>
<li>Example policies and the installer template set explicit rule <code>priority</code> and <code>&quot;domain&quot;: &quot;*&quot;</code> so committed policies actually fire.</li>
</ul>
<h2 id="-onboarding">🚀 Onboarding</h2>
<ul>
<li><strong>install.sh</strong> ships in the repo: <code>curl -fsSL https://decionis.com/govern/install.sh | sh -s -- --pr --inject</code> writes a shadow workflow + starter policy, injects observe-only (<code>continue-on-error</code>) gate steps into existing workflows, and opens the onboarding PR.</li>
<li>Badge/verify URLs pin the policy revision: <code>&amp;policy=sha256:&lt;hash&gt;</code>.</li>
</ul>
<h2 id="-compatibility">✅ Compatibility</h2>
<p>All existing inputs/outputs unchanged; repos without a rules block see no decision-flow change. 143 tests, including end-to-end timing proofs against a mock API.</p>
<p><strong>Full diff</strong>: <a href="https://github.com/decionis/govern/compare/v1.8.8...v1.9.0">https://github.com/decionis/govern/compare/v1.8.8...v1.9.0</a></p>
]]></content:encoded></item><item><title>Zabbly Incus for GitHub Actions</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/zabbly-incus-for-github-actions/</link><pubDate>Sun, 05 Jul 2026 15:02:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/zabbly-incus-for-github-actions/</guid><description>Version updated for https://github.com/dionysius/incus-zabbly-actions to version v1.0.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/dionysius/incus-zabbly-actions/compare/v1...v1.0.4</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/dionysius/incus-zabbly-actions">https://github.com/dionysius/incus-zabbly-actions</a></strong> to version <strong>v1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zabbly-incus-for-github-actions">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/dionysius/incus-zabbly-actions/compare/v1...v1.0.4">https://github.com/dionysius/incus-zabbly-actions/compare/v1...v1.0.4</a></p>
]]></content:encoded></item><item><title>MUADDIB Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/muaddib-scanner/</link><pubDate>Sun, 05 Jul 2026 15:02:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/muaddib-scanner/</guid><description>Version updated for https://github.com/DNSZLSK/muad-dib to version v2.11.157.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Mutes the BURST PRE-ALERT Discord webhook by default (~700x/day, anti-corrélé avec les vrais incidents). Re-enable via MUADDIB_BURST_PREALERT_WEBHOOK=1. Console log + stats du daily summary inchangés.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/DNSZLSK/muad-dib">https://github.com/DNSZLSK/muad-dib</a></strong> to version <strong>v2.11.157</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/muad-dib-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Mutes the BURST PRE-ALERT Discord webhook by default (~700x/day, anti-corrélé avec les vrais incidents). Re-enable via MUADDIB_BURST_PREALERT_WEBHOOK=1. Console log + stats du daily summary inchangés.</p>
]]></content:encoded></item><item><title>DoesQA Trigger</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/doesqa-trigger/</link><pubDate>Sun, 05 Jul 2026 15:01:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/doesqa-trigger/</guid><description>Version updated for https://github.com/Does-QA/action to version v1.1.29.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Security patch: fixed 1 → 1 vulnerabilities via npm audit fix.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Does-QA/action">https://github.com/Does-QA/action</a></strong> to version <strong>v1.1.29</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/doesqa-trigger">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Security patch: fixed 1 → 1 vulnerabilities via <code>npm audit fix</code>.</p>
]]></content:encoded></item><item><title>Setup Umka</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/setup-umka/</link><pubDate>Sun, 05 Jul 2026 15:01:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/setup-umka/</guid><description>Version updated for https://github.com/fabasoad/setup-umka-action to version v1.5.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps): bump actions/checkout from 4 to 5 by @dependabot[bot] in https://github.com/fabasoad/setup-umka-action/pull/148 fix: issue found by markdownlint by @fabasoad in https://github.com/fabasoad/setup-umka-action/pull/149 chore(deps): bump actions/checkout from 5 to 6 by @dependabot[bot] in https://github.com/fabasoad/setup-umka-action/pull/150 Update license copyright year to 2026 by @github-actions[bot] in https://github.com/fabasoad/setup-umka-action/pull/151 chore(deps): bump gitleaks from 8.30.0 to 8.30.1 by @fabasoad in https://github.com/fabasoad/setup-umka-action/pull/152 Full Changelog: https://github.com/fabasoad/setup-umka-action/compare/v1.5.1...v1.5.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/fabasoad/setup-umka-action">https://github.com/fabasoad/setup-umka-action</a></strong> to version <strong>v1.5.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-umka">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): bump actions/checkout from 4 to 5 by @dependabot[bot] in <a href="https://github.com/fabasoad/setup-umka-action/pull/148">https://github.com/fabasoad/setup-umka-action/pull/148</a></li>
<li>fix: issue found by markdownlint by @fabasoad in <a href="https://github.com/fabasoad/setup-umka-action/pull/149">https://github.com/fabasoad/setup-umka-action/pull/149</a></li>
<li>chore(deps): bump actions/checkout from 5 to 6 by @dependabot[bot] in <a href="https://github.com/fabasoad/setup-umka-action/pull/150">https://github.com/fabasoad/setup-umka-action/pull/150</a></li>
<li>Update license copyright year to 2026 by @github-actions[bot] in <a href="https://github.com/fabasoad/setup-umka-action/pull/151">https://github.com/fabasoad/setup-umka-action/pull/151</a></li>
<li>chore(deps): bump gitleaks from 8.30.0 to 8.30.1 by @fabasoad in <a href="https://github.com/fabasoad/setup-umka-action/pull/152">https://github.com/fabasoad/setup-umka-action/pull/152</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/fabasoad/setup-umka-action/compare/v1.5.1...v1.5.2">https://github.com/fabasoad/setup-umka-action/compare/v1.5.1...v1.5.2</a></p>
]]></content:encoded></item><item><title>Ansible Molecule</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/ansible-molecule/</link><pubDate>Sun, 05 Jul 2026 15:00:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/ansible-molecule/</guid><description>Version updated for https://github.com/gofrolist/molecule-action to version v2.7.103.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.7.103 (2026-07-04) Bug Fixes deps: Bump ansible-lint from 26.4.0 to 26.6.0 (12f1ba1)
deps: Bump docker/build-push-action from 7.2.0 to 7.3.0 (3c32800)
deps: Bump docker/login-action from 4.2.0 to 4.3.0 (a0106d0)
deps: Bump docker/metadata-action from 6.1.0 to 6.2.0 (bc9c924)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/gofrolist/molecule-action">https://github.com/gofrolist/molecule-action</a></strong> to version <strong>v2.7.103</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ansible-molecule">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v27103-2026-07-04">v2.7.103 (2026-07-04)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>
<p><strong>deps</strong>: Bump ansible-lint from 26.4.0 to 26.6.0 (<a href="https://github.com/gofrolist/molecule-action/commit/12f1ba1853c361769c998e2dd876f8e34667ffba"><code>12f1ba1</code></a>)</p>
</li>
<li>
<p><strong>deps</strong>: Bump docker/build-push-action from 7.2.0 to 7.3.0 (<a href="https://github.com/gofrolist/molecule-action/commit/3c32800f8061e9b63464dd256f6bdda4b88b1695"><code>3c32800</code></a>)</p>
</li>
<li>
<p><strong>deps</strong>: Bump docker/login-action from 4.2.0 to 4.3.0 (<a href="https://github.com/gofrolist/molecule-action/commit/a0106d01a2c7cedd7b7cc0348feaeb8795eb8dc4"><code>a0106d0</code></a>)</p>
</li>
<li>
<p><strong>deps</strong>: Bump docker/metadata-action from 6.1.0 to 6.2.0 (<a href="https://github.com/gofrolist/molecule-action/commit/bc9c9244d0c9691842547f8d0a4a8bc11276e882"><code>bc9c924</code></a>)</p>
</li>
<li>
<p><strong>deps</strong>: Bump docker/setup-buildx-action from 4.1.0 to 4.2.0 (<a href="https://github.com/gofrolist/molecule-action/commit/989183a5609304dfbe5defd55bc5831cb5dd9d09"><code>989183a</code></a>)</p>
</li>
</ul>
<hr>
<p><strong>Detailed Changes</strong>: <a href="https://github.com/gofrolist/molecule-action/compare/v2.7.102...v2.7.103">v2.7.102&hellip;v2.7.103</a></p>
]]></content:encoded></item><item><title>Setup poly CLI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/setup-poly-cli/</link><pubDate>Sun, 05 Jul 2026 15:00:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/setup-poly-cli/</guid><description>Version updated for https://github.com/Goldziher/polylint to version v0.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v0.6.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Goldziher/polylint">https://github.com/Goldziher/polylint</a></strong> to version <strong>v0.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-poly-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release v0.6.0</p>
]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/ai-plugin-scanner/</link><pubDate>Sun, 05 Jul 2026 14:59:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.387.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/4ae7b7b1a9f2f618e9121afd1270023751de69ab with plugin-scanner 2.0.987.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.386...v1.2.387</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.387</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>18</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/4ae7b7b1a9f2f618e9121afd1270023751de69ab">https://github.com/hashgraph-online/hol-guard/tree/4ae7b7b1a9f2f618e9121afd1270023751de69ab</a> with plugin-scanner 2.0.987.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.386...v1.2.387">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.386...v1.2.387</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/hol-codex-plugin-scanner/</link><pubDate>Sun, 05 Jul 2026 14:59:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.387.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.387</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.387</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.387">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.387</a></p>
]]></content:encoded></item><item><title>JFrog Boost</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/jfrog-boost/</link><pubDate>Sun, 05 Jul 2026 14:58:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/jfrog-boost/</guid><description>Version updated for https://github.com/jfrog/boost to version v0.8.5.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 2 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Release v0.7.23 by @yahav-ohana in https://github.com/jfrog/boost/pull/41 Release v0.7.25 by @menachemm-byte in https://github.com/jfrog/boost/pull/44 New Contributors @menachemm-byte made their first contribution in https://github.com/jfrog/boost/pull/44 Full Changelog: https://github.com/jfrog/boost/compare/v0.7.23...v0.8.5</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jfrog/boost">https://github.com/jfrog/boost</a></strong> to version <strong>v0.8.5</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>2</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jfrog-boost">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Release v0.7.23 by @yahav-ohana in <a href="https://github.com/jfrog/boost/pull/41">https://github.com/jfrog/boost/pull/41</a></li>
<li>Release v0.7.25 by @menachemm-byte in <a href="https://github.com/jfrog/boost/pull/44">https://github.com/jfrog/boost/pull/44</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@menachemm-byte made their first contribution in <a href="https://github.com/jfrog/boost/pull/44">https://github.com/jfrog/boost/pull/44</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jfrog/boost/compare/v0.7.23...v0.8.5">https://github.com/jfrog/boost/compare/v0.7.23...v0.8.5</a></p>
]]></content:encoded></item><item><title>Setup runner cli</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/setup-runner-cli/</link><pubDate>Sun, 05 Jul 2026 14:58:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/setup-runner-cli/</guid><description>Version updated for https://github.com/kjanat/runner to version v0.19.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added doctor --json overrides now reports every resolver override state except parent_group_open (internal runner-to-runner plumbing, never a user override): failure_policy, install_pms, output_grouping (group_output/github_group_parallel/parallel_grouped), prefer_sources, script_policy, and task_source_pins. Previously only pm/pm_by_ecosystem/runner/prefer_runners/fallback/ on_mismatch/explain/no_warnings/quiet were surfaced, so -k/-K, [tasks].prefer, [tasks.overrides], [install], and [github]/ [parallel] config could be set without doctor ever showing it. Changed Breaking: doctor --json and why --json now always emit the structured report (previously reachable via --schema-version 3); the flat v1/v2 shape is gone from both. --schema-version now only accepts 1; 2/3 are rejected. runner config init’s scaffold is now generated from RunnerConfig’s schemars metadata instead of hand-typed: section headers and their leading comments come straight from the section structs’ doc comments, and every enum-valued field’s inline hint (pm.node, pm.python, resolution.fallback, resolution.on_mismatch, install.scripts, task_runner.prefer) is generated from the same types the resolver parses those values with, not hand-typed prose. A config field, or an accepted value for one of these, can no longer ship without scaffold coverage — drift-guard tests fail the build instead. A few section descriptions read slightly differently as a result. FallbackPolicy, MismatchPolicy, and ScriptPolicy gained real label()/ALL (or SETTABLE) methods, replacing four separate hardcoded copies of their accepted strings (parse function, two display call sites, and now the scaffold) with one. Removed The v1/v2/v3 schema split. Not enough external adoption yet to justify carrying three versions per surface — today’s shape is the only one, retroactively called v1. Committed schema files dropped their version suffix (doctor.v3.schema.json → doctor.schema.json, etc.); the 10 superseded schema/example files are deleted.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kjanat/runner">https://github.com/kjanat/runner</a></strong> to version <strong>v0.19.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-runner-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><code>doctor --json</code> <code>overrides</code> now reports every resolver override state
except <code>parent_group_open</code> (internal runner-to-runner plumbing, never a
user override): <code>failure_policy</code>, <code>install_pms</code>, <code>output_grouping</code>
(<code>group_output</code>/<code>github_group_parallel</code>/<code>parallel_grouped</code>),
<code>prefer_sources</code>, <code>script_policy</code>, and <code>task_source_pins</code>. Previously
only <code>pm</code>/<code>pm_by_ecosystem</code>/<code>runner</code>/<code>prefer_runners</code>/<code>fallback</code>/
<code>on_mismatch</code>/<code>explain</code>/<code>no_warnings</code>/<code>quiet</code> were surfaced, so <code>-k</code>/<code>-K</code>,
<code>[tasks].prefer</code>, <code>[tasks.overrides]</code>, <code>[install]</code>, and <code>[github]</code>/
<code>[parallel]</code> config could be set without <code>doctor</code> ever showing it.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>Breaking:</strong> <code>doctor --json</code> and <code>why --json</code> now always emit the
structured report (previously reachable via <code>--schema-version 3</code>); the
flat v1/v2 shape is gone from both. <code>--schema-version</code> now only accepts
<code>1</code>; <code>2</code>/<code>3</code> are rejected.</li>
<li><code>runner config init</code>&rsquo;s scaffold is now generated from <code>RunnerConfig</code>&rsquo;s
schemars metadata instead of hand-typed: section headers and their
leading comments come straight from the section structs&rsquo; doc comments,
and every enum-valued field&rsquo;s inline hint (<code>pm.node</code>, <code>pm.python</code>,
<code>resolution.fallback</code>, <code>resolution.on_mismatch</code>, <code>install.scripts</code>,
<code>task_runner.prefer</code>) is generated from the same types the resolver
parses those values with, not hand-typed prose. A config field, or an
accepted value for one of these, can no longer ship without scaffold
coverage — drift-guard tests fail the build instead. A few section
descriptions read slightly differently as a result. <code>FallbackPolicy</code>,
<code>MismatchPolicy</code>, and <code>ScriptPolicy</code> gained real <code>label()</code>/<code>ALL</code> (or
<code>SETTABLE</code>) methods, replacing four separate hardcoded copies of their
accepted strings (parse function, two display call sites, and now the
scaffold) with one.</li>
</ul>
<h3 id="removed">Removed</h3>
<ul>
<li>
<p>The v1/v2/v3 schema split. Not enough external adoption yet to justify
carrying three versions per surface — today&rsquo;s shape is the only one,
retroactively called v1. Committed schema files dropped their version
suffix (<code>doctor.v3.schema.json</code> → <code>doctor.schema.json</code>, etc.); the 10
superseded schema/example files are deleted.</p>
</li>
<li>
<p><code>doctor --json</code> <code>overrides.fallback</code>, <code>on_mismatch</code>, <code>pm</code>,
<code>pm_by_ecosystem</code>, <code>runner</code>, and <code>prefer_runners</code> are now closed enums in
<code>doctor.schema.json</code> (with the accepted values documented per variant),
not generic strings — editors and validators can now catch a typo&rsquo;d
override value against the committed schema instead of silently
accepting anything. <code>pm_by_ecosystem</code>&rsquo;s keys are constrained the same
way: the schema now lists the seven ecosystem names explicitly instead
of allowing any string key, and its values are plain (non-nullable)
package-manager labels — the report never emits a <code>null</code> there.
<code>failure_policy</code>, <code>script_policy</code>, and <code>install_pms</code> (new fields, see
Added above) get the same closed-enum treatment from the start.</p>
</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><code>runner schema --all</code> no longer surfaces a raw Rust panic if the
init-template generator ever drifts from <code>RunnerConfig</code> in a released
binary (the drift-guard test should already catch this before merge);
it now reports a clean CLI error instead.</li>
<li><code>doctor --json</code> <code>overrides.quiet</code> is now listed as required in
<code>doctor.schema.json</code>, like every other boolean override — it was kept
optional for compatibility with the pre-collapse <code>doctor</code> v3 schema,
which this same release already removed.</li>
<li><code>runner lsp</code> diagnostics for a wrong-typed known field (e.g.
<code>pms = &quot;bun&quot;</code>) now point at the offending value instead of line one.</li>
<li><code>runner lsp</code> value completion for sequence-typed fields
(<code>[install].pms</code>, <code>[tasks].prefer</code>, <code>[task_runner].prefer</code>) wraps the
first element as <code>[&quot;bun&quot;]</code> when no <code>[</code> is typed yet — accepting a
completion previously inserted a bare scalar, minting the exact type
error above. Inside an open <code>[</code> the element stays bare.</li>
<li><code>runner lsp</code> header completion after a dotted partial (<code>[tasks.</code>) now
offers only that parent&rsquo;s sub-tables (<code>overrides</code>) instead of the full
top-level section list, and offers nothing under a parent with no
sub-tables (<code>[github.</code>). Deprecated sections and fields
(<code>[task_runner]</code>) now carry the LSP deprecated tag (strikethrough) in
completions and a deprecation banner in hover.</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(schema): close 3 findings from #77; fix release-URL regression by @kjanat in <a href="https://github.com/kjanat/runner/pull/79">https://github.com/kjanat/runner/pull/79</a></li>
<li>feat(schema)!: collapse doctor/why/list versioning to a single v1 by @kjanat in <a href="https://github.com/kjanat/runner/pull/82">https://github.com/kjanat/runner/pull/82</a></li>
<li>feat(schema): surface all ResolutionOverrides fields in <code>doctor --json</code> by @kjanat in <a href="https://github.com/kjanat/runner/pull/83">https://github.com/kjanat/runner/pull/83</a></li>
<li>fix(lsp): span type errors, array-aware and dotted-header-aware completion by @kjanat in <a href="https://github.com/kjanat/runner/pull/84">https://github.com/kjanat/runner/pull/84</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/kjanat/runner/compare/v0.18.1...v0.19.0">https://github.com/kjanat/runner/compare/v0.18.1...v0.19.0</a></p>
]]></content:encoded></item><item><title>pslrm Bump Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/pslrm-bump-action/</link><pubDate>Sun, 05 Jul 2026 14:57:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/pslrm-bump-action/</guid><description>Version updated for https://github.com/krymtkts/pslrm-bump-action to version v0.0.2.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added Add skip-psresourceget-install input to skip PSResourceGet installation. Changed Avoid unconditional Microsoft.PowerShell.PSResourceGet install. Check if version 1.0.1+ exists. Create bump commits through GitHub’s Git Database API so GitHub can mark them as verified. Notes Documentation now recommends GITHUB_TOKEN for most repositories. GitHub now allows workflows to run for approved pull requests created by github-actions[bot]. Use a PAT when subsequent workflows must run automatically without human approval.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/krymtkts/pslrm-bump-action">https://github.com/krymtkts/pslrm-bump-action</a></strong> to version <strong>v0.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pslrm-bump-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>Add <code>skip-psresourceget-install</code> input to skip PSResourceGet installation.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>Avoid unconditional <code>Microsoft.PowerShell.PSResourceGet</code> install. Check if version <code>1.0.1</code>+ exists.</li>
<li>Create bump commits through GitHub&rsquo;s Git Database API so GitHub can mark them as verified.</li>
</ul>
<h3 id="notes">Notes</h3>
<ul>
<li>Documentation now recommends <code>GITHUB_TOKEN</code> for most repositories.
GitHub now allows workflows to run for approved pull requests created by
<code>github-actions[bot]</code>.
Use a PAT when subsequent workflows must run automatically without human
approval.</li>
</ul>
]]></content:encoded></item><item><title>Nox Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/nox-security-scanner/</link><pubDate>Sun, 05 Jul 2026 14:56:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/nox-security-scanner/</guid><description>Version updated for https://github.com/Nox-HQ/nox to version v1.6.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Nox v1.6.0 (2026-07-05T11:53:33Z) Language-agnostic security scanner with first-class AI application security.
Installation macOS/Linux (Homebrew) brew tap felixgeelhaar/tap brew install nox Direct Download Download the appropriate archive for your platform from the assets below.
What’s Changed Changelog Others d7b896556efae04fd506e5073a24f939f4f451b4 docs(readme): refresh for v1.5.0 (#166) 91c967a5a94b90137ec7bb5e95de6f952385c239 docs(usage): document v1.5.0 commands (#167) e41f301347d60e6a6843868fca34df9d482108cb release: v1.6.0 (#174) Full Changelog: https://github.com/nox-hq/nox/compare/v1.5.0...v1.6.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Nox-HQ/nox">https://github.com/Nox-HQ/nox</a></strong> to version <strong>v1.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nox-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="nox-v160-2026-07-05t115333z">Nox v1.6.0 (2026-07-05T11:53:33Z)</h2>
<p>Language-agnostic security scanner with first-class AI application security.</p>
<h3 id="installation">Installation</h3>
<h4 id="macoslinux-homebrew">macOS/Linux (Homebrew)</h4>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>brew tap felixgeelhaar/tap
</span></span><span style="display:flex;"><span>brew install nox
</span></span></code></pre></div><h4 id="direct-download">Direct Download</h4>
<p>Download the appropriate archive for your platform from the assets below.</p>
<h3 id="whats-changed-1">What&rsquo;s Changed</h3>
<h2 id="changelog">Changelog</h2>
<h3 id="others">Others</h3>
<ul>
<li>d7b896556efae04fd506e5073a24f939f4f451b4 docs(readme): refresh for v1.5.0 (#166)</li>
<li>91c967a5a94b90137ec7bb5e95de6f952385c239 docs(usage): document v1.5.0 commands (#167)</li>
<li>e41f301347d60e6a6843868fca34df9d482108cb release: v1.6.0 (#174)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nox-hq/nox/compare/v1.5.0...v1.6.0">https://github.com/nox-hq/nox/compare/v1.5.0...v1.6.0</a></p>
]]></content:encoded></item><item><title>Podcast Generator NS</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/podcast-generator-ns/</link><pubDate>Sun, 05 Jul 2026 14:56:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/podcast-generator-ns/</guid><description>Version updated for https://github.com/nshportun/podcast-generator to version v1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/nshportun/podcast-generator/commits/v1.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nshportun/podcast-generator">https://github.com/nshportun/podcast-generator</a></strong> to version <strong>v1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/podcast-generator-ns">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nshportun/podcast-generator/commits/v1.0">https://github.com/nshportun/podcast-generator/commits/v1.0</a></p>
]]></content:encoded></item><item><title>Changelog Bot Runner Nyaomaru</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/changelog-bot-runner-nyaomaru/</link><pubDate>Sun, 05 Jul 2026 14:55:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/changelog-bot-runner-nyaomaru/</guid><description>Version updated for https://github.com/nyaomaru/changelog-bot to version v0.6.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed docs(changelog): 0.6.3 by @github-actions[bot] in https://github.com/nyaomaru/changelog-bot/pull/154 feat: improve why template extraction by @nyaomaru in https://github.com/nyaomaru/changelog-bot/pull/155 Release: 0.6.4 by @github-actions[bot] in https://github.com/nyaomaru/changelog-bot/pull/156 Full Changelog: https://github.com/nyaomaru/changelog-bot/compare/v0...v0.6.4</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nyaomaru/changelog-bot">https://github.com/nyaomaru/changelog-bot</a></strong> to version <strong>v0.6.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/changelog-bot-runner-nyaomaru">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs(changelog): 0.6.3 by @github-actions[bot] in <a href="https://github.com/nyaomaru/changelog-bot/pull/154">https://github.com/nyaomaru/changelog-bot/pull/154</a></li>
<li>feat: improve why template extraction by @nyaomaru in <a href="https://github.com/nyaomaru/changelog-bot/pull/155">https://github.com/nyaomaru/changelog-bot/pull/155</a></li>
<li>Release: 0.6.4 by @github-actions[bot] in <a href="https://github.com/nyaomaru/changelog-bot/pull/156">https://github.com/nyaomaru/changelog-bot/pull/156</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nyaomaru/changelog-bot/compare/v0...v0.6.4">https://github.com/nyaomaru/changelog-bot/compare/v0...v0.6.4</a></p>
]]></content:encoded></item><item><title>lacuna-cli</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/lacuna-cli/</link><pubDate>Sun, 05 Jul 2026 14:55:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/lacuna-cli/</guid><description>Version updated for https://github.com/Octagon-simon/lacuna to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/Octagon-simon/lacuna/compare/v0.2.4...v0.3.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Octagon-simon/lacuna">https://github.com/Octagon-simon/lacuna</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lacuna-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Octagon-simon/lacuna/compare/v0.2.4...v0.3.0">https://github.com/Octagon-simon/lacuna/compare/v0.2.4...v0.3.0</a></p>
]]></content:encoded></item><item><title>J-Bot Code Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/j-bot-code-review/</link><pubDate>Sun, 05 Jul 2026 14:54:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/j-bot-code-review/</guid><description>Version updated for https://github.com/pgup-ai/jbot-review-action to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First Marketplace release of J-Bot Review — an open-source agentic PR reviewer that runs as a single GitHub Action inside your own CI, with a model you already pay for.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pgup-ai/jbot-review-action">https://github.com/pgup-ai/jbot-review-action</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/j-bot-code-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p align="center">
  <img src="https://raw.githubusercontent.com/pgup-ai/jbot-review-action/main/docs/assets/social-preview.png" alt="J-Bot Review — code review that runs inside your own CI" />
</p>
<p>First Marketplace release of <strong>J-Bot Review</strong> — an open-source agentic PR reviewer that runs as a single GitHub Action inside your own CI, with a model you already pay for.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>One file, one secret to install</strong> — a Docker container action on your runner; least-privilege defaults (<code>contents: read</code>, <code>pull-requests: write</code>)</li>
<li><strong>Bring your own model</strong> — OpenCode gateways (Claude, OpenAI, Gemini, DeepSeek, and 28+ backends) or a coding-CLI subscription: Codex (ChatGPT Plus/Pro), Cursor, Devin, Cline, Kilo, Command Code</li>
<li><strong>Verified findings</strong> — every blocking finding is adversarially re-checked in a dedicated session before posting; refuted findings dropped, nits demoted</li>
<li><strong>Reads your house rules</strong> — AGENTS.md, REVIEW.md, .coderabbit.yaml, greptile.json, Cursor rules</li>
<li><strong>Current-docs checks</strong> — Context7 verifies changes against live documentation when a PR touches an external API or SDK</li>
<li><strong><code>/jbot</code> comment command</strong> — one-off reviews with a stronger model, sharing the per-PR concurrency group</li>
</ul>
<h2 id="install">Install</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">pgup-ai/jbot-review-action@v0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">provider</span>: <span style="color:#ae81ff">${{ vars.JBOT_REVIEW_PROVIDER || &#39;opencode&#39; }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">opencode-api-key</span>: <span style="color:#ae81ff">${{ secrets.OPENCODE_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">github-token</span>: <span style="color:#ae81ff">${{ secrets.GITHUB_TOKEN }}</span>
</span></span></code></pre></div><p>Docs: <a href="https://github.com/pgup-ai/jbot-review-action#readme">README</a> · Setup guides: <a href="https://www.pgupai.com/guides">pgupai.com/guides</a></p>
<p>Full changes since v0.1.0: <a href="https://github.com/pgup-ai/jbot-review-action/compare/v0.1.0...v0.2.0">https://github.com/pgup-ai/jbot-review-action/compare/v0.1.0...v0.2.0</a></p>
]]></content:encoded></item><item><title>PingRoom Notify</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/pingroom-notify/</link><pubDate>Sun, 05 Jul 2026 14:54:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/pingroom-notify/</guid><description>Version updated for https://github.com/pingroom/cli to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Turn a human decision into a shell gate. This release adds the Question commands to the CLI, alongside the existing ping.
New commands ask — ask a human a question in a room; with --wait, block until they tap an answer on their phone. Prints the chosen value to stdout and encodes the outcome in the exit code (0 answered · 3 expired · 4 cancelled), so it drops straight into a shell conditional. watch — block on an existing question until it resolves. list — list your agent’s questions by state. cancel — withdraw a pending question. if [ &amp;#34;$(pingroom ask --token &amp;#34;$PINGROOM_TOKEN&amp;#34; --room ab12cd --wait -p &amp;#39;Deploy 1.4.0 to production?&amp;#39;)&amp;#34; = approve ]; then ./deploy-prod.sh fi The Action The PingRoom Notify action sends a ping on deploy/CI and now runs on @pingroom/cli@0.2.0:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pingroom/cli">https://github.com/pingroom/cli</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pingroom-notify">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Turn a human decision into a shell gate. This release adds the <strong>Question</strong> commands to the CLI, alongside the existing <code>ping</code>.</p>
<h3 id="new-commands">New commands</h3>
<ul>
<li><strong><code>ask</code></strong> — ask a human a question in a room; with <code>--wait</code>, block until they tap an answer on their phone. Prints the chosen value to stdout and encodes the outcome in the exit code (<code>0</code> answered · <code>3</code> expired · <code>4</code> cancelled), so it drops straight into a shell conditional.</li>
<li><strong><code>watch</code></strong> — block on an existing question until it resolves.</li>
<li><strong><code>list</code></strong> — list your agent&rsquo;s questions by state.</li>
<li><strong><code>cancel</code></strong> — withdraw a pending question.</li>
</ul>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span><span style="color:#66d9ef">if</span> <span style="color:#f92672">[</span> <span style="color:#e6db74">&#34;</span><span style="color:#66d9ef">$(</span>pingroom ask --token <span style="color:#e6db74">&#34;</span>$PINGROOM_TOKEN<span style="color:#e6db74">&#34;</span> --room ab12cd --wait 
</span></span><span style="display:flex;"><span>      -p <span style="color:#e6db74">&#39;Deploy 1.4.0 to production?&#39;</span><span style="color:#66d9ef">)</span><span style="color:#e6db74">&#34;</span> <span style="color:#f92672">=</span> approve <span style="color:#f92672">]</span>; <span style="color:#66d9ef">then</span>
</span></span><span style="display:flex;"><span>  ./deploy-prod.sh
</span></span><span style="display:flex;"><span><span style="color:#66d9ef">fi</span>
</span></span></code></pre></div><h3 id="the-action">The Action</h3>
<p>The <code>PingRoom Notify</code> action sends a ping on deploy/CI and now runs on <code>@pingroom/cli@0.2.0</code>:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">pingroom/cli@v0.2.0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">webhook-url</span>: <span style="color:#ae81ff">${{ secrets.PINGROOM_WEBHOOK_URL }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">message</span>: <span style="color:#e6db74">&#34;🚀 Deployed ${{ github.sha }}&#34;</span>
</span></span></code></pre></div><p><code>ping</code> is unchanged and fully backward-compatible.</p>
]]></content:encoded></item><item><title>FoundRuu Doctor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/foundruu-doctor/</link><pubDate>Sun, 05 Jul 2026 14:53:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/foundruu-doctor/</guid><description>Version updated for https://github.com/Ruu5LP/foundruu to version v0.11.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Broaden doctor –deep document detection by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/16 Release 0.11.0 by @Ruu5LP in https://github.com/Ruu5LP/foundruu/pull/17 Full Changelog: https://github.com/Ruu5LP/foundruu/compare/v0.10.0...v0.11.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Ruu5LP/foundruu">https://github.com/Ruu5LP/foundruu</a></strong> to version <strong>v0.11.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/foundruu-doctor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Broaden doctor &ndash;deep document detection by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/16">https://github.com/Ruu5LP/foundruu/pull/16</a></li>
<li>Release 0.11.0 by @Ruu5LP in <a href="https://github.com/Ruu5LP/foundruu/pull/17">https://github.com/Ruu5LP/foundruu/pull/17</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Ruu5LP/foundruu/compare/v0.10.0...v0.11.0">https://github.com/Ruu5LP/foundruu/compare/v0.10.0...v0.11.0</a></p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/bernstein-multi-agent-orchestration/</link><pubDate>Sun, 05 Jul 2026 14:52:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v2.15.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.15.0 Released 2026-07-05.
Feature release built around five community contributions by Shane Mattner (@shanemmattner), plus scheduler and test-infrastructure fixes.
Features Hold/release API (/orchestrator/holds): heartbeat-renewed leases that keep the spawner alive while an external workflow driver is active, replacing the fixed quiescence settle timer. TTL is a grace window; expired holds release on their own. Operator docs in docs/operations/HOLDS.md. (#2218, thanks @shanemmattner) Explicit max_turns on TaskCreate: per-task turn budgets flow end to end to the adapter spawn, bypassing the complexity heuristic when set; bounded 1..10000 at the schema boundary; retries carry the value forward. Docs in docs/operations/MAX_TURNS.md. (#2217, thanks @shanemmattner) Per-agent run instrumentation: JSONL records for every LLM call, tool call, and conversation message, captured in real time via SDK hooks and anchored to the project root (not the per-task worktree). Docs in docs/operations/INSTRUMENTATION.md. (#2219, thanks @shanemmattner) Council-of-agents redesign: per-member cost attribution, judge synthesis over candidate outputs, enable_thinking=false injected for Qwen models served from Alibaba Cloud endpoints (hostname-suffix detection), and BERNSTEIN_BUILTIN_ALLOW_RUN_COMMAND passthrough in env isolation. (#2220, thanks @shanemmattner) Inline role_model_policy.&amp;lt;role&amp;gt;.council seed blocks now forward into the runner manifest, behaving identically to the councils/*.yaml file convention. (#2231) Fixes Model selection no longer falls back to hardcoded model strings: every selection flows from configuration, and unconfigured paths raise ModelNotConfiguredError instead of silently guessing. (#2216, thanks @shanemmattner) Critical-path priority boost applies on the first spawn batch, so a low-priority dependency of a high-priority task is claimed first. (#2233) Worker exit codes: when the whole process group receives SIGINT, the worker no longer re-forwards the signal into the child’s interpreter shutdown window, so it reports the child handler’s exit code instead of 130. (#2238) Five integration tests repaired and re-enabled after root-causing failures that predated this cycle. (#2232) Internal Unit coverage for the council runner path. (#2230) Log-injection sanitization on hold fields; scanner findings resolved across instrumentation and council logging. (#2229)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v2.15.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v2150">v2.15.0</h1>
<p>Released 2026-07-05.</p>
<p>Feature release built around five community contributions by Shane Mattner (@shanemmattner), plus scheduler and test-infrastructure fixes.</p>
<h2 id="features">Features</h2>
<ul>
<li>Hold/release API (<code>/orchestrator/holds</code>): heartbeat-renewed leases that keep the spawner alive while an external workflow driver is active, replacing the fixed quiescence settle timer. TTL is a grace window; expired holds release on their own. Operator docs in <code>docs/operations/HOLDS.md</code>. (#2218, thanks @shanemmattner)</li>
<li>Explicit <code>max_turns</code> on <code>TaskCreate</code>: per-task turn budgets flow end to end to the adapter spawn, bypassing the complexity heuristic when set; bounded 1..10000 at the schema boundary; retries carry the value forward. Docs in <code>docs/operations/MAX_TURNS.md</code>. (#2217, thanks @shanemmattner)</li>
<li>Per-agent run instrumentation: JSONL records for every LLM call, tool call, and conversation message, captured in real time via SDK hooks and anchored to the project root (not the per-task worktree). Docs in <code>docs/operations/INSTRUMENTATION.md</code>. (#2219, thanks @shanemmattner)</li>
<li>Council-of-agents redesign: per-member cost attribution, judge synthesis over candidate outputs, <code>enable_thinking=false</code> injected for Qwen models served from Alibaba Cloud endpoints (hostname-suffix detection), and <code>BERNSTEIN_BUILTIN_ALLOW_RUN_COMMAND</code> passthrough in env isolation. (#2220, thanks @shanemmattner)</li>
<li>Inline <code>role_model_policy.&lt;role&gt;.council</code> seed blocks now forward into the runner manifest, behaving identically to the <code>councils/*.yaml</code> file convention. (#2231)</li>
</ul>
<h2 id="fixes">Fixes</h2>
<ul>
<li>Model selection no longer falls back to hardcoded model strings: every selection flows from configuration, and unconfigured paths raise <code>ModelNotConfiguredError</code> instead of silently guessing. (#2216, thanks @shanemmattner)</li>
<li>Critical-path priority boost applies on the first spawn batch, so a low-priority dependency of a high-priority task is claimed first. (#2233)</li>
<li>Worker exit codes: when the whole process group receives SIGINT, the worker no longer re-forwards the signal into the child&rsquo;s interpreter shutdown window, so it reports the child handler&rsquo;s exit code instead of 130. (#2238)</li>
<li>Five integration tests repaired and re-enabled after root-causing failures that predated this cycle. (#2232)</li>
</ul>
<h2 id="internal">Internal</h2>
<ul>
<li>Unit coverage for the council runner path. (#2230)</li>
<li>Log-injection sanitization on hold fields; scanner findings resolved across instrumentation and council logging. (#2229)</li>
</ul>
]]></content:encoded></item><item><title>Setup UniRTM</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/setup-unirtm/</link><pubDate>Sun, 05 Jul 2026 14:52:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/setup-unirtm/</guid><description>Version updated for https://github.com/snowdreamtech/setup-unirtm to version v0.5.0.
This action is used across all versions by 34 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.5.0 (2026-07-05) Features add job summary output (23587ed) atomic caching to prevent corrupted cache on install failure (2f09505) Bug Fixes polyfill import.meta.url for esbuild CJS bundle (3ff3077) remove esbuild minify to fix createRequire(import.meta.url) cjs interop bug (0be14b5) temporarily disable pip auto-detection and integration test (9d019b4)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/snowdreamtech/setup-unirtm">https://github.com/snowdreamtech/setup-unirtm</a></strong> to version <strong>v0.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>34</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-unirtm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="050-2026-07-05"><a href="https://github.com/snowdreamtech/setup-unirtm/compare/v0.4.1...v0.5.0">0.5.0</a> (2026-07-05)</h2>
<h3 id="features">Features</h3>
<ul>
<li>add job summary output (<a href="https://github.com/snowdreamtech/setup-unirtm/commit/23587ed14e5d14273098cd42059b0467f6a1e1c8">23587ed</a>)</li>
<li>atomic caching to prevent corrupted cache on install failure (<a href="https://github.com/snowdreamtech/setup-unirtm/commit/2f095057de7fc0af68a6f9514d4f056c81c56d76">2f09505</a>)</li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>polyfill import.meta.url for esbuild CJS bundle (<a href="https://github.com/snowdreamtech/setup-unirtm/commit/3ff3077b5a9cb257747cd77d69fba16859f49968">3ff3077</a>)</li>
<li>remove esbuild minify to fix createRequire(import.meta.url) cjs interop bug (<a href="https://github.com/snowdreamtech/setup-unirtm/commit/0be14b5c2fb1a0633bc255f53fe461bf7ba0b27e">0be14b5</a>)</li>
<li>temporarily disable pip auto-detection and integration test (<a href="https://github.com/snowdreamtech/setup-unirtm/commit/9d019b4818b55ea33febcaa4b15cf6bfc56c5635">9d019b4</a>)</li>
</ul>
]]></content:encoded></item><item><title>Generate Pong SVGs</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/generate-pong-svgs/</link><pubDate>Sun, 05 Jul 2026 14:51:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/generate-pong-svgs/</guid><description>Version updated for https://github.com/st1vms/PongSVG to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed CHANGELOG New modes! avatar, follower, star</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/st1vms/PongSVG">https://github.com/st1vms/PongSVG</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/generate-pong-svgs">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">CHANGELOG</h2>
<ul>
<li>New modes!</li>
<li><code>avatar</code>, <code>follower</code>, <code>star</code></li>
</ul>
]]></content:encoded></item><item><title>SignalBrain receipt gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/signalbrain-receipt-gate/</link><pubDate>Sun, 05 Jul 2026 14:50:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/signalbrain-receipt-gate/</guid><description>Version updated for https://github.com/whitestone1121-web/signalbrain to version v0.1.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Merge pull request #12 from whitestone1121-web/codex/release-0.1.4-license (c809682) release-0.1.4-license-detection (7d1c13b) Merge pull request #11 from whitestone1121-web/codex/release-0.1.3-readiness (07056b8) release: prepare SignalBrain 0.1.3 (9185882) Merge pull request #10 from whitestone1121-web/codex/integrity-docs-hardening (f7cb57d) docs: define SignalBrain integrity boundary (4ac82fc) docs: GitHub mirror of the confidence-inversion essay (AI-readable) (01e1382) docs: emission guide wrongly claimed pipe support — spec and scorer disagree (1119308) study: pre-register the Overclaiming Report task sample (n=50, seed 58) (372b069) docs: link the live confidence-inversion essay (d2247ac)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/whitestone1121-web/signalbrain">https://github.com/whitestone1121-web/signalbrain</a></strong> to version <strong>v0.1.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/signalbrain-receipt-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Merge pull request #12 from whitestone1121-web/codex/release-0.1.4-license (c809682)</li>
<li>release-0.1.4-license-detection (7d1c13b)</li>
<li>Merge pull request #11 from whitestone1121-web/codex/release-0.1.3-readiness (07056b8)</li>
<li>release: prepare SignalBrain 0.1.3 (9185882)</li>
<li>Merge pull request #10 from whitestone1121-web/codex/integrity-docs-hardening (f7cb57d)</li>
<li>docs: define SignalBrain integrity boundary (4ac82fc)</li>
<li>docs: GitHub mirror of the confidence-inversion essay (AI-readable) (01e1382)</li>
<li>docs: emission guide wrongly claimed pipe support — spec and scorer disagree (1119308)</li>
<li>study: pre-register the Overclaiming Report task sample (n=50, seed 58) (372b069)</li>
<li>docs: link the live confidence-inversion essay (d2247ac)</li>
</ul>
]]></content:encoded></item><item><title>backlog-to-pr</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/backlog-to-pr/</link><pubDate>Sun, 05 Jul 2026 14:50:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/backlog-to-pr/</guid><description>Version updated for https://github.com/wrbl606/backlog.md-to-pr to version 0.0.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/wrbl606/backlog.md-to-pr/compare/0.0.3...0.0.4</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wrbl606/backlog.md-to-pr">https://github.com/wrbl606/backlog.md-to-pr</a></strong> to version <strong>0.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/backlog-to-pr">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/wrbl606/backlog.md-to-pr/compare/0.0.3...0.0.4">https://github.com/wrbl606/backlog.md-to-pr/compare/0.0.3...0.0.4</a></p>
]]></content:encoded></item><item><title>Intent Guarantor — Differential Enforcement</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/intent-guarantor-differential-enforcement/</link><pubDate>Sun, 05 Jul 2026 14:49:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/intent-guarantor-differential-enforcement/</guid><description>Version updated for https://github.com/zAnshn/guarantor to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Intent Guarantor v0.1.0 — first public release A tenant-isolation gate for Next.js + Supabase/Prisma/Drizzle apps: it flags cross-tenant data-leak (IDOR) bugs — the class that’s #1 on the OWASP API Top 10 and that generic scanners miss.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zAnshn/guarantor">https://github.com/zAnshn/guarantor</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/intent-guarantor-differential-enforcement">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="intent-guarantor-v010--first-public-release">Intent Guarantor v0.1.0 — first public release</h2>
<p>A tenant-isolation gate for <strong>Next.js + Supabase/Prisma/Drizzle</strong> apps: it flags cross-tenant
data-leak (IDOR) bugs — the class that&rsquo;s #1 on the OWASP API Top 10 and that generic scanners miss.</p>
<h3 id="whats-in-it">What&rsquo;s in it</h3>
<ul>
<li><strong><code>guarantor sweep</code></strong> — deterministic, LLM-free <em>differential enforcement</em>: mine a fix commit&rsquo;s
shape, flag the unfixed sibling endpoints (&ldquo;you scoped this query in commit X; here are the 6 you
didn&rsquo;t&rdquo;). The piece with no direct equivalent elsewhere.</li>
<li><strong><code>guarantor analyze</code></strong> — goal-inference mode (the research thesis), behind a firewall that keeps the
goals-on/off ablation honest.</li>
<li><strong>SARIF 2.1.0</strong> output + a <strong>GitHub Action</strong> → findings in the Security tab / PR annotations.</li>
<li>Two correctness classes (tenant-isolation + PII-egress) on one Engine/Pack seam; three ORM
front-ends; synthetic fixtures pinning every behavior. MIT licensed.</li>
</ul>
<h3 id="honest-positioning">Honest positioning</h3>
<p>Published as <strong>open source + a validated research result, not a commercial product.</strong> The thesis held
up under adversarial evaluation on a frozen, hand-adjudicated corpus; the false-positive modes are
measured and reported, not hidden. See <code>docs/RESULTS.md</code> and the README&rsquo;s &ldquo;Honest positioning&rdquo;.</p>
<h3 id="note">Note</h3>
<p>The wild-app evaluation corpus is intentionally excluded and its results anonymized — the raw labels
quoted code from third-party repos whose vulnerabilities were never coordinated-disclosed.</p>
<p><strong>Try it:</strong> <code>npm install &amp;&amp; npm run build &amp;&amp; node dist/guarantor.js sweep &lt;repo&gt; --sarif out.sarif</code></p>
]]></content:encoded></item><item><title>Doc Detective</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/doc-detective/</link><pubDate>Sun, 05 Jul 2026 06:32:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/doc-detective/</guid><description>Version updated for https://github.com/doc-detective/github-action to version v1.6.1.
This action is used across all versions by 9 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed fix: reload udev rules before triggering when enabling KVM (#72) Follow-up to v1.6.0. enableLinuxKvm now runs udevadm control --reload-rules before udevadm trigger, so the freshly-written kvm rule is actually loaded and /dev/kvm becomes accessible — without it the android: auto KVM setup was a no-op and Android contexts still SKIPped.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/doc-detective/github-action">https://github.com/doc-detective/github-action</a></strong> to version <strong>v1.6.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>9</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/doc-detective">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="fix-reload-udev-rules-before-triggering-when-enabling-kvm-72">fix: reload udev rules before triggering when enabling KVM (#72)</h2>
<p>Follow-up to v1.6.0. <code>enableLinuxKvm</code> now runs <code>udevadm control --reload-rules</code> before <code>udevadm trigger</code>, so the freshly-written kvm rule is actually loaded and /dev/kvm becomes accessible — without it the <code>android: auto</code> KVM setup was a no-op and Android contexts still SKIPped.</p>
]]></content:encoded></item><item><title>AgentGuard Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/agentguard-security-scan/</link><pubDate>Sun, 05 Jul 2026 06:31:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/agentguard-security-scan/</guid><description>Version updated for https://github.com/dockfixlabs/agentguard to version v0.6.8.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ASI-STEGANO-INJECT: 6th novel rule. 19 rules, 102 tests, 50 benchmark.
Full Changelog: https://github.com/dockfixlabs/agentguard/compare/v0.6.6...v0.6.8</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/dockfixlabs/agentguard">https://github.com/dockfixlabs/agentguard</a></strong> to version <strong>v0.6.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agentguard-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>ASI-STEGANO-INJECT: 6th novel rule. 19 rules, 102 tests, 50 benchmark.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/dockfixlabs/agentguard/compare/v0.6.6...v0.6.8">https://github.com/dockfixlabs/agentguard/compare/v0.6.6...v0.6.8</a></p>
]]></content:encoded></item><item><title>terraform-monorepo-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/terraform-monorepo-action/</link><pubDate>Sun, 05 Jul 2026 06:31:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/terraform-monorepo-action/</guid><description>Version updated for https://github.com/fr12k/terraform-monorepo-action to version v3.0.10.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed build(deps-dev): bump eslint from 10.2.1 to 10.3.0 by @dependabot[bot] in https://github.com/fr12k/terraform-monorepo-action/pull/169 build(deps): bump @actions/core from 2.0.2 to 3.0.1 by @dependabot[bot] in https://github.com/fr12k/terraform-monorepo-action/pull/167 build(deps-dev): bump eslint from 10.3.0 to 10.4.1 by @dependabot[bot] in https://github.com/fr12k/terraform-monorepo-action/pull/175 build(deps-dev): bump @types/node from 25.6.0 to 25.9.1 by @dependabot[bot] in https://github.com/fr12k/terraform-monorepo-action/pull/174 build(deps): bump @actions/github from 9.1.0 to 9.1.1 by @dependabot[bot] in https://github.com/fr12k/terraform-monorepo-action/pull/168 build(deps): bump actions/checkout from 6 to 7 by @dependabot[bot] in https://github.com/fr12k/terraform-monorepo-action/pull/180 build(deps-dev): bump eslint from 10.4.1 to 10.6.0 by @dependabot[bot] in https://github.com/fr12k/terraform-monorepo-action/pull/184 build(deps-dev): bump @types/node from 25.9.1 to 26.0.0 by @dependabot[bot] in https://github.com/fr12k/terraform-monorepo-action/pull/181 build(deps-dev): bump prettier from 3.8.3 to 3.9.4 by @dependabot[bot] in https://github.com/fr12k/terraform-monorepo-action/pull/185 build(deps): bump undici from 6.25.0 to 6.27.0 by @dependabot[bot] in https://github.com/fr12k/terraform-monorepo-action/pull/182 Full Changelog: https://github.com/fr12k/terraform-monorepo-action/compare/v3.0.9...v3.0.10</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/fr12k/terraform-monorepo-action">https://github.com/fr12k/terraform-monorepo-action</a></strong> to version <strong>v3.0.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/terraform-monorepo-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>build(deps-dev): bump eslint from 10.2.1 to 10.3.0 by @dependabot[bot] in <a href="https://github.com/fr12k/terraform-monorepo-action/pull/169">https://github.com/fr12k/terraform-monorepo-action/pull/169</a></li>
<li>build(deps): bump @actions/core from 2.0.2 to 3.0.1 by @dependabot[bot] in <a href="https://github.com/fr12k/terraform-monorepo-action/pull/167">https://github.com/fr12k/terraform-monorepo-action/pull/167</a></li>
<li>build(deps-dev): bump eslint from 10.3.0 to 10.4.1 by @dependabot[bot] in <a href="https://github.com/fr12k/terraform-monorepo-action/pull/175">https://github.com/fr12k/terraform-monorepo-action/pull/175</a></li>
<li>build(deps-dev): bump @types/node from 25.6.0 to 25.9.1 by @dependabot[bot] in <a href="https://github.com/fr12k/terraform-monorepo-action/pull/174">https://github.com/fr12k/terraform-monorepo-action/pull/174</a></li>
<li>build(deps): bump @actions/github from 9.1.0 to 9.1.1 by @dependabot[bot] in <a href="https://github.com/fr12k/terraform-monorepo-action/pull/168">https://github.com/fr12k/terraform-monorepo-action/pull/168</a></li>
<li>build(deps): bump actions/checkout from 6 to 7 by @dependabot[bot] in <a href="https://github.com/fr12k/terraform-monorepo-action/pull/180">https://github.com/fr12k/terraform-monorepo-action/pull/180</a></li>
<li>build(deps-dev): bump eslint from 10.4.1 to 10.6.0 by @dependabot[bot] in <a href="https://github.com/fr12k/terraform-monorepo-action/pull/184">https://github.com/fr12k/terraform-monorepo-action/pull/184</a></li>
<li>build(deps-dev): bump @types/node from 25.9.1 to 26.0.0 by @dependabot[bot] in <a href="https://github.com/fr12k/terraform-monorepo-action/pull/181">https://github.com/fr12k/terraform-monorepo-action/pull/181</a></li>
<li>build(deps-dev): bump prettier from 3.8.3 to 3.9.4 by @dependabot[bot] in <a href="https://github.com/fr12k/terraform-monorepo-action/pull/185">https://github.com/fr12k/terraform-monorepo-action/pull/185</a></li>
<li>build(deps): bump undici from 6.25.0 to 6.27.0 by @dependabot[bot] in <a href="https://github.com/fr12k/terraform-monorepo-action/pull/182">https://github.com/fr12k/terraform-monorepo-action/pull/182</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/fr12k/terraform-monorepo-action/compare/v3.0.9...v3.0.10">https://github.com/fr12k/terraform-monorepo-action/compare/v3.0.9...v3.0.10</a></p>
]]></content:encoded></item><item><title>RunRight CI Resource Monitor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/runright-ci-resource-monitor/</link><pubDate>Sun, 05 Jul 2026 06:30:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/runright-ci-resource-monitor/</guid><description>Version updated for https://github.com/gbudjeakp/run-right to version v1.5.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v1.5.0 - Email Notifications, Analytics Dashboard, Alerts UX New Features Email notification destination - SMTP support with demo fallback Analytics dashboard - Cost breakdown by repo/job/runner with trends Search bars for Alert Rules and Ownership tabs SSO support - SAML and OIDC authentication API keys management Backend EmailChannel adapter in notification package SMTP config via RUNRIGHT_SMTP_* environment variables Analytics API endpoints Frontend Email tab in Destinations with subject prefix and recipients Analytics page with charts and filters Improved alert rules filtering Docs Added CHANGELOG.md Updated comparison page with honest feature matrix Added SMTP environment variables to install docs Full Changelog: https://github.com/gbudjeakp/run-right/compare/v1.2.3...v1.5.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/gbudjeakp/run-right">https://github.com/gbudjeakp/run-right</a></strong> to version <strong>v1.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/runright-ci-resource-monitor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="release-v150---email-notifications-analytics-dashboard-alerts-ux">Release v1.5.0 - Email Notifications, Analytics Dashboard, Alerts UX</h2>
<h3 id="new-features">New Features</h3>
<ul>
<li><strong>Email notification destination</strong> - SMTP support with demo fallback</li>
<li><strong>Analytics dashboard</strong> - Cost breakdown by repo/job/runner with trends</li>
<li><strong>Search bars</strong> for Alert Rules and Ownership tabs</li>
<li><strong>SSO support</strong> - SAML and OIDC authentication</li>
<li><strong>API keys management</strong></li>
</ul>
<h3 id="backend">Backend</h3>
<ul>
<li>EmailChannel adapter in notification package</li>
<li>SMTP config via <code>RUNRIGHT_SMTP_*</code> environment variables</li>
<li>Analytics API endpoints</li>
</ul>
<h3 id="frontend">Frontend</h3>
<ul>
<li>Email tab in Destinations with subject prefix and recipients</li>
<li>Analytics page with charts and filters</li>
<li>Improved alert rules filtering</li>
</ul>
<h3 id="docs">Docs</h3>
<ul>
<li>Added CHANGELOG.md</li>
<li>Updated comparison page with honest feature matrix</li>
<li>Added SMTP environment variables to install docs</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/gbudjeakp/run-right/compare/v1.2.3...v1.5.0">https://github.com/gbudjeakp/run-right/compare/v1.2.3...v1.5.0</a></p>
]]></content:encoded></item><item><title>Setup poly CLI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/setup-poly-cli/</link><pubDate>Sun, 05 Jul 2026 06:30:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/setup-poly-cli/</guid><description>Version updated for https://github.com/Goldziher/polylint to version v0.5.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v0.5.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Goldziher/polylint">https://github.com/Goldziher/polylint</a></strong> to version <strong>v0.5.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-poly-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release v0.5.1</p>
]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/ai-plugin-scanner/</link><pubDate>Sun, 05 Jul 2026 06:29:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.386.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/e96dd6853a6672b8a87ea1b9f9f183add027bb95 with plugin-scanner 2.0.986.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.385...v1.2.386</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.386</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>18</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/e96dd6853a6672b8a87ea1b9f9f183add027bb95">https://github.com/hashgraph-online/hol-guard/tree/e96dd6853a6672b8a87ea1b9f9f183add027bb95</a> with plugin-scanner 2.0.986.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.385...v1.2.386">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.385...v1.2.386</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/hol-codex-plugin-scanner/</link><pubDate>Sun, 05 Jul 2026 06:28:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.386.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.386</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.386</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.386">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.386</a></p>
]]></content:encoded></item><item><title>hide-comment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/hide-comment/</link><pubDate>Sun, 05 Jul 2026 06:28:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/hide-comment/</guid><description>Version updated for https://github.com/int128/hide-comment-action to version v1.64.0.
This action is used across all versions by 227 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed uses: int128/hide-comment-action@769d2f65928cb6477a9993aab4ed7a02c33f4588 # v1.64.0 What’s Changed chore(deps): update int128/release-typescript-action action to v1.74.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1643 chore(deps): update dependency @biomejs/biome to v2.5.1 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1642 chore(deps): update int128/wait-for-workflows-action action to v1.83.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1644 chore(deps): update node.js to v24.18.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1645 chore(deps): update int128/wait-for-workflows-action action to v1.84.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1647 chore(deps): update dependency js-yaml to v4.3.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1646 chore(deps): update pnpm to v11.9.0 by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1648 chore(deps): lock file maintenance by @renovate[bot] in https://github.com/int128/hide-comment-action/pull/1649 Full Changelog: https://github.com/int128/hide-comment-action/compare/v1.63.0...v1.64.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/int128/hide-comment-action">https://github.com/int128/hide-comment-action</a></strong> to version <strong>v1.64.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>227</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hide-comment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">uses</span>: <span style="color:#ae81ff">int128/hide-comment-action@769d2f65928cb6477a9993aab4ed7a02c33f4588</span> <span style="color:#75715e"># v1.64.0</span>
</span></span></code></pre></div><h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): update int128/release-typescript-action action to v1.74.0 by @renovate[bot] in <a href="https://github.com/int128/hide-comment-action/pull/1643">https://github.com/int128/hide-comment-action/pull/1643</a></li>
<li>chore(deps): update dependency @biomejs/biome to v2.5.1 by @renovate[bot] in <a href="https://github.com/int128/hide-comment-action/pull/1642">https://github.com/int128/hide-comment-action/pull/1642</a></li>
<li>chore(deps): update int128/wait-for-workflows-action action to v1.83.0 by @renovate[bot] in <a href="https://github.com/int128/hide-comment-action/pull/1644">https://github.com/int128/hide-comment-action/pull/1644</a></li>
<li>chore(deps): update node.js to v24.18.0 by @renovate[bot] in <a href="https://github.com/int128/hide-comment-action/pull/1645">https://github.com/int128/hide-comment-action/pull/1645</a></li>
<li>chore(deps): update int128/wait-for-workflows-action action to v1.84.0 by @renovate[bot] in <a href="https://github.com/int128/hide-comment-action/pull/1647">https://github.com/int128/hide-comment-action/pull/1647</a></li>
<li>chore(deps): update dependency js-yaml to v4.3.0 by @renovate[bot] in <a href="https://github.com/int128/hide-comment-action/pull/1646">https://github.com/int128/hide-comment-action/pull/1646</a></li>
<li>chore(deps): update pnpm to v11.9.0 by @renovate[bot] in <a href="https://github.com/int128/hide-comment-action/pull/1648">https://github.com/int128/hide-comment-action/pull/1648</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/int128/hide-comment-action/pull/1649">https://github.com/int128/hide-comment-action/pull/1649</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/int128/hide-comment-action/compare/v1.63.0...v1.64.0">https://github.com/int128/hide-comment-action/compare/v1.63.0...v1.64.0</a></p>
]]></content:encoded></item><item><title>cibuild-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/cibuild-action/</link><pubDate>Sun, 05 Jul 2026 06:27:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/cibuild-action/</guid><description>Version updated for https://github.com/invarnhq/cibuild to version v2.3.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v2.3.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/invarnhq/cibuild">https://github.com/invarnhq/cibuild</a></strong> to version <strong>v2.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cibuild-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release v2.3.1</p>
]]></content:encoded></item><item><title>probelock gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/probelock-gate/</link><pubDate>Sun, 05 Jul 2026 06:27:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/probelock-gate/</guid><description>Version updated for https://github.com/kelkalot/probelock to version v0.3.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Make –tools optional when using traces/mined by @kelkalot in https://github.com/kelkalot/probelock/pull/3 Full Changelog: https://github.com/kelkalot/probelock/compare/v0...v0.3.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kelkalot/probelock">https://github.com/kelkalot/probelock</a></strong> to version <strong>v0.3.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/probelock-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Make &ndash;tools optional when using traces/mined by @kelkalot in <a href="https://github.com/kelkalot/probelock/pull/3">https://github.com/kelkalot/probelock/pull/3</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/kelkalot/probelock/compare/v0...v0.3.1">https://github.com/kelkalot/probelock/compare/v0...v0.3.1</a></p>
]]></content:encoded></item><item><title>Setup runner cli</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/setup-runner-cli/</link><pubDate>Sun, 05 Jul 2026 06:26:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/setup-runner-cli/</guid><description>Version updated for https://github.com/kjanat/runner to version v0.18.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed The v0.18.0 npm packages spawn-failed with EACCES: the platform packages’ new explicit bin field disabled directories.bin linking, so npm no longer marked the native binaries executable at install — breaking both npx @runner-run/&amp;lt;platform&amp;gt; … and the runner-run facade. Platform bin entries now point directly at the native binaries and expose both commands (npx --package=@runner-run/&amp;lt;platform&amp;gt; runner … and … run …); the launcher shim and the erroneous bin + directories.bin combination are gone. Versions up to 0.17.0 were unaffected; 0.18.0 is deprecated on npm. The npm dist artifact now crosses the build→publish handoff as a tarball so unix file modes survive the zip-based artifact store; the publish job refuses non-executable binaries and smoke-tests the packed tarballs (install + execute every bin) before publishing. Full Changelog: https://github.com/kjanat/runner/compare/v0.18.0...v0.18.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kjanat/runner">https://github.com/kjanat/runner</a></strong> to version <strong>v0.18.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-runner-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li>The v0.18.0 npm packages spawn-failed with <code>EACCES</code>: the platform
packages&rsquo; new explicit <code>bin</code> field disabled <code>directories.bin</code> linking, so
npm no longer marked the native binaries executable at install — breaking
both <code>npx @runner-run/&lt;platform&gt; …</code> and the <code>runner-run</code> facade. Platform
<code>bin</code> entries now point directly at the native binaries and expose both
commands (<code>npx --package=@runner-run/&lt;platform&gt; runner …</code> and <code>… run …</code>);
the launcher shim and the erroneous <code>bin</code> + <code>directories.bin</code> combination
are gone. Versions up to 0.17.0 were unaffected; 0.18.0 is deprecated on
npm.</li>
<li>The npm dist artifact now crosses the build→publish handoff as a tarball
so unix file modes survive the zip-based artifact store; the publish job
refuses non-executable binaries and smoke-tests the packed tarballs
(install + execute every bin) before publishing.</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/kjanat/runner/compare/v0.18.0...v0.18.1">https://github.com/kjanat/runner/compare/v0.18.0...v0.18.1</a></p>
]]></content:encoded></item><item><title>Skilldrift — Skills Drift Monitor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/skilldrift-skills-drift-monitor/</link><pubDate>Sun, 05 Jul 2026 06:26:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/skilldrift-skills-drift-monitor/</guid><description>Version updated for https://github.com/kpab/skilldrift to version v0.1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog 1ecdde4a554e5e2817954060cd83e326217bf5f6 action.yml: marketplace公開向けにname一意化とdescription短縮</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kpab/skilldrift">https://github.com/kpab/skilldrift</a></strong> to version <strong>v0.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skilldrift-skills-drift-monitor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>1ecdde4a554e5e2817954060cd83e326217bf5f6 action.yml: marketplace公開向けにname一意化とdescription短縮</li>
</ul>
]]></content:encoded></item><item><title>invAIriant audit gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/invairiant-audit-gate/</link><pubDate>Sun, 05 Jul 2026 06:25:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/invairiant-audit-gate/</guid><description>Version updated for https://github.com/mindicator/invAIriant to version v0.2.5.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed The CLI seatbelt now uses semantic color on a real terminal — green ✓/OK, red ✗/FAILED/S0, amber S1 — so a live terminal recording reads clearly. Color is emitted only on a TTY (honoring NO_COLOR); piped and CI output stay byte-for-byte plain, so exit codes and parsed output are unaffected. Auto-published to PyPI via Trusted Publishing. No new lenses; the CLI still performs no judgment.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mindicator/invAIriant">https://github.com/mindicator/invAIriant</a></strong> to version <strong>v0.2.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/invairiant-audit-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The CLI seatbelt now uses semantic color on a real terminal — green <code>✓</code>/<code>OK</code>, red <code>✗</code>/<code>FAILED</code>/S0, amber S1 — so a live terminal recording reads clearly. Color is emitted <strong>only</strong> on a TTY (honoring <code>NO_COLOR</code>); piped and CI output stay byte-for-byte plain, so exit codes and parsed output are unaffected. Auto-published to PyPI via Trusted Publishing. No new lenses; the CLI still performs no judgment.</p>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/totem-shield/</link><pubDate>Sun, 05 Jul 2026 06:25:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.89.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Cohort-link bump (no direct package changes). See .changeset/config.json for the fixed-cohort definition.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.89.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>DeepRabbit Code Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/deeprabbit-code-review/</link><pubDate>Sun, 05 Jul 2026 06:24:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/deeprabbit-code-review/</guid><description>Version updated for https://github.com/n0namedeveloper/DeepRabbit to version v1.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Minor stuctural rework of comments. Should look perfect by now.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/n0namedeveloper/DeepRabbit">https://github.com/n0namedeveloper/DeepRabbit</a></strong> to version <strong>v1.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deeprabbit-code-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Minor stuctural rework of comments. Should look perfect by now.</p>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/go-proxy-cache-updater/</link><pubDate>Sun, 05 Jul 2026 06:23:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.14.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.1.14 (2026-07-04)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.14</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1114-2026-07-04"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.13...v1.1.14">1.1.14</a> (2026-07-04)</h2>
]]></content:encoded></item><item><title>Run AER Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/run-aer-tests/</link><pubDate>Sun, 05 Jul 2026 06:23:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/run-aer-tests/</guid><description>Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.8.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Version v1.2.8
Resolve Method Calls To Methods, Not Constructors Sharing The Class Name
Maintain Map Insertion Order In Builtins So values() And keySet() See Every Entry</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/octoberswimmer/aer-dist">https://github.com/octoberswimmer/aer-dist</a></strong> to version <strong>v1.2.8</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-aer-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Version v1.2.8</p>
<ul>
<li>
<p>Resolve Method Calls To Methods, Not Constructors Sharing The Class Name</p>
</li>
<li>
<p>Maintain Map Insertion Order In Builtins So values() And keySet() See Every Entry</p>
</li>
</ul>
]]></content:encoded></item><item><title>Next CalVer Version</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/next-calver-version/</link><pubDate>Sun, 05 Jul 2026 06:22:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/next-calver-version/</guid><description>Version updated for https://github.com/okaryo/calver to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s changed Use @actions/github and GitHub matching refs to load only tags for the resolved release date, reducing API requests in repositories with many tags. Change previous-version to report the latest matching version for the resolved date only. Full Changelog: https://github.com/okaryo/calver/compare/v1.0.0...v1.1.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/okaryo/calver">https://github.com/okaryo/calver</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/next-calver-version">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s changed</h2>
<ul>
<li>Use <code>@actions/github</code> and GitHub matching refs to load only tags for the resolved release date, reducing API requests in repositories with many tags.</li>
<li>Change <code>previous-version</code> to report the latest matching version for the resolved date only.</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/okaryo/calver/compare/v1.0.0...v1.1.0">https://github.com/okaryo/calver/compare/v1.0.0...v1.1.0</a></p>
]]></content:encoded></item><item><title>SkillTotal AI Component Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/skilltotal-ai-component-security-scan/</link><pubDate>Sun, 05 Jul 2026 06:22:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/skilltotal-ai-component-security-scan/</guid><description>Version updated for https://github.com/pezhik/skilltotal to version v0.29.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added skilltotal inventory --sbom — AI-BOM export. The installed-component inventory (every MCP server and skill your agent hosts reference) as a standard CycloneDX 1.6 JSON document, ready for Dependency-Track / compliance pipelines. Components carry a purl when the source is an npm:/pypi: spec and the SkillTotal scan verdict as skilltotal:* properties (host, kind, risk level/score, verdict). New pure module skilltotal.sbom. skilltotal scan --provenance — opt-in registry provenance signals. For npm: / pypi: sources: recently published (&amp;lt;30 days), deprecated (npm) / yanked (PyPI), no recent releases (&amp;gt;3 years), no repository link. Registry metadata is context about a component, not component content, so the component-only invariant holds: opt-in flag, fetched at the CLI layer (never inside the engine), and emitted only as needs_review — never findings, never the score, never the verdict. New pure module skilltotal.provenance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pezhik/skilltotal">https://github.com/pezhik/skilltotal</a></strong> to version <strong>v0.29.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skilltotal-ai-component-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong><code>skilltotal inventory --sbom</code> — AI-BOM export.</strong> The installed-component inventory
(every MCP server and skill your agent hosts reference) as a standard CycloneDX 1.6 JSON
document, ready for Dependency-Track / compliance pipelines. Components carry a <code>purl</code>
when the source is an <code>npm:</code>/<code>pypi:</code> spec and the SkillTotal scan verdict as
<code>skilltotal:*</code> properties (host, kind, risk level/score, verdict). New pure module
<code>skilltotal.sbom</code>.</li>
<li><strong><code>skilltotal scan --provenance</code> — opt-in registry provenance signals.</strong> For <code>npm:</code> /
<code>pypi:</code> sources: <em>recently published</em> (&lt;30 days), <em>deprecated</em> (npm) / <em>yanked</em> (PyPI),
<em>no recent releases</em> (&gt;3 years), <em>no repository link</em>. Registry metadata is context about
a component, not component content, so the component-only invariant holds: opt-in flag,
fetched at the CLI layer (never inside the engine), and emitted only as <code>needs_review</code> —
never findings, never the score, never the verdict. New pure module
<code>skilltotal.provenance</code>.</li>
</ul>
]]></content:encoded></item><item><title>PR Explainer AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/pr-explainer-ai/</link><pubDate>Sun, 05 Jul 2026 06:21:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/pr-explainer-ai/</guid><description>Version updated for https://github.com/rafaeltorresng/pr-explainer-action to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Patch release for PR Explainer AI.\n\n- Add a minimal success message to the PR comment\n- Keep the artifact and run link concise and readable\n- Preserve the existing v1.0.1 pipeline and compatibility fixes</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rafaeltorresng/pr-explainer-action">https://github.com/rafaeltorresng/pr-explainer-action</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pr-explainer-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Patch release for PR Explainer AI.\n\n- Add a minimal success message to the PR comment\n- Keep the artifact and run link concise and readable\n- Preserve the existing v1.0.1 pipeline and compatibility fixes</p>
]]></content:encoded></item><item><title>MaintainerOps AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/maintainerops-ai/</link><pubDate>Sun, 05 Jul 2026 06:20:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/maintainerops-ai/</guid><description>Version updated for https://github.com/rtonf/maintainerops-ai to version v0.1.13.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Summary Adds maintainerops demo, a no-key/no-token/no-fixture CLI path that prints a real offline review packet. Demo mode is forced offline and rejects live GitHub/model options. Updates README, Marketplace notes, and external feedback docs so testers can try a packet with one npm command. Records an API-free security diff review for the demo path. Verification node dist/cli.js demo --format markdown node dist/cli.js demo --format json node dist/cli.js demo --model gpt-4o-mini fails closed node dist/cli.js demo --repo owner/repo fails closed npm run format:check git diff --check npm run verify PR #79 checks passed post-merge CodeQL passed Safety The demo command does not require OPENAI_API_KEY, GITHUB_TOKEN, repository access, or local fixture files. It does not modify GitHub state.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rtonf/maintainerops-ai">https://github.com/rtonf/maintainerops-ai</a></strong> to version <strong>v0.1.13</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/maintainerops-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="summary">Summary</h2>
<ul>
<li>Adds <code>maintainerops demo</code>, a no-key/no-token/no-fixture CLI path that prints a real offline review packet.</li>
<li>Demo mode is forced offline and rejects live GitHub/model options.</li>
<li>Updates README, Marketplace notes, and external feedback docs so testers can try a packet with one npm command.</li>
<li>Records an API-free security diff review for the demo path.</li>
</ul>
<h2 id="verification">Verification</h2>
<ul>
<li><code>node dist/cli.js demo --format markdown</code></li>
<li><code>node dist/cli.js demo --format json</code></li>
<li><code>node dist/cli.js demo --model gpt-4o-mini</code> fails closed</li>
<li><code>node dist/cli.js demo --repo owner/repo</code> fails closed</li>
<li><code>npm run format:check</code></li>
<li><code>git diff --check</code></li>
<li><code>npm run verify</code></li>
<li>PR #79 checks passed</li>
<li>post-merge CodeQL passed</li>
</ul>
<h2 id="safety">Safety</h2>
<p>The demo command does not require <code>OPENAI_API_KEY</code>, <code>GITHUB_TOKEN</code>, repository access, or local fixture files. It does not modify GitHub state.</p>
]]></content:encoded></item><item><title>Setup Swamp</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/setup-swamp/</link><pubDate>Sun, 05 Jul 2026 06:20:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/setup-swamp/</guid><description>Version updated for https://github.com/systeminit/setup-swamp to version v0.1.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Hide the whoami information from the output</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/systeminit/setup-swamp">https://github.com/systeminit/setup-swamp</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-swamp">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Hide the whoami information from the output</p>
]]></content:encoded></item><item><title>overllm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/overllm/</link><pubDate>Sun, 05 Jul 2026 06:19:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/overllm/</guid><description>Version updated for https://github.com/theadamdanielsson/overllm to version v0.7.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Recall improvements + one new rule, each validated on ~14k files of real code (framework-heavy and amateur) with no new false positives.
Matured call detection — follow a model through composition. LangChain chain.invoke(...) and bound-model .invoke(...) are now detected (an LCEL | pipe, .with_structured_output(), or an alias that composes a known model). A prompt | parser chain (no model) or a dict | dict merge is not tracked — precise. langchain detection 385→492. kwargs-splat — create(**params) on the unambiguous chains. Embeddings — embeddings.create in a per-item loop → llm-in-loop. Module-constant prompts — a prompt/model held in a top-level constant used inside a function is resolved. New rule json-mode-missing-json — response_format=json_object with a static prompt lacking “json” is a provable OpenAI 400 (fires only when the absence is provable). 155 tests. Precision held: amateur-corpus findings byte-identical to 0.6.2.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/theadamdanielsson/overllm">https://github.com/theadamdanielsson/overllm</a></strong> to version <strong>v0.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/overllm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Recall improvements + one new rule, each validated on ~14k files of real code (framework-heavy and amateur) with no new false positives.</p>
<ul>
<li><strong>Matured call detection — follow a model through composition.</strong> LangChain <code>chain.invoke(...)</code> and bound-model <code>.invoke(...)</code> are now detected (an LCEL <code>|</code> pipe, <code>.with_structured_output()</code>, or an alias that composes a <em>known model</em>). A <code>prompt | parser</code> chain (no model) or a <code>dict | dict</code> merge is not tracked — precise. langchain detection 385→492.</li>
<li><strong>kwargs-splat</strong> — <code>create(**params)</code> on the unambiguous chains.</li>
<li><strong>Embeddings</strong> — <code>embeddings.create</code> in a per-item loop → <code>llm-in-loop</code>.</li>
<li><strong>Module-constant prompts</strong> — a prompt/model held in a top-level constant used inside a function is resolved.</li>
<li><strong>New rule <code>json-mode-missing-json</code></strong> — <code>response_format=json_object</code> with a static prompt lacking &ldquo;json&rdquo; is a provable OpenAI 400 (fires only when the absence is provable).</li>
</ul>
<p>155 tests. Precision held: amateur-corpus findings byte-identical to 0.6.2.</p>
]]></content:encoded></item><item><title>compose-lint</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/compose-lint/</link><pubDate>Sun, 05 Jul 2026 06:19:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/compose-lint/</guid><description>Version updated for https://github.com/tmatens/compose-lint to version v0.13.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added Validated profiles must declare immutable version tags. The profile ci-smoke gate (scripts/validate_profiles.py) now rejects a status: validated profile whose applies_to.tags includes a mutable rolling tag (latest, stable, edge, main, nightly, …): such a tag points to a different image over time, so a derivation done against it cannot be trusted to still apply to the image a consumer later pulls. Exploratory profiles are unaffected, and no existing catalog profile uses a mutable tag, so this guards against a future mistake without changing current data. Profile schema 1.3: app_tier_verified. An optional top-level block on a profile recording that the whole hardening was verified at the service level — the multi-container stack brought up with every dimension applied and a real service-level check passed — a stronger signal than the per-dimension workload, which exercises only one container. Fields: service, service_version, method, check, verified_date, result, and an optional over_hardening (applied + result) that proves the check catches a too-tight config (not a rubber stamp). Requires status: validated (schema) and result: pass (ci-smoke gate). Optional and additive — all 1.0–1.2 documents remain valid, and it never substitutes for the per-dimension validated_via evidence. ADR-017 §10. Fixed Profile-enrichment hints no longer collapse across services in text output. The fix-block dedup keyed on rule_id alone, so when two services were flagged by the same rule but enrichment gave them different image-specific guidance (e.g. postgres → cap_add: [CHOWN, DAC_OVERRIDE, SETGID, SETUID], caddy → cap_add: [NET_BIND_SERVICE]), the second service was rendered (see fix above) — pointing at the first service’s wrong-image recommendation. The dedup now keys on (rule_id, fix, references), so distinct hints each print in full while identical fixes still collapse. Changed Profile enrichment is now labeled experimental. The feature is already opt-in and off by default (profiles.enabled); this makes its provisional status explicit. When enrichment is active, compose-lint prints a one-line stderr reminder that fix recommendations are advisory, derived for a specific invocation, and not validated against your runtime — and the config docs mark the section experimental. No behavior change to the findings themselves. Clearer profile-enrichment caveat. The provenance tail not independently verified here is replaced with compose-lint can&amp;#39;t see your runtime, confirm it fits your setup — it names the actual limit (a static linter reads the compose text, not the running container, and can’t confirm the recommendation matches your invocation) rather than a vague disclaimer. Added Profile schema 1.2 (ADR-017 §9): an optional derivation.run_config block recording the invocation a minimum was derived under — user, command, entrypoint, network, pid, devices, security_opt, mounts, and env (keys only, never values). A derived minimum is only valid for its invocation (postgres run with user: set skips the root→user drop and needs none of the startup caps a default-invocation profile lists), so a consumer can diff a target service against it and downgrade to a hint on divergence. Emitted by csd’s drop-test producer, not hand-authored. Additive — all 1.0/1.1 documents remain valid. Opt-in profile enrichment (ADR-017). Set profiles.enabled: true and point profiles.path at a catalog of container-sec-derive (csd) profiles you trust; findings from CL-0006/0007/0002/0011/0016 then gain image-specific fix guidance — e.g. the observed minimum cap_add for that image. Enrichment is advisory and additive only (it never creates, drops, or reclassifies a finding) and the hint is attributed and marked unverified. Off by default. Per ADR-017 §7, compose-lint ships no catalog of its own — the catalog is a user-configured external source, so the linter neither grows nor endorses profile data. Profile contribution path (ADR-017): scripts/validate_profiles.py (the ci-smoke gate — schema, validated/exploratory invariants, and workload-hash verification), a profile-validate CI job that runs it on catalog changes, and a contributor guide (docs/profiles.md).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tmatens/compose-lint">https://github.com/tmatens/compose-lint</a></strong> to version <strong>v0.13.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/compose-lint">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>Validated profiles must declare immutable version tags.</strong> The profile ci-smoke
gate (<code>scripts/validate_profiles.py</code>) now rejects a <code>status: validated</code> profile
whose <code>applies_to.tags</code> includes a mutable rolling tag (<code>latest</code>, <code>stable</code>,
<code>edge</code>, <code>main</code>, <code>nightly</code>, …): such a tag points to a different image over time,
so a derivation done against it cannot be trusted to still apply to the image a
consumer later pulls. Exploratory profiles are unaffected, and no existing catalog
profile uses a mutable tag, so this guards against a future mistake without
changing current data.</li>
<li><strong>Profile schema 1.3: <code>app_tier_verified</code>.</strong> An optional top-level block on a
profile recording that the whole hardening was verified at the <strong>service</strong> level
— the multi-container stack brought up with every dimension applied and a real
service-level check passed — a stronger signal than the per-dimension workload,
which exercises only one container. Fields: <code>service</code>, <code>service_version</code>,
<code>method</code>, <code>check</code>, <code>verified_date</code>, <code>result</code>, and an optional <code>over_hardening</code>
(<code>applied</code> + <code>result</code>) that proves the check catches a too-tight config (not a
rubber stamp). Requires <code>status: validated</code> (schema) and <code>result: pass</code>
(ci-smoke gate). Optional and additive — all 1.0–1.2 documents remain valid, and
it never substitutes for the per-dimension <code>validated_via</code> evidence. ADR-017 §10.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>Profile-enrichment hints no longer collapse across services in text output.</strong>
The fix-block dedup keyed on <code>rule_id</code> alone, so when two services were flagged
by the same rule but enrichment gave them <strong>different</strong> image-specific guidance
(e.g. postgres → <code>cap_add: [CHOWN, DAC_OVERRIDE, SETGID, SETUID]</code>, caddy →
<code>cap_add: [NET_BIND_SERVICE]</code>), the second service was rendered
<code>(see fix above)</code> — pointing at the <em>first</em> service&rsquo;s wrong-image recommendation.
The dedup now keys on <code>(rule_id, fix, references)</code>, so distinct hints each print
in full while identical fixes still collapse.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>Profile enrichment is now labeled experimental.</strong> The feature is already
opt-in and off by default (<code>profiles.enabled</code>); this makes its provisional
status explicit. When enrichment is active, compose-lint prints a one-line
stderr reminder that fix recommendations are advisory, derived for a specific
invocation, and not validated against your runtime — and the config docs mark
the section experimental. No behavior change to the findings themselves.</li>
<li><strong>Clearer profile-enrichment caveat.</strong> The provenance tail <code>not independently verified here</code> is replaced with <code>compose-lint can't see your runtime, confirm it fits your setup</code> — it names the actual limit (a static linter reads the
compose text, not the running container, and can&rsquo;t confirm the recommendation
matches your invocation) rather than a vague disclaimer.</li>
</ul>
<h3 id="added-1">Added</h3>
<ul>
<li>Profile schema <strong>1.2</strong> (ADR-017 §9): an optional <code>derivation.run_config</code> block
recording the invocation a minimum was derived under — <code>user</code>, <code>command</code>,
<code>entrypoint</code>, <code>network</code>, <code>pid</code>, <code>devices</code>, <code>security_opt</code>, <code>mounts</code>, and <code>env</code>
(keys only, never values). A derived minimum is only valid for its invocation
(postgres run with <code>user:</code> set skips the root→user drop and needs none of the
startup caps a default-invocation profile lists), so a consumer can diff a
target service against it and downgrade to a hint on divergence. Emitted by
csd&rsquo;s drop-test producer, not hand-authored. Additive — all 1.0/1.1 documents
remain valid.</li>
<li>Opt-in profile enrichment (ADR-017). Set <code>profiles.enabled: true</code> and point
<code>profiles.path</code> at a catalog of container-sec-derive (csd) profiles you trust;
findings from CL-0006/0007/0002/0011/0016 then gain image-specific fix guidance
— e.g. the observed minimum <code>cap_add</code> for that image. Enrichment is advisory
and additive only (it never creates, drops, or reclassifies a finding) and the
hint is attributed and marked unverified. Off by default. Per ADR-017 §7,
compose-lint ships <strong>no catalog of its own</strong> — the catalog is a user-configured
external source, so the linter neither grows nor endorses profile data.</li>
<li>Profile contribution path (ADR-017): <code>scripts/validate_profiles.py</code> (the
ci-smoke gate — schema, validated/exploratory invariants, and workload-hash
verification), a <code>profile-validate</code> CI job that runs it on catalog changes, and
a contributor guide (<code>docs/profiles.md</code>).</li>
</ul>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/vibgrate-scan/</link><pubDate>Sun, 05 Jul 2026 06:18:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/05/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.704.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Vibgrate CLI 2026.704.3 Released 2026-07-04
Routine maintenance update for the CLI.
What changed Changed Maintenance release with internal improvements and dependency updates. Benchmarks Two-arm benchmark of this release against 2026.704.1, interleaved on one runner against the pinned corpus (157 metrics compared).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.704.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20267043">Vibgrate CLI 2026.704.3</h1>
<p><em>Released 2026-07-04</em></p>
<p>Routine maintenance update for the CLI.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>Maintenance release with internal improvements and dependency updates.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.704.1, interleaved on one runner against the pinned corpus (157 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>18444 count</td>
          <td>18444 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>6946 count</td>
          <td>6946 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.97 ratio</td>
          <td>0.97 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>606.70 ms</td>
          <td>607.60 ms</td>
      </tr>
  </tbody>
</table>
<p>No regressions against the previous release.</p>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.704.3">https://vibgrate.com/changelog/cli/2026.704.3</a></p>
]]></content:encoded></item><item><title>Hwaro Deploy to Pages</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/hwaro-deploy-to-pages/</link><pubDate>Sat, 04 Jul 2026 22:01:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/hwaro-deploy-to-pages/</guid><description>Version updated for https://github.com/hahwul/hwaro to version v0.17.0.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v0.17.0 Added [outputs] config: extra per-page/section output formats (json, txt, xml, csv) from user templates/page.&amp;lt;fmt&amp;gt;.jinja / section.&amp;lt;fmt&amp;gt;.jinja, overridable per page via a front-matter outputs key (cascades), exposed as {{ alternate_output_tags }}, cache-aware under --cache Markdown render hooks: templates/hooks/render-{link,image,heading,codeblock}.html override element rendering (Hugo/Zola-style), no-op when absent; existing @//shortcode/srcset/anchor resolvers still run. See Render Hooks Fenced code block options after the language ({linenos=true, hl_lines=&amp;#34;2-4 7&amp;#34;, linenostart=5}) plus [highlight] line_numbers; mode = &amp;#34;server&amp;#34; bakes the result at build time, mode = &amp;#34;client&amp;#34; emits data-* attributes Opt-in inline markup behind [markdown] flags (off by default): ins (++), mark (==), sub (~), sup (^) Generalized {#id .class key=val} attribute blocks on headings and inline images ([markdown] attributes) First-class menu system (Hugo-style): [[menus.&amp;lt;name&amp;gt;]], per-language overrides, front-matter registration; exposed via site.menus/get_menu() with an active_path filter; doctor validates undefined parents and menu names hwaro init --wizard and hwaro new (no &amp;lt;path&amp;gt;) open interactive terminal wizards; archetypes gain a {{ description }} placeholder Scaffold design tokens (“Hwaro Ember” :root with light-dark() pairs, fluid type/space scales) and a header theme switcher (auto → light → dark, persisted, flash-free) across every styled scaffold just scaffold-previews: regenerate docs scaffold screenshots headlessly Changed hwaro init initializes immediately with defaults; --wizard opens the interactive flow (removed -y/--yes) Terminal output: the remaining commands (list/stats/validate/check-links/deploy/export/import/unused-assets/convert/platform/agents-md) adopt the ember language and shared glyph set; machine surfaces (--json, serve ready line, --version, exit codes) are byte-for-byte unchanged Scaffold design pass across docs/blog/book (~1,600 lines of duplicated dark CSS deleted) Removed The blog-dark, docs-dark, and book-dark scaffolds — scaffolds follow the OS scheme and ship a manual switcher; pin one permanently with :root { color-scheme: dark; } in css/style.css Fixed macOS release binaries shipped as portable .tar.gz archives with bundled OpenSSL, dropping the hardcoded Homebrew openssl@3 dependency Shortcodes: Jinja control tags ({% if %}, {% set %}) in block bodies no longer desync the nesting scan; mixed positional + named args no longer drop the positional value PWA service worker: offline→root navigation fallback restored across all three cache strategies llms-full.txt honors in_search_index = false Internal @/ links with a query string or anchor no longer double-escape &amp;amp; hwaro serve: authors front-matter edits update the taxonomy incrementally; equal-weight sections keep a stable prev/next order --cache: deleting a page regenerates the sitemap/feeds/search index even when no surviving page re-rendered Parallel builds surface sitemap/feed/search failures instead of exiting 0; closed section-list and shortcode-init fiber-safety gaps under -Dpreview_mt AMP: &amp;lt;img&amp;gt; with &amp;gt; inside a quoted attribute value converts without corrupting the markup Performance Flat N-page sites avoid an O(N²) render cost — section-page arrays and SEO/OG/canonical/JSON-LD strings are built only when the template’s static closure can reach them Parallel render workers read prewarmed Crinja caches lock-free (-Dpreview_mt); taxonomy generation reuses the running Builder instead of a second O(N) Crinja pass Markdown skips footnote/definition-list passes when the markers are absent; builds no longer run the markdown pipeline twice (dropped the legacy hook pre-pass) JS minification is no longer O(n²) on non-ASCII files (128KB CJK bundle: 59.5s → 9.6ms); HTML minifier compiles protected-tag patterns once at startup --cache: touched-but-identical files re-hashed once, page-bundle assets no longer recopied, lock-free hit/miss counters; serve incremental rebuilds render the affected set in parallel 404 page reuses render-phase template vars; --stream builds per-worker engines once per run; load_data() memoized per file mtime Full Changelog: https://github.com/hahwul/hwaro/compare/v0.16.0...v0.17.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hahwul/hwaro">https://github.com/hahwul/hwaro</a></strong> to version <strong>v0.17.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hwaro-deploy-to-pages">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v0170">v0.17.0</h2>
<h3 id="added">Added</h3>
<ul>
<li><code>[outputs]</code> config: extra per-page/section output formats (<code>json</code>, <code>txt</code>, <code>xml</code>, <code>csv</code>) from user <code>templates/page.&lt;fmt&gt;.jinja</code> / <code>section.&lt;fmt&gt;.jinja</code>, overridable per page via a front-matter <code>outputs</code> key (cascades), exposed as <code>{{ alternate_output_tags }}</code>, cache-aware under <code>--cache</code></li>
<li>Markdown render hooks: <code>templates/hooks/render-{link,image,heading,codeblock}.html</code> override element rendering (Hugo/Zola-style), no-op when absent; existing <code>@/</code>/shortcode/<code>srcset</code>/anchor resolvers still run. See <a href="https://hwaro.hahwul.com/templates/render-hooks/">Render Hooks</a></li>
<li>Fenced code block options after the language (<code>{linenos=true, hl_lines=&quot;2-4 7&quot;, linenostart=5}</code>) plus <code>[highlight] line_numbers</code>; <code>mode = &quot;server&quot;</code> bakes the result at build time, <code>mode = &quot;client&quot;</code> emits <code>data-*</code> attributes</li>
<li>Opt-in inline markup behind <code>[markdown]</code> flags (off by default): <code>ins</code> (<code>++</code>), <code>mark</code> (<code>==</code>), <code>sub</code> (<code>~</code>), <code>sup</code> (<code>^</code>)</li>
<li>Generalized <code>{#id .class key=val}</code> attribute blocks on headings and inline images (<code>[markdown] attributes</code>)</li>
<li>First-class menu system (Hugo-style): <code>[[menus.&lt;name&gt;]]</code>, per-language overrides, front-matter registration; exposed via <code>site.menus</code>/<code>get_menu()</code> with an <code>active_path</code> filter; <code>doctor</code> validates undefined parents and menu names</li>
<li><code>hwaro init --wizard</code> and <code>hwaro new</code> (no <code>&lt;path&gt;</code>) open interactive terminal wizards; archetypes gain a <code>{{ description }}</code> placeholder</li>
<li>Scaffold design tokens (&ldquo;Hwaro Ember&rdquo; <code>:root</code> with <code>light-dark()</code> pairs, fluid type/space scales) and a header theme switcher (auto → light → dark, persisted, flash-free) across every styled scaffold</li>
<li><code>just scaffold-previews</code>: regenerate docs scaffold screenshots headlessly</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><code>hwaro init</code> initializes immediately with defaults; <code>--wizard</code> opens the interactive flow (removed <code>-y</code>/<code>--yes</code>)</li>
<li>Terminal output: the remaining commands (<code>list</code>/<code>stats</code>/<code>validate</code>/<code>check-links</code>/<code>deploy</code>/<code>export</code>/<code>import</code>/<code>unused-assets</code>/<code>convert</code>/<code>platform</code>/<code>agents-md</code>) adopt the ember language and shared glyph set; machine surfaces (<code>--json</code>, <code>serve</code> ready line, <code>--version</code>, exit codes) are byte-for-byte unchanged</li>
<li>Scaffold design pass across docs/blog/book (~1,600 lines of duplicated dark CSS deleted)</li>
</ul>
<h3 id="removed">Removed</h3>
<ul>
<li>The <code>blog-dark</code>, <code>docs-dark</code>, and <code>book-dark</code> scaffolds — scaffolds follow the OS scheme and ship a manual switcher; pin one permanently with <code>:root { color-scheme: dark; }</code> in <code>css/style.css</code></li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>macOS release binaries shipped as portable <code>.tar.gz</code> archives with bundled OpenSSL, dropping the hardcoded Homebrew <code>openssl@3</code> dependency</li>
<li>Shortcodes: Jinja control tags (<code>{% if %}</code>, <code>{% set %}</code>) in block bodies no longer desync the nesting scan; mixed positional + named args no longer drop the positional value</li>
<li>PWA service worker: offline→root navigation fallback restored across all three cache strategies</li>
<li><code>llms-full.txt</code> honors <code>in_search_index = false</code></li>
<li>Internal <code>@/</code> links with a query string or anchor no longer double-escape <code>&amp;</code></li>
<li><code>hwaro serve</code>: <code>authors</code> front-matter edits update the taxonomy incrementally; equal-weight sections keep a stable prev/next order</li>
<li><code>--cache</code>: deleting a page regenerates the sitemap/feeds/search index even when no surviving page re-rendered</li>
<li>Parallel builds surface sitemap/feed/search failures instead of exiting 0; closed section-list and shortcode-init fiber-safety gaps under <code>-Dpreview_mt</code></li>
<li>AMP: <code>&lt;img&gt;</code> with <code>&gt;</code> inside a quoted attribute value converts without corrupting the markup</li>
</ul>
<h3 id="performance">Performance</h3>
<ul>
<li>Flat N-page sites avoid an O(N²) render cost — section-page arrays and SEO/OG/canonical/JSON-LD strings are built only when the template&rsquo;s static closure can reach them</li>
<li>Parallel render workers read prewarmed Crinja caches lock-free (<code>-Dpreview_mt</code>); taxonomy generation reuses the running Builder instead of a second O(N) Crinja pass</li>
<li>Markdown skips footnote/definition-list passes when the markers are absent; builds no longer run the markdown pipeline twice (dropped the legacy hook pre-pass)</li>
<li>JS minification is no longer O(n²) on non-ASCII files (128KB CJK bundle: 59.5s → 9.6ms); HTML minifier compiles protected-tag patterns once at startup</li>
<li><code>--cache</code>: touched-but-identical files re-hashed once, page-bundle assets no longer recopied, lock-free hit/miss counters; <code>serve</code> incremental rebuilds render the affected set in parallel</li>
<li>404 page reuses render-phase template vars; <code>--stream</code> builds per-worker engines once per run; <code>load_data()</code> memoized per file mtime</li>
</ul>
<hr>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hahwul/hwaro/compare/v0.16.0...v0.17.0">https://github.com/hahwul/hwaro/compare/v0.16.0...v0.17.0</a></p>
]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/ai-plugin-scanner/</link><pubDate>Sat, 04 Jul 2026 22:01:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.380.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/90c7ce1e7c3346d7c1d85d79ff61f8fd56adad8b with plugin-scanner 2.0.980.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.379...v1.2.380</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.380</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>18</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/90c7ce1e7c3346d7c1d85d79ff61f8fd56adad8b">https://github.com/hashgraph-online/hol-guard/tree/90c7ce1e7c3346d7c1d85d79ff61f8fd56adad8b</a> with plugin-scanner 2.0.980.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.379...v1.2.380">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.379...v1.2.380</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/hol-codex-plugin-scanner/</link><pubDate>Sat, 04 Jul 2026 22:00:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.380.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.380</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.380</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.380">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.380</a></p>
]]></content:encoded></item><item><title>Holon Solve</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/holon-solve/</link><pubDate>Sat, 04 Jul 2026 22:00:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/holon-solve/</guid><description>Version updated for https://github.com/holon-run/holon to version v0.26.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Runtime line Holon v0.26.0 is part of the Rust runtime line. The Rust runtime is now the main holon binary.
This release introduces the Agent Template package and registry line: local and remote template sources, GitHub repository discovery, daemon sync and diagnostics APIs, web GUI template browsing, and template skill preinstallation. It also adds GitHub Actions-style skill uses shorthand, improves the web GUI skills/file experience, and fixes template/skill install edge cases plus several runtime and provider issues.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/holon-run/holon">https://github.com/holon-run/holon</a></strong> to version <strong>v0.26.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/holon-solve">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="runtime-line">Runtime line</h2>
<p>Holon v0.26.0 is part of the Rust runtime line. The Rust runtime is now the main <code>holon</code> binary.</p>
<p>This release introduces the Agent Template package and registry line: local and remote template sources, GitHub repository discovery, daemon sync and diagnostics APIs, web GUI template browsing, and template skill preinstallation. It also adds GitHub Actions-style skill <code>uses</code> shorthand, improves the web GUI skills/file experience, and fixes template/skill install edge cases plus several runtime and provider issues.</p>
<p>Supported binary assets for this release are Linux amd64, macOS amd64, and macOS arm64.</p>
<h2 id="changes">Changes</h2>
<ul>
<li>Implement the AgentTemplate package format, catalog/detail model, provenance events, GitHub repository discovery, and lifecycle daemon APIs (<a href="https://github.com/holon-run/holon/pull/1981">#1981</a>, <a href="https://github.com/holon-run/holon/pull/1982">#1982</a>, <a href="https://github.com/holon-run/holon/pull/1983">#1983</a>, <a href="https://github.com/holon-run/holon/pull/1984">#1984</a>, <a href="https://github.com/holon-run/holon/pull/1985">#1985</a>, <a href="https://github.com/holon-run/holon/pull/2086">#2086</a>, <a href="https://github.com/holon-run/holon/pull/2102">#2102</a>).</li>
<li>Add Agent Templates Web UI pages, Create Agent entry points, remote-source cache handling, and related navigation/file-viewer improvements (<a href="https://github.com/holon-run/holon/pull/2094">#2094</a>, <a href="https://github.com/holon-run/holon/pull/2105">#2105</a>, <a href="https://github.com/holon-run/holon/pull/2082">#2082</a>, <a href="https://github.com/holon-run/holon/pull/2090">#2090</a>, <a href="https://github.com/holon-run/holon/pull/2092">#2092</a>).</li>
<li>Preinstall skills for agent templates, split official templates from builtin fallback, remove user-facing builtin skills, resolve omitted template skill refs via HEAD, add skill <code>uses</code> shorthand, and make global skill install idempotent (<a href="https://github.com/holon-run/holon/pull/2100">#2100</a>, <a href="https://github.com/holon-run/holon/pull/2106">#2106</a>, <a href="https://github.com/holon-run/holon/pull/2107">#2107</a>, <a href="https://github.com/holon-run/holon/pull/2108">#2108</a>, <a href="https://github.com/holon-run/holon/pull/2109">#2109</a>, <a href="https://github.com/holon-run/holon/pull/2110">#2110</a>).</li>
<li>Derive template remote source IDs, fix template install/home-dir handling, authenticate GitHub template API requests, and use the source solve template in action builds (<a href="https://github.com/holon-run/holon/pull/2098">#2098</a>, <a href="https://github.com/holon-run/holon/pull/2101">#2101</a>, <a href="https://github.com/holon-run/holon/pull/2104">#2104</a>).</li>
<li>Retry transient OpenAI streaming server errors, make first-run intro runtime-owned, remove legacy message fallback, remove baseline_unfit turn-projection early exit, and correct Volcengine GLM catalog limits (<a href="https://github.com/holon-run/holon/pull/2093">#2093</a>, <a href="https://github.com/holon-run/holon/pull/2097">#2097</a>, <a href="https://github.com/holon-run/holon/pull/2091">#2091</a>, <a href="https://github.com/holon-run/holon/pull/2088">#2088</a>, <a href="https://github.com/holon-run/holon/pull/2096">#2096</a>).</li>
</ul>
<h2 id="install">Install</h2>
<p>Homebrew:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>brew tap holon-run/tap
</span></span><span style="display:flex;"><span>brew install holon
</span></span></code></pre></div><p>Direct binary:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -L <span style="color:#e6db74">&#34;https://github.com/holon-run/holon/releases/download/v0.26.0/holon-linux-amd64.tar.gz&#34;</span> | tar -xz
</span></span><span style="display:flex;"><span>chmod +x holon
</span></span><span style="display:flex;"><span>./holon --help
</span></span></code></pre></div><p>Replace <code>holon-linux-amd64.tar.gz</code> with <code>holon-darwin-amd64.tar.gz</code> or <code>holon-darwin-arm64.tar.gz</code> on macOS.</p>
]]></content:encoded></item><item><title>offsec-ai Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/offsec-ai-security-scanner/</link><pubDate>Sat, 04 Jul 2026 21:59:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/offsec-ai-security-scanner/</guid><description>Version updated for https://github.com/Htunn/offsec-ai to version v2.5.9.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed fix: define OUTPUT_ARGS before use; -o was silently dropped (v2.5.9) (889e688) chore: replace all example.com targets with simpleportchecker.com (676106d) fix: –format not -f for ai-owasp-scan; use simpleportchecker target (v2.5.8) (504b6e8) fix: skip –timeout for ai-owasp-scan which does not support it (v2.5.7) (67a28cd) chore: use Gemini public endpoint in ai-owasp-scan job (6a13857) fix: use case statement for format flag routing; no more grep substring match (v2.5.6) (1a8ac41) fix: per-command format flag; base64 report-json; bump to v2.5.5 (813d327) chore: update offsec-ai-action.yml to use v2.5.4 (c9ebc12) fix: switch action to GEMINI_API_KEY; remove secrets expression from action.yml (9bbe4cc) fix: pin offsec-ai-action.yml to v2.5.3 (secrets expression fix) (c4a71c5)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Htunn/offsec-ai">https://github.com/Htunn/offsec-ai</a></strong> to version <strong>v2.5.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/offsec-ai-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix: define OUTPUT_ARGS before use; -o was silently dropped (v2.5.9) (889e688)</li>
<li>chore: replace all example.com targets with simpleportchecker.com (676106d)</li>
<li>fix: &ndash;format not -f for ai-owasp-scan; use simpleportchecker target (v2.5.8) (504b6e8)</li>
<li>fix: skip &ndash;timeout for ai-owasp-scan which does not support it (v2.5.7) (67a28cd)</li>
<li>chore: use Gemini public endpoint in ai-owasp-scan job (6a13857)</li>
<li>fix: use case statement for format flag routing; no more grep substring match (v2.5.6) (1a8ac41)</li>
<li>fix: per-command format flag; base64 report-json; bump to v2.5.5 (813d327)</li>
<li>chore: update offsec-ai-action.yml to use v2.5.4 (c9ebc12)</li>
<li>fix: switch action to GEMINI_API_KEY; remove secrets expression from action.yml (9bbe4cc)</li>
<li>fix: pin offsec-ai-action.yml to v2.5.3 (secrets expression fix) (c4a71c5)</li>
</ul>
]]></content:encoded></item><item><title>cibuild-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/cibuild-action/</link><pubDate>Sat, 04 Jul 2026 21:59:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/cibuild-action/</guid><description>Version updated for https://github.com/invarnhq/cibuild to version v2.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v2.3.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/invarnhq/cibuild">https://github.com/invarnhq/cibuild</a></strong> to version <strong>v2.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cibuild-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release v2.3.0</p>
]]></content:encoded></item><item><title>Versionary Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/versionary-action/</link><pubDate>Sat, 04 Jul 2026 21:58:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/versionary-action/</guid><description>Version updated for https://github.com/jolars/versionary to version v0.32.0.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Features artifact-rules: support templated regex replacement (1bc89e5), closes #68 Bug Fixes pr: honor r-news format in single-package PR body (d8004c0) deps: bump vite to 8 and esbuild to 0.28.1 (b571e22)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jolars/versionary">https://github.com/jolars/versionary</a></strong> to version <strong>v0.32.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/versionary-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="features">Features</h3>
<ul>
<li><strong>artifact-rules:</strong> support templated regex replacement (<a href="https://github.com/jolars/versionary/commit/1bc89e5cbf2bf3e6135ae7f50c737a843217edc0"><code>1bc89e5</code></a>), closes <a href="https://github.com/jolars/versionary/issues/68">#68</a></li>
</ul>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>pr:</strong> honor r-news format in single-package PR body (<a href="https://github.com/jolars/versionary/commit/d8004c047d6099d2849b0a34bea4bcb94398106a"><code>d8004c0</code></a>)</li>
<li><strong>deps:</strong> bump vite to 8 and esbuild to 0.28.1 (<a href="https://github.com/jolars/versionary/commit/b571e2226e2afdf8ecc2f34836fd20e9166fec81"><code>b571e22</code></a>)</li>
</ul>
]]></content:encoded></item><item><title>Setup runner cli</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/setup-runner-cli/</link><pubDate>Sat, 04 Jul 2026 21:57:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/setup-runner-cli/</guid><description>Version updated for https://github.com/kjanat/runner to version v0.17.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added FQN task syntax: the root:&amp;lt;source&amp;gt;#&amp;lt;name&amp;gt; identity that doctor --json / why --json print for a task is now runnable — run &amp;#39;root:package.json#deno:importsmap&amp;#39; (the root: scope prefix is optional) dispatches that exact task. Every source label of every schema version round-trips, including v3’s cargo-alias, which previously named a task no syntax could invoke. runner why interprets its argument exactly like run does — qualified syntax (why deno:lint), FQN (why root:package.json#build), and the colon-name fallback below — so it explains the very dispatch run would perform instead of reporting “no candidates” for tokens run accepts. Makefile descriptions from the inline self-documenting form (build: deps ## Build the project), the idiom ## help targets are built on. The preceding-line ## doc form still wins when both are present. Changed A qualified or FQN miss (deno:nope, package.json#nope) is now a hard error in every path. Previously an FQN token fell through to the PM-exec fallback, where bunx/npx treated it as a package spec and resolved it off the network — a typo could hang on registry resolution or download an arbitrary package. Bare unmatched names still fall through; user/repo#ref package specs still work. Single runs and chain pre-validation (run -p/-s) report a qualified miss with one unified message, and miss errors add a note when a source’s task list failed to load (a broken package.json used to produce only a misleading did you mean …? hint). A CLI chain-failure flag now beats the opposite polarity from a lower layer: run -s a b -k with [chain] kill_on_fail = true in runner.toml keeps going instead of aborting with a cross-source conflict — the config polarity had no command-line escape hatch. Same-source conflicts (-k -K, both env vars, both config keys) still error. Boolean RUNNER_* env vars (RUNNER_QUIET, RUNNER_EXPLAIN, RUNNER_NO_WARNINGS, RUNNER_KEEP_GOING, RUNNER_KILL_ON_FAIL) warn and are ignored when set to an unrecognized token. RUNNER_KEEP_GOING=flase (typo’d “false”) used to silently read as truthy — the opposite of the intent. Recognized, case-insensitive: 1/true/yes/on and 0/false/no/off. Fixed package.json scripts whose names start with a source label (deno:importsmap, cargo:check, …) are reachable by their bare name again. The qualifier parser claimed the prefix (deno → deno.json), the qualified lookup missed, and dispatch fell through to PM-exec; an exact full-name match now wins on a qualified miss. A genuine deno.json task still outranks the colon-named script when both exist. Streaming parallel chains (run -p, the default outside GitHub Actions) no longer hang when a task exits but leaves a backgrounded descendant holding the inherited stdout/stderr pipe (some-daemon &amp;amp; exit 0). Pipe readers are now drained with the same bounded grace the grouped path already used, instead of an unbounded join that blocked until the descendant died. A try_wait error while polling a parallel chain no longer orphans the already-spawned sibling processes and their reader threads; both parallel paths route the error through the same kill-and-reap cleanup as a spawn failure. A malformed devEngines value in package.json (e.g. a Corepack-style string where the spec wants an object) no longer erases every script and the packageManager signal behind a false not valid JSON warning. The field degrades to “absent”; the rest of the manifest parses normally. The Taskfile fallback parser (used when the task binary is absent) is a real YAML parse now: quoted and namespaced task names (&amp;#34;build:prod&amp;#34;:) are no longer silently dropped, and a Taskfile that fails to parse surfaces a failed to read tasks warning instead of silently yielding zero tasks. A Makefile target whose header appears twice (legal in make) is listed once instead of twice; a later documented duplicate still contributes the description when the first occurrence had none. Full Changelog: https://github.com/kjanat/runner/compare/v0.16.1...v0.17.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kjanat/runner">https://github.com/kjanat/runner</a></strong> to version <strong>v0.17.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-runner-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li>FQN task syntax: the <code>root:&lt;source&gt;#&lt;name&gt;</code> identity that <code>doctor --json</code> /
<code>why --json</code> print for a task is now runnable —
<code>run 'root:package.json#deno:importsmap'</code> (the <code>root:</code> scope prefix is
optional) dispatches that exact task. Every source label of every schema
version round-trips, including v3&rsquo;s <code>cargo-alias</code>, which previously named a
task no syntax could invoke.</li>
<li><code>runner why</code> interprets its argument exactly like <code>run</code> does — qualified
syntax (<code>why deno:lint</code>), FQN (<code>why root:package.json#build</code>), and the
colon-name fallback below — so it explains the very dispatch <code>run</code> would
perform instead of reporting &ldquo;no candidates&rdquo; for tokens <code>run</code> accepts.</li>
<li>Makefile descriptions from the inline self-documenting form
(<code>build: deps ## Build the project</code>), the idiom <code>##</code> help targets are built
on. The preceding-line <code>## doc</code> form still wins when both are present.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>A qualified or FQN miss (<code>deno:nope</code>, <code>package.json#nope</code>) is now a hard
error in every path. Previously an FQN token fell through to the PM-exec
fallback, where bunx/npx treated it as a package spec and resolved it off
the network — a typo could hang on registry resolution or download an
arbitrary package. Bare unmatched names still fall through; <code>user/repo#ref</code>
package specs still work.</li>
<li>Single runs and chain pre-validation (<code>run -p</code>/<code>-s</code>) report a qualified
miss with one unified message, and miss errors add a note when a source&rsquo;s
task list failed to load (a broken <code>package.json</code> used to produce only a
misleading <code>did you mean …?</code> hint).</li>
<li>A CLI chain-failure flag now beats the opposite polarity from a lower
layer: <code>run -s a b -k</code> with <code>[chain] kill_on_fail = true</code> in <code>runner.toml</code>
keeps going instead of aborting with a cross-source conflict — the config
polarity had no command-line escape hatch. Same-source conflicts
(<code>-k -K</code>, both env vars, both config keys) still error.</li>
<li>Boolean <code>RUNNER_*</code> env vars (<code>RUNNER_QUIET</code>, <code>RUNNER_EXPLAIN</code>,
<code>RUNNER_NO_WARNINGS</code>, <code>RUNNER_KEEP_GOING</code>, <code>RUNNER_KILL_ON_FAIL</code>) warn and
are ignored when set to an unrecognized token. <code>RUNNER_KEEP_GOING=flase</code>
(typo&rsquo;d &ldquo;false&rdquo;) used to silently read as truthy — the opposite of the
intent. Recognized, case-insensitive: <code>1</code>/<code>true</code>/<code>yes</code>/<code>on</code> and
<code>0</code>/<code>false</code>/<code>no</code>/<code>off</code>.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><code>package.json</code> scripts whose names start with a source label
(<code>deno:importsmap</code>, <code>cargo:check</code>, …) are reachable by their bare name
again. The qualifier parser claimed the prefix (<code>deno</code> → deno.json), the
qualified lookup missed, and dispatch fell through to PM-exec; an exact
full-name match now wins on a qualified miss. A genuine <code>deno.json</code> task
still outranks the colon-named script when both exist.</li>
<li>Streaming parallel chains (<code>run -p</code>, the default outside GitHub Actions)
no longer hang when a task exits but leaves a backgrounded descendant
holding the inherited stdout/stderr pipe (<code>some-daemon &amp; exit 0</code>). Pipe
readers are now drained with the same bounded grace the grouped path
already used, instead of an unbounded join that blocked until the
descendant died.</li>
<li>A <code>try_wait</code> error while polling a parallel chain no longer orphans the
already-spawned sibling processes and their reader threads; both parallel
paths route the error through the same kill-and-reap cleanup as a spawn
failure.</li>
<li>A malformed <code>devEngines</code> value in <code>package.json</code> (e.g. a Corepack-style
string where the spec wants an object) no longer erases every script and
the <code>packageManager</code> signal behind a false <code>not valid JSON</code> warning. The
field degrades to &ldquo;absent&rdquo;; the rest of the manifest parses normally.</li>
<li>The Taskfile fallback parser (used when the <code>task</code> binary is absent) is a
real YAML parse now: quoted and namespaced task names (<code>&quot;build:prod&quot;:</code>)
are no longer silently dropped, and a Taskfile that fails to parse
surfaces a <code>failed to read tasks</code> warning instead of silently yielding
zero tasks.</li>
<li>A Makefile target whose header appears twice (legal in make) is listed
once instead of twice; a later documented duplicate still contributes the
description when the first occurrence had none.</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/kjanat/runner/compare/v0.16.1...v0.17.0">https://github.com/kjanat/runner/compare/v0.16.1...v0.17.0</a></p>
]]></content:encoded></item><item><title>Quorum consensus security scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/quorum-consensus-security-scan/</link><pubDate>Sat, 04 Jul 2026 21:57:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/quorum-consensus-security-scan/</guid><description>Version updated for https://github.com/Martinez1991/quorum-sec-scan to version v0.8.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog 9146db25b4fd57deb4446de10bfd5909f25431c6: Merge pull request #68 from Martinez1991/feat/rag-semantic-index (@Martinez1991) 1eb7ebfec1ef184043bb47c189a90af66229d4e9: Merge pull request #69 from Martinez1991/feat/advice-metrics (@Martinez1991) edaa5707bb5fd5867f3a42526505875a9bb3ca8e: Merge pull request #70 from Martinez1991/feat/action-advice-cache (@Martinez1991) a54b996adf53910362ad3d915753c64e4f0db24d: Merge pull request #71 from Martinez1991/feat/knowledge-expand (@Martinez1991) a93090e9ffff9bb05a77233465f006cb13a25694: Merge pull request #72 from Martinez1991/feat/advisor-evals (@Martinez1991) a70c6cfcb83736adb8102a4d1f05edafd7b30ebf: Merge pull request #73 from Martinez1991/feat/attest-knowledge (@Martinez1991) 58936fe1b14e9f937a6fd9ac3e0ad462f4d9bfa1: feat(action): expose advice-cache for reproducible AI advice across CI runs (@Martinez1991) 931c74c009a9c5a5204da2199735f675954a2124: feat(release): attest the advisory knowledge pack (SLSA provenance) (@Martinez1991) a6e45860d6ca5800623e4c87416a834ec93b3e26: feat: Prometheus metrics for the advisory layer (observability) (@Martinez1991) 63b490cc396d7d0845955c5184a7e31e0ead8b8b: feat: advise-index — bake embeddings into the OWASP corpus (semantic RAG) (@Martinez1991) 497624cb934d9aa486858733890123b743f38436: feat: advisor eval harness (deterministic quality + verify-the-fix rate) (@Martinez1991) 97e6ab512cc8146470e29f56e877e9a581a85ea0: feat: expand the advisory knowledge pack (Azure/GCP templates + OWASP corpus) (@Martinez1991)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Martinez1991/quorum-sec-scan">https://github.com/Martinez1991/quorum-sec-scan</a></strong> to version <strong>v0.8.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/quorum-consensus-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>9146db25b4fd57deb4446de10bfd5909f25431c6: Merge pull request #68 from Martinez1991/feat/rag-semantic-index (@Martinez1991)</li>
<li>1eb7ebfec1ef184043bb47c189a90af66229d4e9: Merge pull request #69 from Martinez1991/feat/advice-metrics (@Martinez1991)</li>
<li>edaa5707bb5fd5867f3a42526505875a9bb3ca8e: Merge pull request #70 from Martinez1991/feat/action-advice-cache (@Martinez1991)</li>
<li>a54b996adf53910362ad3d915753c64e4f0db24d: Merge pull request #71 from Martinez1991/feat/knowledge-expand (@Martinez1991)</li>
<li>a93090e9ffff9bb05a77233465f006cb13a25694: Merge pull request #72 from Martinez1991/feat/advisor-evals (@Martinez1991)</li>
<li>a70c6cfcb83736adb8102a4d1f05edafd7b30ebf: Merge pull request #73 from Martinez1991/feat/attest-knowledge (@Martinez1991)</li>
<li>58936fe1b14e9f937a6fd9ac3e0ad462f4d9bfa1: feat(action): expose advice-cache for reproducible AI advice across CI runs (@Martinez1991)</li>
<li>931c74c009a9c5a5204da2199735f675954a2124: feat(release): attest the advisory knowledge pack (SLSA provenance) (@Martinez1991)</li>
<li>a6e45860d6ca5800623e4c87416a834ec93b3e26: feat: Prometheus metrics for the advisory layer (observability) (@Martinez1991)</li>
<li>63b490cc396d7d0845955c5184a7e31e0ead8b8b: feat: advise-index — bake embeddings into the OWASP corpus (semantic RAG) (@Martinez1991)</li>
<li>497624cb934d9aa486858733890123b743f38436: feat: advisor eval harness (deterministic quality + verify-the-fix rate) (@Martinez1991)</li>
<li>97e6ab512cc8146470e29f56e877e9a581a85ea0: feat: expand the advisory knowledge pack (Azure/GCP templates + OWASP corpus) (@Martinez1991)</li>
</ul>
]]></content:encoded></item><item><title>invAIriant audit gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/invairiant-audit-gate/</link><pubDate>Sat, 04 Jul 2026 21:56:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/invairiant-audit-gate/</guid><description>Version updated for https://github.com/mindicator/invAIriant to version v0.2.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixes the two public front doors and enables the first automated PyPI publish.
PyPI page invairiant 0.2.3’s project page was immutable with the old pip install -e . text (the readme was fixed just after that release). 0.2.4 lands the corrected page: the CLI readme (the package’s long_description) leads with pip install invairiant and uses absolute GitHub links so they resolve on pypi.org.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mindicator/invAIriant">https://github.com/mindicator/invAIriant</a></strong> to version <strong>v0.2.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/invairiant-audit-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Fixes the two public front doors and enables the first automated PyPI publish.</p>
<h2 id="pypi-page">PyPI page</h2>
<p><code>invairiant</code> 0.2.3&rsquo;s project page was immutable with the old <code>pip install -e .</code> text (the readme was fixed just after that release). 0.2.4 lands the corrected page: the CLI readme (the package&rsquo;s long_description) leads with <strong><code>pip install invairiant</code></strong> and uses absolute GitHub links so they resolve on pypi.org.</p>
<h2 id="github-marketplace-eligibility">GitHub Marketplace eligibility</h2>
<p><code>action.yml</code>&rsquo;s description was 141 chars; the Marketplace limit is 125. Trimmed to 104 without losing meaning (validate → render to the job summary → gate on open S0/S1). Name/icon/color already passed — the Action can now be listed (pick a category on the release edit page).</p>
<h2 id="automated-publishing">Automated publishing</h2>
<p>This is the <strong>first release published to PyPI automatically</strong> over GitHub Trusted Publishing (OIDC, no stored token) via <a href=".github/workflows/publish.yml"><code>publish.yml</code></a> — cutting the release fired it. Guide: <a href="docs/publishing.md"><code>docs/publishing.md</code></a>.</p>
<hr>
<p>No new lenses, and <strong>no code change to the CLI</strong> — the packaged module and bundled framework are byte-identical to v0.2.3 (verified). Released only after CI went green on the tag (enforced by the local pre-push gate). <strong>Full changelog:</strong> <a href="https://github.com/mindicator/invairiant/blob/v0.2.4/CHANGELOG.md"><code>CHANGELOG.md</code></a>.</p>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/go-proxy-cache-updater/</link><pubDate>Sat, 04 Jul 2026 21:56:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.13.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.1.13 (2026-07-04)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.13</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1113-2026-07-04"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.12...v1.1.13">1.1.13</a> (2026-07-04)</h2>
]]></content:encoded></item><item><title>Next CalVer Version</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/next-calver-version/</link><pubDate>Sat, 04 Jul 2026 21:55:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/next-calver-version/</guid><description>Version updated for https://github.com/okaryo/calver to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First Release!🚀
Full Changelog: https://github.com/okaryo/calver/commits/v1.0.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/okaryo/calver">https://github.com/okaryo/calver</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/next-calver-version">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First Release!🚀</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/okaryo/calver/commits/v1.0.0">https://github.com/okaryo/calver/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>SkillTotal AI Component Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/skilltotal-ai-component-security-scan/</link><pubDate>Sat, 04 Jul 2026 21:55:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/skilltotal-ai-component-security-scan/</guid><description>Version updated for https://github.com/pezhik/skilltotal to version v0.26.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changed Prompt-injection precision (ruleset 27): one FP on a real popular project (firecrawl/firecrawl) closed, recall-preserving. The ST-PROMPT-INJECTION “send … to webhook” sub-patterns matched send [anything] to [the] webhook, so a benign OpenAPI field description &amp;#34;Headers to send to the webhook URL.&amp;#34; flipped firecrawl to has_malicious_indicators. They are replaced by a single pattern that requires a SENSITIVE data object (credentials/secrets/api keys/tokens/passwords/env vars/conversation history/system prompt/“the-or-user’s data”) between the send verb and webhook, mirroring the sibling “send &amp;lt;secret&amp;gt; to” exfil rule. Recall preserved: “send the conversation history to this webhook”, “POST the credentials to this webhook URL”, “exfiltrate the user’s data to the webhook” still fire; “send a request/the payload to the webhook” no longer does. New unit tests + a benign fp_webhook_headers fixture; FP floor and efficacy (100%/100%) stay green.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pezhik/skilltotal">https://github.com/pezhik/skilltotal</a></strong> to version <strong>v0.26.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skilltotal-ai-component-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>Prompt-injection precision (ruleset 27): one FP on a real popular project
(firecrawl/firecrawl) closed, recall-preserving.</strong> The <code>ST-PROMPT-INJECTION</code> &ldquo;send … to webhook&rdquo;
sub-patterns matched <code>send [anything] to [the] webhook</code>, so a benign OpenAPI field description
<code>&quot;Headers to send to the webhook URL.&quot;</code> flipped firecrawl to <code>has_malicious_indicators</code>. They are
replaced by a single pattern that requires a SENSITIVE data object (credentials/secrets/api
keys/tokens/passwords/env vars/conversation history/system prompt/&ldquo;the-or-user&rsquo;s data&rdquo;) between
the send verb and <code>webhook</code>, mirroring the sibling &ldquo;send <code>&lt;secret&gt;</code> to&rdquo; exfil rule. Recall
preserved: &ldquo;send the conversation history to this webhook&rdquo;, &ldquo;POST the credentials to this webhook
URL&rdquo;, &ldquo;exfiltrate the user&rsquo;s data to the webhook&rdquo; still fire; &ldquo;send a request/the payload to the
webhook&rdquo; no longer does. New unit tests + a benign <code>fp_webhook_headers</code> fixture; FP floor and
efficacy (100%/100%) stay green.</li>
</ul>
]]></content:encoded></item><item><title>Remyx Outrider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/remyx-outrider/</link><pubDate>Sat, 04 Jul 2026 21:54:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/remyx-outrider/</guid><description>Version updated for https://github.com/remyxai/outrider to version v1.7.10.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Reorders the two attribution gates in _retry_license_via_arxiv_html so the stronger evidence (README references the paper’s arxiv id or ≥2 title words) runs first, with title-overlap demoted to a tie-breaker among survivors. Fixes silent license_class=no-code-link classifications on acronym-named repos whose acronym isn’t literally in the paper title.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remyxai/outrider">https://github.com/remyxai/outrider</a></strong> to version <strong>v1.7.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/remyx-outrider">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Reorders the two attribution gates in <code>_retry_license_via_arxiv_html</code> so the stronger evidence (README references the paper&rsquo;s arxiv id or ≥2 title words) runs first, with title-overlap demoted to a tie-breaker among survivors. Fixes silent <code>license_class=no-code-link</code> classifications on acronym-named repos whose acronym isn&rsquo;t literally in the paper title.</p>
<p><strong>Concrete regression case:</strong> <a href="https://github.com/smellslikeml/trl/issues/6">smellslikeml/trl#6</a> — arXiv:2607.02490 (VRRL) resolved to <code>no-code-link</code> despite <a href="https://github.com/fc2869/VRRL">fc2869/VRRL</a> being the paper&rsquo;s own Apache-2.0 repo, discoverable via the arxiv HTML surface.</p>
]]></content:encoded></item><item><title>codemetrics complexity gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/codemetrics-complexity-gate/</link><pubDate>Sat, 04 Jul 2026 21:53:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/codemetrics-complexity-gate/</guid><description>Version updated for https://github.com/richardwooding/codemetrics to version v0.11.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog Features c3734720572df8dba08deeca4dda37adecdf4e70: feat(cli): real colorized output — honors NO_COLOR, TTY, and –color (#18) (@richardwooding) Others ee913ecf0e9f550f0c21d830fabc0067671be3de: ci(pages): self-enable Pages so the deploy can’t fail on a fresh repo (#17) (@richardwooding) e2bfa55d72e6af97d657c8247f22024eb01cebfb: docs(site): GitHub Pages marketing landing page (#16) (@richardwooding)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/richardwooding/codemetrics">https://github.com/richardwooding/codemetrics</a></strong> to version <strong>v0.11.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/codemetrics-complexity-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<h3 id="features">Features</h3>
<ul>
<li>c3734720572df8dba08deeca4dda37adecdf4e70: feat(cli): real colorized output — honors NO_COLOR, TTY, and &ndash;color (#18) (@richardwooding)</li>
</ul>
<h3 id="others">Others</h3>
<ul>
<li>ee913ecf0e9f550f0c21d830fabc0067671be3de: ci(pages): self-enable Pages so the deploy can&rsquo;t fail on a fresh repo (#17) (@richardwooding)</li>
<li>e2bfa55d72e6af97d657c8247f22024eb01cebfb: docs(site): GitHub Pages marketing landing page (#16) (@richardwooding)</li>
</ul>
]]></content:encoded></item><item><title>MaintainerOps AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/maintainerops-ai/</link><pubDate>Sat, 04 Jul 2026 21:52:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/maintainerops-ai/</guid><description>Version updated for https://github.com/rtonf/maintainerops-ai to version v0.1.12.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed MaintainerOps AI v0.1.12 expands model-backed eval readiness and records the first passing 10-case live eval run.
Highlights:
Added a dedicated 10-case model-backed eval file. Added smoke / expanded / all suites plus targeted –case execution. Added –cases-file, –summary-json, and API-free npm run eval:model:list. Added stricter recommended-action and risk-bound checks. Improved normalization for dependency updates, license metadata issues, and direct security-boundary findings. Recorded the approved 10-case live model-backed eval result. Live eval evidence:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rtonf/maintainerops-ai">https://github.com/rtonf/maintainerops-ai</a></strong> to version <strong>v0.1.12</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/maintainerops-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>MaintainerOps AI v0.1.12 expands model-backed eval readiness and records the first passing 10-case live eval run.</p>
<p>Highlights:</p>
<ul>
<li>Added a dedicated 10-case model-backed eval file.</li>
<li>Added smoke / expanded / all suites plus targeted &ndash;case execution.</li>
<li>Added &ndash;cases-file, &ndash;summary-json, and API-free npm run eval:model:list.</li>
<li>Added stricter recommended-action and risk-bound checks.</li>
<li>Improved normalization for dependency updates, license metadata issues, and direct security-boundary findings.</li>
<li>Recorded the approved 10-case live model-backed eval result.</li>
</ul>
<p>Live eval evidence:</p>
<ul>
<li>Command: npm run eval:model &ndash; &ndash;suite all &ndash;budget-usd 0.5 &ndash;max-cases 10 &ndash;max-output-tokens 1200 &ndash;summary-json</li>
<li>Result: passed 10 cases.</li>
<li>Model: gpt-4o-mini.</li>
<li>Successful-run estimated cost: $0.001724.</li>
<li>Cumulative estimate across failed/adjusted/passing runs: $0.005114.</li>
<li>Approved ceiling: $0.50.</li>
</ul>
<p>Guardrails remain unchanged: live model-backed evals are manual-only, not part of CI, and MaintainerOps AI does not auto-merge, auto-close, auto-label, publish releases, or scan unauthorized repositories.</p>
]]></content:encoded></item><item><title>skill-switch audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/skill-switch-audit/</link><pubDate>Sat, 04 Jul 2026 21:52:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/skill-switch-audit/</guid><description>Version updated for https://github.com/rtwsvj/skill-switch to version v0.9.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 安装 / Install macOS(Apple Silicon)桌面 App:下载下方 skill-switch_0.9.0_aarch64.dmg(29M,Developer ID 签名 + Apple 公证),拖进「应用程序」即可。
SHA-256: d415f3b1346de71c57b1e537e3da961c9cc9d19d375f743af7bc15e1adc7c0fd CLI:npx @rtwsvj/skill-switch audit
[0.9.0] - 2026-07-01 自 v0.6.0(npm 上最后一个已发布版本)以来累积的所有内容一次发布:含原 0.7 / 0.8 批次 + 第三波(RE2/shadcn/bun)+ 第四波「集众家之所长」+ SkillsMP 源 + GUI 各屏 shadcn 迁移。</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rtwsvj/skill-switch">https://github.com/rtwsvj/skill-switch</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skill-switch-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="安装--install">安装 / Install</h2>
<p><strong>macOS(Apple Silicon)桌面 App</strong>:下载下方 <code>skill-switch_0.9.0_aarch64.dmg</code>(29M,Developer ID 签名 + Apple 公证),拖进「应用程序」即可。</p>
<ul>
<li>SHA-256: <code>d415f3b1346de71c57b1e537e3da961c9cc9d19d375f743af7bc15e1adc7c0fd</code></li>
</ul>
<p><strong>CLI</strong>:<code>npx @rtwsvj/skill-switch audit</code></p>
<hr>
<h2 id="090---2026-07-01">[0.9.0] - 2026-07-01</h2>
<blockquote>
<p>自 v0.6.0(npm 上最后一个已发布版本)以来累积的所有内容一次发布:含原 0.7 / 0.8 批次 + 第三波(RE2/shadcn/bun)+ 第四波「集众家之所长」+ SkillsMP 源 + GUI 各屏 shadcn 迁移。</p>
<p>本轮:11 路并行的「开源对标」实现(见 <a href="docs/oss-comparison.md">docs/oss-comparison.md</a>)。第二波再上 5 项获批新依赖(下方「质量&amp;GUI 增强」)。第三波全部落地:RE2 线性正则引擎、GUI shadcn 重设计基建、bun compile 并列打包路径。第四波「集众家之所长」(见 <a href="docs/best-of-breed-plan.md">docs/best-of-breed-plan.md</a>):安全深度(二进制魔数伪装 / taint 数据流 / 跨-skill 协同 / OWASP Agentic+ATLAS 映射)+ apm.yml 互操作 + GUI Markdown 渲染 + registry 注册表只读接入(见 <a href="docs/registry-integration-plan.md">docs/registry-integration-plan.md</a>);全部自研重写、零复制竞品代码。</p>
</blockquote>
<h3 id="新增-added">新增 Added</h3>
<ul>
<li><strong>二进制魔数伪装检测(第四波·安全深度)</strong>:<code>masquerade/binary-magic-bytes</code>(critical)+ <code>masquerade/binary-lossy-head</code>(high)——识别声明为文本却以 PE/ELF/Mach-O/PDF/ZIP/JAR/gzip/7z/RAR/Wasm 等可执行/归档魔数开头的伪装文件;只看文件起始,正文提及魔数名不误报。魔数表从公开格式规范自写。</li>
<li><strong>taint 数据流多步攻击链(第四波·安全深度)</strong>:<code>exfiltration/taint-source-to-sink</code>(high)——单文件内识别&quot;读敏感源(环境变量/凭据文件/历史/浏览器·钱包数据)→ 近距离外发(curl 上传/nc//dev/tcp/外渗端点/base64 管道/scp 等)&ldquo;的跨行数据外渗链;仅命令上下文计数,散文零误报。</li>
<li><strong>跨-skill 协同攻击检测(第四波·安全深度)</strong>:<code>analyzeCrossSkillCollusion</code>——识别多个 skill 经共享 dropzone 路径 / 共享外部端点(high)或全局配置蔓延(medium)联合构成的凭据外泄与提权链;需具体共享线索、能力横跨两个 skill 才报,重精确低误报;接入 audit home 全格式输出与退出码,补齐已有跨-MCP-server 检测。</li>
<li><strong>OWASP Agentic Top10 + MITRE ATLAS 映射(第四波·安全深度)</strong>:规则类目新增 MITRE ATLAS 技法(<code>atlas:AML.Txxxx</code>)与 OWASP Agentic Top10(<code>owasp-agentic:Txx</code>)标签,additive 并入 SARIF rule properties.tags,与既有 OWASP LLM 标签并存;不影响 severity 或阻断逻辑。</li>
<li><strong><code>apm-import &lt;apm.yml&gt;</code> — 与 microsoft/apm 互操作(第四波,只读)</strong>:默认 dry-run 预览将纳管的 skill,<code>--apply</code> 才写入声明;只挑 skill 类原语映射到 skill-switch 治理模型,明确跳过 prompts/agents/hooks 等非 skill 原语。绝不执行 apm.yml 中的命令/脚本、绝不联网,纯本地文件解析。定位:互操作而非硬刚,做 APM 生态里&quot;最强安全+治理&quot;那一环。</li>
<li><strong>GUI 技能描述 Markdown 安全渲染(第四波)</strong>:技能详情的描述用 <code>react-markdown</code> + <code>rehype-sanitize</code>(默认 schema、禁 raw HTML、外链 <code>noopener</code>)渲染为富文本,杜绝描述内 XSS/钓鱼链接;样式走设计系统 token、明暗自适应。</li>
<li><strong><code>registry</code> 命令 — 注册表只读接入(第四波·C 线)</strong>:从官方 <strong>MCP Registry</strong>(<code>registry.modelcontextprotocol.io</code>)、GitHub <code>marketplace.json</code> 市场、<strong>SkillsMP</strong>(可选)<strong>只读搜索</strong>(<code>registry search</code>)并<strong>经安全审计后安装</strong>(<code>registry install</code>)skill / MCP server。纯 opt-in(仅运行该命令才联网)、仅 HTTPS、零遥测(<code>credentials:'omit'</code>、不带指纹)、零新依赖(Node 内置 fetch)、限时限大小;安装复用既有「解析→克隆→审计→拦截」管线,DANGER 默认拦截需 <code>--force</code> 留痕放行,绝不执行远端内容。SkillsMP 是唯一需鉴权的源:严格 opt-in + 用户自带 <code>SKILLSMP_TOKEN</code> 环境变量,token 只发往 skillsmp.com、只进请求头(不进 URL/日志)、skill-switch 绝不存储;未设 token 则该源自动跳过。不抓无公开 API 的聚合站 HTML。</li>
</ul>
<h3 id="变更-changed">变更 Changed</h3>
<ul>
<li><strong>GUI 各屏迁移到 shadcn 设计系统</strong>:继 W4 基建后,「安全」(审计 + 配置安全)、「历史/撤销」、「使用」统计、「安装维护 + 一键装」各屏全部从手写 CSS 迁到 shadcn(Card/Table/Badge/Button/Input + 设计 token),卡片化、语义色 Badge(good/warn/danger)、明暗主题自适应,与总览统一;数据流 / props / 安全文案 / 无障碍语义(toast a11y)一律不变,四语言 i18n 齐全。</li>
<li><strong>测试稳定性</strong>:全局 <code>testTimeout</code> 提到 30s——大量 CLI 集成测试每例 spawn tsx 冷启动子进程,满负载并发下曾偶发 5s 超时误红(隔离重跑皆过);w3-re2 病态输入墙钟预算 50ms→500ms(吸收 GC/JIT 抖动,真 ReDoS 秒级仍判失败)。</li>
<li><strong>审计引擎 → RE2 线性正则(第三波)</strong>:<code>compileMatcher</code> 用 RE2(线性时间、无回溯)匹配审计规则,从根上消除 ReDoS;<code>prompt-injection/zero-width-chars</code> 去 lookbehind/lookahead、<code>base64-payload</code> rm-rf 去 lookahead(均附 <code>test()</code> 语义等价证明,findings 不变);4 条 <code>{0,2048}</code> 超量词规则回退原生 RegExp + 行截断保护;编译结果 WeakMap 缓存。corpus/评分/verdict 行为零改变。</li>
<li><strong>GUI 重设计基建(第三波)</strong>:引入 <code>shadcn/ui + Tailwind</code> 设计系统(Button/Card/Badge/Tabs/Dialog/Input/Select/Tooltip/Skeleton/Table)+ 明暗主题(跟随系统、localStorage 持久化、Header 一键切换)+ Overview 卡片化(指标卡 + lucide 图标 + 骨架占位);CSS 变量走 shadcn 标准 token + 语义色 <code>--good/--warn/--danger</code>;为后续各屏迁移提供设计系统契约。四语言 i18n 100%(新增主题切换/对话框关闭文案)。</li>
<li><strong>bun compile 并列打包路径(第三波,实验性)</strong>:新增 <code>gui/scripts/bundle-cli-bun.mjs</code>(<code>pnpm bundle:cli:bun</code>),用 <code>bun build --compile</code> 产出单文件 CLI(产物命名/路径与现有 SEA 路径一致),wrapper 入口绕过 <code>node:sea</code> 禁区;实测冷启动 ~71ms vs tsx ~765ms(约 10x)。bun 为 devDependency(不随应用发),测试用 <code>it.skipIf(!bunAvailable)</code> 守卫(无 bun 环境不红);现有 <code>bundle:cli</code>(SEA)/<code>src/**</code>/Tauri sidecar 完全保留。</li>
<li><strong>质量门禁(第二波)</strong>:<code>recheck</code> ReDoS 静态守卫——遍历全部审计规则正则,写规则时即拦下会回溯灾难的 evil 正则(测试门禁,无需 eslint);<code>stryker</code> 变异测试配置(<code>pnpm mutate</code>,收敛到 audit engine/score,衡量测试有效性);<code>i18next-cli</code> GUI 漏译检测进 CI(<code>pnpm --dir gui i18n:check</code>,漏译即失败,当前四语言 100%)。</li>
<li><strong>GUI 数据层 → TanStack Query(第二波)</strong>:App 手写的 sections 加载状态机替换为 <code>@tanstack/react-query</code>(<code>staleTime</code> 5min / <code>retry</code> 1 / 不随窗口聚焦重取,贴合 Tauri 本地 IPC);写操作后精细 <code>invalidateQueries</code>(toggle/remove/install/sync 后不重跑 stats),取代全量刷新;DashboardShell 对外接口不变。</li>
<li><strong>GUI 自动更新(第二波)</strong>:接入 <code>tauri-plugin-updater</code> + <code>tauri-plugin-process</code>,<code>UpdateChecker</code> 横幅组件(有更新提示版本+一键更新+重启,非 Tauri 运行时优雅 no-op),四语言 <code>update.*</code> 文案;更新源指向 GitHub Releases 的 <code>latest.json</code>,发布前需 <code>tauri signer generate</code> 填真实 pubkey(已占位+注释)。</li>
<li><strong>审计引擎/SARIF 增强</strong>:SARIF result 加 <code>partialFingerprints</code>(GitHub code-scanning 跨 run 去重)+ <code>suppression.status=&quot;accepted&quot;</code> + rule <code>helpUri</code>;Unicode 同形字表 18 → <strong>140+</strong>(Cyrillic 全集 / 希腊 / 全角 / Latin lookalike);Markdown 围栏代码块内的 finding 加 <code>inCodeBlock</code> 标注(additive,不改 severity);SARIF rule 加 OWASP LLM Top10 标签。</li>
<li><strong>审计输出 &amp; CI 适配</strong>:<code>audit --format codeclimate</code>(GitLab Code Quality)、<code>--format rdjson</code>(reviewdog PR 内联)、<code>--diff-from &lt;commit&gt;</code>(只报 PR 改动文件的 finding)、<code>.skill-switch-ignore</code>(.gitignore 风格忽略);<code>ci --format codeclimate|rdjson</code> 生成对应工作流。</li>
<li><strong>MCP/配置安全</strong>:<code>mcp/tool-name-collision</code> 跨文件同名 server 影子化检测(2025 高危向量);密钥检测加 Shannon 熵 + 示例白名单降误报;Claude Desktop(<code>~/Library/Application Support/Claude/…</code> 等)路径纳入深扫。</li>
<li><strong>供应链 &amp; 漂移</strong>:<code>drift --osv</code>(opt-in,POST OSV.dev querybatch 查 skill 依赖的已知 CVE,默认关、仅 flag 时联网)、审批 <code>--criteria safe-to-run|safe-to-deploy</code> 分级、<code>drift --upstream-summary</code>(本地 git log 拼上游新增 commit 摘要)。</li>
<li><strong>套餐 &amp; 用法挖掘</strong>:共现分析加 <code>lift</code>/<code>confidence</code> 关联规则指标(过滤&quot;高频 skill 与谁都共现&quot;的假关联);transcript adapter 架构 + 内置 <strong>Codex CLI</strong> 解析器(<code>~/.codex/sessions/</code>);内置套餐改 readdir 自动发现。</li>
<li><strong>MCP server 深化</strong>:协议升级 <code>2025-06-18</code>;5 个只读工具加 <code>readOnlyHint</code> 注解(客户端可免确认弹窗);实现 <code>resources</code>(规则知识库 / 最近审计报告)、<code>prompts</code>(3 条审计模板)、audit 工具 <code>outputSchema</code>;新增 <code>server.json</code> + <code>package.json</code> <code>mcpName</code>(MCP Registry 上架)。</li>
<li><strong><code>completion</code> 命令 + CLI 分发</strong>:<code>skill-switch completion [bash|zsh|fish]</code> 输出 shell 自动补全;<code>--help</code> 用 Commander 原生 helpGroup 分组;新增 <code>release.yml</code>(tauri-action 跨平台构建 DMG/AppImage/deb/MSI)+ Homebrew Formula + Scoop manifest + <a href="docs/distribution.md">docs/distribution.md</a>。</li>
<li><strong>GUI 无障碍加固</strong>:撤销 toast 升为有名 landmark + 关闭后焦点恢复;技能列表行 <code>aria-current</code> + 键盘 Enter/Space 选中;写操作按钮带技能名 <code>aria-label</code>。</li>
<li><strong>质量门禁</strong>:CI 加 coverage 阈值门禁(保守下限,防倒退);audit/doctor/add 的 golden snapshot 扩面;零依赖安全自检(查自身 shell 注入/path traversal 等)。</li>
<li><strong>文档</strong>:<a href="docs/oss-comparison.md">docs/oss-comparison.md</a>(11 领域 × 开源对标的产品路线图,带来源 URL);<a href="docs/auditing-ai-agent-skills.md">docs/auditing-ai-agent-skills.md</a> 加「静态装前审计 ≠ 运行时防护」诚实定位节(指向 garak/mcp-scan 等互补工具)。</li>
<li><strong>GUI i18n 修复</strong>:数据层超时/取消/JSON 错误改结构化 <code>LocalizedCommandError</code>(英文兜底 + UI 按语言渲染),窗口标题 <code>skill-switch Governance</code> → <code>skill-switch</code>,英文/日/西模式不再泄漏中文。</li>
<li><strong><code>sync --out &lt;file&gt;</code> / <code>sync --plan &lt;file&gt;</code> — plan artifact 持久化(对标 Terraform plan -out)</strong>:<code>sync --out &lt;file&gt;</code> 把 planSync 结果 + 声明文件 sha256 摘要 + 时间戳序列化写盘;<code>sync --plan &lt;file&gt;</code> 读回后先校验声明 sha256 未变(变了则拒绝并提示重 plan),校验通过再执行——保证&quot;看到的 plan&quot;和&quot;实际执行的 plan&quot;完全一致。现有 <code>sync</code> / <code>sync --dry-run</code> 行为零改变。</li>
<li><strong><code>doctor --fix</code> — 漂移自修复(对标 chezmoi apply)</strong>:doctor 已产结构化 finding,<code>--fix</code> 按 kind 映射:<code>content-drift</code> → 从声明 source 重铺(copy/symlink);<code>extra-locked</code> → removeLockEntries 清孤儿锁条目;<code>missing</code>/<code>stale-lock</code> → 提示手动跑 sync/install。写操作前自动先快照受影响的 agent 目录。无 <code>--fix</code> 时只报告,行为不变。</li>
<li><strong><code>restore prune</code> — 快照生命周期清理(对标 Nix expire-generations)</strong>:<code>restore prune --keep-last &lt;N&gt;</code> 保留最近 N 个快照删除其余;<code>--older-than &lt;Nd&gt;</code> 删除 N 天前的快照;两者可组合;<code>--dry-run</code> 只列将删不执行。基于 listSnapshots 的 epochMs 排序,.tar.gz 与 .json sidecar 一并删除。</li>
<li><strong><code>import --apply</code> — 一条命令 bootstrap(对标 chezmoi init &ndash;apply)</strong>:import 后追加 <code>--apply</code> 即直接执行 applySync,快照 + 同步一气呵成;无 <code>--apply</code> 时行为不变,仍只写声明/锁文件并提示手动 sync。</li>
</ul>
]]></content:encoded></item><item><title>verified-bot-commit-rs</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/verified-bot-commit-rs/</link><pubDate>Sat, 04 Jul 2026 21:51:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/verified-bot-commit-rs/</guid><description>Version updated for https://github.com/siiway/verified_bot_commit to version v0.2.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/siiway/verified_bot_commit/compare/v0.1.1...v0.2.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/siiway/verified_bot_commit">https://github.com/siiway/verified_bot_commit</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/verified-bot-commit-rs">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/siiway/verified_bot_commit/compare/v0.1.1...v0.2.0">https://github.com/siiway/verified_bot_commit/compare/v0.1.1...v0.2.0</a></p>
]]></content:encoded></item><item><title>Muninn Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/muninn-security-scanner/</link><pubDate>Sat, 04 Jul 2026 21:51:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/muninn-security-scanner/</guid><description>Version updated for https://github.com/skaldlab/muninn to version v0.3.4.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog [0.3.4] - 2026-07-04 Changed Docker image scanner updates: osv-scanner 2.4.0, trivy 0.72.0, semgrep 1.168.0, zizmor 1.26.1 (checkov remains at 3.2.531 pending aiohttp cap lift). [0.3.3] - 2026-06-17 Changed Trivy default severity is now all levels (UNKNOWN through CRITICAL) instead of CRITICAL and HIGH only. osv-scanner and trivy now overlap on medium/low advisories by default so cross-scanner dedup and Detected by work without extra config. Consumers can narrow the Trivy scan with scanners.trivy.severity; fail-on still controls which findings fail the run. [0.3.2] - 2026-06-16 Fixed Suppressions with tool and/or rule-id are now applied. Previously only id (path substring) and fingerprint matchers worked; tool+rule-id entries parsed from muninn.yml but silently no-op’d. [0.3.1] - 2026-06-16 Fixed Poutine v1.x JSON parsing: findings from poutine 1.1.6+ (rule_id, meta, rules, blobshas) now populate title, rule, and file in PR comments instead of empty shells (File: :0, `Rule: ``) (#41). Actionlint PR comments: fall back to kind (e.g. expression) when rule.name is absent; omit empty Rule lines. Poutine injection findings: render injection_sources as formatted Sources instead of plain meta.details text. Changed PR comment layout: shared field helpers; non-dependency findings follow File → Rule → optional extras → description; single-scanner dependency findings use File instead of a redundant Source line. [0.3.0] - 2026-06-16 Added Cross-scanner deduplication by advisory id: findings that report the same CVE/GHSA for the same package from different scanners (e.g. OSV-Scanner from a lockfile and Trivy from a container layer) are now collapsed into a single finding. The contributing scanners are recorded in a new detected_by field (surfaced in the JSON report, the PR comment’s “Detected by” line, and a detectedBy SARIF result property). A CVE is preferred over GHSA so the same vulnerability converges on one id across scanners (#27). Richer dependency finding rendering: aggregated dependency findings now appear under a neutral [dependency] heading (instead of a single scanner’s name) with Package, Advisory (including the shared CVE), Detected by, and a Sources list showing where each scanner observed it. A new sources field on the finding (per-scanner tool + file) backs the JSON report (#27). Fixed PR comment rendering: scanner descriptions are flattened to a single line and their Markdown (code fences, headings) neutralized, so an unbalanced ``` fence can no longer swallow later findings and the footer into a code block. [0.2.0] - 2026-06-15 Supply-chain hardening for the scanner image and signed, verifiable releases (closes #30).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/skaldlab/muninn">https://github.com/skaldlab/muninn</a></strong> to version <strong>v0.3.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/muninn-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="changelog">Changelog</h1>
<h2 id="034---2026-07-04">[0.3.4] - 2026-07-04</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>Docker image scanner updates: osv-scanner 2.4.0, trivy 0.72.0, semgrep
1.168.0, zizmor 1.26.1 (checkov remains at 3.2.531 pending aiohttp cap lift).</li>
</ul>
<h2 id="033---2026-06-17">[0.3.3] - 2026-06-17</h2>
<h3 id="changed-1">Changed</h3>
<ul>
<li>Trivy default severity is now all levels (<code>UNKNOWN</code> through <code>CRITICAL</code>) instead
of <code>CRITICAL</code> and <code>HIGH</code> only. osv-scanner and trivy now overlap on
medium/low advisories by default so cross-scanner dedup and <code>Detected by</code>
work without extra config. Consumers can narrow the Trivy scan with
<code>scanners.trivy.severity</code>; <code>fail-on</code> still controls which findings fail the run.</li>
</ul>
<h2 id="032---2026-06-16">[0.3.2] - 2026-06-16</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Suppressions with <code>tool</code> and/or <code>rule-id</code> are now applied. Previously only <code>id</code>
(path substring) and <code>fingerprint</code> matchers worked; tool+rule-id entries
parsed from <code>muninn.yml</code> but silently no-op&rsquo;d.</li>
</ul>
<h2 id="031---2026-06-16">[0.3.1] - 2026-06-16</h2>
<h3 id="fixed-1">Fixed</h3>
<ul>
<li>Poutine v1.x JSON parsing: findings from poutine 1.1.6+ (<code>rule_id</code>, <code>meta</code>,
<code>rules</code>, <code>blobshas</code>) now populate title, rule, and file in PR comments instead
of empty shells (<code>File: :0</code>, `Rule: ``) (#41).</li>
<li>Actionlint PR comments: fall back to <code>kind</code> (e.g. <code>expression</code>) when
<code>rule.name</code> is absent; omit empty Rule lines.</li>
<li>Poutine injection findings: render <code>injection_sources</code> as formatted
<strong>Sources</strong> instead of plain <code>meta.details</code> text.</li>
</ul>
<h3 id="changed-2">Changed</h3>
<ul>
<li>PR comment layout: shared field helpers; non-dependency findings follow
File → Rule → optional extras → description; single-scanner dependency
findings use <strong>File</strong> instead of a redundant <strong>Source</strong> line.</li>
</ul>
<h2 id="030---2026-06-16">[0.3.0] - 2026-06-16</h2>
<h3 id="added">Added</h3>
<ul>
<li>Cross-scanner deduplication by advisory id: findings that report the same
CVE/GHSA for the same package from different scanners (e.g. OSV-Scanner from a
lockfile and Trivy from a container layer) are now collapsed into a single
finding. The contributing scanners are recorded in a new <code>detected_by</code> field
(surfaced in the JSON report, the PR comment&rsquo;s &ldquo;Detected by&rdquo; line, and a
<code>detectedBy</code> SARIF result property). A CVE is preferred over GHSA so the same
vulnerability converges on one id across scanners (#27).</li>
<li>Richer dependency finding rendering: aggregated dependency findings now appear
under a neutral <code>[dependency]</code> heading (instead of a single scanner&rsquo;s name)
with <code>Package</code>, <code>Advisory</code> (including the shared CVE), <code>Detected by</code>, and a
<code>Sources</code> list showing where each scanner observed it. A new <code>sources</code> field on
the finding (per-scanner <code>tool</code> + <code>file</code>) backs the JSON report (#27).</li>
</ul>
<h3 id="fixed-2">Fixed</h3>
<ul>
<li>PR comment rendering: scanner descriptions are flattened to a single line and
their Markdown (code fences, headings) neutralized, so an unbalanced ``` fence
can no longer swallow later findings and the footer into a code block.</li>
</ul>
<h2 id="020---2026-06-15">[0.2.0] - 2026-06-15</h2>
<p>Supply-chain hardening for the scanner image and signed, verifiable releases
(closes #30).</p>
<h3 id="added-1">Added</h3>
<ul>
<li>Pinned every bundled binary scanner to an exact version with SHA256 checksum
verification in the Docker image — gitleaks, zizmor, actionlint, poutine,
osv-scanner, trivy (#31)</li>
<li>Hash-locked the pip-installed scanners (semgrep, checkov, zizmor) via a fully
pinned, multi-arch <code>requirements-scanners.txt</code> installed with
<code>pip --require-hashes</code> (#33)</li>
<li>Renovate configuration to auto-PR scanner version bumps, with a CI job that
refreshes the pinned checksums (#32)</li>
<li>Keyless (OIDC) cosign signing of the published container image and of the
release binary checksums (Sigstore bundle <code>checksums.txt.sigstore.json</code>) (#34)</li>
<li>SBOM (SPDX) attached to every release and as an image attestation (#34)</li>
<li>Max-mode SLSA build provenance attestation on the container image (#34)</li>
<li>&ldquo;Verifying releases&rdquo; instructions in the README (#34)</li>
</ul>
<h3 id="changed-3">Changed</h3>
<ul>
<li>Pinned checkov to 3.2.531 (from 3.3.1) so its dependency tree resolves the
patched aiohttp 3.14.1 and drops the unfixable python-ecdsa Minerva
dependency that checkov 3.3.x introduced. Revisit when a newer checkov lifts
its <code>aiohttp&lt;3.14</code> cap (#33)</li>
</ul>
<h2 id="010---2026-06-14">[0.1.0] - 2026-06-14</h2>
<h3 id="added-2">Added</h3>
<ul>
<li>8 security scanners: gitleaks, zizmor, actionlint, poutine,
semgrep, osv-scanner, trivy, checkov</li>
<li>Unified Finding schema with fingerprinting</li>
<li>Three output formats: SARIF 2.1.0, JSON, GitHub PR comment</li>
<li>GitHub Action with outputs</li>
<li>Config-driven scanner behavior via muninn.yml</li>
<li>Suppression management with expiry dates</li>
<li>90%+ test coverage enforced in CI</li>
<li>Integration tests with real scanner binaries</li>
<li>Self-scan: Muninn scans itself on every PR</li>
</ul>
<p>Built by Skald Lab — skaldlab.dev</p>
]]></content:encoded></item><item><title>SFDX Run Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/sfdx-run-tests/</link><pubDate>Sat, 04 Jul 2026 21:50:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/sfdx-run-tests/</guid><description>Version updated for https://github.com/svierk/sfdx-run-tests to version v0.0.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed await flow test results via flow get test polling Full Changelog: https://github.com/svierk/sfdx-run-tests/compare/v0.0.1...v0.0.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/svierk/sfdx-run-tests">https://github.com/svierk/sfdx-run-tests</a></strong> to version <strong>v0.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sfdx-run-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>await flow test results via flow get test polling</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/svierk/sfdx-run-tests/compare/v0.0.1...v0.0.2">https://github.com/svierk/sfdx-run-tests/compare/v0.0.1...v0.0.2</a></p>
]]></content:encoded></item><item><title>MIU PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/miu-pr-review/</link><pubDate>Sat, 04 Jul 2026 21:50:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/miu-pr-review/</guid><description>Version updated for https://github.com/vanducng/miu-cr to version v0.85.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed miu-cr v0.85.2 AI code review for local changes and GitHub pull requests. Use it as a CLI, CI gate, or GitHub Action with your own LLM key.
Install curl -fsSL https://cr.miu.sh/install.sh | sh -s -- v0.85.2 brew install vanducng/tap/miucr go install github.com/vanducng/miu-cr/cmd/miucr@v0.85.2 GitHub Action:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vanducng/miu-cr">https://github.com/vanducng/miu-cr</a></strong> to version <strong>v0.85.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/miu-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="miu-cr-v0852">miu-cr v0.85.2</h2>
<p>AI code review for local changes and GitHub pull requests. Use it as a CLI, CI gate, or GitHub Action with your own LLM key.</p>
<h3 id="install">Install</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>curl -fsSL https://cr.miu.sh/install.sh | sh -s -- v0.85.2
</span></span><span style="display:flex;"><span>brew install vanducng/tap/miucr
</span></span><span style="display:flex;"><span>go install github.com/vanducng/miu-cr/cmd/miucr@v0.85.2
</span></span></code></pre></div><p>GitHub Action:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v6</span>
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">vanducng/miu-cr@v0.85.2</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span></code></pre></div><h3 id="common-commands">Common commands</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>miucr login --provider openai
</span></span><span style="display:flex;"><span>miucr review --staged
</span></span><span style="display:flex;"><span>miucr review --from main --to HEAD --gate high
</span></span><span style="display:flex;"><span>miucr review --pr owner/repo#123 --post
</span></span><span style="display:flex;"><span>miucr upgrade
</span></span></code></pre></div><p>Docs: <a href="https://cr.miu.sh">https://cr.miu.sh</a></p>
]]></content:encoded></item><item><title>PHP Scoper GitHub Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/php-scoper-github-action/</link><pubDate>Sat, 04 Jul 2026 21:49:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/php-scoper-github-action/</guid><description>Version updated for https://github.com/WPTechnix/action-php-scoper to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v1.0.0 — Initial Release A GitHub Action that runs PHP-Scoper to prefix PHP namespaces, preventing dependency conflicts when distributing PHP code as PHARs, WordPress plugins, or Composer libraries.
Features Docker-based action built on humbugphp/php-scoper:0.18.19 with Composer 2 baked in Automatic dependency installation — runs composer install before scoping (configurable) 5 configurable inputs: working-directory, scoper-config, run-composer-install, composer-args, output-directory Graceful fallbacks when scoper.inc.php or composer.json are missing 2 outputs: output-path (absolute path to scoped files) and count-scoped (file count) Proper CI/CD annotations — uses ::error:: and ::warning:: for clear workflow logs Dependabot integration for automated Docker/Actions dependency updates What It Solves PHP distributable code (plugins, libraries, PHARs) often bundles third-party dependencies that can clash with the same dependencies loaded by the host application. This action automates PHP-Scoper’s namespace prefixing so every build produces isolated, conflict-free code.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/WPTechnix/action-php-scoper">https://github.com/WPTechnix/action-php-scoper</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/php-scoper-github-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v100--initial-release">v1.0.0 — Initial Release</h2>
<p>A GitHub Action that runs <a href="https://github.com/humbug/php-scoper">PHP-Scoper</a> to prefix PHP namespaces, preventing dependency conflicts when distributing PHP code as PHARs, WordPress plugins, or Composer libraries.</p>
<h3 id="features">Features</h3>
<ul>
<li><strong>Docker-based action</strong> built on <code>humbugphp/php-scoper:0.18.19</code> with Composer 2 baked in</li>
<li><strong>Automatic dependency installation</strong> — runs <code>composer install</code> before scoping (configurable)</li>
<li><strong>5 configurable inputs</strong>: <code>working-directory</code>, <code>scoper-config</code>, <code>run-composer-install</code>, <code>composer-args</code>, <code>output-directory</code></li>
<li><strong>Graceful fallbacks</strong> when <code>scoper.inc.php</code> or <code>composer.json</code> are missing</li>
<li><strong>2 outputs</strong>: <code>output-path</code> (absolute path to scoped files) and <code>count-scoped</code> (file count)</li>
<li><strong>Proper CI/CD annotations</strong> — uses <code>::error::</code> and <code>::warning::</code> for clear workflow logs</li>
<li><strong>Dependabot integration</strong> for automated Docker/Actions dependency updates</li>
</ul>
<h3 id="what-it-solves">What It Solves</h3>
<p>PHP distributable code (plugins, libraries, PHARs) often bundles third-party dependencies that can clash with the same dependencies loaded by the host application. This action automates PHP-Scoper&rsquo;s namespace prefixing so every build produces isolated, conflict-free code.</p>
<p>See the <a href="https://github.com/wptechnix/php-scoper-action">README</a> for usage examples and full reference.</p>
]]></content:encoded></item><item><title>WP POT Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/wp-pot-generator/</link><pubDate>Sat, 04 Jul 2026 21:49:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/wp-pot-generator/</guid><description>Version updated for https://github.com/WPTechnix/wp-pot-generator to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v1.0.0 – Initial Release First public release of WP POT Generator, a GitHub Action for generating WordPress .pot translation files using WP-CLI inside a Docker container.
✨ Features Generate .pot files for WordPress plugins and themes Powered by wp i18n make-pot running in Docker Automatic detection of plugin/theme slug Automatic detection of the text domain Support for the &amp;lt;slug&amp;gt; placeholder in custom output paths 10 configurable inputs for flexible generation 4 action outputs for use in GitHub Actions workflows Validation and clear GitHub Actions log annotations for improved error reporting 🧪 Quality Comprehensive test suite covering plugins, themes, custom configurations, include/exclude patterns, and source subdirectories CI pipeline with schema validation, ShellCheck, actionlint, and end-to-end tests Dependabot configuration for GitHub Actions and Docker dependencies Conventional Commit enforcement with Commitlint 🚀 Quick Start - name: Generate POT file uses: WPTechnix/wp-pot-generator@v1 See the README for full documentation and configuration examples.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/WPTechnix/wp-pot-generator">https://github.com/WPTechnix/wp-pot-generator</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/wp-pot-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v100--initial-release">v1.0.0 – Initial Release</h1>
<p>First public release of <strong>WP POT Generator</strong>, a GitHub Action for generating WordPress <code>.pot</code> translation files using WP-CLI inside a Docker container.</p>
<h2 id="-features">✨ Features</h2>
<ul>
<li>Generate <code>.pot</code> files for WordPress plugins and themes</li>
<li>Powered by <code>wp i18n make-pot</code> running in Docker</li>
<li>Automatic detection of plugin/theme slug</li>
<li>Automatic detection of the text domain</li>
<li>Support for the <code>&lt;slug&gt;</code> placeholder in custom output paths</li>
<li>10 configurable inputs for flexible generation</li>
<li>4 action outputs for use in GitHub Actions workflows</li>
<li>Validation and clear GitHub Actions log annotations for improved error reporting</li>
</ul>
<h2 id="-quality">🧪 Quality</h2>
<ul>
<li>Comprehensive test suite covering plugins, themes, custom configurations, include/exclude patterns, and source subdirectories</li>
<li>CI pipeline with schema validation, ShellCheck, actionlint, and end-to-end tests</li>
<li>Dependabot configuration for GitHub Actions and Docker dependencies</li>
<li>Conventional Commit enforcement with Commitlint</li>
</ul>
<h2 id="-quick-start">🚀 Quick Start</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">name</span>: <span style="color:#ae81ff">Generate POT file</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">WPTechnix/wp-pot-generator@v1</span>
</span></span></code></pre></div><p>See the README for full documentation and configuration examples.</p>
]]></content:encoded></item><item><title>AI-Driven ADR Enforcer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/ai-driven-adr-enforcer/</link><pubDate>Sat, 04 Jul 2026 21:48:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/ai-driven-adr-enforcer/</guid><description>Version updated for https://github.com/y-matsuo081991/ai-adr-enforcer to version v1.1.6.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/y-matsuo081991/ai-adr-enforcer/compare/v1.1.5...v1.1.6</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/y-matsuo081991/ai-adr-enforcer">https://github.com/y-matsuo081991/ai-adr-enforcer</a></strong> to version <strong>v1.1.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-driven-adr-enforcer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/y-matsuo081991/ai-adr-enforcer/compare/v1.1.5...v1.1.6">https://github.com/y-matsuo081991/ai-adr-enforcer/compare/v1.1.5...v1.1.6</a></p>
]]></content:encoded></item><item><title>Powderworks Housekeeping</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/powderworks-housekeeping/</link><pubDate>Sat, 04 Jul 2026 21:47:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/powderworks-housekeeping/</guid><description>Version updated for https://github.com/zmaril/housekeeping to version v1.6.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Multi-language coverage: ci-exists demands test+lint+fmt per detected language (rust, js, python, ruby, go); ruby joins ecosystem detection; new builds check (every build target runs in CI, tauri heavy-target rules) and codegen-drift check ([[codegen]]-declared regen commands must run + zero-diff in CI). v1 fast-forwarded.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zmaril/housekeeping">https://github.com/zmaril/housekeeping</a></strong> to version <strong>v1.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/powderworks-housekeeping">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Multi-language coverage: ci-exists demands test+lint+fmt per detected language (rust, js, python, ruby, go); ruby joins ecosystem detection; new builds check (every build target runs in CI, tauri heavy-target rules) and codegen-drift check ([[codegen]]-declared regen commands must run + zero-diff in CI). <code>v1</code> fast-forwarded.</p>
]]></content:encoded></item><item><title>Setup poly CLI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/setup-poly-cli/</link><pubDate>Sat, 04 Jul 2026 14:36:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/setup-poly-cli/</guid><description>Version updated for https://github.com/Goldziher/polylint to version v0.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added Colored poly hooks install / uninstall output — a green ✓ header with the hook count and the (relative) hooks directory, then one line per hook name, replacing the flat list of absolute paths. Changed Installed git-hook shims resolve poly from PATH rather than baking in an absolute path to the binary, so a hook always runs whatever poly is current (a recorded absolute path could pin a stale or moved build). When poly is not on PATH the shim now fails with a clear, actionable message and a non-zero exit instead of proceeding as though the hook had passed. Re-run poly hooks install to migrate existing shims. Fixed Native-toolchain formatter output is normalized to LF line endings; some first-party CLIs emit CRLF on Windows, which made output platform-dependent.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Goldziher/polylint">https://github.com/Goldziher/polylint</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-poly-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>Colored <code>poly hooks install</code> / <code>uninstall</code> output</strong> — a green ✓ header with
the hook count and the (relative) hooks directory, then one line per hook name,
replacing the flat list of absolute paths.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>Installed git-hook shims resolve <code>poly</code> from <code>PATH</code></strong> rather than baking in an
absolute path to the binary, so a hook always runs whatever <code>poly</code> is current
(a recorded absolute path could pin a stale or moved build). When <code>poly</code> is not
on <code>PATH</code> the shim now fails with a clear, actionable message and a non-zero exit
instead of proceeding as though the hook had passed. Re-run <code>poly hooks install</code>
to migrate existing shims.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Native-toolchain formatter output is normalized to LF line endings; some
first-party CLIs emit CRLF on Windows, which made output platform-dependent.</li>
</ul>
]]></content:encoded></item><item><title>Vizb Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/vizb-action/</link><pubDate>Sat, 04 Jul 2026 14:36:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/vizb-action/</guid><description>Version updated for https://github.com/goptics/vizb to version v0.14.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat(ci): replace artifact storage with R2 in stateful CI example by @fahimfaisaal in https://github.com/goptics/vizb/pull/180 fix(merge): replace only colliding tag data on same-tag merge by @fahimfaisaal in https://github.com/goptics/vizb/pull/181 fix(merge): ensure tag-axis dimension is present in axes by @fahimfaisaal in https://github.com/goptics/vizb/pull/182 docs(merge): document same-tag replacement and auto-axis behavior by @fahimfaisaal in https://github.com/goptics/vizb/pull/183 Full Changelog: https://github.com/goptics/vizb/compare/v0.14.0...v0.14.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/goptics/vizb">https://github.com/goptics/vizb</a></strong> to version <strong>v0.14.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vizb-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(ci): replace artifact storage with R2 in stateful CI example by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/180">https://github.com/goptics/vizb/pull/180</a></li>
<li>fix(merge): replace only colliding tag data on same-tag merge by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/181">https://github.com/goptics/vizb/pull/181</a></li>
<li>fix(merge): ensure tag-axis dimension is present in axes by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/182">https://github.com/goptics/vizb/pull/182</a></li>
<li>docs(merge): document same-tag replacement and auto-axis behavior by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/183">https://github.com/goptics/vizb/pull/183</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/goptics/vizb/compare/v0.14.0...v0.14.1">https://github.com/goptics/vizb/compare/v0.14.0...v0.14.1</a></p>
]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/ai-plugin-scanner/</link><pubDate>Sat, 04 Jul 2026 14:35:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.379.
This action is used across all versions by 18 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/30cfc3007d8b9e711c803695d20105735964ad29 with plugin-scanner 2.0.979.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.378...v1.2.379</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.379</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>18</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/30cfc3007d8b9e711c803695d20105735964ad29">https://github.com/hashgraph-online/hol-guard/tree/30cfc3007d8b9e711c803695d20105735964ad29</a> with plugin-scanner 2.0.979.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.378...v1.2.379">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.378...v1.2.379</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/hol-codex-plugin-scanner/</link><pubDate>Sat, 04 Jul 2026 14:35:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.379.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.379</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.379</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.379">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.379</a></p>
]]></content:encoded></item><item><title>PHP Obfuscator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/php-obfuscator/</link><pubDate>Sat, 04 Jul 2026 14:34:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/php-obfuscator/</guid><description>Version updated for https://github.com/iSerter/php-obfuscator to version v0.1.7.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.1.7 (2026-07-04) Bug Fixes resolve named-argument label scrambling for non-obfuscated code (3646805) Miscellaneous Chores update php-obfuscator version in README to 0.1.7 (b06bed8)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/iSerter/php-obfuscator">https://github.com/iSerter/php-obfuscator</a></strong> to version <strong>v0.1.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/php-obfuscator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="017-2026-07-04"><a href="https://github.com/iSerter/php-obfuscator/compare/v0.1.6...v0.1.7">0.1.7</a> (2026-07-04)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>resolve named-argument label scrambling for non-obfuscated code (<a href="https://github.com/iSerter/php-obfuscator/commit/36468056c2d1cb5fcfc48d4bed24382d912103a8">3646805</a>)</li>
</ul>
<h3 id="miscellaneous-chores">Miscellaneous Chores</h3>
<ul>
<li>update php-obfuscator version in README to 0.1.7 (<a href="https://github.com/iSerter/php-obfuscator/commit/b06bed824163a243c448f4cf7f987fa997b89146">b06bed8</a>)</li>
</ul>
]]></content:encoded></item><item><title>ShipSignal readiness gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/shipsignal-readiness-gate/</link><pubDate>Sat, 04 Jul 2026 14:34:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/shipsignal-readiness-gate/</guid><description>Version updated for https://github.com/jpaul67/ShipSignal to version v0.9.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added Release cadence &amp;amp; lead time from tags (Package K) — tags-per-month, median inter-tag gap, and median lead time from commit to release tag, derived entirely from git tags. Filters to release-shaped tags (overridable via .shipsignal.toml’s release_tag_pattern). Context only, never scored — tags aren’t deploys. Outcomes: revert pairs &amp;amp; time-to-correction (Package J) — median time-to-correction from matched revert pairs, plus the change-failure proxy relabeled and rendered alongside it. Context only, never scored. .shipsignal.toml config file (Package G) — repo-local defaults for AI aliases, squash detection, release-tag pattern, readiness thresholds, and badge label, picked up automatically by every command. Full details: CHANGELOG.md</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jpaul67/ShipSignal">https://github.com/jpaul67/ShipSignal</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/shipsignal-readiness-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="added">Added</h2>
<ul>
<li>Release cadence &amp; lead time from tags (Package K) — tags-per-month, median inter-tag gap, and median lead time from commit to release tag, derived entirely from git tags. Filters to release-shaped tags (overridable via <code>.shipsignal.toml</code>&rsquo;s <code>release_tag_pattern</code>). Context only, never scored — tags aren&rsquo;t deploys.</li>
<li>Outcomes: revert pairs &amp; time-to-correction (Package J) — median time-to-correction from matched revert pairs, plus the change-failure proxy relabeled and rendered alongside it. Context only, never scored.</li>
<li><code>.shipsignal.toml</code> config file (Package G) — repo-local defaults for AI aliases, squash detection, release-tag pattern, readiness thresholds, and badge label, picked up automatically by every command.</li>
</ul>
<p>Full details: <a href="https://github.com/jpaul67/ShipSignal/blob/v0.9.0/CHANGELOG.md#090--2026-07-03">CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/neurolink-ai/</link><pubDate>Sat, 04 Jul 2026 14:33:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v9.81.1.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 9.81.1 (2026-07-04) Bug Fixes (landing): prerender homepage so crawlers see content (was ssr=false → empty shell) (cfa704e)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v9.81.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="9811-2026-07-04"><a href="https://github.com/juspay/neurolink/compare/v9.81.0...v9.81.1">9.81.1</a> (2026-07-04)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(landing):</strong>  prerender homepage so crawlers see content (was ssr=false → empty shell) (<a href="https://github.com/juspay/neurolink/commit/cfa704e93ab2db6ddf3ccc6f33088e5c18a5635a">cfa704e</a>)</li>
</ul>
]]></content:encoded></item><item><title>spek - OpenSpec Static Site</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/spek-openspec-static-site/</link><pubDate>Sat, 04 Jul 2026 14:32:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/spek-openspec-static-site/</guid><description>Version updated for https://github.com/kewang/spek to version v1.3.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fix: the IntelliJ plugin now installs on IntelliJ Platform 2026.1 (build 261.x) and newer — the until-build upper bound (253.*) that caused “requires IDE build 253.* or earlier” has been removed, so the plugin tracks current and future IDE releases (#4) Update the published kewang/spek GitHub Action off the deprecated Node 20 runtime — bump actions/checkout to v7, actions/setup-node to v6, and actions/cache to v6; internal CI workflows and README examples updated to match (#7)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kewang/spek">https://github.com/kewang/spek</a></strong> to version <strong>v1.3.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spek-openspec-static-site">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Fix: the IntelliJ plugin now installs on IntelliJ Platform 2026.1 (build 261.x) and newer — the <code>until-build</code> upper bound (<code>253.*</code>) that caused &ldquo;requires IDE build 253.* or earlier&rdquo; has been removed, so the plugin tracks current and future IDE releases (#4)</li>
<li>Update the published <code>kewang/spek</code> GitHub Action off the deprecated Node 20 runtime — bump <code>actions/checkout</code> to v7, <code>actions/setup-node</code> to v6, and <code>actions/cache</code> to v6; internal CI workflows and README examples updated to match (#7)</li>
</ul>
]]></content:encoded></item><item><title>Setup runner cli</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/setup-runner-cli/</link><pubDate>Sat, 04 Jul 2026 14:32:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/setup-runner-cli/</guid><description>Version updated for https://github.com/kjanat/runner to version v0.16.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed npx runner-run now resolves to the full CLI. Added a runner-run bin alias; previously npx failed with could not determine executable to run because neither shipped bin (run, runner) matched the package name. (Reaches users only on this published release; npx runner-run@0.16.0 stays broken.) The no-prebuilt-binary error now names the bun minimumReleaseAge pitfall: its age gate also filters the @runner-run/* platform packages, which must be excluded by exact name (no scope/glob), not just the runner-run facade. Changed Internal: the run alias binary now dispatches through the same dispatch entry point as runner, building a typed Cli from the parsed alias rather than keeping a second resolver-override and command-dispatch copy in dispatch_run_alias. The alias keeps its bespoke help/version forwarding, flat completions, and run man page. One behavior delta: a bare run -k/-K (a chain-failure flag with no task and no -s/-p) now maps to the project dashboard (command: None) and drops the inert chain-failure flag before resolving overrides, so it no longer errors when the opposite polarity is supplied out-of-band via RUNNER_KILL_ON_FAIL/RUNNER_KEEP_GOING or a [chain] config. The old eager builder kept the flag and hit the cross-source conflict; the dashboard never consults the failure policy, so dropping it is correct. See https://github.com/kjanat/runner/issues/52. What’s Changed refactor(run): unify run alias dispatch; do not remove RunAliasCli by @kjanat in https://github.com/kjanat/runner/pull/72 Full Changelog: https://github.com/kjanat/runner/compare/v0.16.0...v0.16.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kjanat/runner">https://github.com/kjanat/runner</a></strong> to version <strong>v0.16.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-runner-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><code>npx runner-run</code> now resolves to the full CLI. Added a <code>runner-run</code> bin
alias; previously npx failed with <code>could not determine executable to run</code>
because neither shipped bin (<code>run</code>, <code>runner</code>) matched the package name.
(Reaches users only on this published release; <code>npx runner-run@0.16.0</code>
stays broken.)</li>
<li>The no-prebuilt-binary error now names the bun <code>minimumReleaseAge</code> pitfall:
its age gate also filters the <code>@runner-run/*</code> platform packages, which must
be excluded by exact name (no scope/glob), not just the <code>runner-run</code> facade.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>Internal: the <code>run</code> alias binary now dispatches through the same
<code>dispatch</code> entry point as <code>runner</code>, building a typed <code>Cli</code> from the parsed
alias rather than keeping a second resolver-override and command-dispatch
copy in <code>dispatch_run_alias</code>. The alias keeps its bespoke help/version
forwarding, flat completions, and <code>run</code> man page. One behavior delta: a
bare <code>run -k</code>/<code>-K</code> (a chain-failure flag with no task and no <code>-s</code>/<code>-p</code>)
now maps to the project dashboard (<code>command: None</code>) and drops the inert
chain-failure flag before resolving overrides, so it no longer errors when
the opposite polarity is supplied out-of-band via
<code>RUNNER_KILL_ON_FAIL</code>/<code>RUNNER_KEEP_GOING</code> or a <code>[chain]</code> config. The old
eager builder kept the flag and hit the cross-source conflict; the
dashboard never consults the failure policy, so dropping it is correct. See
<a href="https://github.com/kjanat/runner/issues/52">https://github.com/kjanat/runner/issues/52</a>.</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>refactor(run): unify run alias dispatch; do not remove RunAliasCli by @kjanat in <a href="https://github.com/kjanat/runner/pull/72">https://github.com/kjanat/runner/pull/72</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/kjanat/runner/compare/v0.16.0...v0.16.1">https://github.com/kjanat/runner/compare/v0.16.0...v0.16.1</a></p>
]]></content:encoded></item><item><title>Clausura Code Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/clausura-code-review/</link><pubDate>Sat, 04 Jul 2026 14:31:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/clausura-code-review/</guid><description>Version updated for https://github.com/liuyanghejerry/Clausura to version v1.0.8.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/liuyanghejerry/Clausura/compare/v1.0.7...v1.0.8</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/liuyanghejerry/Clausura">https://github.com/liuyanghejerry/Clausura</a></strong> to version <strong>v1.0.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/clausura-code-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/liuyanghejerry/Clausura/compare/v1.0.7...v1.0.8">https://github.com/liuyanghejerry/Clausura/compare/v1.0.7...v1.0.8</a></p>
]]></content:encoded></item><item><title>ReviewGate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/reviewgate/</link><pubDate>Sat, 04 Jul 2026 14:31:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/reviewgate/</guid><description>Version updated for https://github.com/LVTD-LLC/reviewgate to version v0.1.10.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed [Action] Simplify ReviewGate configuration by @rasulkireev in https://github.com/LVTD-LLC/reviewgate/pull/28 Full Changelog: https://github.com/LVTD-LLC/reviewgate/compare/v0...v0.1.10</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/LVTD-LLC/reviewgate">https://github.com/LVTD-LLC/reviewgate</a></strong> to version <strong>v0.1.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/reviewgate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>[Action] Simplify ReviewGate configuration by @rasulkireev in <a href="https://github.com/LVTD-LLC/reviewgate/pull/28">https://github.com/LVTD-LLC/reviewgate/pull/28</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/LVTD-LLC/reviewgate/compare/v0...v0.1.10">https://github.com/LVTD-LLC/reviewgate/compare/v0...v0.1.10</a></p>
]]></content:encoded></item><item><title>Setup Raven</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/setup-raven/</link><pubDate>Sat, 04 Jul 2026 14:30:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/setup-raven/</guid><description>Version updated for https://github.com/martian56/setup-raven to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Installs the Raven toolchain (raven, rvpm) on Linux and Windows runners from the Raven GitHub releases and caches the rvpm package cache between runs.
raven-version input: a release like 2.22.0, or latest (the default) cache input: caches ~/.rvpm/cache keyed on the repository’s rv.toml files raven-version output: the tag that was installed Use it with:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/martian56/setup-raven">https://github.com/martian56/setup-raven</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-raven">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Installs the Raven toolchain (raven, rvpm) on Linux and Windows runners from the Raven GitHub releases and caches the rvpm package cache between runs.</p>
<ul>
<li>raven-version input: a release like 2.22.0, or latest (the default)</li>
<li>cache input: caches ~/.rvpm/cache keyed on the repository&rsquo;s rv.toml files</li>
<li>raven-version output: the tag that was installed</li>
</ul>
<p>Use it with:</p>
<pre><code>- uses: martian56/setup-raven@v1
</code></pre>
]]></content:encoded></item><item><title>hestia-cache</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/hestia-cache/</link><pubDate>Sat, 04 Jul 2026 14:30:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/hestia-cache/</guid><description>Version updated for https://github.com/Mic92/hestia to version v2.0.0.
This action is used across all versions by 8 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Usage - uses: Mic92/hestia@v2.0.0 with: version: v2.0.0 ⚠️ New cache format — one-time reset v2 introduces a new on-disk cache format, so existing cache entries from v1 will not be reused. The first runs after upgrading repopulate the cache from scratch; old data ages out automatically via GC. No action is required.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Mic92/hestia">https://github.com/Mic92/hestia</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hestia-cache">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Mic92/hestia@v2.0.0</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">version</span>: <span style="color:#ae81ff">v2.0.0</span>
</span></span></code></pre></div><h2 id="-new-cache-format--one-time-reset">⚠️ New cache format — one-time reset</h2>
<p>v2 introduces a new on-disk cache format, so <strong>existing cache entries from
v1 will not be reused</strong>. The first runs after upgrading repopulate the cache
from scratch; old data ages out automatically via GC. No action is required.</p>
<p>The format change unlocks the headline improvement below.</p>
<h2 id="highlights">Highlights</h2>
<ul>
<li>
<p><strong>Reference normalization for cross-rebuild dedup.</strong> Nix store paths embed
the hashes of their dependencies in file contents. Previously, rebuilding a
dependency changed those embedded hashes and churned the cache, defeating
deduplication. v2 zeroes out (nullifies) these reference hashes before
chunking and restores them on the way out, so unchanged files stay identical
across rebuilds. Result: far better dedup and smaller uploads when only a
low-level dependency changes.</p>
</li>
<li>
<p><strong>Much faster chunking.</strong> Parallel chunking of large files across cores,<br>
BLAKE3 instead of SHA-256 for internal content addresses (~3x faster hashing)
and general drain-path tuning roughly tripled throughput (~25 → ~70+ Mbit/s on my Framework laptop).</p>
</li>
<li>
<p><strong>Clear message for read-only tokens.</strong> On workflows without cache write
access (forks, <code>pull_request</code> from forks, <code>check_run</code>), hestia now detects
the read-only token at startup and reports it clearly instead of failing at
the end of the run with a confusing &ldquo;drain failed&rdquo; warning. Reads still work,
so substitutions keep being served.</p>
</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Mic92/hestia/compare/v1...v2.0.0">https://github.com/Mic92/hestia/compare/v1...v2.0.0</a></p>
]]></content:encoded></item><item><title>Miso PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/miso-pr-review/</link><pubDate>Sat, 04 Jul 2026 14:29:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/miso-pr-review/</guid><description>Version updated for https://github.com/misospace/pr-reviewer-action to version v2.1.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore: dead-code removal and dedup sweep by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/366 fix(forgejo): structured gh api for GitHub comments, unified sticky-comment selection by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/376 refactor(classifier): declarative rule tables for pr_kind and risk flags by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/377 fix(security): derive fork-ness once, fail closed on degraded PR metadata by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/380 fix(precheck): read prior-review metadata via JSON side-file, drop eval by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/378 refactor(ci-gate): normalize external checks once in the platform seam by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/379 test(redact): comprehensive secret-redaction coverage by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/381 docs(verdict): pin the bash/Python verdict-turn contract with equivalence tests by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/385 refactor(enrichment): extract run_enrichment core into pr_reviewer modules by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/386 ci: enforce pytest coverage gate (baseline 76%, gate 72%) by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/382 test(forgejo): unit-test _diff_positions in isolation by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/383 test(env): hard gate on cross-block env binding drift in action.yml by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/384 fix(platform): resolve platform once in the precheck; PLATFORM-aware _is_forgejo_mode by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/387 fix(mcp): correct tool-name docs, log loop outcome, resolve separator aliases by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/390 refactor(utils): consolidate env_int, DeadlineBudget, and compare summarization by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/391 ci(github-action): update action misospace/pr-reviewer-action (v2.0.0 → v2.0.5) by @its-miso[bot] in https://github.com/misospace/pr-reviewer-action/pull/392 docs(agents): replace stale saffron-lane label table with ad-hoc agent/ convention by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/393 docs(release): document versioning policy; keep pre-releases off the floating major tag by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/394 perf(native-loop): dedup verdict-turn corpus sections; collapse skipped-source boilerplate by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/395 refactor(review): unify primary/fallback/smart model calls behind call_model_tier by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/396 perf(context): parallelize advisory phases, fan out enrichment API calls, collapse repo-impact scans by @joryirving in https://github.com/misospace/pr-reviewer-action/pull/397 Full Changelog: https://github.com/misospace/pr-reviewer-action/compare/v2.0.5...v2.1.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/misospace/pr-reviewer-action">https://github.com/misospace/pr-reviewer-action</a></strong> to version <strong>v2.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/miso-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore: dead-code removal and dedup sweep by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/366">https://github.com/misospace/pr-reviewer-action/pull/366</a></li>
<li>fix(forgejo): structured gh api for GitHub comments, unified sticky-comment selection by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/376">https://github.com/misospace/pr-reviewer-action/pull/376</a></li>
<li>refactor(classifier): declarative rule tables for pr_kind and risk flags by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/377">https://github.com/misospace/pr-reviewer-action/pull/377</a></li>
<li>fix(security): derive fork-ness once, fail closed on degraded PR metadata by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/380">https://github.com/misospace/pr-reviewer-action/pull/380</a></li>
<li>fix(precheck): read prior-review metadata via JSON side-file, drop eval by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/378">https://github.com/misospace/pr-reviewer-action/pull/378</a></li>
<li>refactor(ci-gate): normalize external checks once in the platform seam by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/379">https://github.com/misospace/pr-reviewer-action/pull/379</a></li>
<li>test(redact): comprehensive secret-redaction coverage by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/381">https://github.com/misospace/pr-reviewer-action/pull/381</a></li>
<li>docs(verdict): pin the bash/Python verdict-turn contract with equivalence tests by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/385">https://github.com/misospace/pr-reviewer-action/pull/385</a></li>
<li>refactor(enrichment): extract run_enrichment core into pr_reviewer modules by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/386">https://github.com/misospace/pr-reviewer-action/pull/386</a></li>
<li>ci: enforce pytest coverage gate (baseline 76%, gate 72%) by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/382">https://github.com/misospace/pr-reviewer-action/pull/382</a></li>
<li>test(forgejo): unit-test _diff_positions in isolation by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/383">https://github.com/misospace/pr-reviewer-action/pull/383</a></li>
<li>test(env): hard gate on cross-block env binding drift in action.yml by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/384">https://github.com/misospace/pr-reviewer-action/pull/384</a></li>
<li>fix(platform): resolve platform once in the precheck; PLATFORM-aware _is_forgejo_mode by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/387">https://github.com/misospace/pr-reviewer-action/pull/387</a></li>
<li>fix(mcp): correct tool-name docs, log loop outcome, resolve separator aliases by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/390">https://github.com/misospace/pr-reviewer-action/pull/390</a></li>
<li>refactor(utils): consolidate env_int, DeadlineBudget, and compare summarization by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/391">https://github.com/misospace/pr-reviewer-action/pull/391</a></li>
<li>ci(github-action): update action misospace/pr-reviewer-action (v2.0.0 → v2.0.5) by @its-miso[bot] in <a href="https://github.com/misospace/pr-reviewer-action/pull/392">https://github.com/misospace/pr-reviewer-action/pull/392</a></li>
<li>docs(agents): replace stale saffron-lane label table with ad-hoc agent/<name> convention by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/393">https://github.com/misospace/pr-reviewer-action/pull/393</a></li>
<li>docs(release): document versioning policy; keep pre-releases off the floating major tag by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/394">https://github.com/misospace/pr-reviewer-action/pull/394</a></li>
<li>perf(native-loop): dedup verdict-turn corpus sections; collapse skipped-source boilerplate by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/395">https://github.com/misospace/pr-reviewer-action/pull/395</a></li>
<li>refactor(review): unify primary/fallback/smart model calls behind call_model_tier by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/396">https://github.com/misospace/pr-reviewer-action/pull/396</a></li>
<li>perf(context): parallelize advisory phases, fan out enrichment API calls, collapse repo-impact scans by @joryirving in <a href="https://github.com/misospace/pr-reviewer-action/pull/397">https://github.com/misospace/pr-reviewer-action/pull/397</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/misospace/pr-reviewer-action/compare/v2.0.5...v2.1.0">https://github.com/misospace/pr-reviewer-action/compare/v2.0.5...v2.1.0</a></p>
]]></content:encoded></item><item><title>Nox Security Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/nox-security-scanner/</link><pubDate>Sat, 04 Jul 2026 14:29:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/nox-security-scanner/</guid><description>Version updated for https://github.com/Nox-HQ/nox to version v1.4.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Nox v1.4.2 (2026-07-04T12:58:01Z) Language-agnostic security scanner with first-class AI application security.
Installation macOS/Linux (Homebrew) brew tap felixgeelhaar/tap brew install nox Direct Download Download the appropriate archive for your platform from the assets below.
What’s Changed Changelog Bug Fixes cf5037c61c7b201a8a53976c0c05096aa089a380 fix(discovery): honor .gitignore when scanning from a git worktree (#140) (#141) Others 2ea7b7ffd9f8ab7ff6cc57842bca1cbe9589edd1 chore(deps): bump golang.org/x/net from 0.48.0 to 0.55.0 in /plugins/nox-plugin-reachability (#138) fb2e6cdd8aa6ee8adc20162aa6436d885ece0ff5 chore(deps): bump golang.org/x/net from 0.54.0 to 0.55.0 in /plugins/nox-plugin-red-team (#139) Full Changelog: https://github.com/nox-hq/nox/compare/v1.4.1...v1.4.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Nox-HQ/nox">https://github.com/Nox-HQ/nox</a></strong> to version <strong>v1.4.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nox-security-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="nox-v142-2026-07-04t125801z">Nox v1.4.2 (2026-07-04T12:58:01Z)</h2>
<p>Language-agnostic security scanner with first-class AI application security.</p>
<h3 id="installation">Installation</h3>
<h4 id="macoslinux-homebrew">macOS/Linux (Homebrew)</h4>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>brew tap felixgeelhaar/tap
</span></span><span style="display:flex;"><span>brew install nox
</span></span></code></pre></div><h4 id="direct-download">Direct Download</h4>
<p>Download the appropriate archive for your platform from the assets below.</p>
<h3 id="whats-changed-1">What&rsquo;s Changed</h3>
<h2 id="changelog">Changelog</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>cf5037c61c7b201a8a53976c0c05096aa089a380 fix(discovery): honor .gitignore when scanning from a git worktree (#140) (#141)</li>
</ul>
<h3 id="others">Others</h3>
<ul>
<li>2ea7b7ffd9f8ab7ff6cc57842bca1cbe9589edd1 chore(deps): bump golang.org/x/net from 0.48.0 to 0.55.0 in /plugins/nox-plugin-reachability (#138)</li>
<li>fb2e6cdd8aa6ee8adc20162aa6436d885ece0ff5 chore(deps): bump golang.org/x/net from 0.54.0 to 0.55.0 in /plugins/nox-plugin-red-team (#139)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nox-hq/nox/compare/v1.4.1...v1.4.2">https://github.com/nox-hq/nox/compare/v1.4.1...v1.4.2</a></p>
]]></content:encoded></item><item><title>Changelog Bot Runner Nyaomaru</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/changelog-bot-runner-nyaomaru/</link><pubDate>Sat, 04 Jul 2026 14:28:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/changelog-bot-runner-nyaomaru/</guid><description>Version updated for https://github.com/nyaomaru/changelog-bot to version v0.6.3.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed refactor: simplify changelog run and why utilities by @nyaomaru in https://github.com/nyaomaru/changelog-bot/pull/151 test: type changelog run mocks by @nyaomaru in https://github.com/nyaomaru/changelog-bot/pull/152 Release: 0.6.3 by @github-actions[bot] in https://github.com/nyaomaru/changelog-bot/pull/153 Full Changelog: https://github.com/nyaomaru/changelog-bot/compare/v0...v0.6.3</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nyaomaru/changelog-bot">https://github.com/nyaomaru/changelog-bot</a></strong> to version <strong>v0.6.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/changelog-bot-runner-nyaomaru">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>refactor: simplify changelog run and why utilities by @nyaomaru in <a href="https://github.com/nyaomaru/changelog-bot/pull/151">https://github.com/nyaomaru/changelog-bot/pull/151</a></li>
<li>test: type changelog run mocks by @nyaomaru in <a href="https://github.com/nyaomaru/changelog-bot/pull/152">https://github.com/nyaomaru/changelog-bot/pull/152</a></li>
<li>Release: 0.6.3 by @github-actions[bot] in <a href="https://github.com/nyaomaru/changelog-bot/pull/153">https://github.com/nyaomaru/changelog-bot/pull/153</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/nyaomaru/changelog-bot/compare/v0...v0.6.3">https://github.com/nyaomaru/changelog-bot/compare/v0...v0.6.3</a></p>
]]></content:encoded></item><item><title>SkillTotal AI Component Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/skilltotal-ai-component-security-scan/</link><pubDate>Sat, 04 Jul 2026 14:28:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/skilltotal-ai-component-security-scan/</guid><description>Version updated for https://github.com/pezhik/skilltotal to version v0.25.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changed Prompt-injection/secret precision (ruleset 26): two FPs on a real popular project (infiniflow/ragflow) closed, recall-preserving. (1) Prompt-injection phrases held in C-family value-strings — a security tool’s own pattern table (Description: &amp;#34;prompt injection: ignore previous instructions&amp;#34;, &amp;#34;DAN (Do Anything Now) …&amp;#34; in a Go file) — no longer flag ST-PROMPT-INJECTION. A new code_context policy strings_and_comments_all demotes matches inside Go/JS/TS/Rust/… string literals (new IndexedFile.in_c_string machinery), opted into only by ST-PROMPT-INJECTION; every other rule still treats a credential path in a C-family string as real access. (2) A commented-out secret in a Python comment (# OAuthConfig(client_secret=&amp;#34;…&amp;#34;)) no longer flags ST-SECRET-EMBEDDED — the rule now uses code_context=&amp;#34;comments&amp;#34;. Recall preserved: a live injection in an instruction surface / prose and a real embedded secret in code still fire. New unit tests + a benign fp_go_pattern_defs fixture; FP floor and efficacy (100%/100%) stay green.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pezhik/skilltotal">https://github.com/pezhik/skilltotal</a></strong> to version <strong>v0.25.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skilltotal-ai-component-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>Prompt-injection/secret precision (ruleset 26): two FPs on a real popular project
(infiniflow/ragflow) closed, recall-preserving.</strong> (1) Prompt-injection phrases held in C-family
value-strings — a security tool&rsquo;s own pattern table (<code>Description: &quot;prompt injection: ignore previous instructions&quot;</code>, <code>&quot;DAN (Do Anything Now) …&quot;</code> in a Go file) — no longer flag
<code>ST-PROMPT-INJECTION</code>. A new <code>code_context</code> policy <code>strings_and_comments_all</code> demotes matches inside
Go/JS/TS/Rust/… string literals (new <code>IndexedFile.in_c_string</code> machinery), opted into only by
<code>ST-PROMPT-INJECTION</code>; every other rule still treats a credential path in a C-family string as real
access. (2) A commented-out secret in a Python comment (<code>#     OAuthConfig(client_secret=&quot;…&quot;)</code>) no
longer flags <code>ST-SECRET-EMBEDDED</code> — the rule now uses <code>code_context=&quot;comments&quot;</code>. Recall preserved:
a live injection in an instruction surface / prose and a real embedded secret in code still fire.
New unit tests + a benign <code>fp_go_pattern_defs</code> fixture; FP floor and efficacy (100%/100%) stay green.</li>
</ul>
]]></content:encoded></item><item><title>Python Semantic Release - Publish</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/python-semantic-release-publish/</link><pubDate>Sat, 04 Jul 2026 14:27:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/python-semantic-release-publish/</guid><description>Version updated for https://github.com/python-semantic-release/publish-action to version v10.6.0.
This action is used across all versions by 660 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v10.6.0 (2026-07-04) Build System deps: Bump python-semantic-release from v10.5.3 to v10.6.0 (#101, 4f3c5d7) Detailed Changes: v10.5.3…v10.6.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/python-semantic-release/publish-action">https://github.com/python-semantic-release/publish-action</a></strong> to version <strong>v10.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>660</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/python-semantic-release-publish">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v1060-2026-07-04">v10.6.0 (2026-07-04)</h2>
<h3 id="build-system">Build System</h3>
<ul>
<li><strong>deps</strong>: Bump <code>python-semantic-release</code> from <code>v10.5.3</code> to <code>v10.6.0</code> (<a href="https://github.com/python-semantic-release/publish-action/pull/101">#101</a>, <a href="https://github.com/python-semantic-release/publish-action/commit/4f3c5d7f5caddf6535050c4bcb55f033f000a7dd"><code>4f3c5d7</code></a>)</li>
</ul>
<hr>
<p><strong>Detailed Changes</strong>: <a href="https://github.com/python-semantic-release/publish-action/compare/v10.5.3...v10.6.0">v10.5.3&hellip;v10.6.0</a></p>
]]></content:encoded></item><item><title>Quant Agent Tools</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/quant-agent-tools/</link><pubDate>Sat, 04 Jul 2026 14:26:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/quant-agent-tools/</guid><description>Version updated for https://github.com/quantcdn/quant-cloud-agent-tools-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix: send edgeFunctionCode per the v3 custom-tools contract (422 on every run) by @steveworley in https://github.com/quantcdn/quant-cloud-agent-tools-action/pull/17 chore(deps-dev): bump @types/node from 20.19.35 to 25.9.1 by @dependabot[bot] in https://github.com/quantcdn/quant-cloud-agent-tools-action/pull/16 New Contributors @steveworley made their first contribution in https://github.com/quantcdn/quant-cloud-agent-tools-action/pull/17 @dependabot[bot] made their first contribution in https://github.com/quantcdn/quant-cloud-agent-tools-action/pull/16 Full Changelog: https://github.com/quantcdn/quant-cloud-agent-tools-action/compare/v1...v1.1.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/quantcdn/quant-cloud-agent-tools-action">https://github.com/quantcdn/quant-cloud-agent-tools-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/quant-agent-tools">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: send edgeFunctionCode per the v3 custom-tools contract (422 on every run) by @steveworley in <a href="https://github.com/quantcdn/quant-cloud-agent-tools-action/pull/17">https://github.com/quantcdn/quant-cloud-agent-tools-action/pull/17</a></li>
<li>chore(deps-dev): bump @types/node from 20.19.35 to 25.9.1 by @dependabot[bot] in <a href="https://github.com/quantcdn/quant-cloud-agent-tools-action/pull/16">https://github.com/quantcdn/quant-cloud-agent-tools-action/pull/16</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@steveworley made their first contribution in <a href="https://github.com/quantcdn/quant-cloud-agent-tools-action/pull/17">https://github.com/quantcdn/quant-cloud-agent-tools-action/pull/17</a></li>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/quantcdn/quant-cloud-agent-tools-action/pull/16">https://github.com/quantcdn/quant-cloud-agent-tools-action/pull/16</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/quantcdn/quant-cloud-agent-tools-action/compare/v1...v1.1.0">https://github.com/quantcdn/quant-cloud-agent-tools-action/compare/v1...v1.1.0</a></p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/bernstein-multi-agent-orchestration/</link><pubDate>Sat, 04 Jul 2026 14:25:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v2.14.1.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.14.1 Released 2026-07-04.
Security and hygiene patch.
Security Log injection: user-controlled values (task ids, roles, session ids, reasons, branches, and git output) are sanitized before they reach a log entry across the task-server routes, task store, spawner, orchestrator, and retrospective paths, so a crafted value can no longer forge log lines. Task-failure/reopen/cancel/block reasons are additionally CR/LF-stripped and length-capped at the request boundary. Sensitive-data logging: the openai_agents adapter and runner no longer log request headers, body, or the resolved API key value; only the env var name is recorded. Fixes The qwen adapter passes --approval-mode yolo, the current documented qwen-code auto-approve flag, clearing the adapter contract drift. (#2197) Internal Restored the integration-test harness (server auth disabled in the fixture, all role templates created, merge-preflight guards satisfied) so the end-to-end orchestration tests pass again. (#2205) Resolved refurb idiom findings across the routes, cost, agents, and orchestration modules.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v2.14.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v2141">v2.14.1</h1>
<p>Released 2026-07-04.</p>
<p>Security and hygiene patch.</p>
<h2 id="security">Security</h2>
<ul>
<li>Log injection: user-controlled values (task ids, roles, session ids, reasons, branches, and git output) are sanitized before they reach a log entry across the task-server routes, task store, spawner, orchestrator, and retrospective paths, so a crafted value can no longer forge log lines. Task-failure/reopen/cancel/block reasons are additionally CR/LF-stripped and length-capped at the request boundary.</li>
<li>Sensitive-data logging: the openai_agents adapter and runner no longer log request headers, body, or the resolved API key value; only the env var name is recorded.</li>
</ul>
<h2 id="fixes">Fixes</h2>
<ul>
<li>The qwen adapter passes <code>--approval-mode yolo</code>, the current documented qwen-code auto-approve flag, clearing the adapter contract drift. (#2197)</li>
</ul>
<h2 id="internal">Internal</h2>
<ul>
<li>Restored the integration-test harness (server auth disabled in the fixture, all role templates created, merge-preflight guards satisfied) so the end-to-end orchestration tests pass again. (#2205)</li>
<li>Resolved refurb idiom findings across the routes, cost, agents, and orchestration modules.</li>
</ul>
]]></content:encoded></item><item><title>Validate Syscribe Model</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/validate-syscribe-model/</link><pubDate>Sat, 04 Jul 2026 14:25:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/validate-syscribe-model/</guid><description>Version updated for https://github.com/sjames/syscribe to version v0.30.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix(find): avoid panic when doc-body cap lands mid-UTF-8-char by @sjames in https://github.com/sjames/syscribe/pull/80 fix(matrix): render covered-but-failing requirement as ▣, not ✗ by @sjames in https://github.com/sjames/syscribe/pull/81 feat(scan): LLM-scale corpus scanning — Tiers A/B/C (stats, digest, search-text, summarize, topics, clusters) by @sjames in https://github.com/sjames/syscribe/pull/82 feat: displayOrder field + W047 unrecognized-field warning by @sjames in https://github.com/sjames/syscribe/pull/83 Full Changelog: https://github.com/sjames/syscribe/compare/v0...v0.30.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sjames/syscribe">https://github.com/sjames/syscribe</a></strong> to version <strong>v0.30.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/validate-syscribe-model">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(find): avoid panic when doc-body cap lands mid-UTF-8-char by @sjames in <a href="https://github.com/sjames/syscribe/pull/80">https://github.com/sjames/syscribe/pull/80</a></li>
<li>fix(matrix): render covered-but-failing requirement as ▣, not ✗ by @sjames in <a href="https://github.com/sjames/syscribe/pull/81">https://github.com/sjames/syscribe/pull/81</a></li>
<li>feat(scan): LLM-scale corpus scanning — Tiers A/B/C (stats, digest, search-text, summarize, topics, clusters) by @sjames in <a href="https://github.com/sjames/syscribe/pull/82">https://github.com/sjames/syscribe/pull/82</a></li>
<li>feat: displayOrder field + W047 unrecognized-field warning by @sjames in <a href="https://github.com/sjames/syscribe/pull/83">https://github.com/sjames/syscribe/pull/83</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/sjames/syscribe/compare/v0...v0.30.0">https://github.com/sjames/syscribe/compare/v0...v0.30.0</a></p>
]]></content:encoded></item><item><title>UUAID Init — give your repos agent a permanent identity</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/uuaid-init-give-your-repos-agent-a-permanent-identity/</link><pubDate>Sat, 04 Jul 2026 14:24:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/uuaid-init-give-your-repos-agent-a-permanent-identity/</guid><description>Version updated for https://github.com/uuaid/init-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed uuaid-init v1 — mint a permanent agent identity + trust badge in one CI step.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/uuaid/init-action">https://github.com/uuaid/init-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/uuaid-init-give-your-repo-s-agent-a-permanent-identity">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>uuaid-init v1 — mint a permanent agent identity + trust badge in one CI step.</p>
]]></content:encoded></item><item><title>VAPT Insights Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/vapt-insights-security-scan/</link><pubDate>Sat, 04 Jul 2026 14:24:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/vapt-insights-security-scan/</guid><description>Version updated for https://github.com/vaptinsights/security-scan-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed VAPT Insights Security Scan v1.0.0 Initial GitHub Marketplace release of the VAPT Insights Security Scan Action.
Features Generates CycloneDX SBOMs using Trivy Uploads SBOM results securely to VAPT Insights Supports complete repository scans Supports nested application folders Supports matrix-based monorepo service scanning Uses commit SHA values for artifact versioning Supports custom artifact names and versions Usage - name: Run VAPT Insights Security Scan uses: vaptinsights/security-scan-action@v1 with: api-key: ${{ secrets.VAPT_INSIGHTS_API_KEY }} scan-path: . artifact-name: ${{ github.event.repository.name }}</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vaptinsights/security-scan-action">https://github.com/vaptinsights/security-scan-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vapt-insights-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="vapt-insights-security-scan-v100">VAPT Insights Security Scan v1.0.0</h2>
<p>Initial GitHub Marketplace release of the VAPT Insights Security Scan Action.</p>
<h3 id="features">Features</h3>
<ul>
<li>Generates CycloneDX SBOMs using Trivy</li>
<li>Uploads SBOM results securely to VAPT Insights</li>
<li>Supports complete repository scans</li>
<li>Supports nested application folders</li>
<li>Supports matrix-based monorepo service scanning</li>
<li>Uses commit SHA values for artifact versioning</li>
<li>Supports custom artifact names and versions</li>
</ul>
<h3 id="usage">Usage</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">name</span>: <span style="color:#ae81ff">Run VAPT Insights Security Scan</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">vaptinsights/security-scan-action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.VAPT_INSIGHTS_API_KEY }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">scan-path</span>: <span style="color:#ae81ff">.</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">artifact-name</span>: <span style="color:#ae81ff">${{ github.event.repository.name }}</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/vibgrate-scan/</link><pubDate>Sat, 04 Jul 2026 14:23:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.704.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Vibgrate CLI 2026.704.1 Released 2026-07-04
Routine maintenance update for the CLI.
What changed Changed Maintenance release with internal improvements and dependency updates. Benchmarks Two-arm benchmark of this release against 2026.703.7, interleaved on one runner against the pinned corpus (157 metrics compared).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.704.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20267041">Vibgrate CLI 2026.704.1</h1>
<p><em>Released 2026-07-04</em></p>
<p>Routine maintenance update for the CLI.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>Maintenance release with internal improvements and dependency updates.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.703.7, interleaved on one runner against the pinned corpus (157 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>18437 count</td>
          <td>18433 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>6934 count</td>
          <td>6928 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.97 ratio</td>
          <td>0.97 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>606.80 ms</td>
          <td>606.80 ms</td>
      </tr>
  </tbody>
</table>
<p>4 regression(s) — published, not omitted:</p>
<ul>
<li>Definitions extracted (corpus total): 18437 → 18433 (-0.0%)</li>
<li>Call edges extracted (corpus total): 6934 → 6928 (-0.1%)</li>
<li>Definitions — ts: 4217 → 4213 (-0.1%)</li>
<li>Call edges — ts: 3215 → 3209 (-0.2%)</li>
</ul>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.704.1">https://vibgrate.com/changelog/cli/2026.704.1</a></p>
]]></content:encoded></item><item><title>Powderworks Housekeeping</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/powderworks-housekeeping/</link><pubDate>Sat, 04 Jul 2026 14:23:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/powderworks-housekeeping/</guid><description>Version updated for https://github.com/zmaril/housekeeping to version v1.4.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Captain dispatch: housekeeper captain --dispatch (action input dispatch: true) triggers every member’s self-audit immediately — new checks reach the fleet on demand, not a week of crons later; workflow_dispatch joins the required member triggers. Unknown keys are surfaced at both scales: [policy.*] typos fail the captain, .housekeeping.toml typos fail the audit. v1 fast-forwarded.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zmaril/housekeeping">https://github.com/zmaril/housekeeping</a></strong> to version <strong>v1.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/powderworks-housekeeping">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Captain dispatch: <code>housekeeper captain --dispatch</code> (action input <code>dispatch: true</code>) triggers every member&rsquo;s self-audit immediately — new checks reach the fleet on demand, not a week of crons later; workflow_dispatch joins the required member triggers. Unknown keys are surfaced at both scales: [policy.*] typos fail the captain, .housekeeping.toml typos fail the audit. <code>v1</code> fast-forwarded.</p>
]]></content:encoded></item><item><title>Send Email with MailKite</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/send-email-with-mailkite/</link><pubDate>Sat, 04 Jul 2026 06:24:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/send-email-with-mailkite/</guid><description>Version updated for https://github.com/mailkite/send-email-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Send email with MailKite from any workflow. See README for inputs + the inbound→repository_dispatch recipe.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mailkite/send-email-action">https://github.com/mailkite/send-email-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/send-email-with-mailkite">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Send email with MailKite from any workflow. See README for inputs + the inbound→repository_dispatch recipe.</p>
]]></content:encoded></item><item><title>Quorum consensus security scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/quorum-consensus-security-scan/</link><pubDate>Sat, 04 Jul 2026 06:23:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/quorum-consensus-security-scan/</guid><description>Version updated for https://github.com/Martinez1991/quorum-sec-scan to version v0.8.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog bf624853a310007127d7223e7f1c1952186b028f: Merge pull request #60 from Martinez1991/feat/action-advice-inputs (@Martinez1991) 1723f878b86eaab1925a57820f79ce9160b8ee96: feat(action): expose the advisory layer (–advice / AI / –fix) as inputs (@Martinez1991)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Martinez1991/quorum-sec-scan">https://github.com/Martinez1991/quorum-sec-scan</a></strong> to version <strong>v0.8.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/quorum-consensus-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>bf624853a310007127d7223e7f1c1952186b028f: Merge pull request #60 from Martinez1991/feat/action-advice-inputs (@Martinez1991)</li>
<li>1723f878b86eaab1925a57820f79ce9160b8ee96: feat(action): expose the advisory layer (&ndash;advice / AI / &ndash;fix) as inputs (@Martinez1991)</li>
</ul>
]]></content:encoded></item><item><title>Docker Swarm Deployment Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/docker-swarm-deployment-action/</link><pubDate>Sat, 04 Jul 2026 06:23:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/docker-swarm-deployment-action/</guid><description>Version updated for https://github.com/matchory/docker-swarm-deployment-action to version v1.2.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix: re-enable YAML merge keys dropped by js-yaml v5 by @Radiergummi in https://github.com/matchory/docker-swarm-deployment-action/pull/152 feat: active Compose → Swarm reconciliation by @Radiergummi in https://github.com/matchory/docker-swarm-deployment-action/pull/153 Full Changelog: https://github.com/matchory/docker-swarm-deployment-action/compare/v1.1...v1.2.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/matchory/docker-swarm-deployment-action">https://github.com/matchory/docker-swarm-deployment-action</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/docker-swarm-deployment-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: re-enable YAML merge keys dropped by js-yaml v5 by @Radiergummi in <a href="https://github.com/matchory/docker-swarm-deployment-action/pull/152">https://github.com/matchory/docker-swarm-deployment-action/pull/152</a></li>
<li>feat: active Compose → Swarm reconciliation by @Radiergummi in <a href="https://github.com/matchory/docker-swarm-deployment-action/pull/153">https://github.com/matchory/docker-swarm-deployment-action/pull/153</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/matchory/docker-swarm-deployment-action/compare/v1.1...v1.2.0">https://github.com/matchory/docker-swarm-deployment-action/compare/v1.1...v1.2.0</a></p>
]]></content:encoded></item><item><title>ansede-static</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/ansede-static/</link><pubDate>Sat, 04 Jul 2026 06:22:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/ansede-static/</guid><description>Version updated for https://github.com/mattybellx/Ansede to version v5.5.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [5.5.0] — 2026-07-03 Added Runtime framework-root detection (_detect_framework_root) — auto-detects framework/library repos from package metadata, enabling noise suppression on arbitrary cloned repos (not just known benchmark paths) Test-file noise policy (_is_test_file, _TEST_FILE_NOISE_RULES) — suppresses CWE-798/327/338 findings in test fixtures, examples, and demos Expanded framework-internal path markers — 60+ new patterns covering cloned campaign repos (py-flask/, js-express/, etc.) and installed packages Confidence downgrading for non-exempt framework-internal findings (0.5 cap) and test-file findings (0.6 cap) Changed rich moved to production dependencies — declared explicitly in pyproject.toml; guardrails updated to 10MB limit with rich allowlist CWE-617 severity: high → medium (error-handling, not direct exploit) CWE-532 severity: high → medium (information leak) README precision claims — replaced “0.4% FP rate” with honest “36-58% precision on web apps” Test count badge: 1,207 → 1,234 Fixed Framework noise suppression now works on cloned repos — previously only matched specific benchmark directory names; now catches py-flask/, js-express/, and 30+ common clone patterns FrameworkFingerprint made mutable — inspect_ast_node() and verify_endpoint_protection() can now set detected_framework at runtime verify_endpoint_protection checks default values — FastAPI = Depends(...) pattern (default value, not annotation) now detected Engineering Spec Compliance Phase 1.3: Dependency declaration (rich as prod dep) Phase 1.4: mypy --strict added to CI Phase 2.2: register_symbol, resolve_call, propagate_taint_cross_file in interprocedural.py Phase 2.3: FrameworkFingerprint.inspect_ast_node + verify_endpoint_protection Phase 2.4: Rule severity recalibration Phase 3.1: generate_remediation_snippet with 6 code-fix templates Phase 3.4: ProcessPoolExecutor parallel analysis Phase 3.5: safe_parse_target with 3-encoding fallback Phase 4.1: docs/rules/index.md rule catalog Phase 4.2: rules/custom_checks.yaml blueprint Phase 4.3: filter_findings_by_git_diff PR isolation</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mattybellx/Ansede">https://github.com/mattybellx/Ansede</a></strong> to version <strong>v5.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ansede-static">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="550--2026-07-03">[5.5.0] — 2026-07-03</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>Runtime framework-root detection</strong> (<code>_detect_framework_root</code>) — auto-detects framework/library repos from package metadata, enabling noise suppression on arbitrary cloned repos (not just known benchmark paths)</li>
<li><strong>Test-file noise policy</strong> (<code>_is_test_file</code>, <code>_TEST_FILE_NOISE_RULES</code>) — suppresses CWE-798/327/338 findings in test fixtures, examples, and demos</li>
<li><strong>Expanded framework-internal path markers</strong> — 60+ new patterns covering cloned campaign repos (<code>py-flask/</code>, <code>js-express/</code>, etc.) and installed packages</li>
<li><strong>Confidence downgrading</strong> for non-exempt framework-internal findings (0.5 cap) and test-file findings (0.6 cap)</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li><strong><code>rich</code> moved to production dependencies</strong> — declared explicitly in <code>pyproject.toml</code>; guardrails updated to 10MB limit with <code>rich</code> allowlist</li>
<li><strong>CWE-617 severity</strong>: <code>high</code> → <code>medium</code> (error-handling, not direct exploit)</li>
<li><strong>CWE-532 severity</strong>: <code>high</code> → <code>medium</code> (information leak)</li>
<li><strong>README precision claims</strong> — replaced &ldquo;0.4% FP rate&rdquo; with honest &ldquo;36-58% precision on web apps&rdquo;</li>
<li><strong>Test count badge</strong>: 1,207 → 1,234</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>Framework noise suppression now works on cloned repos</strong> — previously only matched specific benchmark directory names; now catches <code>py-flask/</code>, <code>js-express/</code>, and 30+ common clone patterns</li>
<li><strong><code>FrameworkFingerprint</code> made mutable</strong> — <code>inspect_ast_node()</code> and <code>verify_endpoint_protection()</code> can now set <code>detected_framework</code> at runtime</li>
<li><strong><code>verify_endpoint_protection</code> checks default values</strong> — FastAPI <code>= Depends(...)</code> pattern (default value, not annotation) now detected</li>
</ul>
<h3 id="engineering-spec-compliance">Engineering Spec Compliance</h3>
<ul>
<li>Phase 1.3: Dependency declaration (rich as prod dep)</li>
<li>Phase 1.4: <code>mypy --strict</code> added to CI</li>
<li>Phase 2.2: <code>register_symbol</code>, <code>resolve_call</code>, <code>propagate_taint_cross_file</code> in interprocedural.py</li>
<li>Phase 2.3: <code>FrameworkFingerprint.inspect_ast_node</code> + <code>verify_endpoint_protection</code></li>
<li>Phase 2.4: Rule severity recalibration</li>
<li>Phase 3.1: <code>generate_remediation_snippet</code> with 6 code-fix templates</li>
<li>Phase 3.4: <code>ProcessPoolExecutor</code> parallel analysis</li>
<li>Phase 3.5: <code>safe_parse_target</code> with 3-encoding fallback</li>
<li>Phase 4.1: <code>docs/rules/index.md</code> rule catalog</li>
<li>Phase 4.2: <code>rules/custom_checks.yaml</code> blueprint</li>
<li>Phase 4.3: <code>filter_findings_by_git_diff</code> PR isolation</li>
</ul>
]]></content:encoded></item><item><title>Synaptic PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/synaptic-pr-review/</link><pubDate>Sat, 04 Jul 2026 06:22:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/synaptic-pr-review/</guid><description>Version updated for https://github.com/minhphu102003/ai-pr-review-action to version v0.2.7.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v0.2.7 Fix: summary comment now updates in-place on re-review instead of duplicating (post_inline.py) Fix: new delete_issue_comment() helper for cleaning up stale OpenCode-created comments ( eview_context.py)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/minhphu102003/ai-pr-review-action">https://github.com/minhphu102003/ai-pr-review-action</a></strong> to version <strong>v0.2.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/synaptic-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v027">v0.2.7</h2>
<ul>
<li>Fix: summary comment now updates in-place on re-review instead of duplicating (<code>post_inline.py</code>)</li>
<li>Fix: new <code>delete_issue_comment()</code> helper for cleaning up stale OpenCode-created comments (<code> eview_context.py</code>)</li>
</ul>
]]></content:encoded></item><item><title>ModelBound Skill Check</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/modelbound-skill-check/</link><pubDate>Sat, 04 Jul 2026 06:21:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/modelbound-skill-check/</guid><description>Version updated for https://github.com/ModelBound/skill-check-action to version v1.1.4.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed GitHub Action that lints, trust-scores, and estimates token savings for agent skill files on every pull request via ModelBound.co context management tools.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ModelBound/skill-check-action">https://github.com/ModelBound/skill-check-action</a></strong> to version <strong>v1.1.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/modelbound-skill-check">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>GitHub Action that lints, trust-scores, and estimates token savings for agent skill files on every pull request via ModelBound.co context management tools.</p>
]]></content:encoded></item><item><title>Run AER Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/run-aer-tests/</link><pubDate>Sat, 04 Jul 2026 06:21:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/run-aer-tests/</guid><description>Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.7.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Version v1.2.7
Fix Resolving Class Names Shadowed By Local Variables</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/octoberswimmer/aer-dist">https://github.com/octoberswimmer/aer-dist</a></strong> to version <strong>v1.2.7</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-aer-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Version v1.2.7</p>
<ul>
<li>Fix Resolving Class Names Shadowed By Local Variables</li>
</ul>
]]></content:encoded></item><item><title>PatchFlow Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/patchflow-security-scan/</link><pubDate>Sat, 04 Jul 2026 06:20:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/patchflow-security-scan/</guid><description>Version updated for https://github.com/Patchflow-security/patchflow-cli to version v0.1.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed PatchFlow CLI v0.1.3 Benchmark Results (v1.0) 18 intentionally vulnerable repos: 100% recall, 918K LOC, 19 CWE categories 5 historical CVE repos: 100% recall, 387K LOC 10 clean repos: 0.094 HC/KLOC, 720K LOC See Benchmark Report v1.0 for details.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Patchflow-security/patchflow-cli">https://github.com/Patchflow-security/patchflow-cli</a></strong> to version <strong>v0.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/patchflow-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="patchflow-cli-v013">PatchFlow CLI v0.1.3</h2>
<h3 id="benchmark-results-v10">Benchmark Results (v1.0)</h3>
<ul>
<li>18 intentionally vulnerable repos: 100% recall, 918K LOC, 19 CWE categories</li>
<li>5 historical CVE repos: 100% recall, 387K LOC</li>
<li>10 clean repos: 0.094 HC/KLOC, 720K LOC</li>
</ul>
<p>See <a href="https://github.com/Patchflow-security/patchflow-benchmarks/blob/main/reports/BENCHMARK_REPORT_v1.0.md">Benchmark Report v1.0</a> for details.</p>
<h2 id="changelog">Changelog</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>6d6dcca8ab3e82afd29d15f6ec26254e80423fc1: fix(install): resolve PATH issues and add containerized install test matrix (Ghertil Abdelmalek <a href="mailto:ghertilabdelmalek@outlook.fr">ghertilabdelmalek@outlook.fr</a>)</li>
</ul>
<h3 id="other-changes">Other Changes</h3>
<ul>
<li>3fd6e36d76c27da5feb9148450e9d887c80c7350: PatchFlow CLI v0.1.2 — local-first security scanner with framework-aware SAST (Ghertil Abdelmalek <a href="mailto:ghertilabdelmalek@outlook.fr">ghertilabdelmalek@outlook.fr</a>)</li>
</ul>
]]></content:encoded></item><item><title>Setup xdrun</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/setup-xdrun/</link><pubDate>Sat, 04 Jul 2026 06:20:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/setup-xdrun/</guid><description>Version updated for https://github.com/phillarmonic/setup-drun to version v2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Drun v2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/phillarmonic/setup-drun">https://github.com/phillarmonic/setup-drun</a></strong> to version <strong>v2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-xdrun">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Drun v2</p>
]]></content:encoded></item><item><title>Polygraph MCP gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/polygraph-mcp-gate/</link><pubDate>Sat, 04 Jul 2026 06:19:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/polygraph-mcp-gate/</guid><description>Version updated for https://github.com/polygraphso/litmus to version litmus-v0.26.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed The lookup tools now attribute the calling agent — and the release pipeline publishes the MCP-registry listing automatically.
Client identity on lookups (#91): check_server, list_servers, and request_grade send the connected client’s handshake identity (name/version plus declared title, website, description, and capability keys such as sampling/roots) to polygraph.so’s aggregate per-agent usage counters. Software metadata only — nothing about the user is read or sent; all fields are optional server-side. Official MCP Registry auto-publish (#93): pushing a litmus-v* tag now also publishes server.json to registry.modelcontextprotocol.io via GitHub OIDC, with a fail-fast version-drift check. polygraph plugin 0.6.0: spawn pinned to this release (#92). No grading-semantics changes: litmus-v12 / litmus-skill-v2 unchanged.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/polygraphso/litmus">https://github.com/polygraphso/litmus</a></strong> to version <strong>litmus-v0.26.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/polygraph-mcp-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The lookup tools now attribute the calling agent — and the release pipeline publishes the MCP-registry listing automatically.</p>
<ul>
<li><strong>Client identity on lookups</strong> (#91): <code>check_server</code>, <code>list_servers</code>, and <code>request_grade</code> send the connected client&rsquo;s handshake identity (name/version plus declared title, website, description, and capability keys such as <code>sampling</code>/<code>roots</code>) to polygraph.so&rsquo;s aggregate per-agent usage counters. Software metadata only — nothing about the user is read or sent; all fields are optional server-side.</li>
<li><strong>Official MCP Registry auto-publish</strong> (#93): pushing a <code>litmus-v*</code> tag now also publishes <code>server.json</code> to registry.modelcontextprotocol.io via GitHub OIDC, with a fail-fast version-drift check.</li>
<li>polygraph plugin 0.6.0: spawn pinned to this release (#92).</li>
</ul>
<p>No grading-semantics changes: <code>litmus-v12</code> / <code>litmus-skill-v2</code> unchanged.</p>
]]></content:encoded></item><item><title>Generate Roq Site</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/generate-roq-site/</link><pubDate>Sat, 04 Jul 2026 06:19:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/generate-roq-site/</guid><description>Version updated for https://github.com/quarkiverse/quarkus-roq to version 2.1.5.
This action is used across all versions by 75 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Enhance Liquid-to-Qute converter for full Jekyll migration by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/978 Fix capture blocks in Jekyll converter blocks by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/982 Expand on how to use bundled sass output by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/984 Fix aliases to work with and without trailing slash by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/995 No co-authored by any LLM in commits. by @jtama in https://github.com/quarkiverse/quarkus-roq/pull/1000 Fix svg diagram rendering by @jtama in https://github.com/quarkiverse/quarkus-roq/pull/997 added code block menu language dropdown by @edewit in https://github.com/quarkiverse/quarkus-roq/pull/994 improved navigation by @edewit in https://github.com/quarkiverse/quarkus-roq/pull/990 Add tips on sanisation for Jekyll migration by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/983 Add utilities for converting Jekyll frontmatter to Roq equivalents by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/998 Hook migration into top-level build and parent by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/1004 Bump info.picocli:picocli from 4.7.5 to 4.7.7 by @dependabot[bot] in https://github.com/quarkiverse/quarkus-roq/pull/1010 Trivial formatting - tidy missing line break in root pom by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/1012 docs: custom search trigger section to Lunr Search documentation by @matheusandre1 in https://github.com/quarkiverse/quarkus-roq/pull/1016 ci: Update action versions for Java setup and GitHub Pages configuration by @matheusandre1 in https://github.com/quarkiverse/quarkus-roq/pull/1015 Add tests specifically checking slug overrides are honoured by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/1008 Add minimum Quarkus version requirement to release notes by @matheusandre1 in https://github.com/quarkiverse/quarkus-roq/pull/1014 Bump org.mvnpm.at.fortawesome:fontawesome-free from 7.2.0 to 7.3.0 by @dependabot[bot] in https://github.com/quarkiverse/quarkus-roq/pull/1017 fix: Enhance image handling for absolute paths in Page model by @matheusandre1 in https://github.com/quarkiverse/quarkus-roq/pull/1024 fix: handle null collections in getPosts method by @matheusandre1 in https://github.com/quarkiverse/quarkus-roq/pull/1023 Allow link defaults to be configured globally by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/1020 Support deeply nested data directories as grouped CDI beans by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/1011 Add list:whereExp filter for Jekyll where_exp migration by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/1021 Evaluate (sort of) conditional directives in asciidoc before yupiik header parsing by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/1003 docs: enhance SEO documentation with per-page meta tag configuration by @matheusandre1 in https://github.com/quarkiverse/quarkus-roq/pull/1025 Honour slug in frontmatter with sneaky path conditional by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/1028 docs: add holly-cummins as a contributor for code by @allcontributors[bot] in https://github.com/quarkiverse/quarkus-roq/pull/1032 docs: add myfear as a contributor for code by @allcontributors[bot] in https://github.com/quarkiverse/quarkus-roq/pull/1031 Add :dir placeholder to support slug overrides and nested paths by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/1013 Add dir segment placeholders by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/1027 Add quarkus-roq-plugin-og-image extension by @myfear in https://github.com/quarkiverse/quarkus-roq/pull/1007 Update Jekyll frontmatter converter for pagination and permalink migration by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/1039 Add linktree theme by @ia3andy in https://github.com/quarkiverse/quarkus-roq/pull/1043 Consistency em FlatMap in review jerome by @matheusandre1 in https://github.com/quarkiverse/quarkus-roq/pull/1038 Revert og-card plugin to unblock release by @ia3andy in https://github.com/quarkiverse/quarkus-roq/pull/1046 Fix theme:base codestart using default theme content by @ia3andy in https://github.com/quarkiverse/quarkus-roq/pull/1047 Jekyll migration: Add converter to transform _config.yml by @holly-cummins in https://github.com/quarkiverse/quarkus-roq/pull/991 Add medium-zoom for image zoom support by @mcruzdev in https://github.com/quarkiverse/quarkus-roq/pull/910 Introduce hybrid mode as a plugin by @ia3andy in https://github.com/quarkiverse/quarkus-roq/pull/1019 Add qute: false alias, CLI –version, alert styling, and collapsible sections by @ia3andy in https://github.com/quarkiverse/quarkus-roq/pull/1048 Bump current version to 2.1.5 by @ia3andy in https://github.com/quarkiverse/quarkus-roq/pull/1049 New Contributors @myfear made their first contribution in https://github.com/quarkiverse/quarkus-roq/pull/1007 Full Changelog: https://github.com/quarkiverse/quarkus-roq/compare/2.1.4...2.1.5</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/quarkiverse/quarkus-roq">https://github.com/quarkiverse/quarkus-roq</a></strong> to version <strong>2.1.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>75</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/generate-roq-site">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Enhance Liquid-to-Qute converter for full Jekyll migration by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/978">https://github.com/quarkiverse/quarkus-roq/pull/978</a></li>
<li>Fix capture blocks in Jekyll converter blocks by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/982">https://github.com/quarkiverse/quarkus-roq/pull/982</a></li>
<li>Expand on how to use bundled sass output by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/984">https://github.com/quarkiverse/quarkus-roq/pull/984</a></li>
<li>Fix aliases to work with and without trailing slash by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/995">https://github.com/quarkiverse/quarkus-roq/pull/995</a></li>
<li>No <code>co-authored by</code> any LLM in commits. by @jtama in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1000">https://github.com/quarkiverse/quarkus-roq/pull/1000</a></li>
<li>Fix svg diagram rendering by @jtama in <a href="https://github.com/quarkiverse/quarkus-roq/pull/997">https://github.com/quarkiverse/quarkus-roq/pull/997</a></li>
<li>added code block menu language dropdown by @edewit in <a href="https://github.com/quarkiverse/quarkus-roq/pull/994">https://github.com/quarkiverse/quarkus-roq/pull/994</a></li>
<li>improved navigation by @edewit in <a href="https://github.com/quarkiverse/quarkus-roq/pull/990">https://github.com/quarkiverse/quarkus-roq/pull/990</a></li>
<li>Add tips on sanisation for Jekyll migration by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/983">https://github.com/quarkiverse/quarkus-roq/pull/983</a></li>
<li>Add utilities for converting Jekyll frontmatter to Roq equivalents by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/998">https://github.com/quarkiverse/quarkus-roq/pull/998</a></li>
<li>Hook migration into top-level build and parent by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1004">https://github.com/quarkiverse/quarkus-roq/pull/1004</a></li>
<li>Bump info.picocli:picocli from 4.7.5 to 4.7.7 by @dependabot[bot] in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1010">https://github.com/quarkiverse/quarkus-roq/pull/1010</a></li>
<li>Trivial formatting - tidy missing line break in root pom by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1012">https://github.com/quarkiverse/quarkus-roq/pull/1012</a></li>
<li>docs: custom search trigger section to Lunr Search documentation by @matheusandre1 in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1016">https://github.com/quarkiverse/quarkus-roq/pull/1016</a></li>
<li>ci: Update action versions for Java setup and GitHub Pages configuration by @matheusandre1 in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1015">https://github.com/quarkiverse/quarkus-roq/pull/1015</a></li>
<li>Add tests specifically checking slug overrides are honoured by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1008">https://github.com/quarkiverse/quarkus-roq/pull/1008</a></li>
<li>Add minimum Quarkus version requirement to release notes by @matheusandre1 in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1014">https://github.com/quarkiverse/quarkus-roq/pull/1014</a></li>
<li>Bump org.mvnpm.at.fortawesome:fontawesome-free from 7.2.0 to 7.3.0 by @dependabot[bot] in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1017">https://github.com/quarkiverse/quarkus-roq/pull/1017</a></li>
<li>fix: Enhance image handling for absolute paths in Page model by @matheusandre1 in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1024">https://github.com/quarkiverse/quarkus-roq/pull/1024</a></li>
<li>fix: handle null collections in getPosts method by @matheusandre1 in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1023">https://github.com/quarkiverse/quarkus-roq/pull/1023</a></li>
<li>Allow link defaults to be configured globally by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1020">https://github.com/quarkiverse/quarkus-roq/pull/1020</a></li>
<li>Support deeply nested data directories as grouped CDI beans by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1011">https://github.com/quarkiverse/quarkus-roq/pull/1011</a></li>
<li>Add list:whereExp filter for Jekyll where_exp migration by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1021">https://github.com/quarkiverse/quarkus-roq/pull/1021</a></li>
<li>Evaluate (sort of) conditional directives in asciidoc before yupiik header parsing by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1003">https://github.com/quarkiverse/quarkus-roq/pull/1003</a></li>
<li>docs: enhance SEO documentation with per-page meta tag configuration by @matheusandre1 in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1025">https://github.com/quarkiverse/quarkus-roq/pull/1025</a></li>
<li>Honour slug in frontmatter with sneaky path conditional by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1028">https://github.com/quarkiverse/quarkus-roq/pull/1028</a></li>
<li>docs: add holly-cummins as a contributor for code by @allcontributors[bot] in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1032">https://github.com/quarkiverse/quarkus-roq/pull/1032</a></li>
<li>docs: add myfear as a contributor for code by @allcontributors[bot] in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1031">https://github.com/quarkiverse/quarkus-roq/pull/1031</a></li>
<li>Add :dir placeholder to support slug overrides and nested paths by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1013">https://github.com/quarkiverse/quarkus-roq/pull/1013</a></li>
<li>Add dir segment placeholders by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1027">https://github.com/quarkiverse/quarkus-roq/pull/1027</a></li>
<li>Add quarkus-roq-plugin-og-image extension by @myfear in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1007">https://github.com/quarkiverse/quarkus-roq/pull/1007</a></li>
<li>Update Jekyll frontmatter converter for pagination and permalink migration by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1039">https://github.com/quarkiverse/quarkus-roq/pull/1039</a></li>
<li>Add linktree theme by @ia3andy in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1043">https://github.com/quarkiverse/quarkus-roq/pull/1043</a></li>
<li>Consistency em FlatMap in review jerome by @matheusandre1 in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1038">https://github.com/quarkiverse/quarkus-roq/pull/1038</a></li>
<li>Revert og-card plugin to unblock release by @ia3andy in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1046">https://github.com/quarkiverse/quarkus-roq/pull/1046</a></li>
<li>Fix theme:base codestart using default theme content by @ia3andy in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1047">https://github.com/quarkiverse/quarkus-roq/pull/1047</a></li>
<li>Jekyll migration: Add converter to transform _config.yml  by @holly-cummins in <a href="https://github.com/quarkiverse/quarkus-roq/pull/991">https://github.com/quarkiverse/quarkus-roq/pull/991</a></li>
<li>Add medium-zoom for image zoom support by @mcruzdev in <a href="https://github.com/quarkiverse/quarkus-roq/pull/910">https://github.com/quarkiverse/quarkus-roq/pull/910</a></li>
<li>Introduce hybrid mode as a plugin by @ia3andy in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1019">https://github.com/quarkiverse/quarkus-roq/pull/1019</a></li>
<li>Add qute: false alias, CLI &ndash;version, alert styling, and collapsible sections by @ia3andy in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1048">https://github.com/quarkiverse/quarkus-roq/pull/1048</a></li>
<li>Bump current version to 2.1.5 by @ia3andy in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1049">https://github.com/quarkiverse/quarkus-roq/pull/1049</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@myfear made their first contribution in <a href="https://github.com/quarkiverse/quarkus-roq/pull/1007">https://github.com/quarkiverse/quarkus-roq/pull/1007</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/quarkiverse/quarkus-roq/compare/2.1.4...2.1.5">https://github.com/quarkiverse/quarkus-roq/compare/2.1.4...2.1.5</a></p>
]]></content:encoded></item><item><title>PR Explainer AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/pr-explainer-ai/</link><pubDate>Sat, 04 Jul 2026 06:17:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/pr-explainer-ai/</guid><description>Version updated for https://github.com/rafaeltorresng/pr-explainer-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Understanding is the new bottleneck Generates architectural background and change intuition from the PR diff Builds HTML flow diagrams and a code walkthrough Includes a 5-question interactive quiz for review comprehension Supports OpenRouter with configurable model selection Defaults to deepseek/deepseek-v4-flash How it works:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rafaeltorresng/pr-explainer-action">https://github.com/rafaeltorresng/pr-explainer-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pr-explainer-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="understanding-is-the-new-bottleneck">Understanding is the new bottleneck</h2>
<ul>
<li>Generates architectural background and change intuition from the PR diff</li>
<li>Builds HTML flow diagrams and a code walkthrough</li>
<li>Includes a 5-question interactive quiz for review comprehension</li>
<li>Supports OpenRouter with configurable model selection</li>
<li>Defaults to <code>deepseek/deepseek-v4-flash</code></li>
</ul>
<p>How it works:</p>
<ol>
<li>Computes the diff against the PR base branch</li>
<li>Skips oversized patches based on a configurable line threshold</li>
<li>Sends the diff to an OpenRouter model</li>
<li>Renders a standalone HTML artifact</li>
<li>Uploads the result to the workflow run and can comment on the PR</li>
</ol>
<p>Recommended usage:</p>
<ul>
<li><code>actions/checkout@v4</code> with <code>fetch-depth: 0</code></li>
<li><code>pull-requests: write</code> permission if PR comments are enabled</li>
<li><code>OPENROUTER_API_KEY</code> stored as a repository secret</li>
</ul>
]]></content:encoded></item><item><title>dotenv Seeder</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/dotenv-seeder/</link><pubDate>Sat, 04 Jul 2026 06:17:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/dotenv-seeder/</guid><description>Version updated for https://github.com/scrlkx/dotenv-seeder to version v2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/scrlkx/dotenv-seeder/compare/v1...v2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/scrlkx/dotenv-seeder">https://github.com/scrlkx/dotenv-seeder</a></strong> to version <strong>v2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/dotenv-seeder">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/scrlkx/dotenv-seeder/compare/v1...v2">https://github.com/scrlkx/dotenv-seeder/compare/v1...v2</a></p>
]]></content:encoded></item><item><title>ShipGate-ai</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/shipgate-ai/</link><pubDate>Sat, 04 Jul 2026 06:16:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/shipgate-ai/</guid><description>Version updated for https://github.com/ShipGate-ai/ShipGate to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed a bug which restricted allowlisted repos to be not processed as well.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ShipGate-ai/ShipGate">https://github.com/ShipGate-ai/ShipGate</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/shipgate-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Fixed a bug which restricted allowlisted repos to be not processed as well.</p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/bernstein-multi-agent-orchestration/</link><pubDate>Sat, 04 Jul 2026 06:16:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v2.14.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.14.0 Released 2026-07-04.
Multi-provider orchestration hardening. A large batch of correctness and run-safety fixes for real-codebase runs across mixed providers (Claude, OpenAI, OpenRouter, DeepSeek, MiniMax, Qwen, Gemini), contributed by @shanemmattner and finished to green.
Fixes Stalled-manager watchdog no longer misdiagnoses a healthy manager as an auth failure: a manager doing real root-cause investigation before it POSTs its first child task is no longer killed at a hardcoded deadline, the config override is honored, and the failure record names the real cause. (#2179) Failure classifier stops false-positive-killing healthy workers: bare-substring patterns (413, 429, 401, max_tokens, context window) no longer match structured tool-call log data; detection is anchored to real error shapes. (#2183) Janitor acceptance checks tolerate idiomatic worker paths: path_exists honors explicit globs and an opt-in fuzzy basename fallback, so a run where workers placed correct output at repo-idiomatic paths is not cascaded to a false sev1. (#2186) Injected .claude/skills/bernstein-*.md files are excluded from work-branch commits, so they stop causing a merge conflict on every worker merge. (#2187) Per-call token usage is priced and surfaced on the openai_agents provider path, so budget guards are no longer inert on non-Claude runs. Model pricing matches the most specific key first, so mini and flash variants price at their own rate instead of the parent model rate. strict_json_schema is disabled for non-OpenAI models that reject it, with diagnostic logging. Plus the rest of the 22-fix batch across adapters, tasks, cost, routing, quality, and observability. Features Tunable agent run-length limits: max_turns, an error-budget floor, and max_agent_runtime_s, configurable per run. Internal Pricing table extracted into a dependency-free cost.model_prices leaf so adapters can price a call without reaching scheduler internals; public create_pr API preserved; a diagnostic pre-call log that dumped request headers/body verbatim is now redacted.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v2.14.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v2140">v2.14.0</h1>
<p>Released 2026-07-04.</p>
<p>Multi-provider orchestration hardening. A large batch of correctness and run-safety fixes for real-codebase runs across mixed providers (Claude, OpenAI, OpenRouter, DeepSeek, MiniMax, Qwen, Gemini), contributed by @shanemmattner and finished to green.</p>
<h2 id="fixes">Fixes</h2>
<ul>
<li>Stalled-manager watchdog no longer misdiagnoses a healthy manager as an auth failure: a manager doing real root-cause investigation before it POSTs its first child task is no longer killed at a hardcoded deadline, the config override is honored, and the failure record names the real cause. (#2179)</li>
<li>Failure classifier stops false-positive-killing healthy workers: bare-substring patterns (413, 429, 401, max_tokens, context window) no longer match structured tool-call log data; detection is anchored to real error shapes. (#2183)</li>
<li>Janitor acceptance checks tolerate idiomatic worker paths: path_exists honors explicit globs and an opt-in fuzzy basename fallback, so a run where workers placed correct output at repo-idiomatic paths is not cascaded to a false sev1. (#2186)</li>
<li>Injected .claude/skills/bernstein-*.md files are excluded from work-branch commits, so they stop causing a merge conflict on every worker merge. (#2187)</li>
<li>Per-call token usage is priced and surfaced on the openai_agents provider path, so budget guards are no longer inert on non-Claude runs. Model pricing matches the most specific key first, so mini and flash variants price at their own rate instead of the parent model rate.</li>
<li>strict_json_schema is disabled for non-OpenAI models that reject it, with diagnostic logging.</li>
<li>Plus the rest of the 22-fix batch across adapters, tasks, cost, routing, quality, and observability.</li>
</ul>
<h2 id="features">Features</h2>
<ul>
<li>Tunable agent run-length limits: max_turns, an error-budget floor, and max_agent_runtime_s, configurable per run.</li>
</ul>
<h2 id="internal">Internal</h2>
<ul>
<li>Pricing table extracted into a dependency-free cost.model_prices leaf so adapters can price a call without reaching scheduler internals; public create_pr API preserved; a diagnostic pre-call log that dumped request headers/body verbatim is now redacted.</li>
</ul>
]]></content:encoded></item><item><title>Docker swarm stack deploy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/docker-swarm-stack-deploy/</link><pubDate>Sat, 04 Jul 2026 06:15:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/docker-swarm-stack-deploy/</guid><description>Version updated for https://github.com/spawnlab-dev/stack-deploy-action to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed hotfix: deps update and CVE fixes by @pradeepbbl in https://github.com/spawnlab-dev/stack-deploy-action/pull/27 Full Changelog: https://github.com/spawnlab-dev/stack-deploy-action/compare/v1...v1.0.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spawnlab-dev/stack-deploy-action">https://github.com/spawnlab-dev/stack-deploy-action</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/docker-swarm-stack-deploy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>hotfix: deps update and CVE fixes by @pradeepbbl in <a href="https://github.com/spawnlab-dev/stack-deploy-action/pull/27">https://github.com/spawnlab-dev/stack-deploy-action/pull/27</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/spawnlab-dev/stack-deploy-action/compare/v1...v1.0.2">https://github.com/spawnlab-dev/stack-deploy-action/compare/v1...v1.0.2</a></p>
]]></content:encoded></item><item><title>MS Teams Notification (Adaptive Card)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/ms-teams-notification-adaptive-card/</link><pubDate>Sat, 04 Jul 2026 06:15:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/ms-teams-notification-adaptive-card/</guid><description>Version updated for https://github.com/stackdone/ms-teams-notification to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed update (#1) (c033c3d) . (75037b1) fix (ab3960a) add . (2a8c9d9) Initial commit (15c66f4)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stackdone/ms-teams-notification">https://github.com/stackdone/ms-teams-notification</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ms-teams-notification-adaptive-card">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>update (#1) (c033c3d)</li>
<li>. (75037b1)</li>
<li>fix (ab3960a)</li>
<li>add . (2a8c9d9)</li>
<li>Initial commit (15c66f4)</li>
</ul>
]]></content:encoded></item><item><title>overllm</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/overllm/</link><pubDate>Sat, 04 Jul 2026 06:14:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/overllm/</guid><description>Version updated for https://github.com/theadamdanielsson/overllm to version v0.4.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Two deterministic model-hygiene rules.
deprecated-model: flags a model id that’s retired (the call 404s) or deprecated and scheduled for removal, and names the current model to switch to. Exact-match against a known list, so a live model or alias is never flagged. unsupported-params: flags temperature/top_p/top_k set on a model that rejects them — the OpenAI o-series and the newest Anthropic models, where the parameter is a no-op or a 400. Both stay silent when the model isn’t a plain string literal.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/theadamdanielsson/overllm">https://github.com/theadamdanielsson/overllm</a></strong> to version <strong>v0.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/overllm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Two deterministic model-hygiene rules.</p>
<ul>
<li><code>deprecated-model</code>: flags a <code>model</code> id that&rsquo;s retired (the call 404s) or deprecated and scheduled for removal, and names the current model to switch to. Exact-match against a known list, so a live model or alias is never flagged.</li>
<li><code>unsupported-params</code>: flags <code>temperature</code>/<code>top_p</code>/<code>top_k</code> set on a model that rejects them — the OpenAI o-series and the newest Anthropic models, where the parameter is a no-op or a 400.</li>
</ul>
<p>Both stay silent when the model isn&rsquo;t a plain string literal.</p>
]]></content:encoded></item><item><title>Expand AWS IAM Wildcards</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/expand-aws-iam-wildcards/</link><pubDate>Sat, 04 Jul 2026 06:14:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/expand-aws-iam-wildcards/</guid><description>Version updated for https://github.com/thekbb/expand-aws-iam-wildcards to version v1.2.7.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Update IAM action data by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/95 deps: bump the npm-dependencies group with 2 updates by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/94 check in codeQL config and workflow by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/98 deps: bump the npm-dependencies group with 6 updates by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/97 ci: bump zizmorcore/zizmor-action from 0.5.3 to 0.5.6 by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/96 Update IAM action data by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/99 deps: bump the npm-dependencies group with 5 updates by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/101 ci: bump codecov/codecov-action from 6.0.0 to 6.0.1 by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/100 ci: bump github/codeql-action from 4.35.3 to 4.36.0 by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/102 Update IAM action data by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/103 deps: bump the npm-dependencies group with 2 updates by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/104 Update IAM action data by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/105 deps: bump the npm-dependencies group with 5 updates by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/108 ci: bump actions/checkout from 6.0.2 to 6.0.3 by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/107 ci: bump github/codeql-action from 4.36.0 to 4.36.2 by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/109 ci: bump codecov/codecov-action from 6.0.1 to 7.0.0 by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/106 Update IAM action data by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/110 deps: bump the npm-dependencies group with 4 updates by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/111 Update IAM action data by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/112 fix release workflow sequencing by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/113 ci: bump actions/checkout from 6.0.3 to 7.0.0 by @dependabot[bot] in https://github.com/thekbb/expand-aws-iam-wildcards/pull/114 Update IAM action data by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/115 make release orchestration deterministic by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/116 Document release preflight checks by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/117 add 0th cut of release shell script by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/118 prep for v1.2.7 by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/119 reset versions to re-test release script by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/120 Prepare v1.2.7 release by @thekbb in https://github.com/thekbb/expand-aws-iam-wildcards/pull/121 Full Changelog: https://github.com/thekbb/expand-aws-iam-wildcards/compare/v1...v1.2.7</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/thekbb/expand-aws-iam-wildcards">https://github.com/thekbb/expand-aws-iam-wildcards</a></strong> to version <strong>v1.2.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/expand-aws-iam-wildcards">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Update IAM action data by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/95">https://github.com/thekbb/expand-aws-iam-wildcards/pull/95</a></li>
<li>deps: bump the npm-dependencies group with 2 updates by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/94">https://github.com/thekbb/expand-aws-iam-wildcards/pull/94</a></li>
<li>check in codeQL config and workflow by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/98">https://github.com/thekbb/expand-aws-iam-wildcards/pull/98</a></li>
<li>deps: bump the npm-dependencies group with 6 updates by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/97">https://github.com/thekbb/expand-aws-iam-wildcards/pull/97</a></li>
<li>ci: bump zizmorcore/zizmor-action from 0.5.3 to 0.5.6 by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/96">https://github.com/thekbb/expand-aws-iam-wildcards/pull/96</a></li>
<li>Update IAM action data by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/99">https://github.com/thekbb/expand-aws-iam-wildcards/pull/99</a></li>
<li>deps: bump the npm-dependencies group with 5 updates by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/101">https://github.com/thekbb/expand-aws-iam-wildcards/pull/101</a></li>
<li>ci: bump codecov/codecov-action from 6.0.0 to 6.0.1 by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/100">https://github.com/thekbb/expand-aws-iam-wildcards/pull/100</a></li>
<li>ci: bump github/codeql-action from 4.35.3 to 4.36.0 by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/102">https://github.com/thekbb/expand-aws-iam-wildcards/pull/102</a></li>
<li>Update IAM action data by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/103">https://github.com/thekbb/expand-aws-iam-wildcards/pull/103</a></li>
<li>deps: bump the npm-dependencies group with 2 updates by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/104">https://github.com/thekbb/expand-aws-iam-wildcards/pull/104</a></li>
<li>Update IAM action data by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/105">https://github.com/thekbb/expand-aws-iam-wildcards/pull/105</a></li>
<li>deps: bump the npm-dependencies group with 5 updates by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/108">https://github.com/thekbb/expand-aws-iam-wildcards/pull/108</a></li>
<li>ci: bump actions/checkout from 6.0.2 to 6.0.3 by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/107">https://github.com/thekbb/expand-aws-iam-wildcards/pull/107</a></li>
<li>ci: bump github/codeql-action from 4.36.0 to 4.36.2 by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/109">https://github.com/thekbb/expand-aws-iam-wildcards/pull/109</a></li>
<li>ci: bump codecov/codecov-action from 6.0.1 to 7.0.0 by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/106">https://github.com/thekbb/expand-aws-iam-wildcards/pull/106</a></li>
<li>Update IAM action data by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/110">https://github.com/thekbb/expand-aws-iam-wildcards/pull/110</a></li>
<li>deps: bump the npm-dependencies group with 4 updates by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/111">https://github.com/thekbb/expand-aws-iam-wildcards/pull/111</a></li>
<li>Update IAM action data by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/112">https://github.com/thekbb/expand-aws-iam-wildcards/pull/112</a></li>
<li>fix release workflow sequencing by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/113">https://github.com/thekbb/expand-aws-iam-wildcards/pull/113</a></li>
<li>ci: bump actions/checkout from 6.0.3 to 7.0.0 by @dependabot[bot] in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/114">https://github.com/thekbb/expand-aws-iam-wildcards/pull/114</a></li>
<li>Update IAM action data by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/115">https://github.com/thekbb/expand-aws-iam-wildcards/pull/115</a></li>
<li>make release orchestration deterministic by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/116">https://github.com/thekbb/expand-aws-iam-wildcards/pull/116</a></li>
<li>Document release preflight checks by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/117">https://github.com/thekbb/expand-aws-iam-wildcards/pull/117</a></li>
<li>add 0th cut of release shell script by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/118">https://github.com/thekbb/expand-aws-iam-wildcards/pull/118</a></li>
<li>prep for v1.2.7 by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/119">https://github.com/thekbb/expand-aws-iam-wildcards/pull/119</a></li>
<li>reset versions to re-test release script by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/120">https://github.com/thekbb/expand-aws-iam-wildcards/pull/120</a></li>
<li>Prepare v1.2.7 release by @thekbb in <a href="https://github.com/thekbb/expand-aws-iam-wildcards/pull/121">https://github.com/thekbb/expand-aws-iam-wildcards/pull/121</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/thekbb/expand-aws-iam-wildcards/compare/v1...v1.2.7">https://github.com/thekbb/expand-aws-iam-wildcards/compare/v1...v1.2.7</a></p>
]]></content:encoded></item><item><title>MIU PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/miu-pr-review/</link><pubDate>Sat, 04 Jul 2026 06:13:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/miu-pr-review/</guid><description>Version updated for https://github.com/vanducng/miu-cr to version v0.85.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed miu-cr v0.85.1 AI code review for local changes and GitHub pull requests. Use it as a CLI, CI gate, or GitHub Action with your own LLM key.
Install curl -fsSL https://cr.miu.sh/install.sh | sh -s -- v0.85.1 brew install vanducng/tap/miucr go install github.com/vanducng/miu-cr/cmd/miucr@v0.85.1 GitHub Action:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vanducng/miu-cr">https://github.com/vanducng/miu-cr</a></strong> to version <strong>v0.85.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/miu-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="miu-cr-v0851">miu-cr v0.85.1</h2>
<p>AI code review for local changes and GitHub pull requests. Use it as a CLI, CI gate, or GitHub Action with your own LLM key.</p>
<h3 id="install">Install</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>curl -fsSL https://cr.miu.sh/install.sh | sh -s -- v0.85.1
</span></span><span style="display:flex;"><span>brew install vanducng/tap/miucr
</span></span><span style="display:flex;"><span>go install github.com/vanducng/miu-cr/cmd/miucr@v0.85.1
</span></span></code></pre></div><p>GitHub Action:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v6</span>
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">vanducng/miu-cr@v0.85.1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span></code></pre></div><h3 id="common-commands">Common commands</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>miucr login --provider openai
</span></span><span style="display:flex;"><span>miucr review --staged
</span></span><span style="display:flex;"><span>miucr review --from main --to HEAD --gate high
</span></span><span style="display:flex;"><span>miucr review --pr owner/repo#123 --post
</span></span><span style="display:flex;"><span>miucr upgrade
</span></span></code></pre></div><p>Docs: <a href="https://cr.miu.sh">https://cr.miu.sh</a></p>
]]></content:encoded></item><item><title>install spaces</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/install-spaces/</link><pubDate>Sat, 04 Jul 2026 06:12:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/install-spaces/</guid><description>Version updated for https://github.com/work-spaces/install-spaces to version v0.17.2.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump version to v0.17.2 by @tyler-gilbert in https://github.com/work-spaces/install-spaces/pull/33 Full Changelog: https://github.com/work-spaces/install-spaces/compare/v0.17.1...v0.17.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/work-spaces/install-spaces">https://github.com/work-spaces/install-spaces</a></strong> to version <strong>v0.17.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-spaces">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump version to v0.17.2 by @tyler-gilbert in <a href="https://github.com/work-spaces/install-spaces/pull/33">https://github.com/work-spaces/install-spaces/pull/33</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/work-spaces/install-spaces/compare/v0.17.1...v0.17.2">https://github.com/work-spaces/install-spaces/compare/v0.17.1...v0.17.2</a></p>
]]></content:encoded></item><item><title>spaces checkout run</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/spaces-checkout-run/</link><pubDate>Sat, 04 Jul 2026 06:12:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/spaces-checkout-run/</guid><description>Version updated for https://github.com/work-spaces/spaces-checkout-run to version v0.17.2.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump version to v0.17.2 by @tyler-gilbert in https://github.com/work-spaces/spaces-checkout-run/pull/27 Full Changelog: https://github.com/work-spaces/spaces-checkout-run/compare/v0.17.1...v0.17.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/work-spaces/spaces-checkout-run">https://github.com/work-spaces/spaces-checkout-run</a></strong> to version <strong>v0.17.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spaces-checkout-run">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump version to v0.17.2 by @tyler-gilbert in <a href="https://github.com/work-spaces/spaces-checkout-run/pull/27">https://github.com/work-spaces/spaces-checkout-run/pull/27</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/work-spaces/spaces-checkout-run/compare/v0.17.1...v0.17.2">https://github.com/work-spaces/spaces-checkout-run/compare/v0.17.1...v0.17.2</a></p>
]]></content:encoded></item><item><title>Move Closed Issue to Top of Project Column</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/move-closed-issue-to-top-of-project-column/</link><pubDate>Sat, 04 Jul 2026 06:11:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/move-closed-issue-to-top-of-project-column/</guid><description>Version updated for https://github.com/wozaki/project-closed-issue-move-to-top-action to version v1.19.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed uses: wozaki/project-closed-issue-move-to-top-action@0636114292c9298d48a87622a2e25e5636ebe6d5 # v1.19.0 What’s Changed chore(deps): update int128/release-typescript-action action to v1.74.0 by @renovate[bot] in https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/147 chore(deps): lock file maintenance by @renovate[bot] in https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/148 Full Changelog: https://github.com/wozaki/project-closed-issue-move-to-top-action/compare/v1.18.0...v1.19.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wozaki/project-closed-issue-move-to-top-action">https://github.com/wozaki/project-closed-issue-move-to-top-action</a></strong> to version <strong>v1.19.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/move-closed-issue-to-top-of-project-column">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">uses</span>: <span style="color:#ae81ff">wozaki/project-closed-issue-move-to-top-action@0636114292c9298d48a87622a2e25e5636ebe6d5</span> <span style="color:#75715e"># v1.19.0</span>
</span></span></code></pre></div><h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): update int128/release-typescript-action action to v1.74.0 by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/147">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/147</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/148">https://github.com/wozaki/project-closed-issue-move-to-top-action/pull/148</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/wozaki/project-closed-issue-move-to-top-action/compare/v1.18.0...v1.19.0">https://github.com/wozaki/project-closed-issue-move-to-top-action/compare/v1.18.0...v1.19.0</a></p>
]]></content:encoded></item><item><title>Setup Modern C++ Development Environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/setup-modern-c-development-environment/</link><pubDate>Sat, 04 Jul 2026 06:11:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/setup-modern-c-development-environment/</guid><description>Version updated for https://github.com/wx257osn2/cxx_environment to version v3.5.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed fix fatal error</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wx257osn2/cxx_environment">https://github.com/wx257osn2/cxx_environment</a></strong> to version <strong>v3.5.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-modern-c-development-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>fix fatal error</p>
]]></content:encoded></item><item><title>Powderworks Housekeeping</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/powderworks-housekeeping/</link><pubDate>Sat, 04 Jul 2026 06:10:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/04/powderworks-housekeeping/</guid><description>Version updated for https://github.com/zmaril/housekeeping to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Marketplace-valid action metadata: display name “Powderworks Housekeeping”, description under 125 characters. The uses: zmaril/housekeeping@v1 interface is unchanged.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/zmaril/housekeeping">https://github.com/zmaril/housekeeping</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/powderworks-housekeeping">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Marketplace-valid action metadata: display name &ldquo;Powderworks Housekeeping&rdquo;, description under 125 characters. The <code>uses: zmaril/housekeeping@v1</code> interface is unchanged.</p>
]]></content:encoded></item><item><title>Setup Smurf</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/setup-smurf/</link><pubDate>Fri, 03 Jul 2026 22:16:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/setup-smurf/</guid><description>Version updated for https://github.com/clouddrove/smurf to version v1.1.5.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v1.1.5 (2026-07-03) Build deps: bump clouddrove/github-shared-workflows/.github/workflows/pr-checks.yml deps: bump helm.sh/helm/v3 from 3.21.1 to 3.21.2 (#432) deps: bump clouddrove/github-shared-workflows/.github/workflows/pr-checks.yml deps: bump actions/cache from 5 to 6 deps: bump msgpack deps: bump github.com/containerd/containerd deps: bump actions/checkout from 6 to 7 deps: bump github.com/Azure/azure-sdk-for-go/sdk/azidentity deps: bump k8s.io/apimachinery from 0.36.1 to 0.36.2 deps: bump the pip group across 1 directory with 2 updates deps: bump helm.sh/helm/v3 from 3.21.0 to 3.21.1 (#426) Fix add pod logs before pod down fix deployment validation for completed Kubernetes Job pods (#430) selm: update smurf selm log structure for failure pod Pull Requests Merge pull request #438 from clouddrove/fix/selm-logs Merge pull request #437 from clouddrove/dependabot/github_actions/clouddrove/github-shared-workflows/dot-github/workflows/pr-checks.yml-f6ef7e54f3a1f4e2a05a66ed1a8702c07ae94346 Merge pull request #436 from clouddrove/dependabot/github_actions/clouddrove/github-shared-workflows/dot-github/workflows/pr-checks.yml-5a15692ae38a05cc3aa3b7ab6744add91e9b8591 Merge pull request #433 from clouddrove/dependabot/go_modules/go_modules-6e0011ac6e Merge pull request #434 from clouddrove/dependabot/pip/docs/sm/docs/pip-b15cf8365f Merge pull request #435 from clouddrove/dependabot/github_actions/actions/cache-6 Merge pull request #431 from clouddrove/dependabot/github_actions/actions/checkout-7 Merge pull request #428 from clouddrove/dependabot/go_modules/k8s.io/apimachinery-0.36.2 Merge pull request #429 from clouddrove/dependabot/go_modules/github.com/Azure/azure-sdk-for-go/sdk/azidentity-1.14.0 Merge pull request #427 from clouddrove/dependabot/pip/docs/sm/docs/pip-cdb1555457</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/clouddrove/smurf">https://github.com/clouddrove/smurf</a></strong> to version <strong>v1.1.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-smurf">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><a name="v1.1.5"></a></p>
<h2 id="v115-2026-07-03"><a href="https://github.com/clouddrove/smurf/compare/v1.1.4...v1.1.5">v1.1.5</a> (2026-07-03)</h2>
<h3 id="build">Build</h3>
<ul>
<li><strong>deps:</strong> bump clouddrove/github-shared-workflows/.github/workflows/pr-checks.yml</li>
<li><strong>deps:</strong> bump helm.sh/helm/v3 from 3.21.1 to 3.21.2 (<a href="https://github.com/clouddrove/smurf/issues/432">#432</a>)</li>
<li><strong>deps:</strong> bump clouddrove/github-shared-workflows/.github/workflows/pr-checks.yml</li>
<li><strong>deps:</strong> bump actions/cache from 5 to 6</li>
<li><strong>deps:</strong> bump msgpack</li>
<li><strong>deps:</strong> bump github.com/containerd/containerd</li>
<li><strong>deps:</strong> bump actions/checkout from 6 to 7</li>
<li><strong>deps:</strong> bump github.com/Azure/azure-sdk-for-go/sdk/azidentity</li>
<li><strong>deps:</strong> bump k8s.io/apimachinery from 0.36.1 to 0.36.2</li>
<li><strong>deps:</strong> bump the pip group across 1 directory with 2 updates</li>
<li><strong>deps:</strong> bump helm.sh/helm/v3 from 3.21.0 to 3.21.1 (<a href="https://github.com/clouddrove/smurf/issues/426">#426</a>)</li>
</ul>
<h3 id="fix">Fix</h3>
<ul>
<li>add pod logs before pod down</li>
<li>fix deployment validation for completed Kubernetes Job pods (<a href="https://github.com/clouddrove/smurf/issues/430">#430</a>)</li>
<li><strong>selm:</strong> update smurf selm log structure for failure pod</li>
</ul>
<h3 id="pull-requests">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/438">#438</a> from clouddrove/fix/selm-logs</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/437">#437</a> from clouddrove/dependabot/github_actions/clouddrove/github-shared-workflows/dot-github/workflows/pr-checks.yml-f6ef7e54f3a1f4e2a05a66ed1a8702c07ae94346</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/436">#436</a> from clouddrove/dependabot/github_actions/clouddrove/github-shared-workflows/dot-github/workflows/pr-checks.yml-5a15692ae38a05cc3aa3b7ab6744add91e9b8591</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/433">#433</a> from clouddrove/dependabot/go_modules/go_modules-6e0011ac6e</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/434">#434</a> from clouddrove/dependabot/pip/docs/sm/docs/pip-b15cf8365f</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/435">#435</a> from clouddrove/dependabot/github_actions/actions/cache-6</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/431">#431</a> from clouddrove/dependabot/github_actions/actions/checkout-7</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/428">#428</a> from clouddrove/dependabot/go_modules/k8s.io/apimachinery-0.36.2</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/429">#429</a> from clouddrove/dependabot/go_modules/github.com/Azure/azure-sdk-for-go/sdk/azidentity-1.14.0</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/427">#427</a> from clouddrove/dependabot/pip/docs/sm/docs/pip-cdb1555457</li>
</ul>
<p><a name="v1.1.4"></a></p>
<h2 id="v114-2026-05-27"><a href="https://github.com/clouddrove/smurf/compare/v1.1.3...v1.1.4">v1.1.4</a> (2026-05-27)</h2>
<h3 id="build-1">Build</h3>
<ul>
<li><strong>deps:</strong> bump clouddrove/github-shared-workflows/.github/workflows/pr-checks.yml</li>
<li><strong>deps:</strong> bump k8s.io/apimachinery from 0.35.4 to 0.36.1 (<a href="https://github.com/clouddrove/smurf/issues/412">#412</a>)</li>
<li><strong>deps:</strong> bump clouddrove/github-shared-workflows/.github/workflows/release-tag.yml (<a href="https://github.com/clouddrove/smurf/issues/413">#413</a>)</li>
<li><strong>deps:</strong> bump clouddrove/github-shared-workflows/.github/workflows/pr-checks.yml (<a href="https://github.com/clouddrove/smurf/issues/414">#414</a>)</li>
<li><strong>deps:</strong> bump helm.sh/helm/v3 from 3.20.2 to 3.21.0 (<a href="https://github.com/clouddrove/smurf/issues/415">#415</a>)</li>
<li><strong>deps:</strong> bump clouddrove/github-shared-workflows/.github/workflows/pr-checks.yml</li>
<li><strong>deps:</strong> bump clouddrove/github-shared-workflows/.github/workflows/release-tag.yml</li>
<li><strong>deps:</strong> bump urllib3</li>
<li><strong>deps:</strong> bump clouddrove/github-shared-workflows/.github/workflows/release-tag.yml</li>
<li><strong>deps:</strong> bump clouddrove/github-shared-workflows/.github/workflows/pr-checks.yml</li>
</ul>
<h3 id="fix-1">Fix</h3>
<ul>
<li>Upgrade Go Version and Remove Auto Release Tag Creation from Workflows (<a href="https://github.com/clouddrove/smurf/issues/419">#419</a>)</li>
</ul>
<h3 id="pull-requests-1">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/423">#423</a> from clouddrove/dependabot/github_actions/clouddrove/github-shared-workflows/dot-github/workflows/pr-checks.yml-ca8d61c90f059d7ed8c3fc608877d19cc5d965f5</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/410">#410</a> from clouddrove/dependabot/github_actions/clouddrove/github-shared-workflows/dot-github/workflows/release-tag.yml-4b2ff708285026c1211445c4acb213af1c6ff3ba</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/411">#411</a> from clouddrove/dependabot/github_actions/clouddrove/github-shared-workflows/dot-github/workflows/pr-checks.yml-4b2ff708285026c1211445c4acb213af1c6ff3ba</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/409">#409</a> from clouddrove/dependabot/pip/docs/sm/docs/pip-c30c77f42d</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/407">#407</a> from clouddrove/dependabot/github_actions/clouddrove/github-shared-workflows/dot-github/workflows/pr-checks.yml-c165f939ce9ad3de94da8fc50b3368565bea4fda</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/408">#408</a> from clouddrove/dependabot/github_actions/clouddrove/github-shared-workflows/dot-github/workflows/release-tag.yml-c165f939ce9ad3de94da8fc50b3368565bea4fda</li>
</ul>
<p><a name="v1.1.3"></a></p>
<h2 id="v113-2026-05-05"><a href="https://github.com/clouddrove/smurf/compare/v1.1.2...v1.1.3">v1.1.3</a> (2026-05-05)</h2>
<h3 id="build-2">Build</h3>
<ul>
<li><strong>deps:</strong> bump clouddrove/github-shared-workflows/.github/workflows/release-tag.yml</li>
<li><strong>deps:</strong> bump clouddrove/github-shared-workflows/.github/workflows/pr-checks.yml</li>
</ul>
<h3 id="docs">Docs</h3>
<ul>
<li>update CHANGELOG.md for v1.1.2</li>
</ul>
<h3 id="fix-2">Fix</h3>
<ul>
<li><strong>provisionGHCR:</strong> add warning for get environment variable (<a href="https://github.com/clouddrove/smurf/issues/403">#403</a>)</li>
</ul>
<h3 id="pull-requests-2">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/405">#405</a> from clouddrove/dependabot/github_actions/clouddrove/github-shared-workflows/dot-github/workflows/pr-checks.yml-c0dc8f22e1836ac0a76ee7a7d9f4c2e30e5293e8</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/406">#406</a> from clouddrove/dependabot/github_actions/clouddrove/github-shared-workflows/dot-github/workflows/release-tag.yml-c0dc8f22e1836ac0a76ee7a7d9f4c2e30e5293e8</li>
</ul>
<p><a name="v1.1.2"></a></p>
<h2 id="v112-2026-04-30"><a href="https://github.com/clouddrove/smurf/compare/v1.1.1...v1.1.2">v1.1.2</a> (2026-04-30)</h2>
<h3 id="build-3">Build</h3>
<ul>
<li><strong>deps:</strong> bump github.com/hashicorp/terraform-exec</li>
<li><strong>deps:</strong> bump clouddrove/github-shared-workflows/.github/workflows/release-tag.yml</li>
<li><strong>deps:</strong> bump clouddrove/github-shared-workflows/.github/workflows/pr-checks.yml</li>
<li><strong>deps:</strong> bump go.opentelemetry.io/otel</li>
<li><strong>deps:</strong> bump clouddrove/github-shared-workflows/.github/workflows/pr-checks.yml</li>
<li><strong>deps:</strong> bump clouddrove/github-shared-workflows/.github/workflows/release-tag.yml</li>
</ul>
<h3 id="fix-3">Fix</h3>
<ul>
<li>replace ANSI escape sequences with pterm for safe, consistent show command output (<a href="https://github.com/clouddrove/smurf/issues/397">#397</a>)</li>
<li>update go version 1.25.5 to 1.25.8 (<a href="https://github.com/clouddrove/smurf/issues/396">#396</a>)</li>
</ul>
<h3 id="pull-requests-3">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/404">#404</a> from clouddrove/dependabot/go_modules/github.com/hashicorp/terraform-exec-0.25.2</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/401">#401</a> from clouddrove/dependabot/github_actions/clouddrove/github-shared-workflows/dot-github/workflows/pr-checks.yml-0d9fa74b29d820d7ffe031704ec53bf7653c97c3</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/402">#402</a> from clouddrove/dependabot/github_actions/clouddrove/github-shared-workflows/dot-github/workflows/release-tag.yml-0d9fa74b29d820d7ffe031704ec53bf7653c97c3</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/400">#400</a> from clouddrove/dependabot/go_modules/go_modules-c9a791322e</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/392">#392</a> from clouddrove/dependabot/github_actions/clouddrove/github-shared-workflows/dot-github/workflows/release-tag.yml-21cd5a8d11a5f01560103ac3fcae05835e9e3699</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/393">#393</a> from clouddrove/dependabot/github_actions/clouddrove/github-shared-workflows/dot-github/workflows/pr-checks.yml-21cd5a8d11a5f01560103ac3fcae05835e9e3699</li>
</ul>
<p><a name="v1.1.1"></a></p>
<h2 id="v111-2026-04-23"><a href="https://github.com/clouddrove/smurf/compare/v1.1.1-beta...v1.1.1">v1.1.1</a> (2026-04-23)</h2>
<h3 id="fix-4">Fix</h3>
<ul>
<li>replace ANSI escape sequences with pterm for safe, consistent show command output</li>
</ul>
<p><a name="v1.1.1-beta"></a></p>
<h2 id="v111-beta-2026-04-23"><a href="https://github.com/clouddrove/smurf/compare/v1.0.11...v1.1.1-beta">v1.1.1-beta</a> (2026-04-23)</h2>
<h3 id="build-4">Build</h3>
<ul>
<li><strong>deps:</strong> bump clouddrove/github-shared-workflows/.github/workflows/pr-checks.yml</li>
<li><strong>deps:</strong> bump clouddrove/github-shared-workflows/.github/workflows/release-tag.yml</li>
</ul>
<h3 id="feat">Feat</h3>
<ul>
<li>add smurf stf show command and fixed issue raised by clouddrove ci (<a href="https://github.com/clouddrove/smurf/issues/388">#388</a>)</li>
</ul>
<h3 id="pull-requests-4">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/392">#392</a> from clouddrove/dependabot/github_actions/clouddrove/github-shared-workflows/dot-github/workflows/release-tag.yml-21cd5a8d11a5f01560103ac3fcae05835e9e3699</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/393">#393</a> from clouddrove/dependabot/github_actions/clouddrove/github-shared-workflows/dot-github/workflows/pr-checks.yml-21cd5a8d11a5f01560103ac3fcae05835e9e3699</li>
</ul>
<p><a name="v1.0.11"></a></p>
<h2 id="v1011-2026-04-17"><a href="https://github.com/clouddrove/smurf/compare/v1.1.0...v1.0.11">v1.0.11</a> (2026-04-17)</h2>
<p><a name="v1.1.0"></a></p>
<h2 id="v110-2026-04-17"><a href="https://github.com/clouddrove/smurf/compare/v1.0.10...v1.1.0">v1.1.0</a> (2026-04-17)</h2>
<h3 id="build-5">Build</h3>
<ul>
<li><strong>deps:</strong> bump k8s.io/client-go from 0.35.3 to 0.35.4</li>
</ul>
<h3 id="pull-requests-5">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/367">#367</a> from clouddrove/dependabot/go_modules/k8s.io/client-go-0.35.4</li>
</ul>
<p><a name="v1.0.10"></a></p>
<h2 id="v1010-2026-04-17"><a href="https://github.com/clouddrove/smurf/compare/v1.0.9...v1.0.10">v1.0.10</a> (2026-04-17)</h2>
<h3 id="build-6">Build</h3>
<ul>
<li><strong>deps:</strong> bump k8s.io/api from 0.35.3 to 0.35.4</li>
</ul>
<h3 id="pull-requests-6">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/368">#368</a> from clouddrove/dependabot/go_modules/k8s.io/api-0.35.4</li>
</ul>
<p><a name="v1.0.9"></a></p>
<h2 id="v109-2026-04-17"><a href="https://github.com/clouddrove/smurf/compare/v1.0.8...v1.0.9">v1.0.9</a> (2026-04-17)</h2>
<h3 id="build-7">Build</h3>
<ul>
<li><strong>deps:</strong> bump k8s.io/apimachinery from 0.35.3 to 0.35.4</li>
</ul>
<h3 id="pull-requests-7">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/369">#369</a> from clouddrove/dependabot/go_modules/k8s.io/apimachinery-0.35.4</li>
</ul>
<p><a name="v1.0.8"></a></p>
<h2 id="v108-2026-04-15"><a href="https://github.com/clouddrove/smurf/compare/v1.0.7...v1.0.8">v1.0.8</a> (2026-04-15)</h2>
<h3 id="build-8">Build</h3>
<ul>
<li><strong>deps:</strong> bump actions/upload-pages-artifact from 4 to 5</li>
<li><strong>deps:</strong> bump pillow</li>
<li><strong>deps:</strong> bump softprops/action-gh-release from 2 to 3</li>
<li><strong>deps:</strong> bump helm.sh/helm/v3 from 3.20.1 to 3.20.2</li>
</ul>
<h3 id="feat-1">Feat</h3>
<ul>
<li>enhance smurf stf init with complete Terraform flags and implement GitHub shared workflows (<a href="https://github.com/clouddrove/smurf/issues/366">#366</a>)</li>
</ul>
<h3 id="pull-requests-8">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/365">#365</a> from clouddrove/dependabot/github_actions/actions/upload-pages-artifact-5</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/364">#364</a> from clouddrove/dependabot/pip/docs/sm/docs/pip-489ca64b8d</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/363">#363</a> from clouddrove/dependabot/github_actions/softprops/action-gh-release-3</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/362">#362</a> from clouddrove/dependabot/go_modules/helm.sh/helm/v3-3.20.2</li>
</ul>
<p><a name="v1.0.7"></a></p>
<h2 id="v107-2026-04-08"><a href="https://github.com/clouddrove/smurf/compare/v1.0.6...v1.0.7">v1.0.7</a> (2026-04-08)</h2>
<h3 id="feat-2">Feat</h3>
<ul>
<li>add github shared workflows and add smurf stf init flags</li>
</ul>
<p><a name="v1.0.6"></a></p>
<h2 id="v106-2026-04-06"><a href="https://github.com/clouddrove/smurf/compare/v1.0.5...v1.0.6">v1.0.6</a> (2026-04-06)</h2>
<h3 id="fix-5">Fix</h3>
<ul>
<li><strong>plan:</strong> Update terraform plan logs structure remove repeated lines</li>
<li><strong>plan:</strong> Update terraform plan logs structure</li>
</ul>
<p><a name="v1.0.5"></a></p>
<h2 id="v105-2026-04-06"><a href="https://github.com/clouddrove/smurf/compare/v1.0.4...v1.0.5">v1.0.5</a> (2026-04-06)</h2>
<h3 id="fix-6">Fix</h3>
<ul>
<li><strong>plan:</strong> Update terraform plan logs structure</li>
</ul>
<p><a name="v1.0.4"></a></p>
<h2 id="v104-2026-04-03"><a href="https://github.com/clouddrove/smurf/compare/v1.0.3...v1.0.4">v1.0.4</a> (2026-04-03)</h2>
<h3 id="fix-7">Fix</h3>
<ul>
<li>Add support for applying Terraform plan file (tfplan) without manual approval in smurf stf (<a href="https://github.com/clouddrove/smurf/issues/359">#359</a>)</li>
</ul>
<p><a name="v1.0.3"></a></p>
<h2 id="v103-2026-04-02"><a href="https://github.com/clouddrove/smurf/compare/v1.0.2...v1.0.3">v1.0.3</a> (2026-04-02)</h2>
<h3 id="fix-8">Fix</h3>
<ul>
<li>fix go vet</li>
<li>resolve sonar qube issue</li>
</ul>
<p><a name="v1.0.2"></a></p>
<h2 id="v102-2026-04-01"><a href="https://github.com/clouddrove/smurf/compare/v1.0.1...v1.0.2">v1.0.2</a> (2026-04-01)</h2>
<h3 id="fix-9">Fix</h3>
<ul>
<li>resolve smurf stf plan and  apply auto approve issue</li>
</ul>
<p><a name="v1.0.1"></a></p>
<h2 id="v101-2026-04-01"><a href="https://github.com/clouddrove/smurf/compare/v1.0.1-beta...v1.0.1">v1.0.1</a> (2026-04-01)</h2>
<p><a name="v1.0.1-beta"></a></p>
<h2 id="v101-beta-2026-04-01"><a href="https://github.com/clouddrove/smurf/compare/v1.0.0...v1.0.1-beta">v1.0.1-beta</a> (2026-04-01)</h2>
<h3 id="build-9">Build</h3>
<ul>
<li><strong>deps:</strong> bump requests</li>
<li><strong>deps:</strong> bump actions/deploy-pages from 4 to 5</li>
<li><strong>deps:</strong> bump k8s.io/client-go from 0.35.2 to 0.35.3</li>
<li><strong>deps:</strong> bump github.com/fatih/color from 1.18.0 to 1.19.0</li>
<li><strong>deps:</strong> bump k8s.io/api from 0.35.2 to 0.35.3</li>
<li><strong>deps:</strong> bump google.golang.org/grpc</li>
<li><strong>deps:</strong> bump helm.sh/helm/v3 from 3.20.0 to 3.20.1</li>
<li><strong>deps:</strong> bump golang.org/x/oauth2 from 0.35.0 to 0.36.0</li>
<li><strong>deps:</strong> bump docker/setup-qemu-action from 3 to 4</li>
<li><strong>deps:</strong> bump docker/login-action from 3 to 4</li>
<li><strong>deps:</strong> bump k8s.io/client-go from 0.35.1 to 0.35.2</li>
<li><strong>deps:</strong> bump k8s.io/api from 0.35.1 to 0.35.2</li>
<li><strong>deps:</strong> bump actions/upload-artifact from 6 to 7</li>
<li><strong>deps:</strong> bump actions/download-artifact from 7 to 8</li>
<li><strong>deps:</strong> bump github.com/pterm/pterm from 0.12.82 to 0.12.83</li>
<li><strong>deps:</strong> bump hashicorp/setup-terraform from 3 to 4</li>
</ul>
<h3 id="fix-10">Fix</h3>
<ul>
<li>resolve smurf apply auto approve issue</li>
<li>update CHANGELOG.md file</li>
</ul>
<h3 id="pull-requests-9">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/357">#357</a> from clouddrove/dependabot/github_actions/actions/deploy-pages-5</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/358">#358</a> from clouddrove/dependabot/pip/docs/sm/docs/pip-aa7cb66ac2</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/354">#354</a> from clouddrove/dependabot/go_modules/k8s.io/client-go-0.35.3</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/352">#352</a> from clouddrove/dependabot/go_modules/go_modules-9c5197dcb8</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/355">#355</a> from clouddrove/dependabot/go_modules/k8s.io/api-0.35.3</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/356">#356</a> from clouddrove/dependabot/go_modules/github.com/fatih/color-1.19.0</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/340">#340</a> from clouddrove/fix/changelog</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/351">#351</a> from clouddrove/dependabot/go_modules/helm.sh/helm/v3-3.20.1</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/350">#350</a> from clouddrove/dependabot/go_modules/golang.org/x/oauth2-0.36.0</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/348">#348</a> from clouddrove/dependabot/github_actions/docker/login-action-4</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/349">#349</a> from clouddrove/dependabot/github_actions/docker/setup-qemu-action-4</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/343">#343</a> from clouddrove/dependabot/github_actions/actions/download-artifact-8</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/344">#344</a> from clouddrove/dependabot/github_actions/actions/upload-artifact-7</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/345">#345</a> from clouddrove/dependabot/go_modules/k8s.io/client-go-0.35.2</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/347">#347</a> from clouddrove/dependabot/go_modules/k8s.io/api-0.35.2</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/342">#342</a> from clouddrove/dependabot/go_modules/github.com/pterm/pterm-0.12.83</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/341">#341</a> from clouddrove/dependabot/github_actions/hashicorp/setup-terraform-4</li>
</ul>
<p><a name="v1.0.0"></a></p>
<h2 id="v100-2026-02-24"><a href="https://github.com/clouddrove/smurf/compare/v0.1.7-Beta...v1.0.0">v1.0.0</a> (2026-02-24)</h2>
<h3 id="build-10">Build</h3>
<ul>
<li><strong>deps:</strong> bump github.com/hashicorp/terraform-exec</li>
<li><strong>deps:</strong> bump pillow (<a href="https://github.com/clouddrove/smurf/issues/337">#337</a>)</li>
<li><strong>deps:</strong> bump k8s.io/api from 0.35.0 to 0.35.1</li>
<li><strong>deps:</strong> bump k8s.io/client-go from 0.35.0 to 0.35.1</li>
<li><strong>deps:</strong> bump golang.org/x/oauth2 from 0.34.0 to 0.35.0</li>
</ul>
<h3 id="pull-requests-10">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/338">#338</a> from clouddrove/dependabot/go_modules/github.com/hashicorp/terraform-exec-0.25.0</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/335">#335</a> from clouddrove/dependabot/go_modules/k8s.io/client-go-0.35.1</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/336">#336</a> from clouddrove/dependabot/go_modules/k8s.io/api-0.35.1</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/333">#333</a> from clouddrove/dependabot/go_modules/golang.org/x/oauth2-0.35.0</li>
</ul>
<p><a name="v0.1.7-Beta"></a></p>
<h2 id="v017-beta-2026-02-20"><a href="https://github.com/clouddrove/smurf/compare/v0.1.6-Beta...v0.1.7-Beta">v0.1.7-Beta</a> (2026-02-20)</h2>
<h3 id="fix-11">Fix</h3>
<ul>
<li>Update deploy command</li>
</ul>
<p><a name="v0.1.6-Beta"></a></p>
<h2 id="v016-beta-2026-02-18"><a href="https://github.com/clouddrove/smurf/compare/v0.1.5-Beta...v0.1.6-Beta">v0.1.6-Beta</a> (2026-02-18)</h2>
<h3 id="fix-12">Fix</h3>
<ul>
<li>smurf selm command update</li>
<li>scan and helm install command update</li>
</ul>
<p><a name="v0.1.5-Beta"></a></p>
<h2 id="v015-beta-2026-02-18"><a href="https://github.com/clouddrove/smurf/compare/v0.1.4-Beta...v0.1.5-Beta">v0.1.5-Beta</a> (2026-02-18)</h2>
<h3 id="feat-3">Feat</h3>
<ul>
<li>update plan commands</li>
<li>add states command</li>
<li>handle empty env variable</li>
</ul>
<h3 id="fix-13">Fix</h3>
<ul>
<li>scan and helm install command update</li>
<li>add parameter for release test</li>
<li>remove unused parameter</li>
<li>increase time out helm upgrade</li>
<li>update kubernetes function for error handling</li>
</ul>
<p><a name="v0.1.4-Beta"></a></p>
<h2 id="v014-beta-2026-01-27"><a href="https://github.com/clouddrove/smurf/compare/v0.1.3...v0.1.4-Beta">v0.1.4-Beta</a> (2026-01-27)</h2>
<h3 id="build-11">Build</h3>
<ul>
<li><strong>deps:</strong> bump helm.sh/helm/v3 from 3.19.5 to 3.20.0</li>
</ul>
<h3 id="pull-requests-11">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/331">#331</a> from clouddrove/dependabot/go_modules/helm.sh/helm/v3-3.20.0</li>
</ul>
<p><a name="v0.1.3"></a></p>
<h2 id="v013-2026-01-20"><a href="https://github.com/clouddrove/smurf/compare/v0.1.3-Beta...v0.1.3">v0.1.3</a> (2026-01-20)</h2>
<h3 id="pull-requests-12">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/330">#330</a> from clouddrove/fix/smurf-stf</li>
</ul>
<p><a name="v0.1.3-Beta"></a></p>
<h2 id="v013-beta-2026-01-20"><a href="https://github.com/clouddrove/smurf/compare/v0.1.2-Beta...v0.1.3-Beta">v0.1.3-Beta</a> (2026-01-20)</h2>
<p><a name="v0.1.2-Beta"></a></p>
<h2 id="v012-beta-2026-01-20"><a href="https://github.com/clouddrove/smurf/compare/v0.1.2...v0.1.2-Beta">v0.1.2-Beta</a> (2026-01-20)</h2>
<p><a name="v0.1.2"></a></p>
<h2 id="v012-2026-01-20"><a href="https://github.com/clouddrove/smurf/compare/v0.0.5-Beta...v0.1.2">v0.1.2</a> (2026-01-20)</h2>
<h3 id="build-12">Build</h3>
<ul>
<li><strong>deps:</strong> bump helm.sh/helm/v3 from 3.19.4 to 3.19.5</li>
<li><strong>deps:</strong> bump filelock</li>
<li><strong>deps:</strong> bump urllib3</li>
</ul>
<h3 id="pull-requests-13">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/329">#329</a> from clouddrove/feat/OCI-chart</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/326">#326</a> from clouddrove/feat/multi-threading</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/328">#328</a> from clouddrove/dependabot/go_modules/helm.sh/helm/v3-3.19.5</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/327">#327</a> from clouddrove/dependabot/pip/docs/sm/docs/pip-81c3d069c8</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/325">#325</a> from clouddrove/dependabot/pip/docs/sm/docs/pip-8177a8837a</li>
</ul>
<p><a name="v0.0.5-Beta"></a></p>
<h2 id="v005-beta-2026-01-20"><a href="https://github.com/clouddrove/smurf/compare/v0.0.4-Beta...v0.0.5-Beta">v0.0.5-Beta</a> (2026-01-20)</h2>
<p><a name="v0.0.4-Beta"></a></p>
<h2 id="v004-beta-2026-01-20"><a href="https://github.com/clouddrove/smurf/compare/v0.0.2-Beta...v0.0.4-Beta">v0.0.4-Beta</a> (2026-01-20)</h2>
<p><a name="v0.0.2-Beta"></a></p>
<h2 id="v002-beta-2026-01-20"><a href="https://github.com/clouddrove/smurf/compare/v0.0.3-Beta...v0.0.2-Beta">v0.0.2-Beta</a> (2026-01-20)</h2>
<p><a name="v0.0.3-Beta"></a></p>
<h2 id="v003-beta-2026-01-20"><a href="https://github.com/clouddrove/smurf/compare/v0.0.2-beta...v0.0.3-Beta">v0.0.3-Beta</a> (2026-01-20)</h2>
<p><a name="v0.0.2-beta"></a></p>
<h2 id="v002-beta-2026-01-20-1"><a href="https://github.com/clouddrove/smurf/compare/v0.0.4-beta...v0.0.2-beta">v0.0.2-beta</a> (2026-01-20)</h2>
<p><a name="v0.0.4-beta"></a></p>
<h2 id="v004-beta-2026-01-20-1"><a href="https://github.com/clouddrove/smurf/compare/v0.0.3-beta...v0.0.4-beta">v0.0.4-beta</a> (2026-01-20)</h2>
<p><a name="v0.0.3-beta"></a></p>
<h2 id="v003-beta-2026-01-20-1"><a href="https://github.com/clouddrove/smurf/compare/v0.1.1-beta...v0.0.3-beta">v0.0.3-beta</a> (2026-01-20)</h2>
<p><a name="v0.1.1-beta"></a></p>
<h2 id="v011-beta-2026-01-20"><a href="https://github.com/clouddrove/smurf/compare/v0.1.0...v0.1.1-beta">v0.1.1-beta</a> (2026-01-20)</h2>
<h3 id="build-13">Build</h3>
<ul>
<li><strong>deps:</strong> bump douglascamata/setup-docker-macos-action</li>
<li><strong>deps:</strong> bump k8s.io/client-go from 0.34.3 to 0.35.0 (<a href="https://github.com/clouddrove/smurf/issues/319">#319</a>)</li>
<li><strong>deps:</strong> bump filelock</li>
<li><strong>deps:</strong> bump pymdown-extensions</li>
</ul>
<h3 id="pull-requests-14">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/322">#322</a> from clouddrove/dependabot/github_actions/douglascamata/setup-docker-macos-action-1.1.0</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/318">#318</a> from clouddrove/dependabot/pip/docs/sm/docs/pip-c4ff2e68b4</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/317">#317</a> from clouddrove/dependabot/pip/docs/sm/docs/pip-d9bbda99d0</li>
</ul>
<p><a name="v0.1.0"></a></p>
<h2 id="v010-2025-12-15"><a href="https://github.com/clouddrove/smurf/compare/v0.2.5-beta...v0.1.0">v0.1.0</a> (2025-12-15)</h2>
<h3 id="build-14">Build</h3>
<ul>
<li><strong>deps:</strong> bump helm.sh/helm/v3 from 3.19.3 to 3.19.4</li>
<li><strong>deps:</strong> bump actions/upload-artifact from 5 to 6</li>
<li><strong>deps:</strong> bump actions/download-artifact from 6 to 7</li>
<li><strong>deps:</strong> bump actions/cache from 4 to 5</li>
<li><strong>deps:</strong> bump helm.sh/helm/v3 from 3.19.2 to 3.19.3</li>
<li><strong>deps:</strong> bump k8s.io/api from 0.34.2 to 0.34.3</li>
<li><strong>deps:</strong> bump k8s.io/apimachinery from 0.34.2 to 0.34.3</li>
<li><strong>deps:</strong> bump k8s.io/client-go from 0.34.2 to 0.34.3</li>
<li><strong>deps:</strong> bump golang.org/x/oauth2 from 0.33.0 to 0.34.0</li>
<li><strong>deps:</strong> bump urllib3</li>
<li><strong>deps:</strong> bump github.com/spf13/cobra from 1.10.1 to 1.10.2</li>
</ul>
<h3 id="pull-requests-15">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/315">#315</a> from clouddrove/dependabot/github_actions/actions/upload-artifact-6</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/314">#314</a> from clouddrove/dependabot/github_actions/actions/download-artifact-7</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/316">#316</a> from clouddrove/dependabot/go_modules/helm.sh/helm/v3-3.19.4</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/312">#312</a> from clouddrove/dependabot/github_actions/actions/cache-5</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/310">#310</a> from clouddrove/dependabot/go_modules/helm.sh/helm/v3-3.19.3</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/306">#306</a> from clouddrove/dependabot/go_modules/k8s.io/api-0.34.3</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/307">#307</a> from clouddrove/dependabot/go_modules/k8s.io/client-go-0.34.3</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/308">#308</a> from clouddrove/dependabot/go_modules/k8s.io/apimachinery-0.34.3</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/305">#305</a> from clouddrove/dependabot/go_modules/golang.org/x/oauth2-0.34.0</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/304">#304</a> from clouddrove/dependabot/pip/docs/sm/docs/pip-a6aa50acab</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/302">#302</a> from clouddrove/dependabot/go_modules/github.com/spf13/cobra-1.10.2</li>
</ul>
<p><a name="v0.2.5-beta"></a></p>
<h2 id="v025-beta-2025-12-12"><a href="https://github.com/clouddrove/smurf/compare/v0.2.4-beta...v0.2.5-beta">v0.2.5-beta</a> (2025-12-12)</h2>
<p><a name="v0.2.4-beta"></a></p>
<h2 id="v024-beta-2025-12-11"><a href="https://github.com/clouddrove/smurf/compare/v0.2.3-beta...v0.2.4-beta">v0.2.4-beta</a> (2025-12-11)</h2>
<h3 id="fix-14">Fix</h3>
<ul>
<li>update smurf terraform provision command</li>
<li>smurf stf plan &ndash;out flag update</li>
</ul>
<p><a name="v0.2.3-beta"></a></p>
<h2 id="v023-beta-2025-12-11"><a href="https://github.com/clouddrove/smurf/compare/v0.2.2-beta...v0.2.3-beta">v0.2.3-beta</a> (2025-12-11)</h2>
<h3 id="fix-15">Fix</h3>
<ul>
<li>smurf stf apply logs</li>
</ul>
<h3 id="reverts">Reverts</h3>
<ul>
<li>added context in ai</li>
</ul>
<p><a name="v0.2.2-beta"></a></p>
<h2 id="v022-beta-2025-12-03"><a href="https://github.com/clouddrove/smurf/compare/v0.0.9...v0.2.2-beta">v0.2.2-beta</a> (2025-12-03)</h2>
<h3 id="fix-16">Fix</h3>
<ul>
<li>smurf terraform plan support -out</li>
</ul>
<p><a name="v0.0.9"></a></p>
<h2 id="v009-2025-11-26"><a href="https://github.com/clouddrove/smurf/compare/v0.2.1-beta...v0.0.9">v0.0.9</a> (2025-11-26)</h2>
<p><a name="v0.2.1-beta"></a></p>
<h2 id="v021-beta-2025-11-24"><a href="https://github.com/clouddrove/smurf/compare/v0.2.0-beat...v0.2.1-beta">v0.2.1-beta</a> (2025-11-24)</h2>
<h3 id="build-15">Build</h3>
<ul>
<li><strong>deps:</strong> bump actions/checkout from 5 to 6</li>
<li><strong>deps:</strong> bump golang.org/x/crypto</li>
</ul>
<h3 id="feat-4">Feat</h3>
<ul>
<li>add smurf sdkr for google cloud platform(GCP)</li>
</ul>
<h3 id="pull-requests-16">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/299">#299</a> from clouddrove/dependabot/github_actions/actions/checkout-6</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/298">#298</a> from clouddrove/dependabot/go_modules/go_modules-dd7da38a6b</li>
</ul>
<p><a name="v0.2.0-beat"></a></p>
<h2 id="v020-beat-2025-11-19"><a href="https://github.com/clouddrove/smurf/compare/v0.0.8...v0.2.0-beat">v0.2.0-beat</a> (2025-11-19)</h2>
<h3 id="build-16">Build</h3>
<ul>
<li><strong>deps:</strong> bump helm.sh/helm/v3 from 3.19.1 to 3.19.2</li>
<li><strong>deps:</strong> bump k8s.io/api from 0.34.1 to 0.34.2</li>
<li><strong>deps:</strong> bump k8s.io/apimachinery from 0.34.1 to 0.34.2</li>
<li><strong>deps:</strong> bump k8s.io/client-go from 0.34.1 to 0.34.2</li>
</ul>
<h3 id="feat-5">Feat</h3>
<ul>
<li>add history max flag for smurf selm</li>
</ul>
<h3 id="pull-requests-17">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/293">#293</a> from clouddrove/dependabot/go_modules/helm.sh/helm/v3-3.19.2</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/294">#294</a> from clouddrove/dependabot/go_modules/k8s.io/client-go-0.34.2</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/295">#295</a> from clouddrove/dependabot/go_modules/k8s.io/apimachinery-0.34.2</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/296">#296</a> from clouddrove/dependabot/go_modules/k8s.io/api-0.34.2</li>
</ul>
<p><a name="v0.0.8"></a></p>
<h2 id="v008-2025-11-11"><a href="https://github.com/clouddrove/smurf/compare/v0.1.9-beta...v0.0.8">v0.0.8</a> (2025-11-11)</h2>
<h3 id="build-17">Build</h3>
<ul>
<li><strong>deps:</strong> bump github.com/Azure/azure-sdk-for-go/sdk/azidentity</li>
<li><strong>deps:</strong> bump helm.sh/helm/v3 from 3.19.0 to 3.19.1</li>
<li><strong>deps:</strong> bump douglascamata/setup-docker-macos-action</li>
<li><strong>deps:</strong> bump golang.org/x/oauth2 from 0.32.0 to 0.33.0</li>
<li><strong>deps:</strong> bump github.com/containerd/containerd</li>
<li><strong>deps:</strong> bump github.com/docker/docker</li>
</ul>
<h3 id="pull-requests-18">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/290">#290</a> from clouddrove/dependabot/github_actions/douglascamata/setup-docker-macos-action-1.0.2</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/291">#291</a> from clouddrove/dependabot/go_modules/helm.sh/helm/v3-3.19.1</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/292">#292</a> from clouddrove/dependabot/go_modules/github.com/Azure/azure-sdk-for-go/sdk/azidentity-1.13.1</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/288">#288</a> from clouddrove/dependabot/go_modules/golang.org/x/oauth2-0.33.0</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/285">#285</a> from clouddrove/dependabot/go_modules/github.com/docker/docker-28.5.2incompatible</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/286">#286</a> from clouddrove/dependabot/go_modules/go_modules-6b61ce4306</li>
</ul>
<p><a name="v0.1.9-beta"></a></p>
<h2 id="v019-beta-2025-11-10"><a href="https://github.com/clouddrove/smurf/compare/v0.1.8-beta...v0.1.9-beta">v0.1.9-beta</a> (2025-11-10)</h2>
<h3 id="feat-6">Feat</h3>
<ul>
<li>change logs and update format command</li>
<li>Add smurf terraform</li>
</ul>
<p><a name="v0.1.8-beta"></a></p>
<h2 id="v018-beta-2025-11-07"><a href="https://github.com/clouddrove/smurf/compare/v0.0.7...v0.1.8-beta">v0.1.8-beta</a> (2025-11-07)</h2>
<h3 id="feat-7">Feat</h3>
<ul>
<li>Add smurf terraform</li>
<li>update docs with latest changes</li>
</ul>
<p><a name="v0.0.7"></a></p>
<h2 id="v007-2025-11-04"><a href="https://github.com/clouddrove/smurf/compare/v0.1.7-beta...v0.0.7">v0.0.7</a> (2025-11-04)</h2>
<h3 id="build-18">Build</h3>
<ul>
<li><strong>deps:</strong> bump actions/download-artifact from 5 to 6</li>
<li><strong>deps:</strong> bump actions/upload-artifact from 4 to 5</li>
</ul>
<h3 id="pull-requests-19">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/280">#280</a> from clouddrove/dependabot/github_actions/actions/upload-artifact-5</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/281">#281</a> from clouddrove/dependabot/github_actions/actions/download-artifact-6</li>
</ul>
<p><a name="v0.1.7-beta"></a></p>
<h2 id="v017-beta-2025-11-04"><a href="https://github.com/clouddrove/smurf/compare/v0.1.6-beta...v0.1.7-beta">v0.1.7-beta</a> (2025-11-04)</h2>
<h3 id="feat-8">Feat</h3>
<ul>
<li>improve code suggested by Gemini AI</li>
</ul>
<p><a name="v0.1.6-beta"></a></p>
<h2 id="v016-beta-2025-11-03"><a href="https://github.com/clouddrove/smurf/compare/v0.1.5-beta...v0.1.6-beta">v0.1.6-beta</a> (2025-11-03)</h2>
<h3 id="feat-9">Feat</h3>
<ul>
<li>improve code suggested by Gemini AI</li>
<li>improve code suggested by Gemini AI</li>
<li>improve code suggested by Gemini AI</li>
<li>improve code suggested by Gemini AI</li>
<li>improve code suggested by Gemini AI</li>
</ul>
<p><a name="v0.1.5-beta"></a></p>
<h2 id="v015-beta-2025-10-31"><a href="https://github.com/clouddrove/smurf/compare/v0.1.4-beta...v0.1.5-beta">v0.1.5-beta</a> (2025-10-31)</h2>
<h3 id="feat-10">Feat</h3>
<ul>
<li>Update the code as suggested by Gemini AI.</li>
</ul>
<p><a name="v0.1.4-beta"></a></p>
<h2 id="v014-beta-2025-10-31"><a href="https://github.com/clouddrove/smurf/compare/v0.1.3-beta...v0.1.4-beta">v0.1.4-beta</a> (2025-10-31)</h2>
<h3 id="feat-11">Feat</h3>
<ul>
<li>update smurf provision GHCR logs</li>
</ul>
<p><a name="v0.1.3-beta"></a></p>
<h2 id="v013-beta-2025-10-31"><a href="https://github.com/clouddrove/smurf/compare/v0.1.2-beta...v0.1.3-beta">v0.1.3-beta</a> (2025-10-31)</h2>
<h3 id="feat-12">Feat</h3>
<ul>
<li>Add GHCR repo feature</li>
</ul>
<p><a name="v0.1.2-beta"></a></p>
<h2 id="v012-beta-2025-10-31"><a href="https://github.com/clouddrove/smurf/compare/v0.1.1...v0.1.2-beta">v0.1.2-beta</a> (2025-10-31)</h2>
<h3 id="feat-13">Feat</h3>
<ul>
<li>Add GHCR repo feature</li>
</ul>
<p><a name="v0.1.1"></a></p>
<h2 id="v011-2025-10-30"><a href="https://github.com/clouddrove/smurf/compare/v0.1.0-beta...v0.1.1">v0.1.1</a> (2025-10-30)</h2>
<h3 id="feat-14">Feat</h3>
<ul>
<li>add smurf deploy command</li>
</ul>
<p><a name="v0.1.0-beta"></a></p>
<h2 id="v010-beta-2025-10-27"><a href="https://github.com/clouddrove/smurf/compare/v0.0.6...v0.1.0-beta">v0.1.0-beta</a> (2025-10-27)</h2>
<h3 id="build-19">Build</h3>
<ul>
<li><strong>deps:</strong> bump github.com/pterm/pterm from 0.12.81 to 0.12.82 (<a href="https://github.com/clouddrove/smurf/issues/279">#279</a>)</li>
<li><strong>deps:</strong> bump golang.org/x/oauth2 from 0.31.0 to 0.32.0 (<a href="https://github.com/clouddrove/smurf/issues/277">#277</a>)</li>
<li><strong>deps:</strong> bump github.com/docker/docker (<a href="https://github.com/clouddrove/smurf/issues/276">#276</a>)</li>
<li><strong>deps:</strong> bump github.com/Azure/azure-sdk-for-go/sdk/azidentity (<a href="https://github.com/clouddrove/smurf/issues/275">#275</a>)</li>
<li><strong>deps:</strong> bump douglascamata/setup-docker-macos-action (<a href="https://github.com/clouddrove/smurf/issues/274">#274</a>)</li>
</ul>
<h3 id="feat-15">Feat</h3>
<ul>
<li>add smurf selm init command</li>
<li>add command for push docker image on ghcr</li>
</ul>
<p><a name="v0.0.6"></a></p>
<h2 id="v006-2025-10-03"><a href="https://github.com/clouddrove/smurf/compare/v0.0.06...v0.0.6">v0.0.6</a> (2025-10-03)</h2>
<p><a name="v0.0.06"></a></p>
<h2 id="v0006-2025-10-03"><a href="https://github.com/clouddrove/smurf/compare/v0.0.8-Beta...v0.0.06">v0.0.06</a> (2025-10-03)</h2>
<h3 id="build-20">Build</h3>
<ul>
<li><strong>deps:</strong> bump github.com/docker/docker</li>
</ul>
<h3 id="feat-16">Feat</h3>
<ul>
<li>Updated smurf selm with code changes suggested by Gemini AI</li>
<li>Updated smurf selm with code changes suggested by Gemini AI</li>
<li>Updated smurf selm with code changes suggested by Gemini AI</li>
<li>Updated smurf selm with code changes suggested by Gemini AI</li>
<li>Updated smurf selm with code changes suggested by Gemini AI</li>
<li>Updated smurf selm with code changes suggested by Gemini AI</li>
<li>Updated smurf selm with code changes suggested by Gemini AI</li>
<li>Updated smurf selm with code changes suggested by Gemini AI</li>
<li>Updated smurf selm with code changes suggested by Gemini AI</li>
<li>Updated smurf selm with code changes suggested by Gemini AI</li>
<li>update error log structure for selm</li>
</ul>
<h3 id="pull-requests-20">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/273">#273</a> from clouddrove/feat/selm-logs</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/271">#271</a> from clouddrove/dependabot/go_modules/github.com/docker/docker-28.5.0incompatible</li>
</ul>
<p><a name="v0.0.8-Beta"></a></p>
<h2 id="v008-beta-2025-10-01"><a href="https://github.com/clouddrove/smurf/compare/v0.0.7-Beta...v0.0.8-Beta">v0.0.8-Beta</a> (2025-10-01)</h2>
<h3 id="feat-17">Feat</h3>
<ul>
<li>update error log structure for selm</li>
</ul>
<p><a name="v0.0.7-Beta"></a></p>
<h2 id="v007-beta-2025-09-30"><a href="https://github.com/clouddrove/smurf/compare/v0.0.6-Beta...v0.0.7-Beta">v0.0.7-Beta</a> (2025-09-30)</h2>
<h3 id="feat-18">Feat</h3>
<ul>
<li>update smurf selm log structure</li>
</ul>
<p><a name="v0.0.6-Beta"></a></p>
<h2 id="v006-beta-2025-09-29"><a href="https://github.com/clouddrove/smurf/compare/v0.0.5...v0.0.6-Beta">v0.0.6-Beta</a> (2025-09-29)</h2>
<p><a name="v0.0.5"></a></p>
<h2 id="v005-2025-09-23"><a href="https://github.com/clouddrove/smurf/compare/v0.0.9-beta...v0.0.5">v0.0.5</a> (2025-09-23)</h2>
<p><a name="v0.0.9-beta"></a></p>
<h2 id="v009-beta-2025-09-23"><a href="https://github.com/clouddrove/smurf/compare/v0.0.8-beta...v0.0.9-beta">v0.0.9-beta</a> (2025-09-23)</h2>
<h3 id="fix-17">Fix</h3>
<ul>
<li>selm template command issue</li>
<li>selm template command issue</li>
</ul>
<h3 id="pull-requests-21">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/268">#268</a> from clouddrove/fix/time-issue</li>
</ul>
<p><a name="v0.0.8-beta"></a></p>
<h2 id="v008-beta-2025-09-22"><a href="https://github.com/clouddrove/smurf/compare/beta-v0.0.5...v0.0.8-beta">v0.0.8-beta</a> (2025-09-22)</h2>
<h3 id="build-21">Build</h3>
<ul>
<li><strong>deps:</strong> bump github.com/hashicorp/terraform-exec</li>
<li><strong>deps:</strong> bump github.com/hashicorp/terraform-json</li>
<li><strong>deps:</strong> bump github.com/hashicorp/terraform-json</li>
<li><strong>deps:</strong> bump github.com/Azure/azure-sdk-for-go/sdk/azidentity</li>
<li><strong>deps:</strong> bump helm.sh/helm/v3 from 3.18.6 to 3.19.0 (<a href="https://github.com/clouddrove/smurf/issues/260">#260</a>)</li>
<li><strong>deps:</strong> bump k8s.io/client-go from 0.34.0 to 0.34.1 (<a href="https://github.com/clouddrove/smurf/issues/257">#257</a>)</li>
</ul>
<h3 id="fix-18">Fix</h3>
<ul>
<li>resolve readiness issue</li>
<li>resolve readiness issue</li>
</ul>
<h3 id="pull-requests-22">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/264">#264</a> from clouddrove/dependabot/go_modules/github.com/hashicorp/terraform-exec-0.24.0</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/265">#265</a> from clouddrove/dependabot/go_modules/github.com/hashicorp/terraform-json-0.27.2</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/262">#262</a> from clouddrove/dependabot/go_modules/github.com/Azure/azure-sdk-for-go/sdk/azidentity-1.12.0</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/263">#263</a> from clouddrove/dependabot/go_modules/github.com/hashicorp/terraform-json-0.27.1</li>
</ul>
<p><a name="beta-v0.0.5"></a></p>
<h2 id="beta-v005-2025-09-15"><a href="https://github.com/clouddrove/smurf/compare/v0.0.7-beta...beta-v0.0.5">beta-v0.0.5</a> (2025-09-15)</h2>
<p><a name="v0.0.7-beta"></a></p>
<h2 id="v007-beta-2025-09-15"><a href="https://github.com/clouddrove/smurf/compare/v0.0.6-beta...v0.0.7-beta">v0.0.7-beta</a> (2025-09-15)</h2>
<h3 id="feat-19">Feat</h3>
<ul>
<li>test new log structure</li>
<li>test new log structure</li>
</ul>
<p><a name="v0.0.6-beta"></a></p>
<h2 id="v006-beta-2025-09-15"><a href="https://github.com/clouddrove/smurf/compare/v0.0.5-beta...v0.0.6-beta">v0.0.6-beta</a> (2025-09-15)</h2>
<h3 id="feat-20">Feat</h3>
<ul>
<li>test new log structure</li>
</ul>
<p><a name="v0.0.5-beta"></a></p>
<h2 id="v005-beta-2025-09-08"><a href="https://github.com/clouddrove/smurf/compare/v0.0.4...v0.0.5-beta">v0.0.5-beta</a> (2025-09-08)</h2>
<h3 id="build-22">Build</h3>
<ul>
<li><strong>deps:</strong> bump golang.org/x/oauth2 from 0.30.0 to 0.31.0 (<a href="https://github.com/clouddrove/smurf/issues/256">#256</a>)</li>
<li><strong>deps:</strong> bump github.com/docker/docker</li>
<li><strong>deps:</strong> bump actions/setup-go from 5 to 6</li>
<li><strong>deps:</strong> bump actions/setup-python from 5 to 6</li>
<li><strong>deps:</strong> bump github.com/spf13/cobra from 1.9.1 to 1.10.1 (<a href="https://github.com/clouddrove/smurf/issues/251">#251</a>)</li>
</ul>
<h3 id="feat-21">Feat</h3>
<ul>
<li>update selm install log structure</li>
</ul>
<h3 id="pull-requests-23">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/252">#252</a> from clouddrove/dependabot/github_actions/actions/setup-python-6</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/253">#253</a> from clouddrove/dependabot/github_actions/actions/setup-go-6</li>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/254">#254</a> from clouddrove/dependabot/go_modules/github.com/docker/docker-28.4.0incompatible</li>
</ul>
<p><a name="v0.0.4"></a></p>
<h2 id="v004-2025-09-01"><a href="https://github.com/clouddrove/smurf/compare/v0.0.3...v0.0.4">v0.0.4</a> (2025-09-01)</h2>
<h3 id="build-23">Build</h3>
<ul>
<li><strong>deps:</strong> bump k8s.io/client-go from 0.33.3 to 0.34.0 (<a href="https://github.com/clouddrove/smurf/issues/247">#247</a>)</li>
<li><strong>deps:</strong> bump github.com/hashicorp/terraform-exec (<a href="https://github.com/clouddrove/smurf/issues/246">#246</a>)</li>
<li><strong>deps:</strong> bump k8s.io/apimachinery from 0.33.4 to 0.34.0 (<a href="https://github.com/clouddrove/smurf/issues/245">#245</a>)</li>
<li><strong>deps:</strong> bump github.com/stretchr/testify from 1.11.0 to 1.11.1 (<a href="https://github.com/clouddrove/smurf/issues/244">#244</a>)</li>
</ul>
<h3 id="feat-22">Feat</h3>
<ul>
<li>Add support for <code>--wait</code> flag in <code>smurf selm upgrade</code> command (<a href="https://github.com/clouddrove/smurf/issues/243">#243</a>)</li>
</ul>
<h3 id="feat-23">Feat</h3>
<ul>
<li>update claude pr workflows for testing (<a href="https://github.com/clouddrove/smurf/issues/242">#242</a>)</li>
</ul>
<h3 id="pull-requests-24">Pull Requests</h3>
<ul>
<li>Merge pull request <a href="https://github.com/clouddrove/smurf/issues/248">#248</a> from clouddrove/fix/cloud-workflow</li>
</ul>
<p><a name="v0.0.3"></a></p>
<h2 id="v003-2025-08-26"><a href="https://github.com/clouddrove/smurf/compare/v0.0.2...v0.0.3">v0.0.3</a> (2025-08-26)</h2>
<h3 id="build-24">Build</h3>
<ul>
<li><strong>deps:</strong> bump actions/upload-pages-artifact from 3 to 4 (<a href="https://github.com/clouddrove/smurf/issues/240">#240</a>)</li>
<li><strong>deps:</strong> bump github.com/stretchr/testify from 1.10.0 to 1.11.0 (<a href="https://github.com/clouddrove/smurf/issues/239">#239</a>)</li>
</ul>
<h3 id="fix-19">Fix</h3>
<ul>
<li>Add repo chart support in upgrade (<a href="https://github.com/clouddrove/smurf/issues/241">#241</a>)</li>
</ul>
<p><a name="v0.0.2"></a></p>
<h2 id="v002-2025-08-21"><a href="https://github.com/clouddrove/smurf/compare/v0.0.1...v0.0.2">v0.0.2</a> (2025-08-21)</h2>
<h3 id="build-25">Build</h3>
<ul>
<li><strong>deps:</strong> bump helm.sh/helm/v3 from 3.18.5 to 3.18.6 (<a href="https://github.com/clouddrove/smurf/issues/237">#237</a>)</li>
<li><strong>deps:</strong> bump github.com/aws/aws-sdk-go from 1.55.7 to 1.55.8 (<a href="https://github.com/clouddrove/smurf/issues/236">#236</a>)</li>
<li><strong>deps:</strong> bump k8s.io/api from 0.33.3 to 0.33.4 (<a href="https://github.com/clouddrove/smurf/issues/235">#235</a>)</li>
<li><strong>deps:</strong> bump github.com/Azure/azure-sdk-for-go/sdk/azidentity (<a href="https://github.com/clouddrove/smurf/issues/234">#234</a>)</li>
<li><strong>deps:</strong> bump github.com/hashicorp/terraform-json (<a href="https://github.com/clouddrove/smurf/issues/233">#233</a>)</li>
</ul>
<p><a name="v0.0.1"></a></p>
<h2 id="v001-2025-08-20">v0.0.1 (2025-08-20)</h2>
<h3 id="build-26">Build</h3>
<ul>
<li><strong>deps:</strong> bump the go_modules group with 2 updates (<a href="https://github.com/clouddrove/smurf/issues/230">#230</a>)</li>
<li><strong>deps:</strong> bump helm.sh/helm/v3 from 3.18.5 to 3.18.6 (<a href="https://github.com/clouddrove/smurf/issues/227">#227</a>)</li>
<li><strong>deps:</strong> bump helm.sh/helm/v3 in the go_modules group (<a href="https://github.com/clouddrove/smurf/issues/226">#226</a>)</li>
<li><strong>deps:</strong> bump k8s.io/api from 0.33.3 to 0.33.4 (<a href="https://github.com/clouddrove/smurf/issues/221">#221</a>)</li>
<li><strong>deps:</strong> bump github.com/hashicorp/terraform-json (<a href="https://github.com/clouddrove/smurf/issues/220">#220</a>)</li>
<li><strong>deps:</strong> bump actions/checkout from 4 to 5 (<a href="https://github.com/clouddrove/smurf/issues/217">#217</a>)</li>
<li><strong>deps:</strong> bump actions/download-artifact from 4 to 5 (<a href="https://github.com/clouddrove/smurf/issues/216">#216</a>)</li>
<li><strong>deps:</strong> bump github.com/Azure/azure-sdk-for-go/sdk/azidentity (<a href="https://github.com/clouddrove/smurf/issues/215">#215</a>)</li>
<li><strong>deps:</strong> bump github.com/aws/aws-sdk-go from 1.55.7 to 1.55.8 (<a href="https://github.com/clouddrove/smurf/issues/214">#214</a>)</li>
<li><strong>deps:</strong> bump github.com/docker/docker in the go_modules group (<a href="https://github.com/clouddrove/smurf/issues/213">#213</a>)</li>
<li><strong>deps:</strong> bump k8s.io/client-go from 0.33.2 to 0.33.3 (<a href="https://github.com/clouddrove/smurf/issues/206">#206</a>)</li>
<li><strong>deps:</strong> bump github.com/docker/docker (<a href="https://github.com/clouddrove/smurf/issues/201">#201</a>)</li>
<li><strong>deps:</strong> bump helm.sh/helm/v3 in the go_modules group (<a href="https://github.com/clouddrove/smurf/issues/197">#197</a>)</li>
<li><strong>deps:</strong> bump github.com/docker/docker (<a href="https://github.com/clouddrove/smurf/issues/194">#194</a>)</li>
<li><strong>deps:</strong> bump github.com/docker/docker (<a href="https://github.com/clouddrove/smurf/issues/193">#193</a>)</li>
<li><strong>deps:</strong> bump k8s.io/api from 0.33.1 to 0.33.2 (<a href="https://github.com/clouddrove/smurf/issues/190">#190</a>)</li>
<li><strong>deps:</strong> bump urllib3 (<a href="https://github.com/clouddrove/smurf/issues/189">#189</a>)</li>
<li><strong>deps:</strong> bump helm.sh/helm/v3 from 3.18.2 to 3.18.3 (<a href="https://github.com/clouddrove/smurf/issues/188">#188</a>)</li>
<li><strong>deps:</strong> bump github.com/Azure/azure-sdk-for-go/sdk/azidentity (<a href="https://github.com/clouddrove/smurf/issues/186">#186</a>)</li>
<li><strong>deps:</strong> bump requests (<a href="https://github.com/clouddrove/smurf/issues/185">#185</a>)</li>
<li><strong>deps:</strong> bump github.com/pterm/pterm from 0.12.80 to 0.12.81 (<a href="https://github.com/clouddrove/smurf/issues/182">#182</a>)</li>
<li><strong>deps:</strong> bump helm.sh/helm/v3 from 3.18.1 to 3.18.2 (<a href="https://github.com/clouddrove/smurf/issues/180">#180</a>)</li>
<li><strong>deps:</strong> bump github.com/docker/docker (<a href="https://github.com/clouddrove/smurf/issues/179">#179</a>)</li>
<li><strong>deps:</strong> bump github.com/docker/docker (<a href="https://github.com/clouddrove/smurf/issues/177">#177</a>)</li>
<li><strong>deps:</strong> bump helm.sh/helm/v3 from 3.18.0 to 3.18.1 (<a href="https://github.com/clouddrove/smurf/issues/176">#176</a>)</li>
<li><strong>deps:</strong> bump k8s.io/api from 0.32.2 to 0.33.1 (<a href="https://github.com/clouddrove/smurf/issues/169">#169</a>)</li>
<li><strong>deps:</strong> bump github.com/hashicorp/terraform-json (<a href="https://github.com/clouddrove/smurf/issues/158">#158</a>)</li>
<li><strong>deps:</strong> bump github.com/Azure/azure-sdk-for-go/sdk/azidentity (<a href="https://github.com/clouddrove/smurf/issues/157">#157</a>)</li>
<li><strong>deps:</strong> bump golang.org/x/oauth2 from 0.29.0 to 0.30.0 (<a href="https://github.com/clouddrove/smurf/issues/156">#156</a>)</li>
<li><strong>deps:</strong> bump github.com/aws/aws-sdk-go from 1.55.6 to 1.55.7 (<a href="https://github.com/clouddrove/smurf/issues/149">#149</a>)</li>
<li><strong>deps:</strong> bump github.com/docker/docker (<a href="https://github.com/clouddrove/smurf/issues/148">#148</a>)</li>
<li><strong>deps:</strong> bump github.com/docker/docker (<a href="https://github.com/clouddrove/smurf/issues/147">#147</a>)</li>
<li><strong>deps:</strong> bump douglascamata/setup-docker-macos-action (<a href="https://github.com/clouddrove/smurf/issues/146">#146</a>)</li>
<li><strong>deps:</strong> bump github.com/hashicorp/terraform-exec (<a href="https://github.com/clouddrove/smurf/issues/144">#144</a>)</li>
<li><strong>deps:</strong> bump helm.sh/helm/v3 from 3.17.2 to 3.17.3 (<a href="https://github.com/clouddrove/smurf/issues/143">#143</a>)</li>
<li><strong>deps:</strong> bump github.com/Azure/azure-sdk-for-go/sdk/azidentity (<a href="https://github.com/clouddrove/smurf/issues/142">#142</a>)</li>
<li><strong>deps:</strong> bump golang.org/x/oauth2 from 0.28.0 to 0.29.0 (<a href="https://github.com/clouddrove/smurf/issues/139">#139</a>)</li>
<li><strong>deps:</strong> bump github.com/docker/docker (<a href="https://github.com/clouddrove/smurf/issues/132">#132</a>)</li>
<li><strong>deps:</strong> bump github.com/golang-jwt/jwt/v5 in the go_modules group (<a href="https://github.com/clouddrove/smurf/issues/130">#130</a>)</li>
<li><strong>deps:</strong> bump github.com/docker/docker (<a href="https://github.com/clouddrove/smurf/issues/125">#125</a>)</li>
<li><strong>deps:</strong> bump github.com/containerd/containerd (<a href="https://github.com/clouddrove/smurf/issues/123">#123</a>)</li>
<li><strong>deps:</strong> bump helm.sh/helm/v3 from 3.17.1 to 3.17.2 (<a href="https://github.com/clouddrove/smurf/issues/119">#119</a>)</li>
<li><strong>deps:</strong> bump golang.org/x/net in the go_modules group (<a href="https://github.com/clouddrove/smurf/issues/117">#117</a>)</li>
<li><strong>deps:</strong> bump k8s.io/apimachinery from 0.32.2 to 0.32.3 (<a href="https://github.com/clouddrove/smurf/issues/115">#115</a>)</li>
<li><strong>deps:</strong> bump golang.org/x/oauth2 from 0.27.0 to 0.28.0 (<a href="https://github.com/clouddrove/smurf/issues/111">#111</a>)</li>
<li><strong>deps:</strong> bump github.com/docker/docker (<a href="https://github.com/clouddrove/smurf/issues/108">#108</a>)</li>
<li><strong>deps:</strong> bump golang.org/x/oauth2 from 0.26.0 to 0.27.0 (<a href="https://github.com/clouddrove/smurf/issues/107">#107</a>)</li>
<li><strong>deps:</strong> bump github.com/docker/docker (<a href="https://github.com/clouddrove/smurf/issues/104">#104</a>)</li>
<li><strong>deps:</strong> bump github.com/spf13/cobra from 1.8.1 to 1.9.1 (<a href="https://github.com/clouddrove/smurf/issues/97">#97</a>)</li>
<li><strong>deps:</strong> bump k8s.io/apimachinery from 0.32.1 to 0.32.2 (<a href="https://github.com/clouddrove/smurf/issues/94">#94</a>)</li>
<li><strong>deps:</strong> bump helm.sh/helm/v3 from 3.16.4 to 3.17.1 (<a href="https://github.com/clouddrove/smurf/issues/91">#91</a>)</li>
<li><strong>deps:</strong> bump github.com/hashicorp/terraform-exec (<a href="https://github.com/clouddrove/smurf/issues/89">#89</a>)</li>
<li><strong>deps:</strong> bump golang.org/x/oauth2 from 0.25.0 to 0.26.0 (<a href="https://github.com/clouddrove/smurf/issues/83">#83</a>)</li>
<li><strong>deps:</strong> bump github.com/docker/docker (<a href="https://github.com/clouddrove/smurf/issues/77">#77</a>)</li>
<li><strong>deps:</strong> bump github.com/hashicorp/terraform-exec (<a href="https://github.com/clouddrove/smurf/issues/78">#78</a>)</li>
<li><strong>deps:</strong> bump github.com/Azure/azure-sdk-for-go/sdk/azidentity (<a href="https://github.com/clouddrove/smurf/issues/69">#69</a>)</li>
<li><strong>deps:</strong> bump k8s.io/apimachinery from 0.31.4 to 0.32.1 (<a href="https://github.com/clouddrove/smurf/issues/66">#66</a>)</li>
<li><strong>deps:</strong> bump github.com/aws/aws-sdk-go from 1.55.5 to 1.55.6 (<a href="https://github.com/clouddrove/smurf/issues/65">#65</a>)</li>
<li><strong>deps:</strong> bump github.com/docker/docker (<a href="https://github.com/clouddrove/smurf/issues/63">#63</a>)</li>
<li><strong>deps:</strong> bump golang.org/x/oauth2 from 0.24.0 to 0.25.0 (<a href="https://github.com/clouddrove/smurf/issues/59">#59</a>)</li>
<li><strong>deps:</strong> bump github.com/moby/term from 0.5.0 to 0.5.2 (<a href="https://github.com/clouddrove/smurf/issues/58">#58</a>)</li>
<li><strong>deps:</strong> bump jinja2 (<a href="https://github.com/clouddrove/smurf/issues/57">#57</a>)</li>
<li><strong>deps:</strong> bump github.com/docker/docker (<a href="https://github.com/clouddrove/smurf/issues/56">#56</a>)</li>
<li><strong>deps:</strong> bump helm.sh/helm/v3 from 3.16.3 to 3.16.4 (<a href="https://github.com/clouddrove/smurf/issues/54">#54</a>)</li>
<li><strong>deps:</strong> bump golang.org/x/crypto in the go_modules group (<a href="https://github.com/clouddrove/smurf/issues/52">#52</a>)</li>
<li><strong>deps:</strong> bump k8s.io/api from 0.31.2 to 0.31.4 (<a href="https://github.com/clouddrove/smurf/issues/48">#48</a>)</li>
<li><strong>deps:</strong> bump github.com/docker/docker (<a href="https://github.com/clouddrove/smurf/issues/46">#46</a>)</li>
<li><strong>deps:</strong> bump github.com/pterm/pterm from 0.12.79 to 0.12.80 (<a href="https://github.com/clouddrove/smurf/issues/34">#34</a>)</li>
<li><strong>deps:</strong> bump k8s.io/apimachinery from 0.31.2 to 0.31.3 (<a href="https://github.com/clouddrove/smurf/issues/32">#32</a>)</li>
<li><strong>deps:</strong> bump helm.sh/helm/v3 from 3.16.2 to 3.16.3 (<a href="https://github.com/clouddrove/smurf/issues/29">#29</a>)</li>
<li><strong>deps:</strong> bump helm.sh/helm/v3 from 3.16.2 to 3.16.3 (<a href="https://github.com/clouddrove/smurf/issues/19">#19</a>)</li>
<li><strong>deps:</strong> bump k8s.io/client-go from 0.31.1 to 0.31.2 (<a href="https://github.com/clouddrove/smurf/issues/16">#16</a>)</li>
</ul>
<h3 id="feat-24">Feat</h3>
<ul>
<li>Enhance smurf sdkr and smurf selm logging structure (<a href="https://github.com/clouddrove/smurf/issues/229">#229</a>)</li>
<li>added install.sh (<a href="https://github.com/clouddrove/smurf/issues/140">#140</a>)</li>
</ul>
<h3 id="feat-25">Feat</h3>
<ul>
<li>new release tag v1.1.1 (<a href="https://github.com/clouddrove/smurf/issues/170">#170</a>)</li>
<li>Improved performance of docker image (<a href="https://github.com/clouddrove/smurf/issues/153">#153</a>)</li>
<li>fixed docs code (<a href="https://github.com/clouddrove/smurf/issues/145">#145</a>)</li>
<li>integrated -f flag in lint and template of smurf selm (<a href="https://github.com/clouddrove/smurf/issues/136">#136</a>)</li>
<li>Working on smurf version command</li>
<li>Added new command in smurf which is helm plugin install (<a href="https://github.com/clouddrove/smurf/issues/127">#127</a>)</li>
<li>added flag for plan &ndash;destroy (<a href="https://github.com/clouddrove/smurf/issues/126">#126</a>)</li>
<li>updated docker image tag and documentation (<a href="https://github.com/clouddrove/smurf/issues/105">#105</a>)</li>
<li>updated naming convention</li>
<li>update contributors url</li>
<li>added major release (<a href="https://github.com/clouddrove/smurf/issues/100">#100</a>)</li>
<li>updated social logo (<a href="https://github.com/clouddrove/smurf/issues/90">#90</a>)</li>
<li>disable tests (<a href="https://github.com/clouddrove/smurf/issues/88">#88</a>)</li>
<li>unit test logic and smurf improvement (<a href="https://github.com/clouddrove/smurf/issues/62">#62</a>)</li>
<li>configured github action to deploy github pages (<a href="https://github.com/clouddrove/smurf/issues/28">#28</a>)</li>
<li>updated permission</li>
<li>added requirement.txt (<a href="https://github.com/clouddrove/smurf/issues/27">#27</a>)</li>
<li>added dns name (<a href="https://github.com/clouddrove/smurf/issues/26">#26</a>)</li>
<li>updated branch name in trigger</li>
<li>added workflows (<a href="https://github.com/clouddrove/smurf/issues/14">#14</a>)</li>
<li>Add initial Go module structure and foundational directories (<a href="https://github.com/clouddrove/smurf/issues/1">#1</a>)</li>
</ul>
<h3 id="fix-20">Fix</h3>
<ul>
<li>fixed test in install_test.go (<a href="https://github.com/clouddrove/smurf/issues/122">#122</a>)</li>
</ul>
<h3 id="fmt">Fmt</h3>
<ul>
<li>improved naming (<a href="https://github.com/clouddrove/smurf/issues/174">#174</a>)</li>
</ul>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>build(deps): bump helm.sh/helm/v3 from 3.21.0 to 3.21.1 by @dependabot[bot] in <a href="https://github.com/clouddrove/smurf/pull/426">https://github.com/clouddrove/smurf/pull/426</a></li>
<li>build(deps): bump the pip group across 1 directory with 2 updates by @dependabot[bot] in <a href="https://github.com/clouddrove/smurf/pull/427">https://github.com/clouddrove/smurf/pull/427</a></li>
<li>build(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azidentity from 1.13.1 to 1.14.0 by @dependabot[bot] in <a href="https://github.com/clouddrove/smurf/pull/429">https://github.com/clouddrove/smurf/pull/429</a></li>
<li>build(deps): bump k8s.io/apimachinery from 0.36.1 to 0.36.2 by @dependabot[bot] in <a href="https://github.com/clouddrove/smurf/pull/428">https://github.com/clouddrove/smurf/pull/428</a></li>
<li>build(deps): bump actions/checkout from 6 to 7 by @dependabot[bot] in <a href="https://github.com/clouddrove/smurf/pull/431">https://github.com/clouddrove/smurf/pull/431</a></li>
<li>build(deps): bump actions/cache from 5 to 6 by @dependabot[bot] in <a href="https://github.com/clouddrove/smurf/pull/435">https://github.com/clouddrove/smurf/pull/435</a></li>
<li>build(deps): bump msgpack from 1.1.0 to 1.2.1 in /docs/sm/docs in the pip group across 1 directory by @dependabot[bot] in <a href="https://github.com/clouddrove/smurf/pull/434">https://github.com/clouddrove/smurf/pull/434</a></li>
<li>build(deps): bump github.com/containerd/containerd from 1.7.32 to 1.7.33 in the go_modules group across 1 directory by @dependabot[bot] in <a href="https://github.com/clouddrove/smurf/pull/433">https://github.com/clouddrove/smurf/pull/433</a></li>
<li>build(deps): bump clouddrove/github-shared-workflows/.github/workflows/pr-checks.yml from ca8d61c90f059d7ed8c3fc608877d19cc5d965f5 to 5a15692ae38a05cc3aa3b7ab6744add91e9b8591 by @dependabot[bot] in <a href="https://github.com/clouddrove/smurf/pull/436">https://github.com/clouddrove/smurf/pull/436</a></li>
<li>build(deps): bump helm.sh/helm/v3 from 3.21.1 to 3.21.2 by @dependabot[bot] in <a href="https://github.com/clouddrove/smurf/pull/432">https://github.com/clouddrove/smurf/pull/432</a></li>
<li>fix: fix deployment validation for completed Kubernetes Job pods by @anket-cd in <a href="https://github.com/clouddrove/smurf/pull/430">https://github.com/clouddrove/smurf/pull/430</a></li>
<li>build(deps): bump clouddrove/github-shared-workflows/.github/workflows/pr-checks.yml from 5a15692ae38a05cc3aa3b7ab6744add91e9b8591 to f6ef7e54f3a1f4e2a05a66ed1a8702c07ae94346 by @dependabot[bot] in <a href="https://github.com/clouddrove/smurf/pull/437">https://github.com/clouddrove/smurf/pull/437</a></li>
<li>feat: enhance smurf selm logs to capture terminated pod details during failed deployments by @anket-cd in <a href="https://github.com/clouddrove/smurf/pull/438">https://github.com/clouddrove/smurf/pull/438</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/clouddrove/smurf/compare/v1.1.4...v1.1.5">https://github.com/clouddrove/smurf/compare/v1.1.4...v1.1.5</a></p>
]]></content:encoded></item><item><title>Devr Codeguard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/devr-codeguard/</link><pubDate>Fri, 03 Jul 2026 22:15:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/devr-codeguard/</guid><description>Version updated for https://github.com/devr-tools/codeguard to version v0.8.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.8.1 (2026-07-03) Bug Fixes release: disable PyPI attestations for reusable-workflow publish (28a147d)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/devr-tools/codeguard">https://github.com/devr-tools/codeguard</a></strong> to version <strong>v0.8.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/devr-codeguard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="081-2026-07-03"><a href="https://github.com/devr-tools/codeguard/compare/v0.8.0...v0.8.1">0.8.1</a> (2026-07-03)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>release:</strong> disable PyPI attestations for reusable-workflow publish (<a href="https://github.com/devr-tools/codeguard/commit/28a147d14834ae20cf59749fcd6f21f51f02a568">28a147d</a>)</li>
</ul>
]]></content:encoded></item><item><title>FacturaScripts Playground PR Preview</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/facturascripts-playground-pr-preview/</link><pubDate>Fri, 03 Jul 2026 22:15:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/facturascripts-playground-pr-preview/</guid><description>Version updated for https://github.com/erseco/action-facturascripts-playground-pr-preview to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s new since v1.0.0 feat: append-to-description publish mode + workflow_run/pr-number support (#13) feat: warn (advisory, non-blocking) when the preview URL risks HTTP 414, and document the mitigation in the README (#19) ci: verify-dist gate, dependabot-dist auto-rebuild, immutable-action publishing Various dependency bumps All changes are backward compatible: new inputs default to the previous behavior, and the URL-length check only warns, it never fails the action. No breaking changes, so the v1 tag is being moved to this release rather than cutting a v2.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/erseco/action-facturascripts-playground-pr-preview">https://github.com/erseco/action-facturascripts-playground-pr-preview</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/facturascripts-playground-pr-preview">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-new-since-v100">What&rsquo;s new since v1.0.0</h2>
<ul>
<li>feat: append-to-description publish mode + workflow_run/pr-number support (#13)</li>
<li>feat: warn (advisory, non-blocking) when the preview URL risks HTTP 414, and document the mitigation in the README (#19)</li>
<li>ci: verify-dist gate, dependabot-dist auto-rebuild, immutable-action publishing</li>
<li>Various dependency bumps</li>
</ul>
<p>All changes are backward compatible: new inputs default to the previous behavior, and the URL-length check only warns, it never fails the action. No breaking changes, so the <code>v1</code> tag is being moved to this release rather than cutting a v2.</p>
]]></content:encoded></item><item><title>Garnet Runtime Visibility</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/garnet-runtime-visibility/</link><pubDate>Fri, 03 Jul 2026 22:14:34 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/garnet-runtime-visibility/</guid><description>Version updated for https://github.com/garnet-org/action to version v2.1.1.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 111 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps-dev): bump @types/node from 26.0.1 to 26.1.0 by @dependabot[bot] in https://github.com/garnet-org/action/pull/81 fix: improve error messages by @nicolasparada in https://github.com/garnet-org/action/pull/84 feat: add agents.md to repo by @nicolasparada in https://github.com/garnet-org/action/pull/85 Full Changelog: https://github.com/garnet-org/action/compare/v2.1.0...v2.1.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/garnet-org/action">https://github.com/garnet-org/action</a></strong> to version <strong>v2.1.1</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>111</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/garnet-runtime-visibility">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps-dev): bump @types/node from 26.0.1 to 26.1.0 by @dependabot[bot] in <a href="https://github.com/garnet-org/action/pull/81">https://github.com/garnet-org/action/pull/81</a></li>
<li>fix: improve error messages by @nicolasparada in <a href="https://github.com/garnet-org/action/pull/84">https://github.com/garnet-org/action/pull/84</a></li>
<li>feat: add agents.md to repo by @nicolasparada in <a href="https://github.com/garnet-org/action/pull/85">https://github.com/garnet-org/action/pull/85</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/garnet-org/action/compare/v2.1.0...v2.1.1">https://github.com/garnet-org/action/compare/v2.1.0...v2.1.1</a></p>
]]></content:encoded></item><item><title>ghcr-manager</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/ghcr-manager/</link><pubDate>Fri, 03 Jul 2026 22:14:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/ghcr-manager/</guid><description>Version updated for https://github.com/ghcr-manager/ghcr-manager to version v1.1.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/ghcr-manager/ghcr-manager/compare/v1.1.4...v1.1.5</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ghcr-manager/ghcr-manager">https://github.com/ghcr-manager/ghcr-manager</a></strong> to version <strong>v1.1.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ghcr-manager">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ghcr-manager/ghcr-manager/compare/v1.1.4...v1.1.5">https://github.com/ghcr-manager/ghcr-manager/compare/v1.1.4...v1.1.5</a></p>
]]></content:encoded></item><item><title>Easy Npm Publish</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/easy-npm-publish/</link><pubDate>Fri, 03 Jul 2026 22:13:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/easy-npm-publish/</guid><description>Version updated for https://github.com/glitch452/easy-npm-publish to version v1.0.43.
This action is used across all versions by 2 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Chores deps: update all non-major dependencies (595d091)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/glitch452/easy-npm-publish">https://github.com/glitch452/easy-npm-publish</a></strong> to version <strong>v1.0.43</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/easy-npm-publish">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="chores">Chores</h2>
<ul>
<li>deps: update all non-major dependencies (<a href="https://github.com/glitch452/easy-npm-publish/commit/595d0911807cc0e37dc46e714fbb5d65c0d71924">595d091</a>)</li>
</ul>
]]></content:encoded></item><item><title>GitHub Action for GraalVM</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/github-action-for-graalvm/</link><pubDate>Fri, 03 Jul 2026 22:12:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/github-action-for-graalvm/</guid><description>Version updated for https://github.com/graalvm/setup-graalvm to version v1.6.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 4,081 repositories.
Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump the “all” group with 2 updates across multiple ecosystems by @dependabot[bot] in https://github.com/graalvm/setup-graalvm/pull/222 Add support for GraalVM innovation releases by @fniephaus in https://github.com/graalvm/setup-graalvm/pull/223 Full Changelog: https://github.com/graalvm/setup-graalvm/compare/v1.5.6...v1.6.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/graalvm/setup-graalvm">https://github.com/graalvm/setup-graalvm</a></strong> to version <strong>v1.6.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>4,081</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/github-action-for-graalvm">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump the &ldquo;all&rdquo; group with 2 updates across multiple ecosystems by @dependabot[bot] in <a href="https://github.com/graalvm/setup-graalvm/pull/222">https://github.com/graalvm/setup-graalvm/pull/222</a></li>
<li>Add support for GraalVM innovation releases by @fniephaus in <a href="https://github.com/graalvm/setup-graalvm/pull/223">https://github.com/graalvm/setup-graalvm/pull/223</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/graalvm/setup-graalvm/compare/v1.5.6...v1.6.0">https://github.com/graalvm/setup-graalvm/compare/v1.5.6...v1.6.0</a></p>
]]></content:encoded></item><item><title>L10n.dev AI Localization Automation</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/l10n.dev-ai-localization-automation/</link><pubDate>Fri, 03 Jul 2026 22:12:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/l10n.dev-ai-localization-automation/</guid><description>Version updated for https://github.com/l10n-dev/ai-l10n to version v1.9.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: add GlossaryManager and LinguisticInstructionsManager and CLI for them by @AntonovAnton in https://github.com/l10n-dev/ai-l10n/pull/48 Full Changelog: https://github.com/l10n-dev/ai-l10n/compare/v1.8.0...v1.9.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/l10n-dev/ai-l10n">https://github.com/l10n-dev/ai-l10n</a></strong> to version <strong>v1.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/l10n-dev-ai-localization-automation">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: add GlossaryManager and LinguisticInstructionsManager and CLI for them by @AntonovAnton in <a href="https://github.com/l10n-dev/ai-l10n/pull/48">https://github.com/l10n-dev/ai-l10n/pull/48</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/l10n-dev/ai-l10n/compare/v1.8.0...v1.9.0">https://github.com/l10n-dev/ai-l10n/compare/v1.8.0...v1.9.0</a></p>
]]></content:encoded></item><item><title>OSS Security Policy as Code</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/oss-security-policy-as-code/</link><pubDate>Fri, 03 Jul 2026 22:11:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/oss-security-policy-as-code/</guid><description>Version updated for https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit to version v10.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed OSS Security Policy as Code Starter Kit v10.0.0 The normalized-findings major (ADR-030). The kit now correlates the scanner evidence it already composes — six kit evidence JSONs plus four external SARIF drops — into one deduplicated, KEV/EPSS-ranked finding view, delivered as a new versioned artifact and a new command. Stateless by design: one clone-only run, no database, no state between runs, no network.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit">https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit</a></strong> to version <strong>v10.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/oss-security-policy-as-code">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="oss-security-policy-as-code-starter-kit-v1000">OSS Security Policy as Code Starter Kit v10.0.0</h2>
<p><strong>The normalized-findings major (ADR-030).</strong> The kit now correlates the scanner evidence it already composes — six kit evidence JSONs plus four external SARIF drops — into <strong>one deduplicated, KEV/EPSS-ranked finding view</strong>, delivered as a new versioned artifact and a new command. Stateless by design: one clone-only run, no database, no state between runs, no network.</p>
<hr>
<h2 id="highlights">Highlights</h2>
<ul>
<li><strong>New command: <code>correlate-findings</code></strong> (23rd command). Normalizes findings from Semgrep, the four IaC/K8s scanners, zizmor, poutine, OSV-Scanner, and Gitleaks into one vocabulary; deduplicates across scanners with deterministic <code>opk-fk/v1</code> fingerprints (conservative under-merge: the same CVE from two tools collapses, distinct issues never do); and ranks CISA-KEV first, then EPSS, then severity. Re-runs are bit-identical.</li>
<li><strong>New contract: <code>findings/1.0</code></strong> (<code>.oss-policy-kit/findings.json</code>) — strict schema, published at <code>reports/schema/findings-1.0.schema.json</code>. Every source&rsquo;s original severity is preserved verbatim; missing/unreadable evidence is recorded honestly, never fatal.</li>
<li><strong>Opt-in gates for the correlated set</strong>: <code>--fail-on-severity</code> and <code>--fail-on-kev</code> (a correlated group gates once, regardless of how many tools reported it). Control evaluators are untouched — fence tests prove <code>evaluate</code> output is byte-identical with the feature present or absent.</li>
<li><strong>Finding-level waivers</strong>: <code>vulnerability_ids:</code>-keyed entries in <code>waivers.yaml</code> (the same ones <code>emit-vex</code> consumes) mark findings as waived — visible in the artifact, exempt from the findings gates, and provably unable to change any control state.</li>
<li><strong>Offline EPSS/KEV enrichment</strong>: <code>--enrichment-file</code> takes a user-supplied snapshot that refines <strong>ranking only</strong> (inferred trust, provenance recorded). The kit ships no bundled advisory data.</li>
<li><strong>Aggregator SARIF export</strong>: <code>--format sarif</code> self-describes as an aggregator/correlator — never the scanner — with per-result source-tool attribution and a double-reporting warning.</li>
<li><strong><code>evaluate --with-findings-summary</code></strong>: additive <code>extensions.findings_summary</code> block (totals, by-severity, KEV/high-EPSS counts, findings digest) computed in-process; changes no state, summary, digest, or exit code.</li>
</ul>
<h2 id="breaking-changes-see-docsv1000-migration-guidemd">Breaking changes (see <a href="https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit/blob/master/docs/v10.0.0-migration-guide.md">docs/v10.0.0-migration-guide.md</a>)</h2>
<ul>
<li>The deprecated <strong><code>cra-eu-ready-2-1</code> profile alias is removed</strong> (ADR-029, one-major cycle complete). Use <code>cra-eu-conformance-evidence-1</code>; the old id exits 2 with a pointer.</li>
<li>The legacy <strong><code>evaluation-report-v1/v2/v3.schema.json</code> files no longer ship</strong> in the wheel or the public <code>reports/schema/</code> mirror (the contracts were removed in v9.0.0). The mirror now carries the real current contracts (reports/2.0 + findings/1.0).</li>
<li><strong><code>scripts/migrate-1.0-to-2.0.py</code> is removed</strong> — retrieve it from the v9.x tags for stored legacy reports.</li>
<li><strong><code>export-evidence</code> requires reports/2.0 input.</strong> The silent reports/1.0 fallbacks are gone, and previously-wrong outputs are fixed: SPDX annotations now carry real states/messages, every renderer reads <code>target_path</code>, chainloop stops reading a nonexistent waivers array.</li>
</ul>
<h2 id="docs">Docs</h2>
<ul>
<li>New <a href="https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit/blob/master/docs/findings-correlation.md">findings-correlation.md</a> — the contract, the <code>opk-fk/v1</code> key spec, the under-merge guarantees, and the anti-ASPM fence.</li>
<li>New v10.0.0 migration guide; CLI reference and README updated for the 23-command surface.</li>
<li><code>triage-cvss-epss-kev.md</code> no longer implies the evaluator thresholds are tunable (they are fixed; tunable prioritization is the findings surface).</li>
</ul>
<h2 id="integrity">Integrity</h2>
<p>Quality gates: 4,310 unit + 19 property tests (including determinism, order-independence, and six mandatory fence tests), mypy strict, coverage 93%+. Pre- and post-publish clean-room validation on the real PyPI artifact. PyPI Trusted Publishing + registry attestations; container signed with cosign keyless.</p>
<p><strong>License:</strong> Apache-2.0.</p>
]]></content:encoded></item><item><title>Run Maester</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/run-maester/</link><pubDate>Fri, 03 Jul 2026 22:11:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/run-maester/</guid><description>Version updated for https://github.com/maester365/maester-action to version v1.2.0.
This action is used across all versions by 7 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed ci: bump actions/checkout from 6 to 7 in the all-actions group by @dependabot[bot] in https://github.com/maester365/maester-action/pull/43 Interactive report available as GitHub artifact with a direct link by @svrooij in https://github.com/maester365/maester-action/pull/42 Full Changelog: https://github.com/maester365/maester-action/compare/v1.1.0...v1.2.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/maester365/maester-action">https://github.com/maester365/maester-action</a></strong> to version <strong>v1.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-maester">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci: bump actions/checkout from 6 to 7 in the all-actions group by @dependabot[bot] in <a href="https://github.com/maester365/maester-action/pull/43">https://github.com/maester365/maester-action/pull/43</a></li>
<li>Interactive report available as GitHub artifact with a direct link by @svrooij in <a href="https://github.com/maester365/maester-action/pull/42">https://github.com/maester365/maester-action/pull/42</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/maester365/maester-action/compare/v1.1.0...v1.2.0">https://github.com/maester365/maester-action/compare/v1.1.0...v1.2.0</a></p>
]]></content:encoded></item><item><title>Quorum consensus security scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/quorum-consensus-security-scan/</link><pubDate>Fri, 03 Jul 2026 22:10:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/quorum-consensus-security-scan/</guid><description>Version updated for https://github.com/Martinez1991/quorum-sec-scan to version v0.7.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog 8b28bef427d98b63b5f50a96aaf0fbc1e4575894: Merge pull request #45 from Martinez1991/feat/crosswalk-multicloud-azure-gcp (@Martinez1991) 8852a90f27d4d886188266d468c6962b3e31f789: feat(crosswalk): multi-cloud consensus — Azure + GCP + more AWS (real overlaps) (@Martinez1991)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Martinez1991/quorum-sec-scan">https://github.com/Martinez1991/quorum-sec-scan</a></strong> to version <strong>v0.7.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/quorum-consensus-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>8b28bef427d98b63b5f50a96aaf0fbc1e4575894: Merge pull request #45 from Martinez1991/feat/crosswalk-multicloud-azure-gcp (@Martinez1991)</li>
<li>8852a90f27d4d886188266d468c6962b3e31f789: feat(crosswalk): multi-cloud consensus — Azure + GCP + more AWS (real overlaps) (@Martinez1991)</li>
</ul>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/go-proxy-cache-updater/</link><pubDate>Fri, 03 Jul 2026 22:10:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.12.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.1.12 (2026-07-03)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.12</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1112-2026-07-03"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.11...v1.1.12">1.1.12</a> (2026-07-03)</h2>
]]></content:encoded></item><item><title>Run AER Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/run-aer-tests/</link><pubDate>Fri, 03 Jul 2026 22:09:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/run-aer-tests/</guid><description>Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.6.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Version v1.2.6
Treat NUL Bytes As Ignorable Whitespace
Type Schema.SObjectType Describe-Result Properties As Their Real Types
Resolve Null-Argument Constructor Overloads By Most-Specific Non-Null Position
Allow Public Override Of A Global Abstract Method</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/octoberswimmer/aer-dist">https://github.com/octoberswimmer/aer-dist</a></strong> to version <strong>v1.2.6</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-aer-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Version v1.2.6</p>
<ul>
<li>
<p>Treat NUL Bytes As Ignorable Whitespace</p>
</li>
<li>
<p>Type Schema.SObjectType Describe-Result Properties As Their Real Types</p>
</li>
<li>
<p>Resolve Null-Argument Constructor Overloads By Most-Specific Non-Null Position</p>
</li>
<li>
<p>Allow Public Override Of A Global Abstract Method</p>
</li>
<li>
<p>Match Namespaced Custom-SObject Type Arguments In Generic Assignability</p>
</li>
<li>
<p>Add Schema.SObjectType Child-Relationship Property Regression Test</p>
</li>
<li>
<p>Return Real Record-Type Infos From Schema.SObjectType Describe Properties</p>
</li>
<li>
<p>Treat Array-Literal Elements As Values, Not Constructor Arguments</p>
</li>
</ul>
]]></content:encoded></item><item><title>SpringSentinel</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/springsentinel/</link><pubDate>Fri, 03 Jul 2026 22:09:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/springsentinel/</guid><description>Version updated for https://github.com/pagano-antonio/springsentinel-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Create README.md (3e1d589) Update test.yml (3a7ed11) Update entrypoint.sh (4e15ea0) Update entrypoint.sh (6418942) Update entrypoint.sh (51f3a42) Create test.yml (d46361f) Create entrypoint.sh (bcf8584) Create Dockerfile (72d2f0b) Create action.yml (89fad1e)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pagano-antonio/springsentinel-action">https://github.com/pagano-antonio/springsentinel-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/springsentinel">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Create README.md (3e1d589)</li>
<li>Update test.yml (3a7ed11)</li>
<li>Update entrypoint.sh (4e15ea0)</li>
<li>Update entrypoint.sh (6418942)</li>
<li>Update entrypoint.sh (51f3a42)</li>
<li>Create test.yml (d46361f)</li>
<li>Create entrypoint.sh (bcf8584)</li>
<li>Create Dockerfile (72d2f0b)</li>
<li>Create action.yml (89fad1e)</li>
</ul>
]]></content:encoded></item><item><title>Rust Lint Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/rust-lint-action/</link><pubDate>Fri, 03 Jul 2026 22:08:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/rust-lint-action/</guid><description>Version updated for https://github.com/Profiidev/rust-lint-action to version v4.3.0.
This action is used across all versions by 25 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Lint action version v4.3.0 has been released!
What’s Changed chore(deps): lock file maintenance by @renovate[bot] in https://github.com/Profiidev/rust-lint-action/pull/25 chore(deps): lock file maintenance by @renovate[bot] in https://github.com/Profiidev/rust-lint-action/pull/26 chore(deps): lock file maintenance by @renovate[bot] in https://github.com/Profiidev/rust-lint-action/pull/27 chore(deps): lock file maintenance by @renovate[bot] in https://github.com/Profiidev/rust-lint-action/pull/28 chore(deps): pin dependencies by @renovate[bot] in https://github.com/Profiidev/rust-lint-action/pull/29 chore(deps): update actions/checkout digest to df4cb1c by @renovate[bot] in https://github.com/Profiidev/rust-lint-action/pull/30 chore: shared renovate config by @Profiidev in https://github.com/Profiidev/rust-lint-action/pull/31 fix: add warnings on linter success by @Profiidev in https://github.com/Profiidev/rust-lint-action/pull/32 Release version v4.3.0 by @profidev-commit-bot[bot] in https://github.com/Profiidev/rust-lint-action/pull/33 Full Changelog: https://github.com/Profiidev/rust-lint-action/compare/v4.2.0...v4.3.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Profiidev/rust-lint-action">https://github.com/Profiidev/rust-lint-action</a></strong> to version <strong>v4.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>25</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rust-lint-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Lint action version v4.3.0 has been released!</p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/Profiidev/rust-lint-action/pull/25">https://github.com/Profiidev/rust-lint-action/pull/25</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/Profiidev/rust-lint-action/pull/26">https://github.com/Profiidev/rust-lint-action/pull/26</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/Profiidev/rust-lint-action/pull/27">https://github.com/Profiidev/rust-lint-action/pull/27</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/Profiidev/rust-lint-action/pull/28">https://github.com/Profiidev/rust-lint-action/pull/28</a></li>
<li>chore(deps): pin dependencies by @renovate[bot] in <a href="https://github.com/Profiidev/rust-lint-action/pull/29">https://github.com/Profiidev/rust-lint-action/pull/29</a></li>
<li>chore(deps): update actions/checkout digest to df4cb1c by @renovate[bot] in <a href="https://github.com/Profiidev/rust-lint-action/pull/30">https://github.com/Profiidev/rust-lint-action/pull/30</a></li>
<li>chore: shared renovate config by @Profiidev in <a href="https://github.com/Profiidev/rust-lint-action/pull/31">https://github.com/Profiidev/rust-lint-action/pull/31</a></li>
<li>fix: add warnings on linter success by @Profiidev in <a href="https://github.com/Profiidev/rust-lint-action/pull/32">https://github.com/Profiidev/rust-lint-action/pull/32</a></li>
<li>Release version v4.3.0 by @profidev-commit-bot[bot] in <a href="https://github.com/Profiidev/rust-lint-action/pull/33">https://github.com/Profiidev/rust-lint-action/pull/33</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Profiidev/rust-lint-action/compare/v4.2.0...v4.3.0">https://github.com/Profiidev/rust-lint-action/compare/v4.2.0...v4.3.0</a></p>
]]></content:encoded></item><item><title>goog - OG Image Generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/goog-og-image-generator/</link><pubDate>Fri, 03 Jul 2026 22:07:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/goog-og-image-generator/</guid><description>Version updated for https://github.com/riceball-tw/goog to version v1.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/riceball-tw/goog/commits/v1.0.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/riceball-tw/goog">https://github.com/riceball-tw/goog</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/goog-og-image-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/riceball-tw/goog/commits/v1.0.0">https://github.com/riceball-tw/goog/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>DiffGate Review Triage</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/diffgate-review-triage/</link><pubDate>Fri, 03 Jul 2026 22:06:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/diffgate-review-triage/</guid><description>Version updated for https://github.com/srbsa/diffgate to version v0.7.10.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed release: 0.7.10 — fix mcpb/Smithery bundle crash, MCP tool metadata (6eb9373) fix: mcpb/Smithery bundle crashed with no node_modules; add MCP tool metadata (8ed0ea0) release: 0.7.9 — per-rule path scoping + docs-prose carve-out (Backstage eval fixes) (54110d9) release: 0.7.8 — dependency-manifest goes section-aware (version bumps no longer flagged) (2f992bc) release: 0.7.7 — fix GH Marketplace action.yml rejection + MCP registry description cap (87b8fdf) fix: action.yml name collision + description over Marketplace’s 125-char cap (05227d2) fix: shorten server.json description under the MCP registry’s 100-char cap (2a4ada1) release: 0.7.6 — distribution plumbing (MCP registry, Docker/GHCR, pre-commit, GH Action, Claude plugin) (56fc4a6) release: 0.7.5, republish with updated README after 0.7.4 publish (3c778dd) docs: promote history-audit as the quick-start aha moment (2611797)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/srbsa/diffgate">https://github.com/srbsa/diffgate</a></strong> to version <strong>v0.7.10</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/diffgate-review-triage">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>release: 0.7.10 — fix mcpb/Smithery bundle crash, MCP tool metadata (6eb9373)</li>
<li>fix: mcpb/Smithery bundle crashed with no node_modules; add MCP tool metadata (8ed0ea0)</li>
<li>release: 0.7.9 — per-rule path scoping + docs-prose carve-out (Backstage eval fixes) (54110d9)</li>
<li>release: 0.7.8 — dependency-manifest goes section-aware (version bumps no longer flagged) (2f992bc)</li>
<li>release: 0.7.7 — fix GH Marketplace action.yml rejection + MCP registry description cap (87b8fdf)</li>
<li>fix: action.yml name collision + description over Marketplace&rsquo;s 125-char cap (05227d2)</li>
<li>fix: shorten server.json description under the MCP registry&rsquo;s 100-char cap (2a4ada1)</li>
<li>release: 0.7.6 — distribution plumbing (MCP registry, Docker/GHCR, pre-commit, GH Action, Claude plugin) (56fc4a6)</li>
<li>release: 0.7.5, republish with updated README after 0.7.4 publish (3c778dd)</li>
<li>docs: promote history-audit as the quick-start aha moment (2611797)</li>
</ul>
]]></content:encoded></item><item><title>Groundskeeper Issue Triage</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/groundskeeper-issue-triage/</link><pubDate>Fri, 03 Jul 2026 22:06:22 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/groundskeeper-issue-triage/</guid><description>Version updated for https://github.com/theadamdanielsson/groundskeeper to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First public release.
Groundskeeper is a first responder for new GitHub issues. When someone opens one, it reads your repo, then posts a single grounded comment: a duplicate check, the repro info that’s missing, a pointer to the relevant file and line, and suggested labels. If it doesn’t have anything solid to say, it stays silent.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/theadamdanielsson/groundskeeper">https://github.com/theadamdanielsson/groundskeeper</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/groundskeeper-issue-triage">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release.</p>
<p>Groundskeeper is a first responder for new GitHub issues. When someone opens one, it reads your repo, then posts a single grounded comment: a duplicate check, the repro info that&rsquo;s missing, a pointer to the relevant file and line, and suggested labels. If it doesn&rsquo;t have anything solid to say, it stays silent.</p>
<p>It runs as a GitHub Action in your own CI on your own Anthropic key. No hosted service, no third-party app to install.</p>
<p>Install:</p>
<ul>
<li>uses: theadamdanielsson/groundskeeper@v1</li>
</ul>
<p>Defaults to claude-sonnet-4-6. Requires an ANTHROPIC_API_KEY repo secret and issues: write permission. See the README for the full setup.</p>
]]></content:encoded></item><item><title>MIU PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/miu-pr-review/</link><pubDate>Fri, 03 Jul 2026 22:05:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/miu-pr-review/</guid><description>Version updated for https://github.com/vanducng/miu-cr to version v0.84.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed miu-cr v0.84.1 AI code review for local changes and GitHub pull requests. Use it as a CLI, CI gate, or GitHub Action with your own LLM key.
Install curl -fsSL https://cr.miu.sh/install.sh | sh -s -- v0.84.1 brew install vanducng/tap/miucr go install github.com/vanducng/miu-cr/cmd/miucr@v0.84.1 GitHub Action:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vanducng/miu-cr">https://github.com/vanducng/miu-cr</a></strong> to version <strong>v0.84.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/miu-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="miu-cr-v0841">miu-cr v0.84.1</h2>
<p>AI code review for local changes and GitHub pull requests. Use it as a CLI, CI gate, or GitHub Action with your own LLM key.</p>
<h3 id="install">Install</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>curl -fsSL https://cr.miu.sh/install.sh | sh -s -- v0.84.1
</span></span><span style="display:flex;"><span>brew install vanducng/tap/miucr
</span></span><span style="display:flex;"><span>go install github.com/vanducng/miu-cr/cmd/miucr@v0.84.1
</span></span></code></pre></div><p>GitHub Action:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v6</span>
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">vanducng/miu-cr@v0.84.1</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span></code></pre></div><h3 id="common-commands">Common commands</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>miucr login --provider openai
</span></span><span style="display:flex;"><span>miucr review --staged
</span></span><span style="display:flex;"><span>miucr review --from main --to HEAD --gate high
</span></span><span style="display:flex;"><span>miucr review --pr owner/repo#123 --post
</span></span><span style="display:flex;"><span>miucr upgrade
</span></span></code></pre></div><p>Docs: <a href="https://cr.miu.sh">https://cr.miu.sh</a></p>
]]></content:encoded></item><item><title>Vibgrate Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/vibgrate-scan/</link><pubDate>Fri, 03 Jul 2026 22:05:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/vibgrate-scan/</guid><description>Version updated for https://github.com/vibgrate/cli to version v2026.703.7.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Vibgrate CLI 2026.703.7 Released 2026-07-03
Routine maintenance update for the CLI.
What changed Changed Maintenance release with internal improvements and dependency updates. Benchmarks Two-arm benchmark of this release against 2026.703.5, interleaved on one runner against the pinned corpus (157 metrics compared).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vibgrate/cli">https://github.com/vibgrate/cli</a></strong> to version <strong>v2026.703.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vibgrate-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="vibgrate-cli-20267037">Vibgrate CLI 2026.703.7</h1>
<p><em>Released 2026-07-03</em></p>
<p>Routine maintenance update for the CLI.</p>
<h2 id="what-changed">What changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li>Maintenance release with internal improvements and dependency updates.</li>
</ul>
<h2 id="benchmarks">Benchmarks</h2>
<p>Two-arm benchmark of this release against 2026.703.5, interleaved on one runner against the pinned corpus (157 metrics compared).</p>
<table>
  <thead>
      <tr>
          <th>Metric</th>
          <th>Previous</th>
          <th>This release</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Languages with extraction</td>
          <td>19 count</td>
          <td>19 count</td>
      </tr>
      <tr>
          <td>Definitions extracted (corpus total)</td>
          <td>18413 count</td>
          <td>18413 count</td>
      </tr>
      <tr>
          <td>Call edges extracted (corpus total)</td>
          <td>6884 count</td>
          <td>6884 count</td>
      </tr>
      <tr>
          <td>Locate accuracy (top-1)</td>
          <td>0.97 ratio</td>
          <td>0.97 ratio</td>
      </tr>
      <tr>
          <td>Dependency detection (authored manifest truth)</td>
          <td>0.96 ratio</td>
          <td>0.96 ratio</td>
      </tr>
      <tr>
          <td>CLI startup (&ndash;version, median)</td>
          <td>613.80 ms</td>
          <td>618.20 ms</td>
      </tr>
  </tbody>
</table>
<p>No regressions against the previous release.</p>
<p>Full report and methodology: <a href="https://vibgrate.com/cli/benchmarks">https://vibgrate.com/cli/benchmarks</a></p>
<h2 id="install-or-update">Install or update</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>npm install -g @vibgrate/cli
</span></span><span style="display:flex;"><span>vg
</span></span></code></pre></div><p>Full changelog: <a href="https://vibgrate.com/changelog/cli/2026.703.7">https://vibgrate.com/changelog/cli/2026.703.7</a></p>
]]></content:encoded></item><item><title>Setup vp</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/setup-vp/</link><pubDate>Fri, 03 Jul 2026 22:04:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/setup-vp/</guid><description>Version updated for https://github.com/voidzero-dev/setup-vp to version v1.14.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed docs: document the version release process by @fengmk2 in https://github.com/voidzero-dev/setup-vp/pull/101 ci: auto-rebuild action bundle on Renovate dependency bumps by @fengmk2 in https://github.com/voidzero-dev/setup-vp/pull/103 feat: resolve Vite+ version from package.json / catalog by @fengmk2 in https://github.com/voidzero-dev/setup-vp/pull/102 Full Changelog: https://github.com/voidzero-dev/setup-vp/compare/v1.13.0...v1.14.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/voidzero-dev/setup-vp">https://github.com/voidzero-dev/setup-vp</a></strong> to version <strong>v1.14.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-vp">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs: document the version release process by @fengmk2 in <a href="https://github.com/voidzero-dev/setup-vp/pull/101">https://github.com/voidzero-dev/setup-vp/pull/101</a></li>
<li>ci: auto-rebuild action bundle on Renovate dependency bumps by @fengmk2 in <a href="https://github.com/voidzero-dev/setup-vp/pull/103">https://github.com/voidzero-dev/setup-vp/pull/103</a></li>
<li>feat: resolve Vite+ version from package.json / catalog by @fengmk2 in <a href="https://github.com/voidzero-dev/setup-vp/pull/102">https://github.com/voidzero-dev/setup-vp/pull/102</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/voidzero-dev/setup-vp/compare/v1.13.0...v1.14.0">https://github.com/voidzero-dev/setup-vp/compare/v1.13.0...v1.14.0</a></p>
]]></content:encoded></item><item><title>graph-sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/graph-sync/</link><pubDate>Fri, 03 Jul 2026 22:04:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/graph-sync/</guid><description>Version updated for https://github.com/wordlift/graph-sync to version v6.11.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/wordlift/graph-sync/compare/v6.11.2...v6.11.3</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wordlift/graph-sync">https://github.com/wordlift/graph-sync</a></strong> to version <strong>v6.11.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/graph-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/wordlift/graph-sync/compare/v6.11.2...v6.11.3">https://github.com/wordlift/graph-sync/compare/v6.11.2...v6.11.3</a></p>
]]></content:encoded></item><item><title>backlog-to-pr</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/backlog-to-pr/</link><pubDate>Fri, 03 Jul 2026 22:03:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/backlog-to-pr/</guid><description>Version updated for https://github.com/wrbl606/backlog.md-to-pr to version 0.0.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/wrbl606/backlog.md-to-pr/compare/0.0.2...0.0.3</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wrbl606/backlog.md-to-pr">https://github.com/wrbl606/backlog.md-to-pr</a></strong> to version <strong>0.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/backlog-to-pr">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/wrbl606/backlog.md-to-pr/compare/0.0.2...0.0.3">https://github.com/wrbl606/backlog.md-to-pr/compare/0.0.2...0.0.3</a></p>
]]></content:encoded></item><item><title>Setup Modern C++ Development Environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/setup-modern-c-development-environment/</link><pubDate>Fri, 03 Jul 2026 22:03:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/setup-modern-c-development-environment/</guid><description>Version updated for https://github.com/wx257osn2/cxx_environment to version v20260703.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed bump up base image to resolute outdated: clang-format 17-20 enabled gnucoreutils bump up many components: gcc: 15.2 -&amp;gt; 16.1 Boost: 1.89.0 -&amp;gt; 1.91.0 CMake: 4.1.1 -&amp;gt; 4.3.3 difftastic: 0.64 -&amp;gt; 0.69 mold: 2.40.4 -&amp;gt; 2.41.0 wild: 0.8.0 -&amp;gt; 0.9.0 removed components: old clang-format s clang-head $ ./pull.bash v20260703</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wx257osn2/cxx_environment">https://github.com/wx257osn2/cxx_environment</a></strong> to version <strong>v20260703</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-modern-c-development-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>bump up base image to resolute
<ul>
<li>outdated: <code>clang-format</code> 17-20</li>
<li>enabled gnucoreutils</li>
</ul>
</li>
<li>bump up many components:
<ul>
<li>gcc: 15.2 -&gt; 16.1</li>
<li>Boost: 1.89.0 -&gt; 1.91.0</li>
<li>CMake: 4.1.1 -&gt; 4.3.3</li>
<li>difftastic: 0.64 -&gt; 0.69</li>
<li>mold: 2.40.4 -&gt; 2.41.0</li>
<li>wild: 0.8.0 -&gt; 0.9.0</li>
</ul>
</li>
<li>removed components:
<ul>
<li>old <code>clang-format</code> s</li>
<li><code>clang-head</code></li>
</ul>
</li>
</ul>
<pre tabindex="0"><code>$ ./pull.bash v20260703
</code></pre>]]></content:encoded></item><item><title>AGENTS.md Lint (Schliff)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/agents.md-lint-schliff/</link><pubDate>Fri, 03 Jul 2026 22:02:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/agents.md-lint-schliff/</guid><description>Version updated for https://github.com/Zandereins/schliff to version v8.4.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added operational_coverage dimension for AGENTS.md (#83). Measures whether an AGENTS.md actually equips a coding agent to operate the repo: real setup/build/test commands (command-family classification, doc-wide, headings never gate) plus code-style / gotchas / PR directive sections with concrete code tokens. Surfaced in the CLI dimension table, the GitHub Action’s PR comment, and accepted by the leaderboard submit API. Changed BREAKING (scores): the AGENTS.md headline profile is now structure 0.40 / operational_coverage 0.40 / efficiency 0.20 (was 0.5/0.5). efficiency was a validated gameable proxy — a junk-fence-stuffed doc scored 92.5/A while the same real commands written inline scored 70.0/C. All AGENTS.md scores re-baseline (30-file corpus: mean 61.06, no file reaches S). SKILL.md / CLAUDE.md / .cursorrules / system-prompt scoring is byte-identical to 8.3.0. Security Fixed a ReDoS in the operational_coverage heading regex (quadratic on whitespace-only heading lines) before it ever shipped — found by a 75-agent adversarial review pass, together with a directive-gate gaming hole, a fence-state desync, and 12 command-recall bugs. Full record: docs/specs/agents-md-operational-coverage.md §11. Full changelog: https://github.com/Zandereins/schliff/compare/v8.3.0...v8.4.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Zandereins/schliff">https://github.com/Zandereins/schliff</a></strong> to version <strong>v8.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agents-md-lint-schliff">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="added">Added</h2>
<ul>
<li><strong><code>operational_coverage</code> dimension for AGENTS.md</strong> (#83). Measures whether an AGENTS.md actually equips a coding agent to operate the repo: real setup/build/test commands (command-family classification, doc-wide, headings never gate) plus code-style / gotchas / PR directive sections with concrete code tokens. Surfaced in the CLI dimension table, the GitHub Action&rsquo;s PR comment, and accepted by the leaderboard submit API.</li>
</ul>
<h2 id="changed">Changed</h2>
<ul>
<li><strong>BREAKING (scores): the AGENTS.md headline profile is now <code>structure 0.40 / operational_coverage 0.40 / efficiency 0.20</code></strong> (was 0.5/0.5). <code>efficiency</code> was a validated gameable proxy — a junk-fence-stuffed doc scored 92.5/A while the same real commands written inline scored 70.0/C. All AGENTS.md scores re-baseline (30-file corpus: mean 61.06, no file reaches S). SKILL.md / CLAUDE.md / .cursorrules / system-prompt scoring is <strong>byte-identical</strong> to 8.3.0.</li>
</ul>
<h2 id="security">Security</h2>
<ul>
<li>Fixed a ReDoS in the operational_coverage heading regex (quadratic on whitespace-only heading lines) <strong>before it ever shipped</strong> — found by a 75-agent adversarial review pass, together with a directive-gate gaming hole, a fence-state desync, and 12 command-recall bugs. Full record: <code>docs/specs/agents-md-operational-coverage.md</code> §11.</li>
</ul>
<p><strong>Full changelog:</strong> <a href="https://github.com/Zandereins/schliff/compare/v8.3.0...v8.4.0">https://github.com/Zandereins/schliff/compare/v8.3.0...v8.4.0</a></p>
]]></content:encoded></item><item><title>GHCR Cleanup Manager</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/ghcr-cleanup-manager/</link><pubDate>Fri, 03 Jul 2026 06:46:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/ghcr-cleanup-manager/</guid><description>Version updated for https://github.com/ghcr-manager/ghcr-cleanup-manager to version v1.1.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/ghcr-manager/ghcr-cleanup-manager/compare/v1.1.4...v1.1.5</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ghcr-manager/ghcr-cleanup-manager">https://github.com/ghcr-manager/ghcr-cleanup-manager</a></strong> to version <strong>v1.1.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ghcr-cleanup-manager">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/ghcr-manager/ghcr-cleanup-manager/compare/v1.1.4...v1.1.5">https://github.com/ghcr-manager/ghcr-cleanup-manager/compare/v1.1.4...v1.1.5</a></p>
]]></content:encoded></item><item><title>SQL/NoSQL Syntax Validator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/sql/nosql-syntax-validator/</link><pubDate>Fri, 03 Jul 2026 06:46:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/sql/nosql-syntax-validator/</guid><description>Version updated for https://github.com/GianfrancoArocutipa/sql-nosql-validator-action to version v1.
This action is used across all versions by 1 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Primera versión del SQL/NoSQL Syntax Validator Action. Valida archivos .sql y .mongo sin servidor requerido.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/GianfrancoArocutipa/sql-nosql-validator-action">https://github.com/GianfrancoArocutipa/sql-nosql-validator-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sql-nosql-syntax-validator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Primera versión del SQL/NoSQL Syntax Validator Action.
Valida archivos .sql y .mongo sin servidor requerido.</p>
]]></content:encoded></item><item><title>Tenter Scan (Rust)</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/tenter-scan-rust/</link><pubDate>Fri, 03 Jul 2026 06:45:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/tenter-scan-rust/</guid><description>Version updated for https://github.com/goweft/tenter-rs to version v2.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/goweft/tenter-rs/compare/v2...v2.1.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/goweft/tenter-rs">https://github.com/goweft/tenter-rs</a></strong> to version <strong>v2.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/tenter-scan-rust">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/goweft/tenter-rs/compare/v2...v2.1.0">https://github.com/goweft/tenter-rs/compare/v2...v2.1.0</a></p>
]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/ai-plugin-scanner/</link><pubDate>Fri, 03 Jul 2026 06:44:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.372.
This action is used across all versions by 17 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/dae00cbd1175595edfdf44f1b84bc3f043d08a0b with plugin-scanner 2.0.972.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.371...v1.2.372</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.372</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>17</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/dae00cbd1175595edfdf44f1b84bc3f043d08a0b">https://github.com/hashgraph-online/hol-guard/tree/dae00cbd1175595edfdf44f1b84bc3f043d08a0b</a> with plugin-scanner 2.0.972.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.371...v1.2.372">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.371...v1.2.372</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/hol-codex-plugin-scanner/</link><pubDate>Fri, 03 Jul 2026 06:44:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.372.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.372</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.372</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.372">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.372</a></p>
]]></content:encoded></item><item><title>Supply Chain Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/supply-chain-guard/</link><pubDate>Fri, 03 Jul 2026 06:43:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/supply-chain-guard/</guid><description>Version updated for https://github.com/homeofe/supply-chain-guard to version v5.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v5.6.0 (2026-07-03) Install-time guard + GitLab-native output + registry hardening (both remaining roadmap bets)
Ships the last two strategic bets from the 2026-07 roadmap. A second 4-lens adversarial verification gate reviewed the diff and BLOCKED the first candidate with 5 confirmed findings, all fixed here (a real Windows RCE among them). 40 new tests (1120 total).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/homeofe/supply-chain-guard">https://github.com/homeofe/supply-chain-guard</a></strong> to version <strong>v5.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/supply-chain-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="v560-2026-07-03">v5.6.0 (2026-07-03)</h3>
<p><strong>Install-time guard + GitLab-native output + registry hardening (both remaining roadmap bets)</strong></p>
<p>Ships the last two strategic bets from the 2026-07 roadmap. A second 4-lens
adversarial verification gate reviewed the diff and BLOCKED the first candidate
with 5 confirmed findings, all fixed here (a real Windows RCE among them).
40 new tests (1120 total).</p>
<ul>
<li><strong>Install Guard</strong> (Bet 2): <code>supply-chain-guard guard &lt;npm|pnpm|yarn|bun&gt; [args...]</code> checks each package spec against the offline IOC feed +
known-bad-version blocklist + typosquat heuristics BEFORE the package manager
runs any lifecycle script; a hit blocks the install (exit 2). <code>--force</code>
overrides with a loud warning, <code>--dry-run</code> never invokes the manager. The
only install blocker whose entire blocklist is auditable in git history,
offline, no account.</li>
<li><strong>GitLab-native output</strong> (Bet 3, delivered on the v5.5.0 GHCR image):
<code>--format gitlab</code> emits a GitLab Dependency Scanning report (schema 15.2.4)
for artifacts:reports:dependency_scanning, so findings surface in the GitLab
security UI. Suppressed findings are excluded (mirrors the SARIF path).</li>
<li><strong>Registry hardening</strong>: the Open VSX download and every redirect hop are now
constrained to an https host allowlist (open-vsx.org + its storage host);
the /tmp -&gt; os.tmpdir() migration is finished across npm/pypi scanners.</li>
<li><strong>CI/infra</strong>: Docker base images pinned by sha256 digest (with a weekly
dependabot docker ecosystem to refresh them); the Jenkins example uses npx;
<code>scan --no-history</code> skips writing .scg-history/ (the pre-commit hook uses it
so hooks never write state into consumer repos).</li>
</ul>
<p>Fixed by the verification gate before release:</p>
<ul>
<li><strong>Windows command injection (critical)</strong> in the Install Guard: the cmd.exe
argument escaping was single-pass, but the npm/pnpm/yarn/bun .cmd shims
re-parse %*, so a crafted package token (<code>x&quot;&amp;echo ...&amp;&quot;</code>) could execute
arbitrary commands. Now double-escaped (cross-spawn doubleEscapeMetaChars),
proven closed by the gate&rsquo;s own PoC.</li>
<li>Install-verb bypasses: <code>npm isntall</code> (and the other documented typo-aliases),
<code>yarn global add</code>, and a value-taking global flag before the verb
(<code>npm --prefix x install evil</code>) all silently skipped scanning. Verb detection
rewritten; flag values are no longer misread as package specs.</li>
<li><code>--format gitlab</code> could emit a &gt;255-char vulnerability name that fails the
GitLab schema, making GitLab discard the whole report; names are now capped.</li>
</ul>
]]></content:encoded></item><item><title>cibuild-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/cibuild-action/</link><pubDate>Fri, 03 Jul 2026 06:43:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/cibuild-action/</guid><description>Version updated for https://github.com/invarnhq/cibuild to version v2.2.9.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v2.2.9</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/invarnhq/cibuild">https://github.com/invarnhq/cibuild</a></strong> to version <strong>v2.2.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cibuild-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release v2.2.9</p>
]]></content:encoded></item><item><title>isreadyai — AI readiness audit</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/isreadyai-ai-readiness-audit/</link><pubDate>Fri, 03 Jul 2026 06:42:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/isreadyai-ai-readiness-audit/</guid><description>Version updated for https://github.com/isreadyai/audit-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial release 🎉 Audit how AI crawlers (GPTBot, ClaudeBot, PerplexityBot) read your site - straight from your CI.
Highlights Deep-crawl audit of any URL, parsed exactly the way Al crawlers see it (no JS execution) 0-100 score + grade, with the full per-page report written to the GitHub job summary CI gate: the step fails when the score drops below your threshold Branch preview support: boot your environment with command, scan it locally before it ships Optional authenticated CI report + repo badge on isready.ai with a Pro/Team api-key (OIDC-verified) Zero setup: pre-bundled, dependency-free - no install step at runtime Usage - name: AI readiness audit uses: isreadyai/audit-action@v1 with: url: ${{ env.DEPLOY_URL }} threshold: 80 See the README for all inputs, outputs, permissions and security notes. Learn more at isready.ai.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/isreadyai/audit-action">https://github.com/isreadyai/audit-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/isreadyai-ai-readiness-audit">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="initial-release-">Initial release 🎉</h2>
<p>Audit how AI crawlers (GPTBot, ClaudeBot, PerplexityBot) read your site - straight from your CI.</p>
<h3 id="highlights">Highlights</h3>
<ul>
<li><strong>Deep-crawl audit</strong> of any URL, parsed exactly the way Al crawlers see it (no JS execution)</li>
<li><strong>0-100 score + grade</strong>, with the full per-page report written to the GitHub job summary</li>
<li><strong>CI gate</strong>: the step fails when the score drops below your <code>threshold</code></li>
<li><strong>Branch preview support</strong>: boot your environment with <code>command</code>, scan it locally before it ships</li>
<li>Optional <strong>authenticated CI report + repo badge</strong> on isready.ai with a Pro/Team <code>api-key</code> (OIDC-verified)</li>
<li>Zero setup: pre-bundled, dependency-free - no install step at runtime</li>
</ul>
<h3 id="usage">Usage</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">name</span>: <span style="color:#ae81ff">AI readiness audit</span>
</span></span><span style="display:flex;"><span>   <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">isreadyai/audit-action@v1</span>
</span></span><span style="display:flex;"><span>   <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>     <span style="color:#f92672">url</span>: <span style="color:#ae81ff">${{ env.DEPLOY_URL }}</span>
</span></span><span style="display:flex;"><span>     <span style="color:#f92672">threshold</span>: <span style="color:#ae81ff">80</span>
</span></span></code></pre></div><p>See the <a href="https://github.com/isreadyai/audit-action#readme">README</a> for all inputs, outputs, permissions and security notes. Learn more at <a href="https://isready.ai">isready.ai</a>.</p>
]]></content:encoded></item><item><title>Agent Guard Secret Guardrails</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/agent-guard-secret-guardrails/</link><pubDate>Fri, 03 Jul 2026 06:42:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/agent-guard-secret-guardrails/</guid><description>Version updated for https://github.com/JeongJaeSoon/agent-guard to version v1.7.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix(shell): make setup-shell rc line self-healing when the CLI leaves $PATH by @JeongJaeSoon in https://github.com/JeongJaeSoon/agent-guard/pull/96 release: v1.7.1 by @github-actions[bot] in https://github.com/JeongJaeSoon/agent-guard/pull/97 Full Changelog: https://github.com/JeongJaeSoon/agent-guard/compare/v1.7.0...v1.7.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/JeongJaeSoon/agent-guard">https://github.com/JeongJaeSoon/agent-guard</a></strong> to version <strong>v1.7.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-guard-secret-guardrails">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(shell): make setup-shell rc line self-healing when the CLI leaves $PATH by @JeongJaeSoon in <a href="https://github.com/JeongJaeSoon/agent-guard/pull/96">https://github.com/JeongJaeSoon/agent-guard/pull/96</a></li>
<li>release: v1.7.1 by @github-actions[bot] in <a href="https://github.com/JeongJaeSoon/agent-guard/pull/97">https://github.com/JeongJaeSoon/agent-guard/pull/97</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/JeongJaeSoon/agent-guard/compare/v1.7.0...v1.7.1">https://github.com/JeongJaeSoon/agent-guard/compare/v1.7.0...v1.7.1</a></p>
]]></content:encoded></item><item><title>sops tools installer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/sops-tools-installer/</link><pubDate>Fri, 03 Jul 2026 06:41:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/sops-tools-installer/</guid><description>Version updated for https://github.com/jkroepke/setup-sops to version v1.5.46.
This action is used across all versions by 4 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed 🛠️ Dependencies chore(deps): update dependencies by @renovate[bot] in https://github.com/jkroepke/setup-sops/pull/238 Full Changelog: https://github.com/jkroepke/setup-sops/compare/v1.5.45...v1.5.46</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jkroepke/setup-sops">https://github.com/jkroepke/setup-sops</a></strong> to version <strong>v1.5.46</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sops-tools-installer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<!-- Release notes generated using configuration in .github/release.yml at v1.5.46 -->
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="-dependencies">🛠️ Dependencies</h3>
<ul>
<li>chore(deps): update dependencies by @renovate[bot] in <a href="https://github.com/jkroepke/setup-sops/pull/238">https://github.com/jkroepke/setup-sops/pull/238</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/jkroepke/setup-sops/compare/v1.5.45...v1.5.46">https://github.com/jkroepke/setup-sops/compare/v1.5.45...v1.5.46</a></p>
]]></content:encoded></item><item><title>ShipSignal readiness gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/shipsignal-readiness-gate/</link><pubDate>Fri, 03 Jul 2026 06:41:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/shipsignal-readiness-gate/</guid><description>Version updated for https://github.com/jpaul67/ShipSignal to version v0.8.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Added README hero image + social-preview card GitHub Action: sticky PR comments (pr-comment input) — score, grade, top 3 fixes, kept updated in place; degrades safely on fork PRs Fixed Security hardening: argument-injection fix in gitinfo.clone, least-privilege GITHUB_TOKEN, all third-party Actions pinned to commit SHAs + Dependabot, secret scanning + branch protection enabled CI: full-history checkout fixes a PR-merge-commit misclassification in the self-scan dogfood tests Full details: CHANGELOG.md</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/jpaul67/ShipSignal">https://github.com/jpaul67/ShipSignal</a></strong> to version <strong>v0.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/shipsignal-readiness-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="added">Added</h2>
<ul>
<li>README hero image + social-preview card</li>
<li>GitHub Action: sticky PR comments (<code>pr-comment</code> input) — score, grade, top 3 fixes, kept updated in place; degrades safely on fork PRs</li>
</ul>
<h2 id="fixed">Fixed</h2>
<ul>
<li>Security hardening: argument-injection fix in <code>gitinfo.clone</code>, least-privilege <code>GITHUB_TOKEN</code>, all third-party Actions pinned to commit SHAs + Dependabot, secret scanning + branch protection enabled</li>
<li>CI: full-history checkout fixes a PR-merge-commit misclassification in the self-scan dogfood tests</li>
</ul>
<p>Full details: <a href="https://github.com/jpaul67/ShipSignal/blob/v0.8.0/CHANGELOG.md#080--2026-07-02">CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>probelock gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/probelock-gate/</link><pubDate>Fri, 03 Jul 2026 06:40:28 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/probelock-gate/</guid><description>Version updated for https://github.com/kelkalot/probelock to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Add ingest pipeline and trace-mined probes by @kelkalot in https://github.com/kelkalot/probelock/pull/1 New Contributors @kelkalot made their first contribution in https://github.com/kelkalot/probelock/pull/1 Full Changelog: https://github.com/kelkalot/probelock/compare/v0.1.0...v0.2.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kelkalot/probelock">https://github.com/kelkalot/probelock</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/probelock-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Add ingest pipeline and trace-mined probes by @kelkalot in <a href="https://github.com/kelkalot/probelock/pull/1">https://github.com/kelkalot/probelock/pull/1</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@kelkalot made their first contribution in <a href="https://github.com/kelkalot/probelock/pull/1">https://github.com/kelkalot/probelock/pull/1</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/kelkalot/probelock/compare/v0.1.0...v0.2.0">https://github.com/kelkalot/probelock/compare/v0.1.0...v0.2.0</a></p>
]]></content:encoded></item><item><title>Repository Languages and CodeQL Support Map</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/repository-languages-and-codeql-support-map/</link><pubDate>Fri, 03 Jul 2026 06:39:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/repository-languages-and-codeql-support-map/</guid><description>Version updated for https://github.com/lfventura/list-repository-languages to version v3.3.0.
This action is used across all versions by 7 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: force_languages input by @lfventura in https://github.com/lfventura/list-repository-languages/pull/8 Full Changelog: https://github.com/lfventura/list-repository-languages/compare/v3.2.1...v3.3.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lfventura/list-repository-languages">https://github.com/lfventura/list-repository-languages</a></strong> to version <strong>v3.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>7</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/repository-languages-and-codeql-support-map">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: force_languages input by @lfventura in <a href="https://github.com/lfventura/list-repository-languages/pull/8">https://github.com/lfventura/list-repository-languages/pull/8</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/lfventura/list-repository-languages/compare/v3.2.1...v3.3.0">https://github.com/lfventura/list-repository-languages/compare/v3.2.1...v3.3.0</a></p>
]]></content:encoded></item><item><title>MCIX Overlay Apply</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/mcix-overlay-apply/</link><pubDate>Fri, 03 Jul 2026 06:39:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/mcix-overlay-apply/</guid><description>Version updated for https://github.com/MettleCI/mcix-overlay-apply to version v0.0.37.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/MettleCI/mcix-overlay-apply/compare/v0.0.36...v0.0.37</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MettleCI/mcix-overlay-apply">https://github.com/MettleCI/mcix-overlay-apply</a></strong> to version <strong>v0.0.37</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcix-overlay-apply">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/MettleCI/mcix-overlay-apply/compare/v0.0.36...v0.0.37">https://github.com/MettleCI/mcix-overlay-apply/compare/v0.0.36...v0.0.37</a></p>
]]></content:encoded></item><item><title>MCIX System Version</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/mcix-system-version/</link><pubDate>Fri, 03 Jul 2026 06:38:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/mcix-system-version/</guid><description>Version updated for https://github.com/MettleCI/mcix-system-version to version v0.0.37.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/MettleCI/mcix-system-version/compare/v0.0.27...v0.0.37</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MettleCI/mcix-system-version">https://github.com/MettleCI/mcix-system-version</a></strong> to version <strong>v0.0.37</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcix-system-version">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/MettleCI/mcix-system-version/compare/v0.0.27...v0.0.37">https://github.com/MettleCI/mcix-system-version/compare/v0.0.27...v0.0.37</a></p>
]]></content:encoded></item><item><title>MCIX Unit-Test Execute</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/mcix-unit-test-execute/</link><pubDate>Fri, 03 Jul 2026 06:38:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/mcix-unit-test-execute/</guid><description>Version updated for https://github.com/MettleCI/mcix-unit-test-execute to version v0.0.37.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/MettleCI/mcix-unit-test-execute/compare/v0.0.27...v0.0.37</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MettleCI/mcix-unit-test-execute">https://github.com/MettleCI/mcix-unit-test-execute</a></strong> to version <strong>v0.0.37</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mcix-unit-test-execute">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/MettleCI/mcix-unit-test-execute/compare/v0.0.27...v0.0.37">https://github.com/MettleCI/mcix-unit-test-execute/compare/v0.0.27...v0.0.37</a></p>
]]></content:encoded></item><item><title>hestia-cache</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/hestia-cache/</link><pubDate>Fri, 03 Jul 2026 06:37:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/hestia-cache/</guid><description>Version updated for https://github.com/Mic92/hestia to version v1.0.4.
This action is used across all versions by 8 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Usage - uses: Mic92/hestia@v1.0.4 with: version: v1.0.4 What’s Changed gha: retry finalize when the uploaded entry is not yet visible by @Mic92 in https://github.com/Mic92/hestia/pull/86 Full Changelog: https://github.com/Mic92/hestia/compare/v1.0.3...v1.0.4</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Mic92/hestia">https://github.com/Mic92/hestia</a></strong> to version <strong>v1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>8</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hestia-cache">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">Mic92/hestia@v1.0.4</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">version</span>: <span style="color:#ae81ff">v1.0.4</span>
</span></span></code></pre></div><h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>gha: retry finalize when the uploaded entry is not yet visible by @Mic92 in <a href="https://github.com/Mic92/hestia/pull/86">https://github.com/Mic92/hestia/pull/86</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Mic92/hestia/compare/v1.0.3...v1.0.4">https://github.com/Mic92/hestia/compare/v1.0.3...v1.0.4</a></p>
]]></content:encoded></item><item><title>Agent Done Or Not</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/agent-done-or-not/</link><pubDate>Fri, 03 Jul 2026 06:37:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/agent-done-or-not/</guid><description>Version updated for https://github.com/mohamedzhioua/agent-done-or-not to version v0.10.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v0.10.1 — Marketplace branding + cleanup A packaging/metadata patch on top of v0.10.0. No engine behavior change — receipts, mode: verify, and the gates are identical.
What changed Marketplace branding on the composite Action (branding.icon: check-circle, color: green) so it can be listed on the GitHub Marketplace with an icon. Removed a now-unreachable inner mode != assert guard in the assert step (already gated by the step if: and the reject-unsupported-mode step). @v0 references in the docs now resolve via a moving v0 major tag that tracks the latest v0.x release. For the security-critical mode: verify gate, keep pinning an exact tag (e.g. @v0.10.1) as the README recommends. Verify quick reference - uses: actions/checkout@v4 # set up your runtime + deps here (setup-node, npm ci, …) - uses: mohamedzhioua/agent-done-or-not@v0.10.1 with: mode: verify checks: | test: npm test build: npm run build Full history in CHANGELOG.md.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mohamedzhioua/agent-done-or-not">https://github.com/mohamedzhioua/agent-done-or-not</a></strong> to version <strong>v0.10.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-done-or-not">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v0101--marketplace-branding--cleanup">v0.10.1 — Marketplace branding + cleanup</h1>
<p>A packaging/metadata patch on top of <a href="https://github.com/mohamedzhioua/agent-done-or-not/releases/tag/v0.10.0">v0.10.0</a>. <strong>No engine behavior change</strong> — receipts, <code>mode: verify</code>, and the gates are identical.</p>
<h2 id="what-changed">What changed</h2>
<ul>
<li><strong>Marketplace branding</strong> on the composite Action (<code>branding.icon: check-circle</code>, <code>color: green</code>) so it can be listed on the GitHub Marketplace with an icon.</li>
<li>Removed a now-unreachable inner <code>mode != assert</code> guard in the <code>assert</code> step (already gated by the step <code>if:</code> and the reject-unsupported-mode step).</li>
<li><code>@v0</code> references in the docs now resolve via a <strong>moving <code>v0</code> major tag</strong> that tracks the latest <code>v0.x</code> release. For the security-critical <code>mode: verify</code> gate, keep pinning an exact tag (e.g. <code>@v0.10.1</code>) as the README recommends.</li>
</ul>
<h2 id="verify-quick-reference">Verify quick reference</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span><span style="color:#75715e"># set up your runtime + deps here (setup-node, npm ci, …)</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">mohamedzhioua/agent-done-or-not@v0.10.1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">mode</span>: <span style="color:#ae81ff">verify</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">checks</span>: |<span style="color:#e6db74">
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">      test: npm test
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">      build: npm run build</span>
</span></span></code></pre></div><p>Full history in <a href="../CHANGELOG.md">CHANGELOG.md</a>.</p>
]]></content:encoded></item><item><title>Agent Security Harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/agent-security-harness/</link><pubDate>Fri, 03 Jul 2026 06:36:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/agent-security-harness/</guid><description>Version updated for https://github.com/msaleme/red-team-blue-team-agent-fabric to version v4.8.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Promotes the funding-instrument checks that were a single dimension of the AP2 harness (AP2-015) into a first-class module — the tokenized card credential (Visa Trusted Agent Protocol / Mastercard Agentic Tokens) that sits inside an AP2 Payment Mandate as the instrument that actually moves money.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/msaleme/red-team-blue-team-agent-fabric">https://github.com/msaleme/red-team-blue-team-agent-fabric</a></strong> to version <strong>v4.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-security-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Promotes the funding-instrument checks that were a single dimension of the AP2 harness (AP2-015) into a <strong>first-class module</strong> — the tokenized card credential (Visa Trusted Agent Protocol / Mastercard Agentic Tokens) that sits <em>inside</em> an AP2 Payment Mandate as the instrument that actually moves money.</p>
<h2 id="new-card_token_harnesspy--12-tests-ctk-001012-229">New: <code>card_token_harness.py</code> — 12 tests (CTK-001..012), #229</h2>
<p>Stdlib-only, deterministic reference verifier, <strong>every check fails closed</strong>.</p>
<ul>
<li><strong>Binding:</strong> agent holder-key, channel/domain, cross-network substitution</li>
<li><strong>Scope:</strong> merchant, per-transaction amount cap (both bounds — negative amounts rejected), cumulative velocity cap, consent policy</li>
<li><strong>Cryptogram:</strong> freshness (monotonic-counter replay), amount-binding (no re-pricing)</li>
<li><strong>Lifecycle:</strong> expiry, revocation/suspension (&ldquo;identify and revoke&rdquo;)</li>
<li><strong>Supply chain:</strong> PAN de-tokenization protection</li>
</ul>
<p>Grounded in EMV payment tokenisation + TAVV/DTVV dynamic cryptograms. AP2 answers <em>&ldquo;is this agent authorized to pay for this cart&rdquo;</em>; the card token answers <em>&ldquo;is this credential valid, unrevoked, fresh, and bound to this agent/merchant/amount/channel&rdquo;</em> — they compose.</p>
<p><strong>520 → 532 tests, 36 → 37 modules.</strong> Two fail-open gaps (negative-amount, <code>None==None</code> binding) surfaced by Bugbot were fixed and are now guarded by negative tests before merge.</p>
<p>The harness now covers all four layers of the agentic-payments stack <strong>plus</strong> the card-network funding rail underneath them. Verified by <code>scripts/count_tests.py</code> (definitive: 532).</p>
]]></content:encoded></item><item><title>Polygraph MCP gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/polygraph-mcp-gate/</link><pubDate>Fri, 03 Jul 2026 06:36:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/polygraph-mcp-gate/</guid><description>Version updated for https://github.com/polygraphso/litmus to version litmus-v0.24.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Methodology litmus-v12 — two false-positive fixes so a server’s correct, defensive behavior is no longer graded as a fault.
C-04 (probe 3.2): a validation error that quotes the rejected input back (e.g. Pydantic input_value=&amp;#39;…&amp;#39;) is a safe rejection, not server-generated amplification — no longer a false D. (#85) C-02 (probe 2.1): a mutation verb under a negation (“Cannot create or revoke keys”) no longer reads as a permission-mislabel lie; clause-scoped, so a real “Deletes… Cannot be undone.” still trips. (#85) methodologyVersion moves litmus-v11 → litmus-v12 (a string, so older attestations coexist). Release bump in #86. Both fixes are covered by regression tests reproduced from real servers.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/polygraphso/litmus">https://github.com/polygraphso/litmus</a></strong> to version <strong>litmus-v0.24.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/polygraph-mcp-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Methodology <strong>litmus-v12</strong> — two false-positive fixes so a server&rsquo;s correct, defensive behavior is no longer graded as a fault.</p>
<ul>
<li><strong>C-04 (probe 3.2):</strong> a validation error that quotes the rejected input back (e.g. Pydantic <code>input_value='…'</code>) is a safe rejection, not server-generated amplification — no longer a false D. (#85)</li>
<li><strong>C-02 (probe 2.1):</strong> a mutation verb under a negation (&ldquo;Cannot create or revoke keys&rdquo;) no longer reads as a permission-mislabel lie; clause-scoped, so a real &ldquo;Deletes… Cannot be undone.&rdquo; still trips. (#85)</li>
</ul>
<p><code>methodologyVersion</code> moves <code>litmus-v11 → litmus-v12</code> (a string, so older attestations coexist). Release bump in #86. Both fixes are covered by regression tests reproduced from real servers.</p>
]]></content:encoded></item><item><title>Remyx Outrider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/remyx-outrider/</link><pubDate>Fri, 03 Jul 2026 06:35:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/remyx-outrider/</guid><description>Version updated for https://github.com/remyxai/outrider to version v1.7.9.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v1.7.8 was tagged on the wrong commit and did not actually contain the enrichment fix; v1 pointer was updated but the deployed code path in fast-paths still skipped _enrich_candidate_licenses. This release ships the real fix: _enrich_candidate_licenses(candidates, target) is now called on the pin-arxiv and search-method fast-paths (gated on REMYX_LICENSE_GATE, idempotent, best-effort). REMYX-190 evidence: https://github.com/remyxai/VQASynth/issues/105 opened with license_class=unknown despite WnQinm/Annotator having a clearly readable BSD-3-Clause LICENSE — the fast-path never called the enrichment step.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remyxai/outrider">https://github.com/remyxai/outrider</a></strong> to version <strong>v1.7.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/remyx-outrider">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>v1.7.8 was tagged on the wrong commit and did not actually contain the enrichment fix; v1 pointer was updated but the deployed code path in fast-paths still skipped <code>_enrich_candidate_licenses</code>. This release ships the real fix: <code>_enrich_candidate_licenses(candidates, target)</code> is now called on the pin-arxiv and search-method fast-paths (gated on <code>REMYX_LICENSE_GATE</code>, idempotent, best-effort). REMYX-190 evidence: <a href="https://github.com/remyxai/VQASynth/issues/105">https://github.com/remyxai/VQASynth/issues/105</a> opened with <code>license_class=unknown</code> despite WnQinm/Annotator having a clearly readable BSD-3-Clause LICENSE — the fast-path never called the enrichment step.</p>
]]></content:encoded></item><item><title>DiffGate Review Triage</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/diffgate-review-triage/</link><pubDate>Fri, 03 Jul 2026 06:34:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/diffgate-review-triage/</guid><description>Version updated for https://github.com/srbsa/diffgate to version v0.7.7.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/srbsa/diffgate/compare/v0.7.6...v0.7.7</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/srbsa/diffgate">https://github.com/srbsa/diffgate</a></strong> to version <strong>v0.7.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/diffgate-review-triage">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/srbsa/diffgate/compare/v0.7.6...v0.7.7">https://github.com/srbsa/diffgate/compare/v0.7.6...v0.7.7</a></p>
]]></content:encoded></item><item><title>rag-redteam</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/rag-redteam/</link><pubDate>Fri, 03 Jul 2026 06:34:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/rag-redteam/</guid><description>Version updated for https://github.com/Srivatsa03/rag-redteam to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Adds embedding_inversion, a 7th probe that flags pipelines exposing raw embedding vectors (invertible back to source text per vec2text). Structural detector, a vulnerable/hardened demo pair, unit tests, and a threat-model section. Install or upgrade: pip install -U rag-redteam</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Srivatsa03/rag-redteam">https://github.com/Srivatsa03/rag-redteam</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rag-redteam">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Adds embedding_inversion, a 7th probe that flags pipelines exposing raw embedding vectors (invertible back to source text per vec2text). Structural detector, a vulnerable/hardened demo pair, unit tests, and a threat-model section. Install or upgrade: pip install -U rag-redteam</p>
]]></content:encoded></item><item><title>Node Semantic Release</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/node-semantic-release/</link><pubDate>Fri, 03 Jul 2026 06:33:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/node-semantic-release/</guid><description>Version updated for https://github.com/stairwaytowonderland/node-semantic-release to version v1.193.0.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed chore(release): 1.193.0
1.193.0 (2026-07-03) ✨ Features remove is-first-release-tag (f210a51)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stairwaytowonderland/node-semantic-release">https://github.com/stairwaytowonderland/node-semantic-release</a></strong> to version <strong>v1.193.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/node-semantic-release">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>chore(release): 1.193.0</p>
<h2 id="11930-2026-07-03"><a href="https://github.com/stairwaytowonderland/node-semantic-release/compare/v1.192.0...v1.193.0">1.193.0</a> (2026-07-03)</h2>
<h3 id="-features">✨ Features</h3>
<ul>
<li>remove is-first-release-tag (<a href="https://github.com/stairwaytowonderland/node-semantic-release/commit/f210a51d58961f446565736f7bfcfd3d8f18a882">f210a51</a>)</li>
</ul>
]]></content:encoded></item><item><title>MIU PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/miu-pr-review/</link><pubDate>Fri, 03 Jul 2026 06:33:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/miu-pr-review/</guid><description>Version updated for https://github.com/vanducng/miu-cr to version v0.82.4.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed miu-cr v0.82.4 AI code review for local changes and GitHub pull requests. Use it as a CLI, CI gate, or GitHub Action with your own LLM key.
Install curl -fsSL https://cr.miu.sh/install.sh | sh -s -- v0.82.4 brew install vanducng/tap/miucr go install github.com/vanducng/miu-cr/cmd/miucr@v0.82.4 GitHub Action:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vanducng/miu-cr">https://github.com/vanducng/miu-cr</a></strong> to version <strong>v0.82.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/miu-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="miu-cr-v0824">miu-cr v0.82.4</h2>
<p>AI code review for local changes and GitHub pull requests. Use it as a CLI, CI gate, or GitHub Action with your own LLM key.</p>
<h3 id="install">Install</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>curl -fsSL https://cr.miu.sh/install.sh | sh -s -- v0.82.4
</span></span><span style="display:flex;"><span>brew install vanducng/tap/miucr
</span></span><span style="display:flex;"><span>go install github.com/vanducng/miu-cr/cmd/miucr@v0.82.4
</span></span></code></pre></div><p>GitHub Action:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v6</span>
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">vanducng/miu-cr@v0.82.4</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span></code></pre></div><h3 id="common-commands">Common commands</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>miucr login --provider openai
</span></span><span style="display:flex;"><span>miucr review --staged
</span></span><span style="display:flex;"><span>miucr review --from main --to HEAD --gate high
</span></span><span style="display:flex;"><span>miucr review --pr owner/repo#123 --post
</span></span><span style="display:flex;"><span>miucr upgrade
</span></span></code></pre></div><p>Docs: <a href="https://cr.miu.sh">https://cr.miu.sh</a></p>
]]></content:encoded></item><item><title>Setup Modern C++ Development Environment</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/setup-modern-c-development-environment/</link><pubDate>Fri, 03 Jul 2026 06:32:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/03/setup-modern-c-development-environment/</guid><description>Version updated for https://github.com/wx257osn2/cxx_environment to version v3.5.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed workaround for non-UTC timezone host environment Singularity/Apptainer binds Etc/UTC to host timezone at default speed up CI bump up actions including apptainer 1.4.4 -&amp;gt; 1.5.2 update msvc-wine</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/wx257osn2/cxx_environment">https://github.com/wx257osn2/cxx_environment</a></strong> to version <strong>v3.5.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-modern-c-development-environment">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>workaround for non-UTC timezone host environment
<ul>
<li>Singularity/Apptainer binds <code>Etc/UTC</code> to host timezone at default</li>
</ul>
</li>
<li>speed up CI</li>
<li>bump up actions
<ul>
<li>including apptainer 1.4.4 -&gt; 1.5.2</li>
</ul>
</li>
<li>update msvc-wine</li>
</ul>
]]></content:encoded></item><item><title>VStyle Curate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/vstyle-curate/</link><pubDate>Thu, 02 Jul 2026 22:26:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/vstyle-curate/</guid><description>Version updated for https://github.com/hack-ink/vibe-style to version v0.2.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Sync language check structure by @yvette-carlisle in https://github.com/hack-ink/vibe-style/pull/35 Roll dependencies by @yvette-carlisle in https://github.com/hack-ink/vibe-style/pull/81 Speed up vstyle tune telemetry by @yvette-carlisle in https://github.com/hack-ink/vibe-style/pull/82 Full Changelog: https://github.com/hack-ink/vibe-style/compare/v0.2.1...v0.2.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hack-ink/vibe-style">https://github.com/hack-ink/vibe-style</a></strong> to version <strong>v0.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vstyle-curate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Sync language check structure by @yvette-carlisle in <a href="https://github.com/hack-ink/vibe-style/pull/35">https://github.com/hack-ink/vibe-style/pull/35</a></li>
<li>Roll dependencies by @yvette-carlisle in <a href="https://github.com/hack-ink/vibe-style/pull/81">https://github.com/hack-ink/vibe-style/pull/81</a></li>
<li>Speed up vstyle tune telemetry by @yvette-carlisle in <a href="https://github.com/hack-ink/vibe-style/pull/82">https://github.com/hack-ink/vibe-style/pull/82</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hack-ink/vibe-style/compare/v0.2.1...v0.2.2">https://github.com/hack-ink/vibe-style/compare/v0.2.1...v0.2.2</a></p>
]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/ai-plugin-scanner/</link><pubDate>Thu, 02 Jul 2026 22:25:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.368.
This action is used across all versions by 17 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/6a3f3b3419536de769697931aecf26e2e0d10df8 with plugin-scanner 2.0.968.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.367...v1.2.368</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.368</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>17</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/6a3f3b3419536de769697931aecf26e2e0d10df8">https://github.com/hashgraph-online/hol-guard/tree/6a3f3b3419536de769697931aecf26e2e0d10df8</a> with plugin-scanner 2.0.968.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.367...v1.2.368">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.367...v1.2.368</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/hol-codex-plugin-scanner/</link><pubDate>Thu, 02 Jul 2026 22:25:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.368.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.368</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.368</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.368">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.368</a></p>
]]></content:encoded></item><item><title>Supply Chain Guard</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/supply-chain-guard/</link><pubDate>Thu, 02 Jul 2026 22:24:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/supply-chain-guard/</guid><description>Version updated for https://github.com/homeofe/supply-chain-guard to version v5.5.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v5.5.0 (2026-07-02) Community batch: all 8 seeded issues shipped, hardened by an adversarial release gate
Implements every open issue (#40-#47) in one release. Before tagging, a 4-lens adversarial verification gate reviewed the full diff and BLOCKED the first candidate with 6 confirmed findings - all fixed here (details below). 35 new tests (1057 total).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/homeofe/supply-chain-guard">https://github.com/homeofe/supply-chain-guard</a></strong> to version <strong>v5.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/supply-chain-guard">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="v550-2026-07-02">v5.5.0 (2026-07-02)</h3>
<p><strong>Community batch: all 8 seeded issues shipped, hardened by an adversarial release gate</strong></p>
<p>Implements every open issue (#40-#47) in one release. Before tagging, a
4-lens adversarial verification gate reviewed the full diff and BLOCKED the
first candidate with 6 confirmed findings - all fixed here (details below).
35 new tests (1057 total).</p>
<ul>
<li><strong>Open VSX registry support</strong> (#40): <code>supply-chain-guard vscode &lt;id&gt; --registry openvsx</code> scans extensions from open-vsx.org (VSCodium, Gitpod,
Theia); marketplace stays the default. Windows fix: scanner temp dirs now
use os.tmpdir() instead of /tmp.</li>
<li><strong>Badge output</strong> (#42): <code>--format badge</code> emits Shields.io endpoint JSON.
The badge derives from the findings summary, mirroring exit-code semantics
(critical = red, high = orange, medium = yellow, else green).</li>
<li><strong>pre-commit hook</strong> (#41): .pre-commit-hooks.yaml + a &ldquo;prepare&rdquo; build script
so git-based installs compile dist/; README documents the
.pre-commit-config.yaml snippet.</li>
<li><strong>CI recipes</strong> (#44, #45, #46): examples/ gains CircleCI, Jenkins, and Azure
Pipelines gate configs.</li>
<li><strong>Official Docker image</strong> (#47): multi-stage Dockerfile (non-root, unzip
included, installs the locally built tarball of the tagged source) +
docker.yml publishing multi-arch (amd64/arm64) images to
ghcr.io/homeofe/supply-chain-guard on every release tag, with provenance and
SBOM attestations. All workflow actions SHA-pinned and verified upstream.</li>
<li><strong>Coverage gate</strong> (#43): vitest v8 coverage with thresholds wired into CI;
coverage summary uploaded as a build artifact.</li>
</ul>
<p>Fixed by the verification gate before release (would have shipped broken):</p>
<ul>
<li>Docker build died at <code>npm ci</code> (the new prepare script ran before
tsconfig/src existed in the layer) - now &ndash;ignore-scripts in the builder.</li>
<li>Badge severity inversion: one critical finding scored &ldquo;medium&rdquo; risk level
and rendered a YELLOW badge while the CLI exited 2 - badges now mirror the
gate.</li>
<li><code>prepare: npx tsc</code> could download and execute the namesquatted &ldquo;tsc&rdquo;
registry package on cold installs - now plain <code>tsc</code> (bin-PATH only).</li>
<li>pre-commit docs pinned rev v5.4.2, a tag that predates the hook file - now
gate-enforced via check:version-sync.</li>
<li>CircleCI example used an invalid <code>when:</code> key and would not compile.</li>
<li>The README badge recipe froze the badge green exactly when findings
appeared (scan exits non-zero, publish step skipped) - now || true +
if: always().</li>
</ul>
]]></content:encoded></item><item><title>Agent Guard Secret Guardrails</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/agent-guard-secret-guardrails/</link><pubDate>Thu, 02 Jul 2026 22:24:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/agent-guard-secret-guardrails/</guid><description>Version updated for https://github.com/JeongJaeSoon/agent-guard to version v1.7.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat(shell): resolve agent-guard without a PATH install for the bang guard by @JeongJaeSoon in https://github.com/JeongJaeSoon/agent-guard/pull/94 release: v1.7.0 by @github-actions[bot] in https://github.com/JeongJaeSoon/agent-guard/pull/95 Full Changelog: https://github.com/JeongJaeSoon/agent-guard/compare/v1.6.0...v1.7.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/JeongJaeSoon/agent-guard">https://github.com/JeongJaeSoon/agent-guard</a></strong> to version <strong>v1.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-guard-secret-guardrails">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(shell): resolve agent-guard without a PATH install for the bang guard by @JeongJaeSoon in <a href="https://github.com/JeongJaeSoon/agent-guard/pull/94">https://github.com/JeongJaeSoon/agent-guard/pull/94</a></li>
<li>release: v1.7.0 by @github-actions[bot] in <a href="https://github.com/JeongJaeSoon/agent-guard/pull/95">https://github.com/JeongJaeSoon/agent-guard/pull/95</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/JeongJaeSoon/agent-guard/compare/v1.6.0...v1.7.0">https://github.com/JeongJaeSoon/agent-guard/compare/v1.6.0...v1.7.0</a></p>
]]></content:encoded></item><item><title>Official Junie GitHub Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/official-junie-github-action/</link><pubDate>Thu, 02 Jul 2026 22:23:42 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/official-junie-github-action/</guid><description>Version updated for https://github.com/JetBrains/junie-github-action to version v1.5.6.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 38 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed [Junie]: Update Junie CLI Version to 2144.7 in Files by @mashan555 in https://github.com/JetBrains/junie-github-action/pull/172 Full Changelog: https://github.com/JetBrains/junie-github-action/compare/v1...v1.5.6</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/JetBrains/junie-github-action">https://github.com/JetBrains/junie-github-action</a></strong> to version <strong>v1.5.6</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>38</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/official-junie-github-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>[Junie]: Update Junie CLI Version to 2144.7 in Files by @mashan555 in <a href="https://github.com/JetBrains/junie-github-action/pull/172">https://github.com/JetBrains/junie-github-action/pull/172</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/JetBrains/junie-github-action/compare/v1...v1.5.6">https://github.com/JetBrains/junie-github-action/compare/v1...v1.5.6</a></p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/neurolink-ai/</link><pubDate>Thu, 02 Jul 2026 22:23:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v9.80.4.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 9.80.4 (2026-07-02) Bug Fixes (core): vertex schema fallback, mcp log dedup, safe serialization, timeout handling (2889ed2)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v9.80.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="9804-2026-07-02"><a href="https://github.com/juspay/neurolink/compare/v9.80.3...v9.80.4">9.80.4</a> (2026-07-02)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(core):</strong>  vertex schema fallback, mcp log dedup, safe serialization, timeout handling (<a href="https://github.com/juspay/neurolink/commit/2889ed23fa542b88606f40ca0756dda0fbc2bd7b">2889ed2</a>)</li>
</ul>
]]></content:encoded></item><item><title>BPFCompat eBPF Compatibility Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/bpfcompat-ebpf-compatibility-gate/</link><pubDate>Thu, 02 Jul 2026 22:22:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/bpfcompat-ebpf-compatibility-gate/</guid><description>Version updated for https://github.com/Kernel-Guard/bpfcompat to version v0.3.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed fix(ci): prefetch quirk-library images before validation in the publish lane (#76) (c7ef4fb) chore(release): prepare v0.3.0 — changelog + version refs (#75) (b2ef03e) docs: consolidate experimental tracks into docs/experimental.md (#73) (8a910a5) feat(examples): ebpf-go validation recipe — loader example + cookbook (#72) (7eed351) feat(ci): publish the quirk-library matrix to GitHub Pages weekly (#71) (1d75677) feat(action): command-mode inputs + built-in matrix names for the GitHub Action (#70) (00e2017) docs: drop internal “Repository Hygiene” section from README (#69) (b127315) fix(docs): readable contrast in test-command screenshot (#68) (2491a69) feat(cli): add test-command verb + README screenshot of a real run (#67) (88971fe) docs: surface command mode as a core feature + soften Falco loader claim (#66) (c790219)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Kernel-Guard/bpfcompat">https://github.com/Kernel-Guard/bpfcompat</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bpfcompat-ebpf-compatibility-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>fix(ci): prefetch quirk-library images before validation in the publish lane (#76) (c7ef4fb)</li>
<li>chore(release): prepare v0.3.0 — changelog + version refs (#75) (b2ef03e)</li>
<li>docs: consolidate experimental tracks into docs/experimental.md (#73) (8a910a5)</li>
<li>feat(examples): ebpf-go validation recipe — loader example + cookbook (#72) (7eed351)</li>
<li>feat(ci): publish the quirk-library matrix to GitHub Pages weekly (#71) (1d75677)</li>
<li>feat(action): command-mode inputs + built-in matrix names for the GitHub Action (#70) (00e2017)</li>
<li>docs: drop internal &ldquo;Repository Hygiene&rdquo; section from README (#69) (b127315)</li>
<li>fix(docs): readable contrast in test-command screenshot (#68) (2491a69)</li>
<li>feat(cli): add <code>test-command</code> verb + README screenshot of a real run (#67) (88971fe)</li>
<li>docs: surface command mode as a core feature + soften Falco loader claim (#66) (c790219)</li>
</ul>
]]></content:encoded></item><item><title>L10n.dev AI Localization Automation</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/l10n.dev-ai-localization-automation/</link><pubDate>Thu, 02 Jul 2026 22:22:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/l10n.dev-ai-localization-automation/</guid><description>Version updated for https://github.com/l10n-dev/ai-l10n to version v1.8.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: implement safety improvements by removing apiKey field and refactoring key management by @AntonovAnton in https://github.com/l10n-dev/ai-l10n/pull/47 Full Changelog: https://github.com/l10n-dev/ai-l10n/compare/v1.7.1...v1.8.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/l10n-dev/ai-l10n">https://github.com/l10n-dev/ai-l10n</a></strong> to version <strong>v1.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/l10n-dev-ai-localization-automation">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: implement safety improvements by removing apiKey field and refactoring key management by @AntonovAnton in <a href="https://github.com/l10n-dev/ai-l10n/pull/47">https://github.com/l10n-dev/ai-l10n/pull/47</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/l10n-dev/ai-l10n/compare/v1.7.1...v1.8.0">https://github.com/l10n-dev/ai-l10n/compare/v1.7.1...v1.8.0</a></p>
]]></content:encoded></item><item><title>crabd</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/crabd/</link><pubDate>Thu, 02 Jul 2026 22:21:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/crabd/</guid><description>Version updated for https://github.com/louisescher/crabd to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: review verdict labels, comment-only reviews, web search by @louisescher in https://github.com/louisescher/crabd/pull/4 feat: Delete crabd.yml, prepare for public release by @louisescher in https://github.com/louisescher/crabd/pull/6 chore: version packages by @github-actions[bot] in https://github.com/louisescher/crabd/pull/5 New Contributors @louisescher made their first contribution in https://github.com/louisescher/crabd/pull/4 Full Changelog: https://github.com/louisescher/crabd/compare/v0.1.0...v0.1.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/louisescher/crabd">https://github.com/louisescher/crabd</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/crab-d">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: review verdict labels, comment-only reviews, web search by @louisescher in <a href="https://github.com/louisescher/crabd/pull/4">https://github.com/louisescher/crabd/pull/4</a></li>
<li>feat: Delete crabd.yml, prepare for public release by @louisescher in <a href="https://github.com/louisescher/crabd/pull/6">https://github.com/louisescher/crabd/pull/6</a></li>
<li>chore: version packages by @github-actions[bot] in <a href="https://github.com/louisescher/crabd/pull/5">https://github.com/louisescher/crabd/pull/5</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@louisescher made their first contribution in <a href="https://github.com/louisescher/crabd/pull/4">https://github.com/louisescher/crabd/pull/4</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/louisescher/crabd/compare/v0.1.0...v0.1.1">https://github.com/louisescher/crabd/compare/v0.1.0...v0.1.1</a></p>
]]></content:encoded></item><item><title>moult-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/moult-action/</link><pubDate>Thu, 02 Jul 2026 22:20:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/moult-action/</guid><description>Version updated for https://github.com/moult-rb/moult-rb to version v0.3.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First gem release since 0.1.0 (v0.2.0 was tagged but its publish failed; its changes are included here). Published to RubyGems as moult.
moult-action The bare uses: moult-rb/moult-rb@v1 workflow now works out of the box: the action installs moult from its own checkout (no Gemfile needed in your repo) and moult-cloud-url defaults to https://moultrb.com. Actionable first-run errors: a missing permissions: id-token: write now says exactly that instead of a Ruby backtrace; non-2xx responses from GitHub’s token endpoint are reported with status and body. Pull requests from forks are gated in CI but skip the upload with a notice — GitHub issues no OIDC identity to fork PRs. base-sha defaults to the PR base branch (or the merge queue’s base SHA), falling back to the repository default branch — repos whose base branch isn’t main no longer fail their first PR scan. merge_group events are supported as pr scans; pull_request_target is rejected in auto mode (it checks out the base branch, which would silently gate an empty diff as a pass). Gem Moult::CloudUpload.projection — the sanitised upload payload builder (allow-listed keys, absolute paths stripped). License changed from MIT to Apache-2.0. Full details in CHANGELOG.md.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/moult-rb/moult-rb">https://github.com/moult-rb/moult-rb</a></strong> to version <strong>v0.3.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/moult-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First gem release since 0.1.0 (v0.2.0 was tagged but its publish failed; its changes are included here). Published to RubyGems as <code>moult</code>.</p>
<h2 id="moult-action">moult-action</h2>
<ul>
<li>The bare <code>uses: moult-rb/moult-rb@v1</code> workflow now works out of the box: the action installs moult from its own checkout (no Gemfile needed in your repo) and <code>moult-cloud-url</code> defaults to <a href="https://moultrb.com">https://moultrb.com</a>.</li>
<li>Actionable first-run errors: a missing <code>permissions: id-token: write</code> now says exactly that instead of a Ruby backtrace; non-2xx responses from GitHub&rsquo;s token endpoint are reported with status and body.</li>
<li>Pull requests from forks are gated in CI but skip the upload with a notice — GitHub issues no OIDC identity to fork PRs.</li>
<li><code>base-sha</code> defaults to the PR base branch (or the merge queue&rsquo;s base SHA), falling back to the repository default branch — repos whose base branch isn&rsquo;t <code>main</code> no longer fail their first PR scan.</li>
<li><code>merge_group</code> events are supported as <code>pr</code> scans; <code>pull_request_target</code> is rejected in auto mode (it checks out the base branch, which would silently gate an empty diff as a pass).</li>
</ul>
<h2 id="gem">Gem</h2>
<ul>
<li><code>Moult::CloudUpload.projection</code> — the sanitised upload payload builder (allow-listed keys, absolute paths stripped).</li>
<li>License changed from MIT to Apache-2.0.</li>
</ul>
<p>Full details in <a href="https://github.com/moult-rb/moult-rb/blob/main/CHANGELOG.md">CHANGELOG.md</a>.</p>
]]></content:encoded></item><item><title>DeepRabbit Code Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/deeprabbit-code-review/</link><pubDate>Thu, 02 Jul 2026 22:20:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/deeprabbit-code-review/</guid><description>Version updated for https://github.com/n0namedeveloper/DeepRabbit to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Github Marketplace release.
Full Changelog: https://github.com/n0namedeveloper/DeepRabbit/compare/v1.1.0...v1.1.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/n0namedeveloper/DeepRabbit">https://github.com/n0namedeveloper/DeepRabbit</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/deeprabbit-code-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Github Marketplace release.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/n0namedeveloper/DeepRabbit/compare/v1.1.0...v1.1.1">https://github.com/n0namedeveloper/DeepRabbit/compare/v1.1.0...v1.1.1</a></p>
]]></content:encoded></item><item><title>Parkstatic Build and Deploy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/parkstatic-build-and-deploy/</link><pubDate>Thu, 02 Jul 2026 22:19:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/parkstatic-build-and-deploy/</guid><description>Version updated for https://github.com/ParkStatic/action to version v1.2.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Bump pnpm/action-setup from v4 to v6 (0b8282d) CI: add Astro, SvelteKit, Remix, and Nuxt fixtures to the test matrix (377d196) Support Astro, SvelteKit, Remix, and Nuxt static builds (2bb9389) Add framework-compatibility test suite and offline build inputs (b31ebe4) Initial release (6857aff)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ParkStatic/action">https://github.com/ParkStatic/action</a></strong> to version <strong>v1.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/parkstatic-build-and-deploy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Bump pnpm/action-setup from v4 to v6 (0b8282d)</li>
<li>CI: add Astro, SvelteKit, Remix, and Nuxt fixtures to the test matrix (377d196)</li>
<li>Support Astro, SvelteKit, Remix, and Nuxt static builds (2bb9389)</li>
<li>Add framework-compatibility test suite and offline build inputs (b31ebe4)</li>
<li>Initial release (6857aff)</li>
</ul>
]]></content:encoded></item><item><title>Blog to Newsletter</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/blog-to-newsletter/</link><pubDate>Thu, 02 Jul 2026 22:19:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/blog-to-newsletter/</guid><description>Version updated for https://github.com/peterpeterparker/blog-to-newsletter-action to version v0.0.4.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: deny closing footer with name and website by @peterpeterparker in https://github.com/peterpeterparker/blog-to-newsletter-action/pull/5 Full Changelog: https://github.com/peterpeterparker/blog-to-newsletter-action/compare/v0.0.3...v0.0.4</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/peterpeterparker/blog-to-newsletter-action">https://github.com/peterpeterparker/blog-to-newsletter-action</a></strong> to version <strong>v0.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/blog-to-newsletter">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: deny closing footer with name and website by @peterpeterparker in <a href="https://github.com/peterpeterparker/blog-to-newsletter-action/pull/5">https://github.com/peterpeterparker/blog-to-newsletter-action/pull/5</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/peterpeterparker/blog-to-newsletter-action/compare/v0.0.3...v0.0.4">https://github.com/peterpeterparker/blog-to-newsletter-action/compare/v0.0.3...v0.0.4</a></p>
]]></content:encoded></item><item><title>Polygraph MCP gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/polygraph-mcp-gate/</link><pubDate>Thu, 02 Jul 2026 22:18:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/polygraph-mcp-gate/</guid><description>Version updated for https://github.com/polygraphso/litmus to version litmus-v0.23.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed litmus-v11 — C-02 gains expected-upstream inference, fixing a first-party-egress false positive.
An honest API-wrapper server — a tool that transparently calls the API it advertises (openai_chat → api.openai.com) — made an undeclared egress attempt and was capped at D, even though the upstream is the very API its own surface names. Before an undeclared host is now counted as overreach, the harness infers whether it is a plausible upstream for the server’s own tool surface: a host named verbatim in the tool text (strong), or an egress host whose registrable label matches a non-generic brand token drawn from the surface and the package owner/name (medium, plain-TLD hosts only). A match reclassifies the attempt from overreach into an informational egress-inferred finding — disclosure, not exoneration.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/polygraphso/litmus">https://github.com/polygraphso/litmus</a></strong> to version <strong>litmus-v0.23.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/polygraph-mcp-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>litmus-v11</strong> — C-02 gains expected-upstream inference, fixing a first-party-egress false positive.</p>
<p>An honest API-wrapper server — a tool that transparently calls the API it advertises (<code>openai_chat</code> → <code>api.openai.com</code>) — made an <em>undeclared</em> egress attempt and was capped at <strong>D</strong>, even though the upstream is the very API its own surface names. Before an undeclared host is now counted as overreach, the harness infers whether it is a plausible upstream for the server&rsquo;s own tool surface: a host named <strong>verbatim</strong> in the tool text (strong), or an egress host whose <strong>registrable label</strong> matches a non-generic <strong>brand token</strong> drawn from the surface and the package owner/name (medium, plain-TLD hosts only). A match reclassifies the attempt from overreach into an informational <code>egress-inferred</code> finding — <strong>disclosure, not exoneration</strong>.</p>
<p>Guardrails keep lookalikes out: whole-label (never substring) matching, a generic-label stoplist, registrable-label-only matching (so <code>openai.evil-cdn.com</code> is not cleared), and shared-tenant suffixes (<code>github.io</code>, <code>vercel.app</code>, …) treated as their own level (so <code>attacker.github.io</code> does not inherit <code>foo.github.io</code>&rsquo;s match). This only ever turns a false <strong>D → a correct pass</strong>, never the reverse, so every <code>litmus-v1…v10</code> attestation stays valid. The independent <strong>C-03 probe 4.2</strong> canary-in-egress check is unchanged and still floors real exfiltration at <strong>F</strong>. The A–F rubric and the on-chain EAS schema are unchanged; the evidence bundle schema advances to <code>1.7.0</code> (adds the <code>egress-inferred</code> finding kind).</p>
<p>Ships #83 (the fix) and #84 (the release bump). <code>methodologyVersion</code> → <code>litmus-v11</code>.</p>
]]></content:encoded></item><item><title>Prowler Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/prowler-security-scan/</link><pubDate>Thu, 02 Jul 2026 22:18:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/prowler-security-scan/</guid><description>Version updated for https://github.com/prowler-cloud/prowler to version 5.32.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ✨ New features to highlight in this version Enjoy them all now for free at https://cloud.prowler.com
🔎 Findings Triage [!NOTE] This feature is available exclusively in Prowler Cloud and Prowler Enterprise with a subscription.
Triage findings straight from the Findings view. Each finding gets a triage status you can move through its lifecycle:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/prowler-cloud/prowler">https://github.com/prowler-cloud/prowler</a></strong> to version <strong>5.32.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/prowler-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="-new-features-to-highlight-in-this-version">✨ New features to highlight in this version</h1>
<p>Enjoy them all now for free at <a href="https://cloud.prowler.com">https://cloud.prowler.com</a></p>
<h2 id="-findings-triage">🔎 Findings Triage</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Enterprise</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>Triage findings straight from the Findings view. Each finding gets a triage status you can move through its lifecycle:</p>
<p><strong>Open → Under Review → Remediating → Risk Accepted → False Positive → Resolved</strong></p>
<p>Add a triage note to record the decision, mute a finding, all from the row&rsquo;s actions menu. The current status shows inline on every finding row, so you keep track of what has been reviewed and stop re-checking the same issues scan after scan.</p>
<img width="1380" height="159" alt="Triage 1" src="https://github.com/user-attachments/assets/f5268766-76ac-4c7f-a745-a3f013c18c23" />
<p>The status also follows the finding automatically across scans: when a finding flips from <code>FAIL</code> to <code>PASS</code> on the next scan it moves to <strong>Resolved</strong>, and when it flips from <code>PASS</code> back to <code>FAIL</code> it moves to <strong>Reopened</strong>. You always know whether an issue is genuinely fixed or has regressed, without touching it by hand.</p>
<img width="1382" height="496" alt="Triage 2" src="https://github.com/user-attachments/assets/258b5302-79f0-4995-a27e-b9b07c1ded57" />
<p>Read more in our <a href="https://docs.prowler.com/user-guide/tutorials/prowler-app-findings-triage">Findings Triage documentation</a>.</p>
<h2 id="-scan-configuration">⚙️ Scan Configuration</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Enterprise</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>Create named, reusable scan configurations from a dedicated <strong>Scans / Configuration</strong> page. Each configuration is YAML that follows the structure of <a href="https://github.com/prowler-cloud/prowler/blob/master/prowler/config/config.yaml"><code>prowler/config/config.yaml</code></a>, so you only include the keys you want to override; the rest fall back to the built-in defaults. Values are validated on save against a per-provider, type-safe configuration schema that range-checks each field and rejects unknown keys, so a malformed config is caught before it ever reaches a scan. Attach a configuration to one or more providers so it applies on their next scan, or save it now and attach providers later.</p>
<img width="1420" height="899" alt="Config 1" src="https://github.com/user-attachments/assets/8065313c-8be5-4613-bdc4-3b255d14ed07" />
<p>From the Providers view you can pick which configuration a provider uses (<code>Default</code> or any of your saved ones) without leaving the page. No more passing config files around by hand.</p>
<img width="1425" height="660" alt="Config 2" src="https://github.com/user-attachments/assets/183f15ea-49dd-4025-a284-a5c664139146" />
<p>Read more in our <a href="https://docs.prowler.com/user-guide/tutorials/prowler-app-scan-configuration">Scan Configuration documentation</a>.</p>
<h2 id="-per-requirement-configuration-validation">✅ Per-Requirement Configuration Validation</h2>
<blockquote>
<p>[!NOTE]
This feature is available exclusively in <strong>Prowler Cloud</strong> and <strong>Prowler Enterprise</strong> with a <a href="https://prowler.com/pricing">subscription</a>.</p>
</blockquote>
<p>Compliance frameworks can now declare <code>ConfigRequirements</code> on a requirement, so it&rsquo;s reported as <strong>FAIL</strong> when its mapped checks ran under a configuration too loose to satisfy it. Even if every individual finding PASSed. This applies across all compliance outputs: CSV, OCSF, and console tables, and is the engine behind Scan Configuration&rsquo;s &ldquo;marked as FAIL&rdquo; behavior described above.</p>
<img width="2838" height="516" alt="compliance 1" src="https://github.com/user-attachments/assets/8992d8c9-7ec1-4ad2-8fc5-639fb5127d35" />
<p>Read more in our <a href="https://docs.prowler.com/user-guide/cli/tutorials/configuration_file">Configuration File documentation</a>.</p>
<h2 id="-okta--request-throttling--retries">⏱️ Okta — Request Throttling &amp; Retries</h2>
<p>Prowler now proactively throttles Okta API requests to stay under rate limits, with reactive retries on HTTP 429 as a safety net. Both are set in the scan configuration (or their equivalent CLI flags):</p>
<ul>
<li><code>okta_requests_per_second</code> (config file) / <code>--okta-requests-per-second</code> (CLI) — cap the request rate. Default: 4 req/s.</li>
<li><code>okta_max_retries</code> (config file) / <code>--okta-retries-max-attempts</code> (CLI) — bound retry attempts. Default: 5.</li>
</ul>
<p>This makes large Okta scans more reliable and less likely to be rate-limited.</p>
<p>Read more in our <a href="https://docs.prowler.com/user-guide/providers/okta/retry-configuration#request-throttling-requests-per-second">Okta rate limit documentation</a>.</p>
<h2 id="-aws--cap-resources-scanned-per-service">📉 AWS — Cap Resources Scanned per Service</h2>
<p>Large AWS accounts can now cap how many resources Prowler analyzes for the highest-volume services, keeping scan time and cost under control. Set a global limit with <code>max_scanned_resources_per_service</code>, or override it per service:</p>
<ul>
<li>EBS snapshots (<code>max_ebs_snapshots</code>)</li>
<li>Backup recovery points (<code>max_backup_recovery_points</code>)</li>
<li>CloudWatch log groups (<code>max_cloudwatch_log_groups</code>)</li>
<li>Lambda functions (<code>max_lambda_functions</code>)</li>
<li>ECS task definitions (<code>max_ecs_task_definitions</code>)</li>
<li>CodeArtifact packages (<code>max_codeartifact_packages</code>)</li>
</ul>
<p>Limits are <strong>disabled by default</strong> (<code>0</code> = unlimited); only positive values cap the analyzed resources.</p>
<blockquote>
<p>[!WARNING]
When a positive limit is set, compliance results reflect only the sampled resources, not every matching resource in the account.</p>
</blockquote>
<p>Read more in our <a href="https://docs.prowler.com/user-guide/cli/tutorials/configuration_file#supported-aws-resource-limits">configuration file documentation</a>.</p>
<h2 id="azure--filter-by-resource-group">🏷️ Azure — Filter by Resource Group</h2>
<p>Azure scans can now be scoped to one or more resource groups with the new <code>--azure-resource-group</code> / <code>--azure-resource-groups</code> option. This lets you run focused assessments against specific environments, teams, or workloads instead of scanning every accessible resource in the subscription.</p>
<p>Prowler validates the requested resource groups across accessible subscriptions and applies the scope across supported Azure services, making targeted Azure scans faster, cleaner, and easier to review.</p>
<p>Examples:</p>
<ul>
<li>Single resource group: <code>prowler azure --az-cli-auth --azure-resource-group rg-prod</code></li>
<li>Multiple resource groups: <code>prowler azure --az-cli-auth --azure-resource-group rg-prod1 rg-prod2</code></li>
</ul>
<p>Read more in our <a href="https://docs.prowler.com/user-guide/providers/azure/resource-groups">Azure Resource Groups documentation</a>.</p>
<p>Thanks to @Legin-ML for contributing this feature!</p>
<h2 id="-provider-group-filter">🧭 Provider Group Filter</h2>
<p>Filter the <strong>Overview, Findings, Resources, Scans, and Providers</strong> views by provider group. Scope the whole app to a team, an environment, or a business unit in one click instead of filtering provider by provider.</p>
<img width="1426" height="517" alt="ProviderGroupFilter 1" src="https://github.com/user-attachments/assets/6df4ec5e-f9d9-4828-a674-a392e5fc852b" />
<p>Read more about managing provider groups in our <a href="https://docs.prowler.com/user-guide/tutorials/prowler-app-rbac">RBAC documentation</a>.</p>
<h2 id="-api--timestamp-precision-in-findings-filters">🔬 API — Timestamp Precision in Findings Filters</h2>
<p>The <code>/api/v1/findings</code> endpoint now accepts full timestamps on the <code>inserted_at</code> and <code>updated_at</code> filters (<code>filter[inserted_at__gte]</code>, <code>filter[inserted_at__lte]</code>, and the <code>updated_at</code> variants), so you can query narrow time windows instead of whole days. Date-only filtering keeps working, so existing integrations are unaffected.</p>
<h3 id="findings-inserted-within-a-precise-timestamp-window">Findings inserted within a precise timestamp window</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-shell" data-lang="shell"><span style="display:flex;"><span>curl --globoff <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>    
</span></span><span style="display:flex;"><span><span style="color:#e6db74">&#39;[http://localhost:8080/api/v1/findings?filter[inserted_at__gte]=2026-07-01T06:12:18Z&amp;filter[inserted_at__lte]=2026-07-02T19:25:55Z](http://localhost:8080/api/v1/findings?filter[inserted_at__gte]=2026-07-01T06:12:18Z&amp;filter[inserted_at__lte]=2026-07-02T19:25:55Z)&#39;</span> <span style="color:#ae81ff">\ </span>   
</span></span><span style="display:flex;"><span>-H <span style="color:#e6db74">&#39;Authorization: Bearer &lt;YOUR_TOKEN&gt;&#39;</span> <span style="color:#ae81ff">\ </span>   
</span></span><span style="display:flex;"><span>-H <span style="color:#e6db74">&#39;Accept: application/vnd.api+json&#39;</span>
</span></span></code></pre></div><h3 id="combine-inserted_at-and-updated_at-windows-in-a-single-request">Combine inserted_at and updated_at windows in a single request</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-shell" data-lang="shell"><span style="display:flex;"><span>curl --globoff <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span><span style="color:#e6db74">&#39;[http://localhost:8080/api/v1/findings?filter[inserted_at__gte]=2026-07-01T05:12:18Z&amp;filter[inserted_at__lte]=2026-07-02T20:25:55Z&amp;filter[updated_at__gte]=2026-07-01T06:12:18Z&amp;filter[updated_at__lte]=2026-07-02T19:25:55Z](http://localhost:8080/api/v1/findings?filter[inserted_at__gte]=2026-07-01T05:12:18Z&amp;filter[inserted_at__lte]=2026-07-02T20:25:55Z&amp;filter[updated_at__gte]=2026-07-01T06:12:18Z&amp;filter[updated_at__lte]=2026-07-02T19:25:55Z)&#39;</span> <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>-H <span style="color:#e6db74">&#39;Authorization: Bearer &lt;YOUR_TOKEN&gt;&#39;</span> <span style="color:#ae81ff">\
</span></span></span><span style="display:flex;"><span>-H <span style="color:#e6db74">&#39;Accept: application/vnd.api+json&#39;</span>
</span></span></code></pre></div><h2 id="-attack-paths--neptune-as-a-persistent-sink">🕸️ Attack Paths — Neptune as a persistent sink</h2>
<p>Attack Paths can now persist its graph in <strong>AWS Neptune</strong> in addition to Neo4j, selectable via <code>ATTACK_PATHS_SINK_DATABASE=neptune</code> (default <code>neo4j</code>). Cartography&rsquo;s per-scan ingest database stays on Neo4j. The scan task preflights the ingest database and the configured sink before ingestion, and provider graph cleanup now deletes relationships in directed batches before deleting nodes.</p>
<p>This is the groundwork for scale: a managed graph database lets Attack Paths hold much larger graphs, extend coverage to more providers, and link resources across them so an attack path can cross provider boundaries instead of stopping at one cloud&rsquo;s edge.</p>
<p>Read more in the <a href="https://docs.prowler.com/user-guide/tutorials/prowler-app-attack-paths">Attack Paths documentation</a>.</p>
<h2 id="-new-secret-scanning-engine--kingfisher">🔐 New Secret-Scanning Engine — Kingfisher</h2>
<p>Prowler&rsquo;s secret-scanning checks now run on <a href="https://github.com/mongodb/kingfisher">Kingfisher</a> instead of <code>detect-secrets</code>. Scans run <strong>fully offline by default</strong>, and obvious placeholder values (e.g. <code>password123</code>, <code>changeme</code>) are no longer reported, cutting down false positives.</p>
<p>Opt in to <strong>live validation</strong> with the new <code>--scan-secrets-validate</code> flag (or the <code>aws.secrets_validate</code> config option): Prowler checks discovered secrets against the provider APIs, and any secret confirmed to be <strong>live is reported as critical</strong>, so you can prioritize the credentials that actually work.</p>
<blockquote>
<p>[!NOTE]
The <code>detect_secrets_plugins</code> configuration option has been removed, as it is no longer used by the new engine.</p>
</blockquote>
<p>Read more in our <a href="https://docs.prowler.com/user-guide/cli/tutorials/pentesting#detect-secrets">secret detection documentation</a>.</p>
<h2 id="-checks">🔍 Checks</h2>
<h3 id="aws">AWS</h3>
<ul>
<li><code>stepfunctions_statemachine_encrypted_with_cmk</code> — Step Functions state machines use a customer-managed KMS key for encryption at rest instead of the default AWS-owned key. Thanks to @Sid-0602!</li>
<li><code>waf_regional_webacl_logging_enabled</code> — AWS WAF Classic Regional Web ACLs have logging enabled to a Kinesis Data Firehose stream. Thanks to @Sid-0602!</li>
<li><strong>IAM privilege escalation</strong> — the privesc checks now cover <strong>AWS Bedrock AgentCore</strong> paths across Runtime, Harness, Code Interpreter, and Custom Browser. Thanks to @MrCloudSec!</li>
<li><code>apigateway_restapi_no_secrets_in_stage_variables</code> - Scans API Gateway REST API stage variables for hardcoded passwords, API keys, and tokens. Thanks to @chirag1206!</li>
<li><code>awslambda_function_no_secrets_in_code</code> — This check now supports a <code>secrets_ignore_files</code> audit-config option to skip files inside the deployment package by glob pattern (e.g. <code>*.deps.json</code>), suppressing .NET dependency-manifest false positives without masking real secrets.</li>
<li><code>s3_bucket_object_public</code> — spot-checks a configurable sample of object ACLs in each bucket and flags objects granted to the <code>AllUsers</code> or <code>AuthenticatedUsers</code> groups. Disabled by default; opt in via the <code>s3_bucket_object_public_enabled</code> configuration option. Thanks to @Synchx00!</li>
</ul>
<p>Read more in our <a href="https://docs.prowler.com/user-guide/providers/aws/getting-started-aws">AWS documentation</a>.</p>
<p>Explore all AWS checks at <a href="https://hub.prowler.com/check?provider=aws">Prowler Hub</a>.</p>
<h3 id="microsoft-365">Microsoft 365</h3>
<p>New <strong>Conditional Access</strong> hardening checks:</p>
<ul>
<li><code>entra_conditional_access_policy_explicitly_targets_azure_devops</code> — at least one enabled policy explicitly includes the Azure DevOps cloud application, rather than relying on a broad &ldquo;All cloud apps&rdquo; policy. Thanks to @mzl2233!</li>
<li><code>entra_conditional_access_policy_no_exclusion_gaps</code> — every user, group, role, or application excluded from an enabled policy stays in scope of another enabled policy. Thanks to @UTKARSH698 with @arieleli01212 as co-author!</li>
<li><code>entra_conditional_access_policy_groups_management_restricted</code> — every security group referenced by an enabled or report-only policy is management-restricted or role-assignable. Thanks to @SAMurai-16!</li>
<li><code>exchange_application_access_policy_restricts_mailbox_apps</code> — every service principal with Microsoft Graph application-level Exchange mailbox permissions is restricted by an Exchange Online Application Access Policy. Thanks to @VasistAcharya!</li>
</ul>
<p>Read more in our <a href="https://docs.prowler.com/user-guide/providers/microsoft365/getting-started-m365">Microsoft 365 documentation</a>.</p>
<p>Explore all Microsoft 365 checks at <a href="https://hub.prowler.com/check?provider=m365">Prowler Hub</a>.</p>
<h2 id="compliance">Compliance</h2>
<h3 id="-cis-benchmark-refresh--six-new-versions">🧩 CIS Benchmark Refresh — Six New Versions</h3>
<p>Prowler ships a coordinated refresh of the CIS Benchmarks across six providers:</p>
<ul>
<li><strong>AWS</strong> — CIS Amazon Web Services Foundations Benchmark v7.0.0, adding the new Organizations section (2.1.1-2.1.6), resource policy (2.21), web front-end access logging (4.10), and VPC Endpoints (6.8) recommendations.</li>
<li><strong>Azure</strong> — CIS Microsoft Azure Foundations Benchmark v6.0.0.</li>
<li><strong>GCP</strong> — CIS Google Cloud Platform Foundation Benchmark v5.0.0.</li>
<li><strong>Kubernetes</strong> — CIS Kubernetes Benchmark v2.0.1.</li>
<li><strong>GitHub</strong> — CIS GitHub Benchmark v1.2.0.</li>
<li><strong>Microsoft 365</strong> — CIS Microsoft 365 Foundations Benchmark v7.0.0.</li>
</ul>
<p>Read more in our <a href="https://docs.prowler.com/user-guide/cli/tutorials/compliance">compliance documentation</a>.</p>
<p>Explore the full compliance catalog at <a href="https://hub.prowler.com/compliance">Prowler Hub</a>.</p>
<h3 id="-cis-controls-v81--universal-framework">🌐 CIS Controls v8.1 — Universal Framework</h3>
<p>A new <strong>universal</strong> (cross-provider) compliance framework mapping existing checks across 18 providers — AWS, Azure, GCP, Kubernetes, M365, GitHub, AlibabaCloud, OracleCloud, GoogleWorkspace, Okta, Cloudflare, Vercel, MongoDB Atlas, OpenStack, Linode, StackIT, NHN, and Scaleway — to the 18 CIS Critical Security Controls and their Safeguards. Ships with a dedicated detail view and report mapping in the UI.</p>
<p>Read more in our <a href="https://docs.prowler.com/user-guide/cli/tutorials/compliance">compliance documentation</a>.</p>
<p>Explore the full compliance catalog at <a href="https://hub.prowler.com/compliance">Prowler Hub</a>.</p>
<h2 id="-external-contributors">🙌 External Contributors</h2>
<p>Thank you to our community contributors for this release!</p>
<ul>
<li>@chirag1206 — <code>apigateway_restapi_no_secrets_in_stage_variables</code> check <a href="https://github.com/prowler-cloud/prowler/pull/11188">(#11188)</a></li>
<li>@MrCloudSec — AWS Bedrock AgentCore privilege escalation paths in the IAM privesc checks <a href="https://github.com/prowler-cloud/prowler/pull/11726">(#11726)</a></li>
<li>@Sid-0602 — <code>stepfunctions_statemachine_encrypted_with_cmk</code> <a href="https://github.com/prowler-cloud/prowler/pull/11538">(#11538)</a> and <code>waf_regional_webacl_logging_enabled</code> <a href="https://github.com/prowler-cloud/prowler/pull/11539">(#11539)</a> checks</li>
<li>@mzl2233 — <code>entra_conditional_access_policy_explicitly_targets_azure_devops</code> check <a href="https://github.com/prowler-cloud/prowler/pull/11182">(#11182)</a></li>
<li>@UTKARSH698 with @arieleli01212 as co-author — <code>entra_conditional_access_policy_no_exclusion_gaps</code> check <a href="https://github.com/prowler-cloud/prowler/pull/11577">(#11577)</a></li>
<li>@SAMurai-16 — <code>entra_conditional_access_policy_groups_management_restricted</code> check <a href="https://github.com/prowler-cloud/prowler/pull/11342">(#11342)</a></li>
<li>@vahidg — Azure PostgreSQL flexible server collection resilience fix <a href="https://github.com/prowler-cloud/prowler/pull/11595">(#11595)</a></li>
<li>@davletd — Azure <code>keyvault_logging_enabled</code> <code>AuditEvent</code> category fix <a href="https://github.com/prowler-cloud/prowler/pull/11660">(#11660)</a></li>
<li>@VasistAcharya — <code>exchange_application_access_policy_restricts_mailbox_apps</code> <a href="https://github.com/prowler-cloud/prowler/pull/11247">(#11247)</a></li>
<li>@Legin-ML — Filter scans at Resource Group level <a href="https://github.com/prowler-cloud/prowler/pull/10657">(#10657)</a></li>
<li>@Synchx00 — <code>s3_bucket_object_public</code> check <a href="https://github.com/prowler-cloud/prowler/pull/9517">(#9517)</a></li>
</ul>
<hr>
<h2 id="ui">UI</h2>
<h3 id="-added">🚀 Added</h3>
<ul>
<li>Filter the Overview, Findings, Resources, Scans, and Providers views by provider group <a href="https://github.com/prowler-cloud/prowler/pull/11659">(#11659)</a></li>
<li>CIS Controls v8.1 compliance support, including its detail view and report mapping <a href="https://github.com/prowler-cloud/prowler/pull/11700">(#11700)</a></li>
</ul>
<h2 id="api">API</h2>
<h3 id="-added-1">🚀 Added</h3>
<ul>
<li>Timestamp precision support for <code>/api/v1/findings</code> <code>inserted_at</code> and <code>updated_at</code> filters <a href="https://github.com/prowler-cloud/prowler/pull/11754">(#11754)</a></li>
</ul>
<h3 id="-changed">🔄 Changed</h3>
<ul>
<li>Attack Paths: AWS Neptune is now supported as a persistent sink database, selectable via <code>ATTACK_PATHS_SINK_DATABASE=neptune</code> (default <code>neo4j</code>), Cartography&rsquo;s (bumped to 0.138.1) per-scan ingest database stays on Neo4j <a href="https://github.com/prowler-cloud/prowler/pull/11524">(#11524)</a></li>
<li>Attack Paths: Scan task now checks the ingest Neo4j database and configured graph sink before starting graph ingestion <a href="https://github.com/prowler-cloud/prowler/pull/11743">(#11743)</a></li>
<li>Disable PowerShell telemetry in the API container image <a href="https://github.com/prowler-cloud/prowler/pull/11746">(#11746)</a></li>
</ul>
<h3 id="-fixed">🐞 Fixed</h3>
<ul>
<li>Attack Paths: Provider graph cleanup now deletes Neo4j and Neptune relationships in directed batches before deleting nodes <a href="https://github.com/prowler-cloud/prowler/pull/11755">(#11755)</a></li>
<li><code>scan-perform</code> no longer reports an error when a provider is deleted during a running scan <a href="https://github.com/prowler-cloud/prowler/pull/11696">(#11696)</a></li>
</ul>
<h2 id="sdk">SDK</h2>
<h3 id="-added-2">🚀 Added</h3>
<ul>
<li><code>exchange_application_access_policy_restricts_mailbox_apps</code> check for M365 provider, verifying every service principal with Microsoft Graph application-level Exchange mailbox permissions is restricted by an Exchange Online Application Access Policy, preventing tenant-wide mailbox access by unscoped applications <a href="https://github.com/prowler-cloud/prowler/pull/11247">(#11247)</a></li>
<li>Per-requirement configuration validation for compliance frameworks via <code>ConfigRequirements</code>, so a requirement is reported as FAIL when its configurable checks ran with a configuration too loose to satisfy it (applied across all compliance outputs: CSV, OCSF, and console tables) <a href="https://github.com/prowler-cloud/prowler/pull/11669">(#11669)</a></li>
<li><code>entra_conditional_access_policy_explicitly_targets_azure_devops</code> check for M365 provider, verifying at least one enabled Conditional Access policy explicitly includes the Azure DevOps cloud application instead of relying on a broad &ldquo;All cloud apps&rdquo; policy <a href="https://github.com/prowler-cloud/prowler/pull/11182">(#11182)</a></li>
<li><code>entra_conditional_access_policy_no_exclusion_gaps</code> check for M365 provider, verifying every user, group, role, or application excluded from an enabled Conditional Access policy stays in scope of another enabled policy <a href="https://github.com/prowler-cloud/prowler/pull/11577">(#11577)</a></li>
<li><code>entra_conditional_access_policy_groups_management_restricted</code> check for M365 provider, verifying every security group referenced by an enabled or report-only Conditional Access policy is management-restricted or role-assignable <a href="https://github.com/prowler-cloud/prowler/pull/11342">(#11342)</a></li>
<li><code>stepfunctions_statemachine_encrypted_with_cmk</code> check for AWS provider, verifying that each Step Functions state machine uses a customer-managed KMS key for encryption at rest rather than the default AWS-owned key <a href="https://github.com/prowler-cloud/prowler/pull/11538">(#11538)</a></li>
<li>CIS Controls v8.1 universal compliance framework mapping existing checks across 18 providers (AWS, Azure, GCP, Kubernetes, M365, GitHub, AlibabaCloud, OracleCloud, GoogleWorkspace, Okta, Cloudflare, Vercel, MongoDB Atlas, OpenStack, Linode, StackIT, NHN, and Scaleway) to the 18 CIS Critical Security Controls and their Safeguards <a href="https://github.com/prowler-cloud/prowler/pull/11700">(#11700)</a></li>
<li>CIS Microsoft 365 Foundations Benchmark v7.0.0 compliance framework for the M365 provider <a href="https://github.com/prowler-cloud/prowler/pull/11699">(#11699)</a></li>
<li><code>waf_regional_webacl_logging_enabled</code> check for AWS provider, verifying that each AWS WAF Classic Regional Web ACL has logging enabled to a Kinesis Data Firehose stream <a href="https://github.com/prowler-cloud/prowler/pull/11539">(#11539)</a></li>
<li><code>sdk_only</code> provider property (default <code>true</code>) and <code>Provider.get_app_providers()</code>, so a provider (built-in or external) stays CLI/SDK-only and hidden from the app unless it declares <code>sdk_only = False</code> <a href="https://github.com/prowler-cloud/prowler/pull/11427">(#11427)</a></li>
<li><code>Provider.get_scan_arguments()</code>, <code>Provider.get_connection_arguments()</code> and <code>Provider.get_credentials_schema()</code> contract methods, so a provider persisted as a stored uid plus a secret dict can be constructed and validated programmatically (to be consumed by the API in a later change) <a href="https://github.com/prowler-cloud/prowler/pull/11578">(#11578)</a></li>
<li>Okta API request throttling to proactively stay under rate limits, configurable via <code>okta_requests_per_second</code> in the config file and the <code>--okta-requests-per-second</code> CLI flag, plus configurable retries via <code>okta_max_retries</code> / <code>--okta-retries-max-attempts</code> as a safety net <a href="https://github.com/prowler-cloud/prowler/pull/11702">(#11702)</a></li>
<li>CIS Amazon Web Services Foundations Benchmark v7.0.0 compliance framework for the AWS provider, adding the new Organizations section (2.1.1-2.1.6), resource policy (2.21), web front-end access logging (4.10), and VPC Endpoints (6.8) recommendations <a href="https://github.com/prowler-cloud/prowler/pull/11707">(#11707)</a></li>
<li>CIS Microsoft Azure Foundations Benchmark v6.0.0 compliance framework for the Azure provider <a href="https://github.com/prowler-cloud/prowler/pull/11708">(#11708)</a></li>
<li>CIS Google Cloud Platform Foundation Benchmark v5.0.0 compliance framework for the GCP provider <a href="https://github.com/prowler-cloud/prowler/pull/11714">(#11714)</a></li>
<li>CIS Kubernetes Benchmark v2.0.1 compliance framework for the Kubernetes provider <a href="https://github.com/prowler-cloud/prowler/pull/11722">(#11722)</a></li>
<li>CIS GitHub Benchmark v1.2.0 compliance framework for the GitHub provider <a href="https://github.com/prowler-cloud/prowler/pull/11719">(#11719)</a></li>
<li>AWS Bedrock AgentCore privilege escalation paths in the IAM privilege escalation checks, covering Runtime, Harness, Code Interpreter and Custom Browser <a href="https://github.com/prowler-cloud/prowler/pull/11726">(#11726)</a></li>
<li><code>--scan-secrets-validate</code> flag and <code>aws.secrets_validate</code> configuration option to optionally validate the secrets discovered by the secret-scanning checks against the provider APIs; secrets confirmed to be live are reported as critical <a href="https://github.com/prowler-cloud/prowler/pull/11694">(#11694)</a></li>
<li><code>apigateway_restapi_no_secrets_in_stage_variables</code> check for AWS provider, scanning API Gateway REST API stage variables for hardcoded secrets such as passwords, API keys, and tokens <a href="https://github.com/prowler-cloud/prowler/pull/11188">(#11188)</a></li>
<li><code>s3_bucket_object_public</code> check for AWS provider, spot-checking a configurable sample of object ACLs in each bucket and flagging objects granted to the AllUsers or AuthenticatedUsers groups; disabled by default and opted into via the <code>s3_bucket_object_public_enabled</code> configuration option <a href="https://github.com/prowler-cloud/prowler/pull/9517">(#9517)</a></li>
<li>Azure provider now supports <code>--azure-resource-group</code> to scope resource-level checks to specific resource groups across all accessible subscriptions <a href="https://github.com/prowler-cloud/prowler/pull/10657">(#10657)</a></li>
</ul>
<h3 id="-changed-1">🔄 Changed</h3>
<ul>
<li>Replaced the <code>detect-secrets</code> library with <a href="https://github.com/mongodb/kingfisher">Kingfisher</a> as the engine for the secret-scanning checks; scans run fully offline by default and obvious placeholder values are no longer reported as findings <a href="https://github.com/prowler-cloud/prowler/pull/11694">(#11694)</a></li>
<li>Removed the <code>detect_secrets_plugins</code> configuration option, which is no longer used by the new secret-scanning engine <a href="https://github.com/prowler-cloud/prowler/pull/11694">(#11694)</a></li>
<li><code>awslambda_function_no_secrets_in_code</code> now supports a <code>secrets_ignore_files</code> audit-config option to skip files inside the deployment package by glob pattern (e.g. <code>*.deps.json</code>), suppressing .NET dependency-manifest false positives without masking real secrets <a href="https://github.com/prowler-cloud/prowler/pull/11222">(#11222)</a></li>
<li>AWS scans for EBS snapshots, Backup recovery points, CloudWatch log groups, Lambda functions, ECS task definitions, and CodeArtifact packages now support configurable resource analysis limits via <code>aws.max_scanned_resources_per_service</code>; limits are disabled by default and only positive values cap analyzed resources <a href="https://github.com/prowler-cloud/prowler/pull/11228">(#11228)</a></li>
</ul>
<h3 id="-fixed-1">🐞 Fixed</h3>
<ul>
<li>GitHub <code>repository_has_codeowners_file</code> check no longer flags archived repositories, since they are read-only and cannot be updated without first being unarchived, making the finding not actionable <a href="https://github.com/prowler-cloud/prowler/pull/11735">(#11735)</a></li>
<li>Report secret-scanning checks as <code>MANUAL</code> instead of <code>PASS</code> when the scanner fails (non-zero exit, timeout, unparseable output or missing binary), so a scanner failure is no longer indistinguishable from &ldquo;no secrets found&rdquo; <a href="https://github.com/prowler-cloud/prowler/pull/11694">(#11694)</a></li>
<li>Avoid a false <code>FAIL</code> in <code>cloudwatch_log_group_no_secrets_in_logs</code> when a multiline event&rsquo;s secrets are all removed by <code>secrets_ignore_patterns</code> during the rescan <a href="https://github.com/prowler-cloud/prowler/pull/11694">(#11694)</a></li>
<li>Key the <code>cloudwatch_log_group_no_secrets_in_logs</code> secret scan by log group ARN instead of name, so same-named log groups and streams in different regions no longer collide and reuse each other&rsquo;s findings <a href="https://github.com/prowler-cloud/prowler/pull/11694">(#11694)</a></li>
<li>Compliance frameworks contributed by several external packages under the same provider are now merged instead of overwritten, so every entry-point directory a provider contributes is discovered <a href="https://github.com/prowler-cloud/prowler/pull/11578">(#11578)</a></li>
<li>Azure PostgreSQL flexible server collection no longer drops the remaining servers in a subscription when one server fails to collect; the <code>connection_throttle.enable</code> parameter (removed in PostgreSQL 16+) is treated as absent only when the Azure SDK reports it as not found, so unexpected lookup failures are not silently reported as throttling disabled <a href="https://github.com/prowler-cloud/prowler/pull/11595">(#11595)</a></li>
<li>Azure <code>keyvault_logging_enabled</code> now accepts Key Vault diagnostic settings that enable the explicit <code>AuditEvent</code> category, avoiding false failures when Azure returns category-based logs without category groups <a href="https://github.com/prowler-cloud/prowler/pull/11660">(#11660)</a></li>
<li>GitHub default branch protection checks now evaluate repository rulesets in addition to classic branch protection, avoiding false positives for repositories that enforce protection through rulesets <a href="https://github.com/prowler-cloud/prowler/pull/11723">(#11723)</a></li>
<li>Okta, Alibaba Cloud and OpenStack scan-config sections are now validated against a registered schema instead of being silently accepted, so their configurable thresholds (session/idle timeouts, retention days, image-sharing and secret-scanning settings) log a warning and fall back to the built-in default whenever a value is out of range <a href="https://github.com/prowler-cloud/prowler/pull/11725">(#11725)</a></li>
</ul>
]]></content:encoded></item><item><title>Assay - AI Agent Security</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/assay-ai-agent-security/</link><pubDate>Thu, 02 Jul 2026 22:17:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/assay-ai-agent-security/</guid><description>Version updated for https://github.com/Rul1an/assay-action to version v3.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v3 is the current major: verify, lint, and diff evidence bundles from AI agent runs in CI, with coding-agent sandbox governance and in-toto/DSSE bundle attestation.
What v3 carries
sandbox-command: run a coding agent under assay sandbox and verify the resulting evidence bundle in the same job. attest-key: in-toto/DSSE attestation over the bundle (assay evidence attest). The v2.1 AI Agent Security feature set: compliance packs, BYOS push, artifact attestation, coverage badges, PR summaries, SARIF for code scanning. v3.0.1 fixes</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Rul1an/assay-action">https://github.com/Rul1an/assay-action</a></strong> to version <strong>v3.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/assay-ai-agent-security">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>v3 is the current major: verify, lint, and diff evidence bundles from AI agent runs in CI, with coding-agent sandbox governance and in-toto/DSSE bundle attestation.</p>
<p><strong>What v3 carries</strong></p>
<ul>
<li><code>sandbox-command</code>: run a coding agent under <code>assay sandbox</code> and verify the resulting evidence bundle in the same job.</li>
<li><code>attest-key</code>: in-toto/DSSE attestation over the bundle (<code>assay evidence attest</code>).</li>
<li>The v2.1 AI Agent Security feature set: compliance packs, BYOS push, artifact attestation, coverage badges, PR summaries, SARIF for code scanning.</li>
</ul>
<p><strong>v3.0.1 fixes</strong></p>
<ul>
<li>Authenticate the latest-release lookup and resolve the release before caching the CLI (#30, #31), removing rate-limit flakes on busy runners.</li>
</ul>
<p><strong>Breaking vs v2</strong>: the legacy marketplace <code>mode</code>/<code>run</code> inputs are not carried; pin <code>Rul1an/assay-action@v2</code> if you depend on those. Migration notes in the <a href="https://github.com/Rul1an/assay/blob/main/docs/architecture/SPEC-GitHub-Action-v2.1.md">action spec</a>.</p>
<p>Pin the major: <code>uses: Rul1an/assay-action@v3</code></p>
]]></content:encoded></item><item><title>CDK Lambda Size Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/cdk-lambda-size-gate/</link><pubDate>Thu, 02 Jul 2026 22:17:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/cdk-lambda-size-gate/</guid><description>Version updated for https://github.com/schuettc/cdk-lambda-size-gate to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog 16da0508205b06be18de0adb4a721ba5fc07182a: ci: e2e verification of the published action (v1.0.0 + v1, linux + windows) (@schuettc) 1d399dc296ec3f1977e607a204deb0fc133a8109: fix(action): shorten description under Marketplace 125-char limit (@schuettc)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/schuettc/cdk-lambda-size-gate">https://github.com/schuettc/cdk-lambda-size-gate</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cdk-lambda-size-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
<ul>
<li>16da0508205b06be18de0adb4a721ba5fc07182a: ci: e2e verification of the published action (v1.0.0 + v1, linux + windows) (@schuettc)</li>
<li>1d399dc296ec3f1977e607a204deb0fc133a8109: fix(action): shorten description under Marketplace 125-char limit (@schuettc)</li>
</ul>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/bernstein-multi-agent-orchestration/</link><pubDate>Thu, 02 Jul 2026 22:16:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v2.13.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.13.0 Released 2026-07-02.
Run-safety guardrails and per-role endpoint configuration.
Fixes (run safety) GitHub backlog auto-sync is now opt-in and off by default. Previously a run in a repository with open GitHub issues would pull every open issue into the backlog before task scoping, which could silently discard a seeded goal and spawn work against the entire issue list. Enable it explicitly with the github.sync_backlog seed config key (or the BERNSTEIN_SYNC_GITHUB_BACKLOG env override). (#2178) A seeded goal is no longer silently dropped when the backlog is non-empty: the run now prints a loud warning naming the precedence and how to force the goal, instead of quietly planning from the backlog. (#2178) Agent worktree merges refuse to land on the repository default branch. The merge and push path resolves the protected default (origin/HEAD, then init.defaultBranch, then the conventional names, treating both main and master as protected when the remote head is ambiguous) and refuses to merge or push agent work onto it, recording the refusal, so a run started from a default-branch checkout can no longer push unreviewed commits straight to the trunk. (#2178) Features (per-role model configuration) role_model_policy entries gain optional base_url and api_key_env next to model/provider, so different roles can target different OpenAI-compatible endpoints in one workflow (for example a fast manager endpoint and cheaper worker endpoints). api_key_env names an environment variable and is validated against the same fail-closed provider allowlist as the runner. YAML anchors give reuse across roles with no new file format. Absent fields keep today’s behavior. (#2159) ModeProfile gains top_p, top_k, and max_tokens beside its existing temperature, and the previously-deferred apply_mode_to_spawn wiring is completed so a mode profile’s sampling parameters actually reach the spawn and the runner manifest. (#2159) Opt-in builtin tools for the openai_agents runner, for runs without an MCP gateway, selected by tool_source: builtin (the gateway remains the default). read_file, write_file, and list_dir are workdir-confined (absolute and parent-escape paths are rejected). run_command is a restricted process-exec primitive: bare-name commands only, shell interpreters blocked, resolved against PATH, available only under a configured OS sandbox provider or an explicit opt-in; its filesystem confinement is the OS sandbox, not the builtin. Every builtin call is recorded to the run event log so a gateway-free run stays auditable. (#2159) Quality Resolved refurb FURB123 findings in the OWASP control-map builders.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v2.13.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v2130">v2.13.0</h1>
<p>Released 2026-07-02.</p>
<p>Run-safety guardrails and per-role endpoint configuration.</p>
<h2 id="fixes-run-safety">Fixes (run safety)</h2>
<ul>
<li>GitHub backlog auto-sync is now opt-in and off by default. Previously a run in a repository with open GitHub issues would pull every open issue into the backlog before task scoping, which could silently discard a seeded goal and spawn work against the entire issue list. Enable it explicitly with the <code>github.sync_backlog</code> seed config key (or the <code>BERNSTEIN_SYNC_GITHUB_BACKLOG</code> env override). (#2178)</li>
<li>A seeded goal is no longer silently dropped when the backlog is non-empty: the run now prints a loud warning naming the precedence and how to force the goal, instead of quietly planning from the backlog. (#2178)</li>
<li>Agent worktree merges refuse to land on the repository default branch. The merge and push path resolves the protected default (origin/HEAD, then <code>init.defaultBranch</code>, then the conventional names, treating both <code>main</code> and <code>master</code> as protected when the remote head is ambiguous) and refuses to merge or push agent work onto it, recording the refusal, so a run started from a default-branch checkout can no longer push unreviewed commits straight to the trunk. (#2178)</li>
</ul>
<h2 id="features-per-role-model-configuration">Features (per-role model configuration)</h2>
<ul>
<li><code>role_model_policy</code> entries gain optional <code>base_url</code> and <code>api_key_env</code> next to <code>model</code>/<code>provider</code>, so different roles can target different OpenAI-compatible endpoints in one workflow (for example a fast manager endpoint and cheaper worker endpoints). <code>api_key_env</code> names an environment variable and is validated against the same fail-closed provider allowlist as the runner. YAML anchors give reuse across roles with no new file format. Absent fields keep today&rsquo;s behavior. (#2159)</li>
<li><code>ModeProfile</code> gains <code>top_p</code>, <code>top_k</code>, and <code>max_tokens</code> beside its existing <code>temperature</code>, and the previously-deferred <code>apply_mode_to_spawn</code> wiring is completed so a mode profile&rsquo;s sampling parameters actually reach the spawn and the runner manifest. (#2159)</li>
<li>Opt-in builtin tools for the openai_agents runner, for runs without an MCP gateway, selected by <code>tool_source: builtin</code> (the gateway remains the default). <code>read_file</code>, <code>write_file</code>, and <code>list_dir</code> are workdir-confined (absolute and parent-escape paths are rejected). <code>run_command</code> is a restricted process-exec primitive: bare-name commands only, shell interpreters blocked, resolved against PATH, available only under a configured OS sandbox provider or an explicit opt-in; its filesystem confinement is the OS sandbox, not the builtin. Every builtin call is recorded to the run event log so a gateway-free run stays auditable. (#2159)</li>
</ul>
<h2 id="quality">Quality</h2>
<ul>
<li>Resolved refurb FURB123 findings in the OWASP control-map builders.</li>
</ul>
]]></content:encoded></item><item><title>Pipr Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/pipr-review/</link><pubDate>Thu, 02 Jul 2026 22:15:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/pipr-review/</guid><description>Version updated for https://github.com/somus/pipr to version v0.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.2.0 (2026-07-02) ⚠ BREAKING CHANGES pipr init –types-only and –no-types are removed and generated .pipr/types/pipr-sdk.d.ts is no longer written; types come from the installed @usepipr/sdk package. structure runtime action logging (#10) consolidate public API contracts (#9) Features consolidate public API contracts (#9) (01db150) support installable npm dependencies in .pipr config (#14) (97794bc) Code Refactoring structure runtime action logging (#10) (64addf1)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somus/pipr">https://github.com/somus/pipr</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pipr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="020-2026-07-02"><a href="https://github.com/somus/pipr/compare/v0.1.3...v0.2.0">0.2.0</a> (2026-07-02)</h2>
<h3 id="-breaking-changes">⚠ BREAKING CHANGES</h3>
<ul>
<li>pipr init &ndash;types-only and &ndash;no-types are removed and generated .pipr/types/pipr-sdk.d.ts is no longer written; types come from the installed @usepipr/sdk package.</li>
<li>structure runtime action logging (<a href="https://github.com/somus/pipr/issues/10">#10</a>)</li>
<li>consolidate public API contracts (<a href="https://github.com/somus/pipr/issues/9">#9</a>)</li>
</ul>
<h3 id="features">Features</h3>
<ul>
<li>consolidate public API contracts (<a href="https://github.com/somus/pipr/issues/9">#9</a>) (<a href="https://github.com/somus/pipr/commit/01db1506ff9af35864f130c27a6d0b2df37fdbe1">01db150</a>)</li>
<li>support installable npm dependencies in .pipr config (<a href="https://github.com/somus/pipr/issues/14">#14</a>) (<a href="https://github.com/somus/pipr/commit/97794bc8c9bd588e69e2935de4f443e704779cd6">97794bc</a>)</li>
</ul>
<h3 id="code-refactoring">Code Refactoring</h3>
<ul>
<li>structure runtime action logging (<a href="https://github.com/somus/pipr/issues/10">#10</a>) (<a href="https://github.com/somus/pipr/commit/64addf117c9c47c2c853bde63e3502d8254468da">64addf1</a>)</li>
</ul>
]]></content:encoded></item><item><title>Repository Create</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/repository-create/</link><pubDate>Thu, 02 Jul 2026 22:15:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/repository-create/</guid><description>Version updated for https://github.com/stairwaytowonderland/repository-create to version v1.74.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed chore(release): 1.74.0
1.74.0 (2026-07-02) ✨ Features updates (328fff6)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stairwaytowonderland/repository-create">https://github.com/stairwaytowonderland/repository-create</a></strong> to version <strong>v1.74.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/repository-create">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>chore(release): 1.74.0</p>
<h2 id="1740-2026-07-02"><a href="https://github.com/stairwaytowonderland/repository-create/compare/v1.73.0...v1.74.0">1.74.0</a> (2026-07-02)</h2>
<h3 id="-features">✨ Features</h3>
<ul>
<li>updates (<a href="https://github.com/stairwaytowonderland/repository-create/commit/328fff62871ca4f2f4b50953a3306ecabcc9472c">328fff6</a>)</li>
</ul>
]]></content:encoded></item><item><title>Frisk — AI supply-chain scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/frisk-ai-supply-chain-scan/</link><pubDate>Thu, 02 Jul 2026 22:14:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/frisk-ai-supply-chain-scan/</guid><description>Version updated for https://github.com/Thandv/frisk to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First release. Static, zero-execution scanner for AI-agent content (MCP servers, skills, plugins): RCE, secret exfiltration, destructive ops, prompt-injection, tool-poisoning, hidden-unicode. Rug-pull detection (lock/verify), OWASP LLM Top 10 mapping, SARIF, GitHub Action, and an MCP server to vet-before-install. Install: pip install frisk-scan</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Thandv/frisk">https://github.com/Thandv/frisk</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/frisk-ai-supply-chain-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First release. Static, zero-execution scanner for AI-agent content (MCP servers, skills, plugins): RCE, secret exfiltration, destructive ops, prompt-injection, tool-poisoning, hidden-unicode. Rug-pull detection (lock/verify), OWASP LLM Top 10 mapping, SARIF, GitHub Action, and an MCP server to vet-before-install. Install: pip install frisk-scan</p>
]]></content:encoded></item><item><title>UnityInFlow Spec Compliance</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/unityinflow-spec-compliance/</link><pubDate>Thu, 02 Jul 2026 22:14:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/unityinflow-spec-compliance/</guid><description>Version updated for https://github.com/UnityInFlow/spec-ci-plugin to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First stable Marketplace release of the UnityInFlow Spec Compliance action.
What’s included Typed status and report action outputs (matching the runtime core.setOutput calls) injection-scanner-version default bumped to v0.0.2 — the tag carrying the Linux musl binaries the action downloads at runtime Deterministic committed dist/ (no sourcemaps) guarded by a git diff --exit-code dist/ staleness gate in CI Public/fork CI runs secretless on GitHub-hosted runners; release automation stays on org self-hosted runners Moving v1 tag maintained automatically on release publish Usage - uses: UnityInFlow/spec-ci-plugin@v1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/UnityInFlow/spec-ci-plugin">https://github.com/UnityInFlow/spec-ci-plugin</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/unityinflow-spec-compliance">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First stable Marketplace release of the UnityInFlow Spec Compliance action.</p>
<h2 id="whats-included">What&rsquo;s included</h2>
<ul>
<li>Typed <code>status</code> and <code>report</code> action outputs (matching the runtime <code>core.setOutput</code> calls)</li>
<li><code>injection-scanner-version</code> default bumped to <code>v0.0.2</code> — the tag carrying the Linux musl binaries the action downloads at runtime</li>
<li>Deterministic committed <code>dist/</code> (no sourcemaps) guarded by a <code>git diff --exit-code dist/</code> staleness gate in CI</li>
<li>Public/fork CI runs secretless on GitHub-hosted runners; release automation stays on org self-hosted runners</li>
<li>Moving <code>v1</code> tag maintained automatically on release publish</li>
</ul>
<h2 id="usage">Usage</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">UnityInFlow/spec-ci-plugin@v1</span>
</span></span></code></pre></div>]]></content:encoded></item><item><title>Polder Drift — Design System Drift Alerts</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/polder-drift-design-system-drift-alerts/</link><pubDate>Thu, 02 Jul 2026 22:13:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/polder-drift-design-system-drift-alerts/</guid><description>Version updated for https://github.com/usepolder/drift to version v1.1.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Polder Drift now works with any design system — including your in-house one. Point library_paths at a checkout of your DS repo (source-only monorepo workspaces work too), and generate the look-alike detection data straight from your DS’s own source:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/usepolder/drift">https://github.com/usepolder/drift</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/polder-drift-design-system-drift-alerts">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Polder Drift now works with any design system — including your in-house one.</strong> Point <code>library_paths</code> at a checkout of your DS repo (source-only monorepo workspaces work too), and generate the look-alike detection data straight from your DS&rsquo;s own source:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npx @usepolder/drift profile   <span style="color:#75715e"># writes .polder.profile.yml — review, prune, commit</span>
</span></span></code></pre></div><p>Also in this release: PRs with 100+ changed files are now fully analysed, the CLI honours <code>.polderignore</code> and shows each finding&rsquo;s suppression id, every finding carries its source line, and scans are ~3× faster. All backward compatible — existing configs, suppression files, and <code>@v1</code> workflows keep working unchanged.</p>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs: add fetch-depth: 0 to the recommended workflow by @jongjesse in <a href="https://github.com/usepolder/drift/pull/9">https://github.com/usepolder/drift/pull/9</a></li>
<li>Five improvements: pagination, CLI suppression parity, detection profiles, finding lines, single parse by @jongjesse in <a href="https://github.com/usepolder/drift/pull/10">https://github.com/usepolder/drift/pull/10</a></li>
<li>Any design system: resolve exports from DS repos + auto-generate detection profiles by @jongjesse in <a href="https://github.com/usepolder/drift/pull/11">https://github.com/usepolder/drift/pull/11</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/usepolder/drift/compare/v1...v1.1.0">https://github.com/usepolder/drift/compare/v1...v1.1.0</a></p>
]]></content:encoded></item><item><title>configure-huawei-cloud-credentials</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/configure-huawei-cloud-credentials/</link><pubDate>Thu, 02 Jul 2026 22:13:14 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/configure-huawei-cloud-credentials/</guid><description>Version updated for https://github.com/vbem/configure-huawei-cloud-credentials to version v1.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/vbem/configure-huawei-cloud-credentials/compare/v0.0.2...v1.0.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vbem/configure-huawei-cloud-credentials">https://github.com/vbem/configure-huawei-cloud-credentials</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/configure-huawei-cloud-credentials">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/vbem/configure-huawei-cloud-credentials/compare/v0.0.2...v1.0.0">https://github.com/vbem/configure-huawei-cloud-credentials/compare/v0.0.2...v1.0.0</a></p>
]]></content:encoded></item><item><title>Install The Hive Skill</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/install-the-hive-skill/</link><pubDate>Thu, 02 Jul 2026 22:12:41 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/install-the-hive-skill/</guid><description>Version updated for https://github.com/yuzuruu29/the-hive-skill to version v0.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed The Hive Skill v0.1.0 Initial public release of The Hive Skill, an open-source autonomous multi-agent orchestration skill for agentic coders.
The Hive Skill turns one AI coding agent into a structured six-role council:
Role Table Role Responsibility Queen Coordinates the council, makes final decisions, and ensures the goal is met. Scout Explores the codebase and gathers necessary context. Architect Designs the solution and plans the changes. Forger Writes the code and implements the Architect’s plan. Sentinel Validates the changes, runs tests, and ensures quality. Scribe Documents the process and writes the final report. What is included SKILL.md core skill definition Six council role files Autonomous execution loop Token efficiency mode Compressed role output mode Default invocation behavior Anti-slop rules Validation rules Final and blocked report formats OpenCode / OpenCode Go adapter Claude Code adapter Codex adapter Generic .agents adapter Install scripts for Bash and PowerShell GitHub Action wrapper Security policy Apache-2.0 license Supported agentic coding workflows The Hive Skill is designed for:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yuzuruu29/the-hive-skill">https://github.com/yuzuruu29/the-hive-skill</a></strong> to version <strong>v0.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-the-hive-skill">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="the-hive-skill-v010">The Hive Skill v0.1.0</h1>
<p>Initial public release of <strong>The Hive Skill</strong>, an open-source autonomous multi-agent orchestration skill for agentic coders.</p>
<p>The Hive Skill turns one AI coding agent into a structured six-role council:</p>
<h2 id="role-table">Role Table</h2>
<table>
  <thead>
      <tr>
          <th>Role</th>
          <th>Responsibility</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td>Queen</td>
          <td>Coordinates the council, makes final decisions, and ensures the goal is met.</td>
      </tr>
      <tr>
          <td>Scout</td>
          <td>Explores the codebase and gathers necessary context.</td>
      </tr>
      <tr>
          <td>Architect</td>
          <td>Designs the solution and plans the changes.</td>
      </tr>
      <tr>
          <td>Forger</td>
          <td>Writes the code and implements the Architect&rsquo;s plan.</td>
      </tr>
      <tr>
          <td>Sentinel</td>
          <td>Validates the changes, runs tests, and ensures quality.</td>
      </tr>
      <tr>
          <td>Scribe</td>
          <td>Documents the process and writes the final report.</td>
      </tr>
  </tbody>
</table>
<h2 id="what-is-included">What is included</h2>
<ul>
<li><code>SKILL.md</code> core skill definition</li>
<li>Six council role files</li>
<li>Autonomous execution loop</li>
<li>Token efficiency mode</li>
<li>Compressed role output mode</li>
<li>Default invocation behavior</li>
<li>Anti-slop rules</li>
<li>Validation rules</li>
<li>Final and blocked report formats</li>
<li>OpenCode / OpenCode Go adapter</li>
<li>Claude Code adapter</li>
<li>Codex adapter</li>
<li>Generic <code>.agents</code> adapter</li>
<li>Install scripts for Bash and PowerShell</li>
<li>GitHub Action wrapper</li>
<li>Security policy</li>
<li>Apache-2.0 license</li>
</ul>
<h2 id="supported-agentic-coding-workflows">Supported agentic coding workflows</h2>
<p>The Hive Skill is designed for:</p>
<ul>
<li>OpenCode / OpenCode Go</li>
<li>Claude Code</li>
<li>Codex</li>
<li>Generic <code>.agents</code> workflows</li>
<li><code>SKILL.md</code>-compatible agent runtimes</li>
</ul>
<h2 id="important-note">Important note</h2>
<p>Version <code>v0.1.0</code> provides <strong>role-simulated orchestration</strong> inside compatible agentic coding tools.</p>
<p>Real multi-model or real subagent execution depends on the runtime being used.</p>
<h2 id="basic-usage">Basic usage</h2>
<p>Invoke the skill with a simple prompt:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-text" data-lang="text"><span style="display:flex;"><span>Use The Hive Skill to fix this.
</span></span></code></pre></div>]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/hol-codex-plugin-scanner/</link><pubDate>Thu, 02 Jul 2026 15:00:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.367.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.367</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.367</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.367">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.367</a></p>
]]></content:encoded></item><item><title>Skill Probe - AI Agent Skill Auditor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/skill-probe-ai-agent-skill-auditor/</link><pubDate>Thu, 02 Jul 2026 14:59:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/skill-probe-ai-agent-skill-auditor/</guid><description>Version updated for https://github.com/HystonKayange/skill-probe to version v0.9.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed skill-probe in your pipeline, gating on statistics instead of vibes The CI question isn’t “are my skills perfect?” — it’s “did this PR make any skill worse?” Activation is stochastic, so raw-rate comparisons make CI flaky. v0.9.0 makes the gate honest.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/HystonKayange/skill-probe">https://github.com/HystonKayange/skill-probe</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skill-probe-ai-agent-skill-auditor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="skill-probe-in-your-pipeline-gating-on-statistics-instead-of-vibes">skill-probe in your pipeline, gating on statistics instead of vibes</h2>
<p>The CI question isn&rsquo;t <em>&ldquo;are my skills perfect?&rdquo;</em> — it&rsquo;s <strong>&ldquo;did this PR make any skill worse?&rdquo;</strong> Activation is stochastic, so raw-rate comparisons make CI flaky. v0.9.0 makes the gate honest.</p>
<h3 id="baseline-regression-gating">Baseline regression gating</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>skill-probe --config probe.config.json --save-baseline baselines/main.json   <span style="color:#75715e"># once, on main</span>
</span></span><span style="display:flex;"><span>skill-probe --config probe.config.json --baseline baselines/main.json        <span style="color:#75715e"># every PR</span>
</span></span></code></pre></div><p>Each case is compared against the baseline with <strong>Fisher&rsquo;s exact test, Benjamini-Hochberg corrected</strong> — noise passes, significant drops fail (exit 1). Drift in config/runtime/model since the baseline warns (matched cases still gated); new/missing cases are reported, not gated; a side with no valid probes is <strong>NOT COMPARABLE</strong>, never a silent pass. Significant improvements are flagged as a nudge to re-save the baseline.</p>
<h3 id="run-manifest">Run manifest</h3>
<p>Every <code>--json</code> result now stamps <em>who/what/when</em>: tool version, command, ISO date, runtime, model, k/threshold/conf, and a <strong>config hash</strong> (cwd excluded — the same library on a laptop and a CI runner is the same experiment). Two runs are comparable; a report is citable.</p>
<h3 id="github-action">GitHub Action</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">HystonKayange/skill-probe@main</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">config</span>: <span style="color:#ae81ff">probe.config.json</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">args</span>: --<span style="color:#ae81ff">baseline baselines/main.json</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">env</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">ANTHROPIC_API_KEY</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span></code></pre></div><p>Installs skill-probe + the runtime CLI (Claude Code by default, swappable) and runs any subcommand (<code>audit</code>/<code>context</code>/<code>diagnose</code>/<code>doctor</code>).</p>
<p>Plus: repo CI (typecheck + tests, no API calls). 83 tests. Baseline save→gate loop proven live.</p>
]]></content:encoded></item><item><title>MLX Model Doctor</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/mlx-model-doctor/</link><pubDate>Thu, 02 Jul 2026 14:59:03 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/mlx-model-doctor/</guid><description>Version updated for https://github.com/IonDen/mlx-model-doctor to version v0.6.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed v0.6.2: memory pass/fail semantics and hardening fixes by @IonDen in https://github.com/IonDen/mlx-model-doctor/pull/22 Full Changelog: https://github.com/IonDen/mlx-model-doctor/compare/v0.6.1...v0.6.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/IonDen/mlx-model-doctor">https://github.com/IonDen/mlx-model-doctor</a></strong> to version <strong>v0.6.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/mlx-model-doctor">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>v0.6.2: memory pass/fail semantics and hardening fixes by @IonDen in <a href="https://github.com/IonDen/mlx-model-doctor/pull/22">https://github.com/IonDen/mlx-model-doctor/pull/22</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/IonDen/mlx-model-doctor/compare/v0.6.1...v0.6.2">https://github.com/IonDen/mlx-model-doctor/compare/v0.6.1...v0.6.2</a></p>
]]></content:encoded></item><item><title>zizmor - static analysis tool for Actions workflows</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/zizmor-static-analysis-tool-for-actions-workflows/</link><pubDate>Thu, 02 Jul 2026 14:58:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/zizmor-static-analysis-tool-for-actions-workflows/</guid><description>Version updated for https://github.com/its-me/action.zizmor to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial release of the action.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/its-me/action.zizmor">https://github.com/its-me/action.zizmor</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/zizmor-static-analysis-tool-for-actions-workflows">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial release of the action.</p>
]]></content:encoded></item><item><title>NeuroLink AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/neurolink-ai/</link><pubDate>Thu, 02 Jul 2026 14:57:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/neurolink-ai/</guid><description>Version updated for https://github.com/juspay/neurolink to version v9.80.3.
This action is used across all versions by 10 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 9.80.3 (2026-07-02) Bug Fixes (vertex): reserve final_result step + graceful cap recovery in native Anthropic loop (ee44e60), closes #1123</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/juspay/neurolink">https://github.com/juspay/neurolink</a></strong> to version <strong>v9.80.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/neurolink-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="9803-2026-07-02"><a href="https://github.com/juspay/neurolink/compare/v9.80.2...v9.80.3">9.80.3</a> (2026-07-02)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>(vertex):</strong>  reserve final_result step + graceful cap recovery in native Anthropic loop (<a href="https://github.com/juspay/neurolink/commit/ee44e6055ee6658ae471ac15c6bee6a890888350">ee44e60</a>), closes <a href="https://github.com/juspay/neurolink/issues/1123">#1123</a></li>
</ul>
]]></content:encoded></item><item><title>OLIVE Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/olive-action/</link><pubDate>Thu, 02 Jul 2026 14:57:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/olive-action/</guid><description>Version updated for https://github.com/kakao/olive-action to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 🚀 OLIVE Action v1 - 첫 번째 릴리즈 📋 릴리즈 개요 OLIVE Action의 첫 번째 공식 릴리즈입니다. 이 Action은 GitHub Actions에서 OLIVE CLI를 사용하여 오픈소스 라이선스 의무사항 준수를 자동화하는 도구입니다.
✨ 주요 기능 🔍 자동 의존성 분석 Pull Request 생성 시 소스코드 의존성을 자동으로 분석 다양한 프로그래밍 언어 지원 (Python, Node.js, Java, Rust, Ruby, Dart, Flutter 등) ORT (OSS Review Toolkit) 기반의 정확한 의존성 추출 💬 PR 코멘트 자동 작성 분석 결과를 Pull Request에 자동으로 코멘트 작성 라이선스 정보, 매핑된 컴포넌트, 매핑되지 않은 의존성 목록 제공 실패 시에도 적절한 에러 메시지 자동 작성 🔗 OLIVE Platform 연동 분석 결과를 OLIVE Platform으로 자동 전송 오픈소스 라이선스 및 취약점 관리 지원 프로젝트별 라이선스 의무사항 추적 📦 분석 결과 저장 GitHub Artifacts를 통한 상세 분석 결과 저장 dependency.csv, dependency.json, mapping.csv, mapping.json, unmapping.csv 파일 제공 설정 파일 (local-config.yaml) 보관 🛠️ 기술적 특징 컨테이너 기반 실행 Docker 컨테이너 환경에서 격리된 실행 다양한 개발 도구가 사전 설치된 통합 환경 안정적이고 재현 가능한 실행 환경 다중 언어 지원 Python: 3.11.10, pip, pipenv, poetry, conan Node.js: 20.14.0, npm, yarn, pnpm, bower Java: Gradle 8.13, OpenJDK 11 Rust: 1.72.0 Ruby: 3.3.5, bundler, cocoapods Dart/Flutter: 2.18.4/3.24.4 PHP: 8.3, composer Android: Android SDK, command-line tools 모듈화된 구조 6단계 실행 프로세스로 명확한 워크플로우 각 기능별 분리된 스크립트로 유지보수성 향상 사용자 정의 설정 파일 지원 🚀 사용법 기본 사용법 name: OLIVE Action on: pull_request: types: [opened, synchronize, reopened] branches: [main, develop] permissions: contents: read issues: write pull-requests: write jobs: olive-scan: runs-on: ubuntu-latest steps: - name: Checkout code uses: actions/checkout@v4 - name: Run OLIVE Action uses: kakao/olive-action@v1 with: olive-token: ${{ secrets.OLIVE_TOKEN }} github-token: ${{ secrets.GITHUB_TOKEN }} 고급 설정 - name: Run OLIVE Action with custom settings uses: kakao/olive-action@v1 with: olive-project-name: &amp;#34;my-custom-project&amp;#34; olive-token: ${{ secrets.OLIVE_TOKEN }} github-token: ${{ secrets.GITHUB_TOKEN }} source-path: &amp;#34;./src&amp;#34; user-config-path: &amp;#34;./user-config.yml&amp;#34; artifact-retention-days: &amp;#34;7&amp;#34; comment-on-pr: &amp;#34;true&amp;#34; analyze-only: &amp;#34;false&amp;#34; debug: &amp;#34;false&amp;#34; 🔧 입력 파라미터 파라미터 설명 필수 기본값 olive-token OLIVE Platform API 토큰 ✅ - github-token PR 코멘트 작성용 GitHub 토큰 ✅ - olive-project-name OLIVE Platform 프로젝트 이름 ❌ 저장소 이름 source-path 분석할 소스코드 경로 ❌ ./ user-config-path 사용자 정의 config 파일 경로 ❌ &amp;#34;&amp;#34; artifact-retention-days 아티팩트 보관 기간 (일) ❌ 30 comment-on-pr PR에 코멘트 작성 여부 ❌ true analyze-only 분석만 수행하고 Platform 연동 생략 ❌ false debug 디버그 모드 활성화 ❌ false 📊 출력 결과 GitHub Artifacts dependency.csv, dependency.json: 의존성 분석 결과 mapping.csv, mapping.json: 컴포넌트 매핑 결과 unmapping.csv: 매핑되지 않은 의존성 목록 local-config.yaml: OLIVE CLI 설정 파일 PR 코멘트 OLIVE CLI 버전 및 프로젝트 정보 라이선스 분석 결과 요약 매핑된 컴포넌트 및 매핑되지 않은 의존성 목록 아티팩트 다운로드 링크 🚨 사전 준비사항 1. OLIVE Platform 토큰 발급 OLIVE Platform에서 API 토큰 발급 토큰 발급 가이드 참고 2. GitHub Secrets 설정 OLIVE_TOKEN: OLIVE Platform API 토큰 GITHUB_TOKEN: GitHub Actions 기본 토큰 (자동 제공) 🔍 실행 단계 소스 위치 검증 - 분석할 소스코드 경로 확인 OLIVE CLI 초기화 - 프로젝트 설정 및 토큰 검증 의존성 분석 - 소스코드 의존성 추출 및 분석 컴포넌트 분석 - 의존성을 OLIVE 컴포넌트에 매핑 라이선스 분석 - 라이선스 정보 추출 및 분석 OLIVE Platform 연동 - 분석 결과를 Platform으로 전송 🛡️ 보안 및 안정성 격리된 실행 환경: Docker 컨테이너를 통한 안전한 실행 토큰 검증: 실행 전 필수 토큰들의 유효성 검증 에러 처리: 실패 시 자동 정리 및 에러 리포팅 리소스 관리: 컨테이너 자동 정리로 메모리 누수 방지 📚 문서 및 지원 사용 가이드: README.md OLIVE Platform: https://olive.kakao.com/ OLIVE CLI: https://github.com/kakao/olive-cli 📄 라이선스 이 프로젝트는 Apache License 2.0 하에 배포됩니다.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/kakao/olive-action">https://github.com/kakao/olive-action</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/olive-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="-olive-action-v1---첫-번째-릴리즈">🚀 OLIVE Action v1 - 첫 번째 릴리즈</h1>
<h3 id="-릴리즈-개요">📋 릴리즈 개요</h3>
<p><strong>OLIVE Action</strong>의 첫 번째 공식 릴리즈입니다. 이 Action은 GitHub Actions에서 OLIVE CLI를 사용하여 오픈소스 라이선스 의무사항 준수를 자동화하는 도구입니다.</p>
<hr>
<h2 id="-주요-기능">✨ 주요 기능</h2>
<h3 id="-자동-의존성-분석">🔍 <strong>자동 의존성 분석</strong></h3>
<ul>
<li>Pull Request 생성 시 소스코드 의존성을 자동으로 분석</li>
<li>다양한 프로그래밍 언어 지원 (Python, Node.js, Java, Rust, Ruby, Dart, Flutter 등)</li>
<li>ORT (OSS Review Toolkit) 기반의 정확한 의존성 추출</li>
</ul>
<h3 id="-pr-코멘트-자동-작성">💬 <strong>PR 코멘트 자동 작성</strong></h3>
<ul>
<li>분석 결과를 Pull Request에 자동으로 코멘트 작성</li>
<li>라이선스 정보, 매핑된 컴포넌트, 매핑되지 않은 의존성 목록 제공</li>
<li>실패 시에도 적절한 에러 메시지 자동 작성</li>
</ul>
<h3 id="-olive-platform-연동">🔗 <strong>OLIVE Platform 연동</strong></h3>
<ul>
<li>분석 결과를 OLIVE Platform으로 자동 전송</li>
<li>오픈소스 라이선스 및 취약점 관리 지원</li>
<li>프로젝트별 라이선스 의무사항 추적</li>
</ul>
<h3 id="-분석-결과-저장">📦 <strong>분석 결과 저장</strong></h3>
<ul>
<li>GitHub Artifacts를 통한 상세 분석 결과 저장</li>
<li><code>dependency.csv</code>, <code>dependency.json</code>, <code>mapping.csv</code>, <code>mapping.json</code>, <code>unmapping.csv</code> 파일 제공</li>
<li>설정 파일 (<code>local-config.yaml</code>) 보관</li>
</ul>
<hr>
<h2 id="-기술적-특징">🛠️ 기술적 특징</h2>
<h3 id="컨테이너-기반-실행"><strong>컨테이너 기반 실행</strong></h3>
<ul>
<li>Docker 컨테이너 환경에서 격리된 실행</li>
<li>다양한 개발 도구가 사전 설치된 통합 환경</li>
<li>안정적이고 재현 가능한 실행 환경</li>
</ul>
<h3 id="다중-언어-지원"><strong>다중 언어 지원</strong></h3>
<ul>
<li><strong>Python</strong>: 3.11.10, pip, pipenv, poetry, conan</li>
<li><strong>Node.js</strong>: 20.14.0, npm, yarn, pnpm, bower</li>
<li><strong>Java</strong>: Gradle 8.13, OpenJDK 11</li>
<li><strong>Rust</strong>: 1.72.0</li>
<li><strong>Ruby</strong>: 3.3.5, bundler, cocoapods</li>
<li><strong>Dart/Flutter</strong>: 2.18.4/3.24.4</li>
<li><strong>PHP</strong>: 8.3, composer</li>
<li><strong>Android</strong>: Android SDK, command-line tools</li>
</ul>
<h3 id="모듈화된-구조"><strong>모듈화된 구조</strong></h3>
<ul>
<li>6단계 실행 프로세스로 명확한 워크플로우</li>
<li>각 기능별 분리된 스크립트로 유지보수성 향상</li>
<li>사용자 정의 설정 파일 지원</li>
</ul>
<hr>
<h2 id="-사용법">🚀 사용법</h2>
<h3 id="기본-사용법"><strong>기본 사용법</strong></h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">name</span>: <span style="color:#ae81ff">OLIVE Action</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">on</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull_request</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">types</span>: [<span style="color:#ae81ff">opened, synchronize, reopened]</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">branches</span>: [<span style="color:#ae81ff">main, develop]</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">contents</span>: <span style="color:#ae81ff">read</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">issues</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">jobs</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">olive-scan</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">runs-on</span>: <span style="color:#ae81ff">ubuntu-latest</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">name</span>: <span style="color:#ae81ff">Checkout code</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span>      - <span style="color:#f92672">name</span>: <span style="color:#ae81ff">Run OLIVE Action</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">kakao/olive-action@v1</span>
</span></span><span style="display:flex;"><span>        <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">olive-token</span>: <span style="color:#ae81ff">${{ secrets.OLIVE_TOKEN }}</span>
</span></span><span style="display:flex;"><span>          <span style="color:#f92672">github-token</span>: <span style="color:#ae81ff">${{ secrets.GITHUB_TOKEN }}</span>
</span></span></code></pre></div><h3 id="고급-설정"><strong>고급 설정</strong></h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">name</span>: <span style="color:#ae81ff">Run OLIVE Action with custom settings</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">kakao/olive-action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">olive-project-name</span>: <span style="color:#e6db74">&#34;my-custom-project&#34;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">olive-token</span>: <span style="color:#ae81ff">${{ secrets.OLIVE_TOKEN }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">github-token</span>: <span style="color:#ae81ff">${{ secrets.GITHUB_TOKEN }}</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">source-path</span>: <span style="color:#e6db74">&#34;./src&#34;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">user-config-path</span>: <span style="color:#e6db74">&#34;./user-config.yml&#34;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">artifact-retention-days</span>: <span style="color:#e6db74">&#34;7&#34;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">comment-on-pr</span>: <span style="color:#e6db74">&#34;true&#34;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">analyze-only</span>: <span style="color:#e6db74">&#34;false&#34;</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">debug</span>: <span style="color:#e6db74">&#34;false&#34;</span>
</span></span></code></pre></div><hr>
<h2 id="-입력-파라미터">🔧 입력 파라미터</h2>
<table>
  <thead>
      <tr>
          <th>파라미터</th>
          <th>설명</th>
          <th>필수</th>
          <th>기본값</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><code>olive-token</code></td>
          <td>OLIVE Platform API 토큰</td>
          <td>✅</td>
          <td>-</td>
      </tr>
      <tr>
          <td><code>github-token</code></td>
          <td>PR 코멘트 작성용 GitHub 토큰</td>
          <td>✅</td>
          <td>-</td>
      </tr>
      <tr>
          <td><code>olive-project-name</code></td>
          <td>OLIVE Platform 프로젝트 이름</td>
          <td>❌</td>
          <td>저장소 이름</td>
      </tr>
      <tr>
          <td><code>source-path</code></td>
          <td>분석할 소스코드 경로</td>
          <td>❌</td>
          <td><code>./</code></td>
      </tr>
      <tr>
          <td><code>user-config-path</code></td>
          <td>사용자 정의 config 파일 경로</td>
          <td>❌</td>
          <td><code>&quot;&quot;</code></td>
      </tr>
      <tr>
          <td><code>artifact-retention-days</code></td>
          <td>아티팩트 보관 기간 (일)</td>
          <td>❌</td>
          <td><code>30</code></td>
      </tr>
      <tr>
          <td><code>comment-on-pr</code></td>
          <td>PR에 코멘트 작성 여부</td>
          <td>❌</td>
          <td><code>true</code></td>
      </tr>
      <tr>
          <td><code>analyze-only</code></td>
          <td>분석만 수행하고 Platform 연동 생략</td>
          <td>❌</td>
          <td><code>false</code></td>
      </tr>
      <tr>
          <td><code>debug</code></td>
          <td>디버그 모드 활성화</td>
          <td>❌</td>
          <td><code>false</code></td>
      </tr>
  </tbody>
</table>
<hr>
<h2 id="-출력-결과">📊 출력 결과</h2>
<h3 id="github-artifacts"><strong>GitHub Artifacts</strong></h3>
<ul>
<li><code>dependency.csv</code>, <code>dependency.json</code>: 의존성 분석 결과</li>
<li><code>mapping.csv</code>, <code>mapping.json</code>: 컴포넌트 매핑 결과</li>
<li><code>unmapping.csv</code>: 매핑되지 않은 의존성 목록</li>
<li><code>local-config.yaml</code>: OLIVE CLI 설정 파일</li>
</ul>
<h3 id="pr-코멘트"><strong>PR 코멘트</strong></h3>
<ul>
<li>OLIVE CLI 버전 및 프로젝트 정보</li>
<li>라이선스 분석 결과 요약</li>
<li>매핑된 컴포넌트 및 매핑되지 않은 의존성 목록</li>
<li>아티팩트 다운로드 링크</li>
</ul>
<hr>
<h2 id="-사전-준비사항">🚨 사전 준비사항</h2>
<h3 id="1-olive-platform-토큰-발급">1. <strong>OLIVE Platform 토큰 발급</strong></h3>
<ul>
<li><a href="https://olive.kakao.com/">OLIVE Platform</a>에서 API 토큰 발급</li>
<li><a href="https://olive.kakao.com/docs/my-page/token">토큰 발급 가이드</a> 참고</li>
</ul>
<h3 id="2-github-secrets-설정">2. <strong>GitHub Secrets 설정</strong></h3>
<ul>
<li><code>OLIVE_TOKEN</code>: OLIVE Platform API 토큰</li>
<li><code>GITHUB_TOKEN</code>: GitHub Actions 기본 토큰 (자동 제공)</li>
</ul>
<hr>
<h2 id="-실행-단계">🔍 실행 단계</h2>
<ol>
<li><strong>소스 위치 검증</strong> - 분석할 소스코드 경로 확인</li>
<li><strong>OLIVE CLI 초기화</strong> - 프로젝트 설정 및 토큰 검증</li>
<li><strong>의존성 분석</strong> - 소스코드 의존성 추출 및 분석</li>
<li><strong>컴포넌트 분석</strong> - 의존성을 OLIVE 컴포넌트에 매핑</li>
<li><strong>라이선스 분석</strong> - 라이선스 정보 추출 및 분석</li>
<li><strong>OLIVE Platform 연동</strong> - 분석 결과를 Platform으로 전송</li>
</ol>
<hr>
<h2 id="-보안-및-안정성">🛡️ 보안 및 안정성</h2>
<ul>
<li><strong>격리된 실행 환경</strong>: Docker 컨테이너를 통한 안전한 실행</li>
<li><strong>토큰 검증</strong>: 실행 전 필수 토큰들의 유효성 검증</li>
<li><strong>에러 처리</strong>: 실패 시 자동 정리 및 에러 리포팅</li>
<li><strong>리소스 관리</strong>: 컨테이너 자동 정리로 메모리 누수 방지</li>
</ul>
<hr>
<h2 id="-문서-및-지원">📚 문서 및 지원</h2>
<ul>
<li><strong>사용 가이드</strong>: <a href="README.md">README.md</a></li>
<li><strong>OLIVE Platform</strong>: <a href="https://olive.kakao.com/">https://olive.kakao.com/</a></li>
<li><strong>OLIVE CLI</strong>: <a href="https://github.com/kakao/olive-cli">https://github.com/kakao/olive-cli</a></li>
</ul>
<hr>
<h2 id="-라이선스">📄 라이선스</h2>
<p>이 프로젝트는 Apache License 2.0 하에 배포됩니다.</p>
<p>Copyright 2025 Kakao Corp. <a href="http://www.kakaocorp.com">http://www.kakaocorp.com</a></p>
]]></content:encoded></item><item><title>Night Sky Contrib</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/night-sky-contrib/</link><pubDate>Thu, 02 Jul 2026 14:56:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/night-sky-contrib/</guid><description>Version updated for https://github.com/maxmode-now/night-sky-contrib to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial release.
night / dawn / city themes real moon phase, longest streak constellation, language mountains or skyline zero dependencies, works with the default GITHUB_TOKEN</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/maxmode-now/night-sky-contrib">https://github.com/maxmode-now/night-sky-contrib</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/night-sky-contrib">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial release.</p>
<ul>
<li>night / dawn / city themes</li>
<li>real moon phase, longest streak constellation, language mountains or skyline</li>
<li>zero dependencies, works with the default GITHUB_TOKEN</li>
</ul>
]]></content:encoded></item><item><title>Pollinations PR Reviewer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/pollinations-pr-reviewer/</link><pubDate>Thu, 02 Jul 2026 14:56:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/pollinations-pr-reviewer/</guid><description>Version updated for https://github.com/mikl-shortcuts/Pollinations-PR-Reviewer to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Small Update: Integrate minimatch Improve comment parsing Add PR descriptions passing Add reasoning-effort and timeout parameters Improve logging Bug fixes</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mikl-shortcuts/Pollinations-PR-Reviewer">https://github.com/mikl-shortcuts/Pollinations-PR-Reviewer</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pollinations-pr-reviewer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="small-update">Small Update:</h3>
<ul>
<li>Integrate minimatch</li>
<li>Improve comment parsing</li>
<li>Add PR descriptions passing</li>
<li>Add reasoning-effort and timeout parameters</li>
<li>Improve logging</li>
<li>Bug fixes</li>
</ul>
]]></content:encoded></item><item><title>Synaptic PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/synaptic-pr-review/</link><pubDate>Thu, 02 Jul 2026 14:55:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/synaptic-pr-review/</guid><description>Version updated for https://github.com/minhphu102003/ai-pr-review-action to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed ✨ New Features Repository Memory Rules — teach the bot your team’s coding conventions Comment @synaptic-ai remember: &amp;lt;rule&amp;gt; on any PR to add a rule Rules stored in .synaptic/rules.json and enforced during every review Collaborator verification before adding rules Dedicated extraction prompt for faster processing 🐛 Bug Fixes Fix pr_number used before defined in main_remember() Fix direct engine not outputting REMEMBER_RULE_JSON Move collaborator check before LLM extraction to avoid wasted API calls Add collaborator check to process_remember_from_comment() Filter find_latest_comment_with_remember() by bot author + review signature 📝 Documentation Add preview screenshots (PR Overview, Issue Summary, Inline Comments) to README Full Changelog: https://github.com/minhphu102003/ai-pr-review-action/compare/v0.1.3...v0.2.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/minhphu102003/ai-pr-review-action">https://github.com/minhphu102003/ai-pr-review-action</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/synaptic-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="-new-features">✨ New Features</h2>
<ul>
<li><strong>Repository Memory Rules</strong> — teach the bot your team&rsquo;s coding conventions
<ul>
<li>Comment <code>@synaptic-ai remember: &lt;rule&gt;</code> on any PR to add a rule</li>
<li>Rules stored in <code>.synaptic/rules.json</code> and enforced during every review</li>
<li>Collaborator verification before adding rules</li>
<li>Dedicated extraction prompt for faster processing</li>
</ul>
</li>
</ul>
<h2 id="-bug-fixes">🐛 Bug Fixes</h2>
<ul>
<li>Fix <code>pr_number</code> used before defined in <code>main_remember()</code></li>
<li>Fix direct engine not outputting <code>REMEMBER_RULE_JSON</code></li>
<li>Move collaborator check before LLM extraction to avoid wasted API calls</li>
<li>Add collaborator check to <code>process_remember_from_comment()</code></li>
<li>Filter <code>find_latest_comment_with_remember()</code> by bot author + review signature</li>
</ul>
<h2 id="-documentation">📝 Documentation</h2>
<ul>
<li>Add preview screenshots (PR Overview, Issue Summary, Inline Comments) to README</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/minhphu102003/ai-pr-review-action/compare/v0.1.3...v0.2.0">https://github.com/minhphu102003/ai-pr-review-action/compare/v0.1.3...v0.2.0</a></p>
]]></content:encoded></item><item><title>moult-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/moult-action/</link><pubDate>Thu, 02 Jul 2026 14:55:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/moult-action/</guid><description>Version updated for https://github.com/moult-rb/moult-rb to version v0.2.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Update README.md by @GoodPie in https://github.com/moult-rb/moult-rb/pull/2 Add GitHub Actions workflow for Moult integration by @GoodPie in https://github.com/moult-rb/moult-rb/pull/3 Support baseline scan uploads in the composite action by @GoodPie in https://github.com/moult-rb/moult-rb/pull/4 New Contributors @GoodPie made their first contribution in https://github.com/moult-rb/moult-rb/pull/2 Full Changelog: https://github.com/moult-rb/moult-rb/compare/v0.1.0...v0.2.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/moult-rb/moult-rb">https://github.com/moult-rb/moult-rb</a></strong> to version <strong>v0.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/moult-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Update README.md by @GoodPie in <a href="https://github.com/moult-rb/moult-rb/pull/2">https://github.com/moult-rb/moult-rb/pull/2</a></li>
<li>Add GitHub Actions workflow for Moult integration by @GoodPie in <a href="https://github.com/moult-rb/moult-rb/pull/3">https://github.com/moult-rb/moult-rb/pull/3</a></li>
<li>Support baseline scan uploads in the composite action by @GoodPie in <a href="https://github.com/moult-rb/moult-rb/pull/4">https://github.com/moult-rb/moult-rb/pull/4</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@GoodPie made their first contribution in <a href="https://github.com/moult-rb/moult-rb/pull/2">https://github.com/moult-rb/moult-rb/pull/2</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/moult-rb/moult-rb/compare/v0.1.0...v0.2.0">https://github.com/moult-rb/moult-rb/compare/v0.1.0...v0.2.0</a></p>
]]></content:encoded></item><item><title>Go Proxy Cache Updater</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/go-proxy-cache-updater/</link><pubDate>Thu, 02 Jul 2026 14:54:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/go-proxy-cache-updater/</guid><description>Version updated for https://github.com/nicholas-fedor/go-proxy-pull-action to version v1.1.11.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.1.11 (2026-07-02)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/nicholas-fedor/go-proxy-pull-action">https://github.com/nicholas-fedor/go-proxy-pull-action</a></strong> to version <strong>v1.1.11</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/go-proxy-cache-updater">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1111-2026-07-02"><a href="https://github.com/nicholas-fedor/go-proxy-pull-action/compare/v1.1.10...v1.1.11">1.1.11</a> (2026-07-02)</h2>
]]></content:encoded></item><item><title>Open Delivery Spec</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/open-delivery-spec/</link><pubDate>Thu, 02 Jul 2026 14:54:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/open-delivery-spec/</guid><description>Version updated for https://github.com/open-delivery-spec/validate-action to version v0.2.1.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed 👻 Maintenance ci: add scheduled workflow to bump the pinned CLI version by @shenxianpeng in #45 chore: pin default cli-ref to a stable release for reproducibility by @shenxianpeng in #43 Full Changelog: https://github.com/open-delivery-spec/validate-action/compare/v0.2.0...v0.2.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/open-delivery-spec/validate-action">https://github.com/open-delivery-spec/validate-action</a></strong> to version <strong>v0.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/open-delivery-spec">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h2 id="-maintenance">👻 Maintenance</h2>
<ul>
<li>ci: add scheduled workflow to bump the pinned CLI version by @shenxianpeng in #45</li>
<li>chore: pin default cli-ref to a stable release for reproducibility by @shenxianpeng in #43</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/open-delivery-spec/validate-action/compare/v0.2.0...v0.2.1">https://github.com/open-delivery-spec/validate-action/compare/v0.2.0...v0.2.1</a></p>
]]></content:encoded></item><item><title>Polygraph MCP gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/polygraph-mcp-gate/</link><pubDate>Thu, 02 Jul 2026 14:53:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/polygraph-mcp-gate/</guid><description>Version updated for https://github.com/polygraphso/litmus to version litmus-v0.22.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Patch release shipping the security and correctness fixes from the 2026-07-02 engineering review.
False-pass paths (grading correctness):
A1 — iptables add-op is now atomic (set -e): a partial rule insertion exits non-zero so the caller falls back to --internal instead of running with broken NAT and silently missing IP-literal/DoH egress A2 — readOnlyHint:true can no longer bypass the exercise skip gate: unsafeToExerciseToolNames now checks the broad STATE_CHANGING_VERBS set regardless of the annotation, so a lying swap_*/buy_*/approve_*/mint_* tool is never actively bait-called A3 — content in a JSON-RPC error response is now scanned: callToolArgs carries errorText; probes 1.2, 1.3 run scanInjection on it, probe 3.1 runs internalsLeak A5 — MCP progress forwarding: void sendNotification(…) → .catch(() =&amp;gt; {}) so a client disconnect during a run can’t kill the server process Sandbox observability:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/polygraphso/litmus">https://github.com/polygraphso/litmus</a></strong> to version <strong>litmus-v0.22.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/polygraph-mcp-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Patch release shipping the security and correctness fixes from the 2026-07-02 engineering review.</p>
<p><strong>False-pass paths (grading correctness):</strong></p>
<ul>
<li>A1 — iptables add-op is now atomic (<code>set -e</code>): a partial rule insertion exits non-zero so the caller falls back to <code>--internal</code> instead of running with broken NAT and silently missing IP-literal/DoH egress</li>
<li>A2 — <code>readOnlyHint:true</code> can no longer bypass the exercise skip gate: <code>unsafeToExerciseToolNames</code> now checks the broad <code>STATE_CHANGING_VERBS</code> set regardless of the annotation, so a lying <code>swap_*</code>/<code>buy_*</code>/<code>approve_*</code>/<code>mint_*</code> tool is never actively bait-called</li>
<li>A3 — content in a JSON-RPC error response is now scanned: <code>callToolArgs</code> carries <code>errorText</code>; probes 1.2, 1.3 run <code>scanInjection</code> on it, probe 3.1 runs <code>internalsLeak</code></li>
<li>A5 — MCP progress forwarding: <code>void sendNotification(…)</code> → <code>.catch(() =&gt; {})</code> so a client disconnect during a run can&rsquo;t kill the server process</li>
</ul>
<p><strong>Sandbox observability:</strong></p>
<ul>
<li>A4 — <code>selectedNetwork()</code> defaults to <code>base</code> (mainnet); <code>server.json</code> and the plugin <code>.mcp.json</code> now ship <code>NEXT_PUBLIC_POLYGRAPH_NETWORK=base</code></li>
<li>A6 — <code>removeHostDnat</code> emits a stderr warning on failure so dangling host iptables rules are visible in operator logs</li>
</ul>
<p><strong>Verify tools:</strong></p>
<ul>
<li>B6 — <code>verify_attestation</code> / <code>verify_skill_attestation</code>: found-but-null now surfaces as <code>lookup_failed</code> rather than <code>not_available</code> (a trusted index disagreeing with the chain is not unevaluated)</li>
<li>B7 — revoked attestations show <code>status:&quot;revoked&quot;</code>, expired ones <code>status:&quot;expired&quot;</code>; <code>expirationTime</code> included in the payload</li>
</ul>
<p><strong>Housekeeping:</strong></p>
<ul>
<li>B11 — dead <code>MINTER_PRIVATE_KEY</code> removed from <code>.env.example</code></li>
<li>B12 — <code>action.yml</code> default version pin updated; CONTRIBUTING release flow now documents all six steps including the <code>v1</code> retag</li>
</ul>
]]></content:encoded></item><item><title>Postman Onboarding Workspace Bootstrap</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/postman-onboarding-workspace-bootstrap/</link><pubDate>Thu, 02 Jul 2026 14:52:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/postman-onboarding-workspace-bootstrap/</guid><description>Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.6.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.6.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-bootstrap-action">https://github.com/postman-cs/postman-bootstrap-action</a></strong> to version <strong>v2.6.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-workspace-bootstrap">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.6.0">https://github.com/postman-cs/postman-bootstrap-action/compare/v2...v2.6.0</a></p>
]]></content:encoded></item><item><title>Notify QA Wolf on Deploy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/notify-qa-wolf-on-deploy/</link><pubDate>Thu, 02 Jul 2026 14:52:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/notify-qa-wolf-on-deploy/</guid><description>Version updated for https://github.com/qawolf/notify-qawolf-on-deploy-action to version v2.0.1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.0.1 Fix the ephemeral-environment input being ignored. Ephemeral deployments are now notified as ephemeral instead of as a regular GitHub deployment, and deployment-url is required when ephemeral-environment is true. v2.0.0 The action now runs on Node 24. v1.2.1 Allow ephemeral-environment as a valid input param v1.2.0 Don’t guess a recent PR number based on SHA for non-PR events v1.1.5 Allow pull-request-number as a valid input param v1.1.4 Fix a problem where the sha passed in via merge_group events was wrong, causing commit checks to never complete v1.1.3 Update README.md to include deployment_type examples v1.1.2 Correct code sample in README where GITHUB_TOKEN is being passed as a secrets instead of an env v1.1.1 Improve logging to facilitate debugging v1.1.0 Expose an eventId on errors Output the environmentId on attemptNotifyDeploy v1.0.4 Extract information from Github Event and send it to attemptNotifyDeploy v1.0.3 Add qawolf-base-url optional input v1.0.2 Fix action name on documentation v1.0.1 Fix build problem and add branding v1.0.0 Initial version</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/qawolf/notify-qawolf-on-deploy-action">https://github.com/qawolf/notify-qawolf-on-deploy-action</a></strong> to version <strong>v2.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/notify-qa-wolf-on-deploy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v201">v2.0.1</h2>
<ul>
<li>Fix the <code>ephemeral-environment</code> input being ignored. Ephemeral deployments are now notified as ephemeral instead of as a regular GitHub deployment, and <code>deployment-url</code> is required when <code>ephemeral-environment</code> is <code>true</code>.</li>
</ul>
<h2 id="v200">v2.0.0</h2>
<ul>
<li>The action now runs on Node 24.</li>
</ul>
<h2 id="v121">v1.2.1</h2>
<ul>
<li>Allow <code>ephemeral-environment</code> as a valid input param</li>
</ul>
<h2 id="v120">v1.2.0</h2>
<ul>
<li>Don&rsquo;t guess a recent PR number based on SHA for non-PR events</li>
</ul>
<h2 id="v115">v1.1.5</h2>
<ul>
<li>Allow <code>pull-request-number</code> as a valid input param</li>
</ul>
<h2 id="v114">v1.1.4</h2>
<ul>
<li>Fix a problem where the <code>sha</code> passed in via <code>merge_group</code> events was wrong, causing commit checks to never complete</li>
</ul>
<h2 id="v113">v1.1.3</h2>
<ul>
<li>Update README.md to include <code>deployment_type</code> examples</li>
</ul>
<h2 id="v112">v1.1.2</h2>
<ul>
<li>Correct code sample in README where <code>GITHUB_TOKEN</code> is being passed as a <code>secrets</code> instead of an <code>env</code></li>
</ul>
<h2 id="v111">v1.1.1</h2>
<ul>
<li>Improve logging to facilitate debugging</li>
</ul>
<h2 id="v110">v1.1.0</h2>
<ul>
<li>Expose an <code>eventId</code> on errors</li>
<li>Output the <code>environmentId</code> on <code>attemptNotifyDeploy</code></li>
</ul>
<h2 id="v104">v1.0.4</h2>
<ul>
<li>Extract information from Github Event and send it to <code>attemptNotifyDeploy</code></li>
</ul>
<h2 id="v103">v1.0.3</h2>
<ul>
<li>Add <code>qawolf-base-url</code> optional input</li>
</ul>
<h2 id="v102">v1.0.2</h2>
<ul>
<li>Fix action name on documentation</li>
</ul>
<h2 id="v101">v1.0.1</h2>
<ul>
<li>Fix build problem and add branding</li>
</ul>
<h2 id="v100">v1.0.0</h2>
<ul>
<li>Initial version</li>
</ul>
]]></content:encoded></item><item><title>Build &amp; Push to Registry</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/build-push-to-registry/</link><pubDate>Thu, 02 Jul 2026 14:51:49 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/build-push-to-registry/</guid><description>Version updated for https://github.com/relybytes/actions-docker-build-push to version v1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Build &amp;amp; Push to Registry v1.0.0 First stable release of actions-docker-build-push, a GitHub Action for building Docker images and pushing them to container registries with a predictable naming convention.
Main features Build Docker images using Docker Buildx Push images to GitHub Container Registry by default Support any container registry, including Docker Hub, Harbor, OVHcloud Managed Private Registry, and custom registries Default authentication with GitHub actor and GITHUB_TOKEN Automatic image naming based on branch, tag, or pull request Environment suffixes such as prod, dev, staging, rc, hotfix, feat, and pr-{number} Auto-generated version tags using YYYY-MM-DD.shortsha Optional :latest tag on main/master builds Support for additional tags Support for multi-platform builds Support for build arguments Support for multi-stage Dockerfile targets Automatic OCI labels Optional local build validation with push: &amp;#34;false&amp;#34; Output image reference, repository, version, suffix, tags, digest, and build timestamp Default behavior With no registry credentials passed, the action defaults to GitHub Container Registry:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/relybytes/actions-docker-build-push">https://github.com/relybytes/actions-docker-build-push</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/build-push-to-registry">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="build--push-to-registry-v100">Build &amp; Push to Registry v1.0.0</h2>
<p>First stable release of <code>actions-docker-build-push</code>, a GitHub Action for building Docker images and pushing them to container registries with a predictable naming convention.</p>
<h3 id="main-features">Main features</h3>
<ul>
<li>Build Docker images using Docker Buildx</li>
<li>Push images to GitHub Container Registry by default</li>
<li>Support any container registry, including Docker Hub, Harbor, OVHcloud Managed Private Registry, and custom registries</li>
<li>Default authentication with GitHub actor and <code>GITHUB_TOKEN</code></li>
<li>Automatic image naming based on branch, tag, or pull request</li>
<li>Environment suffixes such as <code>prod</code>, <code>dev</code>, <code>staging</code>, <code>rc</code>, <code>hotfix</code>, <code>feat</code>, and <code>pr-{number}</code></li>
<li>Auto-generated version tags using <code>YYYY-MM-DD.shortsha</code></li>
<li>Optional <code>:latest</code> tag on main/master builds</li>
<li>Support for additional tags</li>
<li>Support for multi-platform builds</li>
<li>Support for build arguments</li>
<li>Support for multi-stage Dockerfile targets</li>
<li>Automatic OCI labels</li>
<li>Optional local build validation with <code>push: &quot;false&quot;</code></li>
<li>Output image reference, repository, version, suffix, tags, digest, and build timestamp</li>
</ul>
<h3 id="default-behavior">Default behavior</h3>
<p>With no registry credentials passed, the action defaults to GitHub Container Registry:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-text" data-lang="text"><span style="display:flex;"><span>ghcr.io/{owner}/{repo}-{suffix}:YYYY-MM-DD.shortsha
</span></span></code></pre></div>]]></content:encoded></item><item><title>Remyx Outrider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/remyx-outrider/</link><pubDate>Thu, 02 Jul 2026 14:51:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/remyx-outrider/</guid><description>Version updated for https://github.com/remyxai/outrider to version v1.7.6.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed The v1.7.5 cocoindex install step ran ccc --version as a sanity check, but the typer app doesn’t expose a –version flag so it raised a red “No such option ‘–version’” error box in the Actions UI. The || true suppression meant the step still succeeded, but the visible error box was misleading.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remyxai/outrider">https://github.com/remyxai/outrider</a></strong> to version <strong>v1.7.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/remyx-outrider">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The v1.7.5 cocoindex install step ran <code>ccc --version</code> as a sanity check, but the typer app doesn&rsquo;t expose a &ndash;version flag so it raised a red &ldquo;No such option &lsquo;&ndash;version&rsquo;&rdquo; error box in the Actions UI. The <code>|| true</code> suppression meant the step still succeeded, but the visible error box was misleading.</p>
<p>Replaces with a quiet <code>command -v ccc</code> PATH check. No functional change.</p>
]]></content:encoded></item><item><title>Gated automerge</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/gated-automerge/</link><pubDate>Thu, 02 Jul 2026 14:50:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/gated-automerge/</guid><description>Version updated for https://github.com/run-action/automerge to version v1.2.3.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed docs: simplify description (#4) (46cd9d2) docs: rename action to gated automerge (d80ec1c) docs: add required checks read permissions (240cb58) feat: add option to disable require-checks (2362745) deps: bump nixpkgs in the dependencies group across 1 directory (#2) (77ebbe4) feat: add support for skip-labels (7cd48f4) Auto update internal actions (bb2e6d1) Add release workflow (6fc2ea8) Add linting and dependabot (499faef) Add action.yaml with examples (0f0d6da)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/run-action/automerge">https://github.com/run-action/automerge</a></strong> to version <strong>v1.2.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gated-automerge">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>docs: simplify description (#4) (46cd9d2)</li>
<li>docs: rename action to gated automerge (d80ec1c)</li>
<li>docs: add required checks read permissions (240cb58)</li>
<li>feat: add option to disable require-checks (2362745)</li>
<li>deps: bump nixpkgs in the dependencies group across 1 directory (#2) (77ebbe4)</li>
<li>feat: add support for skip-labels (7cd48f4)</li>
<li>Auto update internal actions (bb2e6d1)</li>
<li>Add release workflow (6fc2ea8)</li>
<li>Add linting and dependabot (499faef)</li>
<li>Add action.yaml with examples (0f0d6da)</li>
</ul>
]]></content:encoded></item><item><title>runs-on/action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/runs-on/action/</link><pubDate>Thu, 02 Jul 2026 14:50:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/runs-on/action/</guid><description>Version updated for https://github.com/runs-on/action to version v2.2.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/runs-on/action/compare/v2.1.2...v2.2.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/runs-on/action">https://github.com/runs-on/action</a></strong> to version <strong>v2.2.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/runs-on-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/runs-on/action/compare/v2.1.2...v2.2.0">https://github.com/runs-on/action/compare/v2.1.2...v2.2.0</a></p>
]]></content:encoded></item><item><title>Bernstein — Multi-Agent Orchestration</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/bernstein-multi-agent-orchestration/</link><pubDate>Thu, 02 Jul 2026 14:49:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/bernstein-multi-agent-orchestration/</guid><description>Version updated for https://github.com/sipyourdrink-ltd/bernstein to version v2.11.0.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v2.11.0 Released 2026-07-02.
Features The openai_agents runner accepts optional sampling and endpoint parameters: temperature, top_p, top_k, base_url, and api_key_env on the runner manifest, flowing into the SDK client and model settings. Absent fields keep the previous behavior byte-identical. When base_url is set the runner switches to the chat-completions API and excludes the custom client from tracing, so a third-party key is never sent to the default tracing endpoint. Every effective parameter is logged in the runner start event, so runs stay self-describing. Design validated in daily runs by @shanemmattner (#2159). (#2173) api_key_env is fail-closed: it must name a known LLM provider key from the built-in allowlist; anything else requires the operator to allow it via BERNSTEIN_ALLOWED_API_KEY_ENVS on the host, which a repository cannot set. Requesting sampling parameters on an adapter without the new SUPPORTS_SAMPLING_PARAMS capability fails loudly instead of silently dropping them. (#2173) SDK runners now write heartbeats, so they are visible to the stall watchdog between spawn and exit. (#2173) Fixes The Docker sandbox path from v2.10.0 is hardened: each spawned agent gets its own sandbox session (one exec timeout no longer tears down every agent’s container), committed work is bundled out of the container and fetched into the host repo under sandbox/&amp;lt;session_id&amp;gt; refs, sandbox lifecycle events land in the HMAC-chained audit log with emissions serialized so concurrent lifecycles cannot fork the chain, and provisioning probes task-server reachability and warns on daemons without host networking. (#2162, #2172) The bernstein worker loop can spawn agents again: it constructed the spawner with arguments that never existed and raised TypeError on the first claimed task. The server URL now also reaches spawned agents through the environment allowlist. (#2163, #2171) Dependencies Routine CI action digest updates (github/codeql-action, docker/setup-buildx-action).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/sipyourdrink-ltd/bernstein">https://github.com/sipyourdrink-ltd/bernstein</a></strong> to version <strong>v2.11.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/bernstein-multi-agent-orchestration">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v2110">v2.11.0</h1>
<p>Released 2026-07-02.</p>
<h2 id="features">Features</h2>
<ul>
<li>The openai_agents runner accepts optional sampling and endpoint parameters: <code>temperature</code>, <code>top_p</code>, <code>top_k</code>, <code>base_url</code>, and <code>api_key_env</code> on the runner manifest, flowing into the SDK client and model settings. Absent fields keep the previous behavior byte-identical. When <code>base_url</code> is set the runner switches to the chat-completions API and excludes the custom client from tracing, so a third-party key is never sent to the default tracing endpoint. Every effective parameter is logged in the runner start event, so runs stay self-describing. Design validated in daily runs by @shanemmattner (#2159). (#2173)</li>
<li><code>api_key_env</code> is fail-closed: it must name a known LLM provider key from the built-in allowlist; anything else requires the operator to allow it via <code>BERNSTEIN_ALLOWED_API_KEY_ENVS</code> on the host, which a repository cannot set. Requesting sampling parameters on an adapter without the new <code>SUPPORTS_SAMPLING_PARAMS</code> capability fails loudly instead of silently dropping them. (#2173)</li>
<li>SDK runners now write heartbeats, so they are visible to the stall watchdog between spawn and exit. (#2173)</li>
</ul>
<h2 id="fixes">Fixes</h2>
<ul>
<li>The Docker sandbox path from v2.10.0 is hardened: each spawned agent gets its own sandbox session (one exec timeout no longer tears down every agent&rsquo;s container), committed work is bundled out of the container and fetched into the host repo under <code>sandbox/&lt;session_id&gt;</code> refs, sandbox lifecycle events land in the HMAC-chained audit log with emissions serialized so concurrent lifecycles cannot fork the chain, and provisioning probes task-server reachability and warns on daemons without host networking. (#2162, #2172)</li>
<li>The <code>bernstein worker</code> loop can spawn agents again: it constructed the spawner with arguments that never existed and raised <code>TypeError</code> on the first claimed task. The server URL now also reaches spawned agents through the environment allowlist. (#2163, #2171)</li>
</ul>
<h2 id="dependencies">Dependencies</h2>
<ul>
<li>Routine CI action digest updates (github/codeql-action, docker/setup-buildx-action).</li>
</ul>
]]></content:encoded></item><item><title>Skyhook Docker Multi-Registry Build Push</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/skyhook-docker-multi-registry-build-push/</link><pubDate>Thu, 02 Jul 2026 14:49:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/skyhook-docker-multi-registry-build-push/</guid><description>Version updated for https://github.com/skyhook-io/docker-build-push-action to version v1.5.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.5.3 (2026-07-02) Bug Fixes run bundled Docker actions on the Node 24 runtime (#8) (526d49e)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/skyhook-io/docker-build-push-action">https://github.com/skyhook-io/docker-build-push-action</a></strong> to version <strong>v1.5.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skyhook-docker-multi-registry-build-push">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="153-2026-07-02"><a href="https://github.com/skyhook-io/docker-build-push-action/compare/v1.5.2...v1.5.3">1.5.3</a> (2026-07-02)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>run bundled Docker actions on the Node 24 runtime (<a href="https://github.com/skyhook-io/docker-build-push-action/issues/8">#8</a>) (<a href="https://github.com/skyhook-io/docker-build-push-action/commit/526d49ec0ce798ebca2a01131f1686b202134316">526d49e</a>)</li>
</ul>
]]></content:encoded></item><item><title>Pipr Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/pipr-review/</link><pubDate>Thu, 02 Jul 2026 14:48:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/pipr-review/</guid><description>Version updated for https://github.com/somus/pipr to version v0.1.3.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.1.3 (2026-07-02) Bug Fixes gate releases on main ci (#7) (eb479e0)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/somus/pipr">https://github.com/somus/pipr</a></strong> to version <strong>v0.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pipr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="013-2026-07-02"><a href="https://github.com/somus/pipr/compare/v0.1.2...v0.1.3">0.1.3</a> (2026-07-02)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>gate releases on main ci (<a href="https://github.com/somus/pipr/issues/7">#7</a>) (<a href="https://github.com/somus/pipr/commit/eb479e003990acbad3a30ca4f7c28f171f120a97">eb479e0</a>)</li>
</ul>
]]></content:encoded></item><item><title>DProvenanceKit regression gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/dprovenancekit-regression-gate/</link><pubDate>Thu, 02 Jul 2026 14:47:55 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/dprovenancekit-regression-gate/</guid><description>Version updated for https://github.com/Therealdk8890/dprovenancekit-action to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Patch over v1.1.0: the golden-context / candidate-context inputs now resolve through the runs subcommand (available in every 0.3.x SDK) instead of requiring gate CLI flags newer than the PyPI release. Caught by this repo’s smoke test before any user hit it. The v1 tag points here.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Therealdk8890/dprovenancekit-action">https://github.com/Therealdk8890/dprovenancekit-action</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/dprovenancekit-regression-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Patch over v1.1.0: the golden-context / candidate-context inputs now resolve through the runs subcommand (available in every 0.3.x SDK) instead of requiring gate CLI flags newer than the PyPI release. Caught by this repo&rsquo;s smoke test before any user hit it. The v1 tag points here.</p>
]]></content:encoded></item><item><title>Agents Shipgate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/agents-shipgate/</link><pubDate>Thu, 02 Jul 2026 14:47:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/agents-shipgate/</guid><description>Version updated for https://github.com/ThreeMoonsLab/agents-shipgate to version v0.14.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Agents Shipgate v0.14.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/ThreeMoonsLab/agents-shipgate">https://github.com/ThreeMoonsLab/agents-shipgate</a></strong> to version <strong>v0.14.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agents-shipgate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Agents Shipgate v0.14.0</p>
]]></content:encoded></item><item><title>Podcast Creator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/podcast-creator/</link><pubDate>Thu, 02 Jul 2026 14:46:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/podcast-creator/</guid><description>Version updated for https://github.com/xDevMe/podcast-generator to version v1.0.
This action is used across all versions by ? repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/xDevMe/podcast-generator/commits/v1.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/xDevMe/podcast-generator">https://github.com/xDevMe/podcast-generator</a></strong> to version <strong>v1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/podcast-creator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/xDevMe/podcast-generator/commits/v1.0">https://github.com/xDevMe/podcast-generator/commits/v1.0</a></p>
]]></content:encoded></item><item><title>AI-Driven ADR Enforcer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/ai-driven-adr-enforcer/</link><pubDate>Thu, 02 Jul 2026 14:46:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/ai-driven-adr-enforcer/</guid><description>Version updated for https://github.com/y-matsuo081991/ai-adr-enforcer to version v1.1.5.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/y-matsuo081991/ai-adr-enforcer/compare/v1.1.3...v1.1.5</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/y-matsuo081991/ai-adr-enforcer">https://github.com/y-matsuo081991/ai-adr-enforcer</a></strong> to version <strong>v1.1.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-driven-adr-enforcer">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/y-matsuo081991/ai-adr-enforcer/compare/v1.1.3...v1.1.5">https://github.com/y-matsuo081991/ai-adr-enforcer/compare/v1.1.3...v1.1.5</a></p>
]]></content:encoded></item><item><title>Setup Prolog</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/setup-prolog/</link><pubDate>Thu, 02 Jul 2026 06:52:01 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/setup-prolog/</guid><description>Version updated for https://github.com/fabasoad/setup-prolog-action to version v1.1.2.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(ci): bump actions/checkout from v6 to v7 by @fabasoad in https://github.com/fabasoad/setup-prolog-action/pull/9 Full Changelog: https://github.com/fabasoad/setup-prolog-action/compare/v1.1.1...v1.1.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/fabasoad/setup-prolog-action">https://github.com/fabasoad/setup-prolog-action</a></strong> to version <strong>v1.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-prolog">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(ci): bump actions/checkout from v6 to v7 by @fabasoad in <a href="https://github.com/fabasoad/setup-prolog-action/pull/9">https://github.com/fabasoad/setup-prolog-action/pull/9</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/fabasoad/setup-prolog-action/compare/v1.1.1...v1.1.2">https://github.com/fabasoad/setup-prolog-action/compare/v1.1.1...v1.1.2</a></p>
]]></content:encoded></item><item><title>Setup Uiua</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/setup-uiua/</link><pubDate>Thu, 02 Jul 2026 06:51:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/setup-uiua/</guid><description>Version updated for https://github.com/fabasoad/setup-uiua-action to version v0.1.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(ci): bump actions/checkout from v6 to v7 by @fabasoad in https://github.com/fabasoad/setup-uiua-action/pull/7 Full Changelog: https://github.com/fabasoad/setup-uiua-action/compare/v0.1.2...v0.1.3</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/fabasoad/setup-uiua-action">https://github.com/fabasoad/setup-uiua-action</a></strong> to version <strong>v0.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-uiua">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(ci): bump actions/checkout from v6 to v7 by @fabasoad in <a href="https://github.com/fabasoad/setup-uiua-action/pull/7">https://github.com/fabasoad/setup-uiua-action/pull/7</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/fabasoad/setup-uiua-action/compare/v0.1.2...v0.1.3">https://github.com/fabasoad/setup-uiua-action/compare/v0.1.2...v0.1.3</a></p>
]]></content:encoded></item><item><title>Fallow - Codebase Intelligence</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/fallow-codebase-intelligence/</link><pubDate>Thu, 02 Jul 2026 06:50:54 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/fallow-codebase-intelligence/</guid><description>Version updated for https://github.com/fallow-rs/fallow to version v2.104.0.
This action is used across all versions by 235 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Highlights This release is heavy on CSS intelligence. fallow health --css now understands CSS-in-JS (styled-components, emotion, linaria, vanilla-extract, StyleX, Panda) as first-class, ships a second styling-health quality axis, and adds a design-token blast-radius index. Plus a staged human review walkthrough, an opt-in unused-prop exemption, and a batch of framework false-positive fixes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/fallow-rs/fallow">https://github.com/fallow-rs/fallow</a></strong> to version <strong>v2.104.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>235</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/fallow-codebase-intelligence">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="highlights">Highlights</h2>
<p>This release is heavy on CSS intelligence. <code>fallow health --css</code> now understands CSS-in-JS (styled-components, emotion, linaria, vanilla-extract, StyleX, Panda) as first-class, ships a second styling-health quality axis, and adds a design-token blast-radius index. Plus a staged human review walkthrough, an opt-in unused-prop exemption, and a batch of framework false-positive fixes.</p>
<h2 id="css-intelligence-css-program-phases-3-4">CSS intelligence (CSS program, Phases 3-4)</h2>
<ul>
<li><strong>CSS-in-JS is first-class in <code>fallow health --css</code>.</strong> styled-components / emotion / linaria (tagged templates) and vanilla-extract / StyleX / Panda / emotion-object (object notation) previously produced <code>null</code> <code>css_analytics</code>. A lexical lifter now extracts the CSS body from both forms and feeds it through the same structural analytics and styling-health pipeline, so a CSS-in-JS app gets real duplicate-block, structural, and token-sprawl signals. Dep-gated on a declared CSS-in-JS library, so non-CSS-in-JS projects are byte-unchanged.</li>
<li><strong>Styling-health: a second CSS-quality axis, confidence-aware.</strong> <code>fallow health --css</code> reports a separate <code>styling_health</code> score (0-100) and A-F grade with a <code>Deductions:</code> breakdown across five capped penalty categories. It carries a <code>confidence</code> marker (<code>high</code> / <code>low</code>) so a thin authored-CSS surface (utility-first Tailwind app) renders dimmed with a caveat instead of an authoritative grade. Descriptive-only: no exit code, badge, or CI gating.</li>
<li><strong>Formula v3 weights value drift over exact repetition.</strong> Research is clear that exact CSS duplication is the least-harmful pattern while design-token inconsistency is the real maintenance harm, so the exact-block penalty is down-weighted to a soft hint and token-erosion gains a hardcoded-value-sprawl drift term (distinct un-tokenized <code>box-shadow</code> / <code>border-radius</code> / <code>line-height</code> values). <code>STYLING_HEALTH_FORMULA_VERSION</code> bumps to 3. If you diff <code>styling_health.score</code>/<code>grade</code> over time, re-baseline or gate on <code>formula_version</code>; the one-time step-change at this boundary is expected.</li>
<li><strong>Design-token blast-radius (<code>token_consumers</code>) for Tailwind v4 AND CSS-in-JS tokens.</strong> <code>fallow health --css --format json</code> now carries a reverse index of where each design token is consumed. Change <code>--color-brand</code> (Tailwind <code>@theme</code>) or a StyleX <code>defineVars</code> / vanilla-extract <code>createTheme</code> token and see a <code>consumer_count</code> plus located <code>consumers[]</code> before touching it. <code>consumer_count</code> is a static lower bound (descriptive context, not a deletion gate); the authoritative dead-token finding stays <code>unused_theme_tokens</code>.</li>
<li><strong>New <code>get_token_blast_radius</code> MCP tool.</strong> A focused, read-only tool that surfaces the token blast-radius directly without the agent needing to know the data hides inside <code>css_analytics</code>.</li>
<li><strong>Fuzzy CSS clones via value canonicalization.</strong> <code>fallow dupes</code> now canonicalizes CSS values on the stylesheet path (a zero-with-unit collapses to bare <code>0</code>, a hex color expands to its long lowercased form), so value-drifted clones (<code>0px</code> vs <code>0</code>, <code>#fff</code> vs <code>#ffffff</code>) hash equal and the same shadow / gradient / transition recipe re-implemented with drift finally matches. Scoped to CSS-family files and SFC/Astro <code>&lt;style&gt;</code> regions; JS/TS clone detection is unchanged.</li>
</ul>
<h2 id="review-and-configuration">Review and configuration</h2>
<ul>
<li><strong><code>fallow review --walkthrough</code>: a staged terminal tour.</strong> Renders the review walkthrough guide as an ordered, human-readable tour (Review Focus header, staged sections, per-file one-line facts and grounded badges, a collapsed &ldquo;cleared&rdquo; panel). <code>--format markdown</code> emits a paste-into-PR artifact; <code>--format json</code> is byte-identical to <code>--walkthrough-guide</code>. Per-file viewed state persists locally (<code>--mark-viewed</code>) and tolerates a moved tree. Always exits 0.</li>
<li><strong><code>unusedComponentProps.ignorePattern</code>: exempt intentionally-unused props.</strong> Set <code>&quot;unusedComponentProps&quot;: { &quot;ignorePattern&quot;: &quot;^_&quot; }</code> to exempt props whose local destructure binding matches the regex (the leading-underscore convention that TS <code>noUnusedParameters</code> and ESLint <code>varsIgnorePattern</code> honor). Applies to Vue, Svelte, Astro, and React/Preact. Opt-in; default behavior is unchanged. Thanks <a href="https://github.com/hniedner">@hniedner</a> for the request. (Closes <a href="https://github.com/fallow-rs/fallow/issues/1648">#1648</a>)</li>
</ul>
<h2 id="ci-coverage-and-architecture">CI, coverage, and architecture</h2>
<ul>
<li><strong>The GitLab CI template can reuse a pre-installed fallow binary.</strong> Set <code>FALLOW_SKIP_INSTALL: &quot;true&quot;</code> to skip <code>npm install -g fallow</code> and run a <code>fallow</code> already on <code>PATH</code> (for example a version pinned through a pnpm catalog), so CI runs the same binary as your local lint gate. The job fails fast when no <code>fallow</code> is found. Thanks <a href="https://github.com/Jerc92">@Jerc92</a> for the patch in <a href="https://github.com/fallow-rs/fallow/pull/1662">#1662</a>.</li>
<li><strong>Coverage upload enrichment.</strong> <code>fallow coverage --with-callers</code> uploads importer edges, and the inventory upload now emits per-function complexity and per-file churn.</li>
<li><strong>Typed architecture boundaries.</strong> <code>fallow-engine</code>, <code>fallow-output</code>, and <code>fallow-api</code> now own the command-neutral analysis runners, output contracts, and programmatic Rust boundary; LSP, MCP, and NAPI callers consume typed results and serialize JSON only at protocol boundaries. The old <code>fallow-programmatic-cli</code> compatibility crate has been removed.</li>
</ul>
<h2 id="bug-fixes">Bug fixes</h2>
<ul>
<li><strong>Iterating a typed class array no longer false-flags the class members as unused.</strong> A cluster of <code>unused-class-member</code> false positives where the class is only used through an iteration loop variable is now fixed across array-method callbacks (<code>.map</code> / <code>.forEach</code> / <code>.filter</code> / &hellip;), <code>for...of</code>, React/Preact JSX <code>.map</code>, Svelte <code>{#each}</code>, Vue <code>v-for</code> (including <code>props.&lt;field&gt;</code> sources), Angular <code>@for</code> / <code>*ngFor</code> inline templates, and Astro template <code>.map</code>. Over-credit only: a genuinely unused member still reports. Thanks <a href="https://github.com/Ericlm">@Ericlm</a> for the report and minimal reproduction. (Closes <a href="https://github.com/fallow-rs/fallow/issues/1707">#1707</a>, <a href="https://github.com/fallow-rs/fallow/issues/1711">#1711</a>, <a href="https://github.com/fallow-rs/fallow/issues/1712">#1712</a>, <a href="https://github.com/fallow-rs/fallow/issues/1713">#1713</a>)</li>
<li><strong><code>unused-files</code> no longer false-flags a Next.js <code>page.mdx</code> when <code>next.config</code> wraps its config object.</strong> <code>export default withMDX(nextConfig)</code> (the official <code>@next/mdx</code> idiom), <code>module.exports = createJestConfig(cfg)</code>, and nested/curried wrappers now resolve, which also fixes the same class for any wrapped Vite / Webpack / Jest config. Thanks <a href="https://github.com/AlonMiz">@AlonMiz</a> for the report. (Closes <a href="https://github.com/fallow-rs/fallow/issues/1642">#1642</a>)</li>
<li><strong><code>unused-files</code> no longer false-flags a <code>commit-and-tag-version</code> updater script.</strong> A new plugin (legacy enabler <code>standard-version</code>) credits each <code>bumpFiles[]</code> / <code>packageFiles[]</code> <code>updater</code> module and <code>filename</code> target, from both the package.json key and standalone <code>.versionrc</code> configs, gated on the file existing on disk. Thanks <a href="https://github.com/rbalet">@rbalet</a> for the report. (Closes <a href="https://github.com/fallow-rs/fallow/issues/1640">#1640</a>)</li>
<li><strong><code>unused-class-members</code> no longer false-flags framework-dispatched OpenLayers methods or a coercion-only <code>toString</code>.</strong> A <code>handleEvent</code> on an <code>ol/interaction/*</code> subclass and a <code>toString</code> used only through string coercion (template interpolation, <code>String(...)</code>, <code>+</code>) are now credited, with tight gating so genuinely-dead members still report. (Closes <a href="https://github.com/fallow-rs/fallow/issues/1638">#1638</a>)</li>
<li><strong>Telemetry <code>findings_present</code> is recorded again for <code>fallow flags</code>, <code>fallow watch</code>, and the <code>security</code> <code>survivors</code> / <code>blind-spots</code> subcommands.</strong> A debug-build invariant now fails fast if any finding-surfacing workflow records an event without noting its find-state, preventing the whole regression class. No change to the telemetry payload shape. (Closes <a href="https://github.com/fallow-rs/fallow/issues/1650">#1650</a>)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/fallow-rs/fallow/compare/v2.103.0...v2.104.0">https://github.com/fallow-rs/fallow/compare/v2.103.0...v2.104.0</a></p>
]]></content:encoded></item><item><title>accessibility-scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/accessibility-scanner/</link><pubDate>Thu, 02 Jul 2026 06:50:21 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/accessibility-scanner/</guid><description>Version updated for https://github.com/github/accessibility-scanner to version v3.3.0.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 43 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed New Features Add group_by option to the accessibility scanner by @taarikashenafi in https://github.com/github/accessibility-scanner/pull/239 Add dry_run option to the accessibility scanner by @taarikashenafi in https://github.com/github/accessibility-scanner/pull/232 Distinguish wcag vs best practice by @kzhou314 in https://github.com/github/accessibility-scanner/pull/233 Match axe findings by rule and report all failing elements by @kzhou314 in https://github.com/github/accessibility-scanner/pull/240 Disable reopen wontfix by @kzhou314 in https://github.com/github/accessibility-scanner/pull/234 Update reflow-scan text to improve clarity and reference WCAG 2.2 by @taarikashenafi in https://github.com/github/accessibility-scanner/pull/231 Dependency/documentation updates chore(deps): Bump ruby/setup-ruby from 1.307.0 to 1.308.0 in the github-actions group across 1 directory by @dependabot[bot] in https://github.com/github/accessibility-scanner/pull/218 chore(deps-dev): Bump the npm-minor-and-patch group across 5 directories with 3 updates by @dependabot[bot] in https://github.com/github/accessibility-scanner/pull/219 chore(deps): Bump ruby/setup-ruby from 1.308.0 to 1.310.0 in the github-actions group across 1 directory by @dependabot[bot] in https://github.com/github/accessibility-scanner/pull/220 chore(deps): Bump puma from 8.0.1 to 8.0.2 in /sites/site-with-errors in the bundler-minor-and-patch group by @dependabot[bot] in https://github.com/github/accessibility-scanner/pull/221 chore(deps): Bump ruby/setup-ruby from 1.310.0 to 1.311.0 in the github-actions group across 1 directory by @dependabot[bot] in https://github.com/github/accessibility-scanner/pull/225 chore(deps): Bump ruby/setup-ruby from 1.311.0 to 1.313.0 in the github-actions group across 1 directory by @dependabot[bot] in https://github.com/github/accessibility-scanner/pull/227 chore(deps-dev): Bump vite from 8.0.12 to 8.0.16 by @dependabot[bot] in https://github.com/github/accessibility-scanner/pull/228 chore(deps-dev): Bump @types/node from 25.9.0 to 26.0.0 by @dependabot[bot] in https://github.com/github/accessibility-scanner/pull/236 chore(deps-dev): Bump undici from 6.24.1 to 6.27.0 by @dependabot[bot] in https://github.com/github/accessibility-scanner/pull/237 chore(deps): Bump the github-actions group across 4 directories with 2 updates by @dependabot[bot] in https://github.com/github/accessibility-scanner/pull/235 chore(deps): Bump concurrent-ruby from 1.3.5 to 1.3.7 in /sites/site-with-errors by @dependabot[bot] in https://github.com/github/accessibility-scanner/pull/238 New Contributors @taarikashenafi made their first contribution in https://github.com/github/accessibility-scanner/pull/231 @kzhou314 made their first contribution in https://github.com/github/accessibility-scanner/pull/234 Full Changelog: https://github.com/github/accessibility-scanner/compare/v3.2.0...v3.3.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/github/accessibility-scanner">https://github.com/github/accessibility-scanner</a></strong> to version <strong>v3.3.0</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>43</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/accessibility-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="new-features">New Features</h3>
<ul>
<li>Add <code>group_by</code> option to the accessibility scanner by @taarikashenafi in <a href="https://github.com/github/accessibility-scanner/pull/239">https://github.com/github/accessibility-scanner/pull/239</a></li>
<li>Add <code>dry_run</code> option to the accessibility scanner by @taarikashenafi in <a href="https://github.com/github/accessibility-scanner/pull/232">https://github.com/github/accessibility-scanner/pull/232</a></li>
<li>Distinguish wcag vs best practice by @kzhou314 in <a href="https://github.com/github/accessibility-scanner/pull/233">https://github.com/github/accessibility-scanner/pull/233</a></li>
<li>Match axe findings by rule and report all failing elements by @kzhou314 in <a href="https://github.com/github/accessibility-scanner/pull/240">https://github.com/github/accessibility-scanner/pull/240</a></li>
<li>Disable reopen wontfix by @kzhou314 in <a href="https://github.com/github/accessibility-scanner/pull/234">https://github.com/github/accessibility-scanner/pull/234</a></li>
<li>Update reflow-scan text to improve clarity and reference WCAG 2.2 by @taarikashenafi in <a href="https://github.com/github/accessibility-scanner/pull/231">https://github.com/github/accessibility-scanner/pull/231</a></li>
</ul>
<h3 id="dependencydocumentation-updates">Dependency/documentation updates</h3>
<ul>
<li>chore(deps): Bump ruby/setup-ruby from 1.307.0 to 1.308.0 in the github-actions group across 1 directory by @dependabot[bot] in <a href="https://github.com/github/accessibility-scanner/pull/218">https://github.com/github/accessibility-scanner/pull/218</a></li>
<li>chore(deps-dev): Bump the npm-minor-and-patch group across 5 directories with 3 updates by @dependabot[bot] in <a href="https://github.com/github/accessibility-scanner/pull/219">https://github.com/github/accessibility-scanner/pull/219</a></li>
<li>chore(deps): Bump ruby/setup-ruby from 1.308.0 to 1.310.0 in the github-actions group across 1 directory by @dependabot[bot] in <a href="https://github.com/github/accessibility-scanner/pull/220">https://github.com/github/accessibility-scanner/pull/220</a></li>
<li>chore(deps): Bump puma from 8.0.1 to 8.0.2 in /sites/site-with-errors in the bundler-minor-and-patch group by @dependabot[bot] in <a href="https://github.com/github/accessibility-scanner/pull/221">https://github.com/github/accessibility-scanner/pull/221</a></li>
<li>chore(deps): Bump ruby/setup-ruby from 1.310.0 to 1.311.0 in the github-actions group across 1 directory by @dependabot[bot] in <a href="https://github.com/github/accessibility-scanner/pull/225">https://github.com/github/accessibility-scanner/pull/225</a></li>
<li>chore(deps): Bump ruby/setup-ruby from 1.311.0 to 1.313.0 in the github-actions group across 1 directory by @dependabot[bot] in <a href="https://github.com/github/accessibility-scanner/pull/227">https://github.com/github/accessibility-scanner/pull/227</a></li>
<li>chore(deps-dev): Bump vite from 8.0.12 to 8.0.16 by @dependabot[bot] in <a href="https://github.com/github/accessibility-scanner/pull/228">https://github.com/github/accessibility-scanner/pull/228</a></li>
<li>chore(deps-dev): Bump @types/node from 25.9.0 to 26.0.0 by @dependabot[bot] in <a href="https://github.com/github/accessibility-scanner/pull/236">https://github.com/github/accessibility-scanner/pull/236</a></li>
<li>chore(deps-dev): Bump undici from 6.24.1 to 6.27.0 by @dependabot[bot] in <a href="https://github.com/github/accessibility-scanner/pull/237">https://github.com/github/accessibility-scanner/pull/237</a></li>
<li>chore(deps): Bump the github-actions group across 4 directories with 2 updates by @dependabot[bot] in <a href="https://github.com/github/accessibility-scanner/pull/235">https://github.com/github/accessibility-scanner/pull/235</a></li>
<li>chore(deps): Bump concurrent-ruby from 1.3.5 to 1.3.7 in /sites/site-with-errors by @dependabot[bot] in <a href="https://github.com/github/accessibility-scanner/pull/238">https://github.com/github/accessibility-scanner/pull/238</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@taarikashenafi made their first contribution in <a href="https://github.com/github/accessibility-scanner/pull/231">https://github.com/github/accessibility-scanner/pull/231</a></li>
<li>@kzhou314 made their first contribution in <a href="https://github.com/github/accessibility-scanner/pull/234">https://github.com/github/accessibility-scanner/pull/234</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/github/accessibility-scanner/compare/v3.2.0...v3.3.0">https://github.com/github/accessibility-scanner/compare/v3.2.0...v3.3.0</a></p>
]]></content:encoded></item><item><title>TrustCheck Package Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/trustcheck-package-scanner/</link><pubDate>Thu, 02 Jul 2026 06:49:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/trustcheck-package-scanner/</guid><description>Version updated for https://github.com/Halfblood-Prince/trustcheck to version v2.1.2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published from immutable commit e6660a53c73391a10e8e721e3a245b25e3289b4b. The release workflow publishes PyPI, GitHub Action, Snap Store, and GHCR Docker distributions after shared tag verification, QA, matrix, and coverage builds.
Release artifacts:
dist/* dist/SHA256SUMS.txt dist/*.cdx.json standalone trustcheck-*-windows-x86_64.exe with checksum unsigned trustcheck-*-store.msix for Microsoft Store submission GHCR Docker images for linux/amd64, linux/arm64, and linux/arm/v7 Verify the direct Windows executable before use:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Halfblood-Prince/trustcheck">https://github.com/Halfblood-Prince/trustcheck</a></strong> to version <strong>v2.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/trustcheck-package-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published from immutable commit <code>e6660a53c73391a10e8e721e3a245b25e3289b4b</code>.
The release workflow publishes PyPI, GitHub Action, Snap Store, and
GHCR Docker distributions after shared tag verification, QA, matrix,
and coverage builds.</p>
<p>Release artifacts:</p>
<ul>
<li><code>dist/*</code></li>
<li><code>dist/SHA256SUMS.txt</code></li>
<li><code>dist/*.cdx.json</code></li>
<li>standalone <code>trustcheck-*-windows-x86_64.exe</code> with checksum</li>
<li>unsigned <code>trustcheck-*-store.msix</code> for Microsoft Store submission</li>
<li>GHCR Docker images for <code>linux/amd64</code>, <code>linux/arm64</code>, and <code>linux/arm/v7</code></li>
</ul>
<p>Verify the direct Windows executable before use:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-powershell" data-lang="powershell"><span style="display:flex;"><span>Get-AuthenticodeSignature .\trustcheck-*-windows-x86_64.exe | Format-List
</span></span><span style="display:flex;"><span>Get-FileHash .\trustcheck-*-windows-x86_64.exe -Algorithm SHA256
</span></span></code></pre></div><p>The Authenticode status must be <code>Valid</code>, include a timestamp
certificate, and match the adjacent <code>.sha256</code> file. The Store signs
the MSIX during submission; the workflow tests its execution alias
with a disposable certificate before upload.</p>
<p>GitHub Action:</p>
<ul>
<li>Immutable: <code>uses: Halfblood-Prince/trustcheck@v2.1.2</code></li>
<li>Compatible major: <code>uses: Halfblood-Prince/trustcheck@v2</code></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/Halfblood-Prince/trustcheck/compare/v2.1.1...v2.1.2">https://github.com/Halfblood-Prince/trustcheck/compare/v2.1.1...v2.1.2</a></p>
]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/ai-plugin-scanner/</link><pubDate>Thu, 02 Jul 2026 06:49:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.366.
This action is used across all versions by 17 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/320919c7979db097e4d0485e97a0a7675bc59620 with plugin-scanner 2.0.966.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.365...v1.2.366</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.366</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>17</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/320919c7979db097e4d0485e97a0a7675bc59620">https://github.com/hashgraph-online/hol-guard/tree/320919c7979db097e4d0485e97a0a7675bc59620</a> with plugin-scanner 2.0.966.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.365...v1.2.366">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.365...v1.2.366</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/hol-codex-plugin-scanner/</link><pubDate>Thu, 02 Jul 2026 06:48:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.366.
This action is used across all versions by 11 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.366</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.366</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>11</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.366">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.366</a></p>
]]></content:encoded></item><item><title>Codex Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/codex-action/</link><pubDate>Thu, 02 Jul 2026 06:48:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/codex-action/</guid><description>Version updated for https://github.com/icoretech/codex-action to version v0.9.16.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.9.16 (2026-07-02) Bug Fixes deps: update codex-docker image to v0.142.5 (#46) (fc08eb8)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/icoretech/codex-action">https://github.com/icoretech/codex-action</a></strong> to version <strong>v0.9.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/codex-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="0916-2026-07-02"><a href="https://github.com/icoretech/codex-action/compare/v0.9.15...v0.9.16">0.9.16</a> (2026-07-02)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>deps:</strong> update codex-docker image to v0.142.5 (<a href="https://github.com/icoretech/codex-action/issues/46">#46</a>) (<a href="https://github.com/icoretech/codex-action/commit/fc08eb82683cc0e6b7aebcf8e76ff102511b6352">fc08eb8</a>)</li>
</ul>
]]></content:encoded></item><item><title>cibuild-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/cibuild-action/</link><pubDate>Thu, 02 Jul 2026 06:47:32 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/cibuild-action/</guid><description>Version updated for https://github.com/invarnhq/cibuild to version v2.2.8.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v2.2.8</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/invarnhq/cibuild">https://github.com/invarnhq/cibuild</a></strong> to version <strong>v2.2.8</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cibuild-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release v2.2.8</p>
]]></content:encoded></item><item><title>AIGate AI Git Workflow Guard CLI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/aigate-ai-git-workflow-guard-cli/</link><pubDate>Thu, 02 Jul 2026 06:46:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/aigate-ai-git-workflow-guard-cli/</guid><description>Version updated for https://github.com/LeeHueeng/aigate-ai-git-workflow-guard-cli to version v0.1.5.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Highlights Added aigate start guided setup routes for quickstart, AI setup, pre-push hooks, release readiness, and full project guard setup. Added aigate test for Git readiness plus detected project test command execution. Added aigate aitest for AI remediation prompt generation and optional Codex, Claude, Gemini, or custom agent execution with --apply. Added repository Claude Code instructions through CLAUDE.md and .aigate/integrations/claude.md. Updated multilingual README, usage, operations, roadmap, AI integration, GitHub Action, examples, and generated HTML overview docs. Extended the reusable GitHub Action to support test and safe aitest prompt generation. Validation npm run ci Release workflow dry run Tagged release workflow publish node src/cli.mjs release-check --npm --language ko Package npm: aigate-cli@0.1.5</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/LeeHueeng/aigate-ai-git-workflow-guard-cli">https://github.com/LeeHueeng/aigate-ai-git-workflow-guard-cli</a></strong> to version <strong>v0.1.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/aigate-ai-git-workflow-guard-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="highlights">Highlights</h2>
<ul>
<li>Added <code>aigate start</code> guided setup routes for quickstart, AI setup, pre-push hooks, release readiness, and full project guard setup.</li>
<li>Added <code>aigate test</code> for Git readiness plus detected project test command execution.</li>
<li>Added <code>aigate aitest</code> for AI remediation prompt generation and optional Codex, Claude, Gemini, or custom agent execution with <code>--apply</code>.</li>
<li>Added repository Claude Code instructions through <code>CLAUDE.md</code> and <code>.aigate/integrations/claude.md</code>.</li>
<li>Updated multilingual README, usage, operations, roadmap, AI integration, GitHub Action, examples, and generated HTML overview docs.</li>
<li>Extended the reusable GitHub Action to support <code>test</code> and safe <code>aitest</code> prompt generation.</li>
</ul>
<h2 id="validation">Validation</h2>
<ul>
<li><code>npm run ci</code></li>
<li>Release workflow dry run</li>
<li>Tagged release workflow publish</li>
<li><code>node src/cli.mjs release-check --npm --language ko</code></li>
</ul>
<h2 id="package">Package</h2>
<ul>
<li>npm: <code>aigate-cli@0.1.5</code></li>
</ul>
]]></content:encoded></item><item><title>OSS Security Policy as Code</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/oss-security-policy-as-code/</link><pubDate>Thu, 02 Jul 2026 06:46:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/oss-security-policy-as-code/</guid><description>Version updated for https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit to version v9.0.3.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed OSS Security Policy as Code Starter Kit v9.0.3 This release is the v9.0.3 release of the OSS Security Policy as Code Starter Kit (refine this line before publishing).
Highlights No feature-level changes in this release. Improvements retitle SAST-OSV-068 — the kit ingests OSV verdicts, it is not reachability-aware honor SOURCE_DATE_EPOCH for every outcome-affecting clock read; freeze the suite clock formalize SELF_ATTESTED in the published reports/2.0 schema (9.0.3) build Gemara state maps from pairs to clear a Snyk Code false positive Notes release 9.0.3 (#110) ADR-030 amendment re-grounding the v10.0.0 surface; flip ADR-021 to accepted suppress reviewed Snyk Code false positive via .snyk; keep the gate strict make Snyk Code + Snyk Open Source advisory (continue-on-error) License: Apache-2.0.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit">https://github.com/lucashgrifoni/OSS-Security-Policy-as-Code-Starter-Kit</a></strong> to version <strong>v9.0.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/oss-security-policy-as-code">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="oss-security-policy-as-code-starter-kit-v903">OSS Security Policy as Code Starter Kit v9.0.3</h2>
<p>This release is the v9.0.3 release of the OSS Security Policy as Code Starter Kit (refine this line before publishing).</p>
<hr>
<h2 id="highlights">Highlights</h2>
<ul>
<li><em>No feature-level changes in this release.</em></li>
</ul>
<hr>
<h2 id="improvements">Improvements</h2>
<ul>
<li>retitle SAST-OSV-068 — the kit ingests OSV verdicts, it is not reachability-aware</li>
<li>honor SOURCE_DATE_EPOCH for every outcome-affecting clock read; freeze the suite clock</li>
<li>formalize SELF_ATTESTED in the published reports/2.0 schema (9.0.3)</li>
<li>build Gemara state maps from pairs to clear a Snyk Code false positive</li>
</ul>
<hr>
<h2 id="notes">Notes</h2>
<ul>
<li>release 9.0.3 (#110)</li>
<li>ADR-030 amendment re-grounding the v10.0.0 surface; flip ADR-021 to accepted</li>
<li>suppress reviewed Snyk Code false positive via .snyk; keep the gate strict</li>
<li>make Snyk Code + Snyk Open Source advisory (continue-on-error)</li>
</ul>
<hr>
<p><strong>License:</strong> Apache-2.0.</p>
]]></content:encoded></item><item><title>SnarkGirl</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/snarkgirl/</link><pubDate>Thu, 02 Jul 2026 06:45:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/snarkgirl/</guid><description>Version updated for https://github.com/mattkelly1991/SnarkGirl to version v1.15.3.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed SnarkGirl v1.15.3 — The Wiki Ledger + a Living Pitch 📖⚽ The World Cup tournament got two big upgrades: it now lives in your repo’s Wiki, and the pitch actually plays.
The tournament moved to the repo Wiki Standings + match reports are now human-readable, browsable wiki pages organized as World Cup → Season → Match: a Home index of seasons, a Season-{slug} standings page each, and one Season-{slug}-Match-{N} report per PR. No more base64 tokens to shuttle around. Every page carries a keyed HMAC signature footer — change a win from 3 to 4 in the wiki editor and wiki.py verify flags it INVALID. Export a private SGWC_SECRET for a real barrier. Resuming a season is just “clone the wiki.” The user names the season (and its duration) at kickoff. New helper wiki.py (render/verify/verify-all/load-season). Retired the old token.py. The live pitch is alive Players roam their formation and pass the ball, holding shape at each kickoff until someone takes it. A goal is scripted end-to-end: the ball is worked to the scorer, who drives at the net and buries it. A red card sets up a penalty kick — a code red is converted, an agent red is saved by the keeper. Sent-off players walk to a bench at the edge (home top-left, away top-right). The champion &amp;amp; awards now present on the wiki season page (the live arena ends on the standings). Full changelog: https://github.com/mattkelly1991/SnarkGirl/blob/main/CHANGELOG.md</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mattkelly1991/SnarkGirl">https://github.com/mattkelly1991/SnarkGirl</a></strong> to version <strong>v1.15.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/snarkgirl">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="snarkgirl-v1153--the-wiki-ledger--a-living-pitch-">SnarkGirl v1.15.3 — The Wiki Ledger + a Living Pitch 📖⚽</h2>
<p>The World Cup tournament got two big upgrades: it now lives in your repo&rsquo;s <strong>Wiki</strong>, and the pitch <strong>actually plays</strong>.</p>
<h3 id="the-tournament-moved-to-the-repo-wiki">The tournament moved to the repo Wiki</h3>
<ul>
<li>Standings + match reports are now <strong>human-readable, browsable wiki pages</strong> organized as <strong>World Cup → Season → Match</strong>: a <code>Home</code> index of seasons, a <code>Season-{slug}</code> standings page each, and one <code>Season-{slug}-Match-{N}</code> report per PR. No more base64 tokens to shuttle around.</li>
<li>Every page carries a keyed <strong>HMAC signature footer</strong> — change a win from 3 to 4 in the wiki editor and <code>wiki.py verify</code> flags it <strong>INVALID</strong>. Export a private <code>SGWC_SECRET</code> for a real barrier.</li>
<li>Resuming a season is just &ldquo;clone the wiki.&rdquo; The user names the season (and its duration) at kickoff.</li>
<li>New helper <code>wiki.py</code> (render/verify/verify-all/load-season). Retired the old <code>token.py</code>.</li>
</ul>
<h3 id="the-live-pitch-is-alive">The live pitch is alive</h3>
<ul>
<li>Players roam their formation and pass the ball, holding shape at each kickoff until someone takes it.</li>
<li>A goal is scripted end-to-end: the ball is worked to the scorer, who drives at the net and buries it.</li>
<li>A red card sets up a <strong>penalty kick</strong> — a code red is converted, an agent red is saved by the keeper.</li>
<li>Sent-off players walk to a <strong>bench</strong> at the edge (home top-left, away top-right).</li>
<li>The champion &amp; awards now present on the <strong>wiki season page</strong> (the live arena ends on the standings).</li>
</ul>
<p><strong>Full changelog:</strong> <a href="https://github.com/mattkelly1991/SnarkGirl/blob/main/CHANGELOG.md">https://github.com/mattkelly1991/SnarkGirl/blob/main/CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>Claude Ralph Loop</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/claude-ralph-loop/</link><pubDate>Thu, 02 Jul 2026 06:45:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/claude-ralph-loop/</guid><description>Version updated for https://github.com/mdelapenya/claude-ralph-github-action to version v0.9.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changes docs: link sbx sandbox docs and document sandbox inputs @mdelapenya (#97) Contributors @mdelapenya</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mdelapenya/claude-ralph-github-action">https://github.com/mdelapenya/claude-ralph-github-action</a></strong> to version <strong>v0.9.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/claude-ralph-loop">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changes">Changes</h2>
<ul>
<li>docs: link sbx sandbox docs and document sandbox inputs @mdelapenya (#97)</li>
</ul>
<h2 id="contributors">Contributors</h2>
<p>@mdelapenya</p>
]]></content:encoded></item><item><title>Synaptic PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/synaptic-pr-review/</link><pubDate>Thu, 02 Jul 2026 06:44:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/synaptic-pr-review/</guid><description>Version updated for https://github.com/minhphu102003/ai-pr-review-action to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v0.1.1 Strip model preamble: remove leading text before ## PR Review heading in both OpenCode and direct engine paths OpenCode engine: post_inline.py now always updates summary comment when body changes (preamble or Key Issues stripped) Direct engine: sanitize_review() strips preamble before posting</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/minhphu102003/ai-pr-review-action">https://github.com/minhphu102003/ai-pr-review-action</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/synaptic-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v011">v0.1.1</h2>
<ul>
<li>Strip model preamble: remove leading text before <code>## PR Review</code> heading in both OpenCode and direct engine paths</li>
<li>OpenCode engine: <code>post_inline.py</code> now always updates summary comment when body changes (preamble or Key Issues stripped)</li>
<li>Direct engine: <code>sanitize_review()</code> strips preamble before posting</li>
</ul>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/totem-shield/</link><pubDate>Thu, 02 Jul 2026 06:44:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.88.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Cohort-link bump (no direct package changes). See .changeset/config.json for the fixed-cohort definition.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.88.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>semvertag</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/semvertag/</link><pubDate>Thu, 02 Jul 2026 06:43:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/semvertag/</guid><description>Version updated for https://github.com/modern-python/semvertag to version 0.8.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed semvertag 0.8.2 — release pipeline on PyPI Trusted Publishing No library changes. The package is identical to 0.8.1; this release exercises the new publish path end-to-end.
CI Releases now authenticate to PyPI via Trusted Publishing (OIDC) instead of a long-lived PYPI_TOKEN secret. uv publish auto-detects the GitHub Actions id-token; the release job runs under a pypi environment that scopes the trusted publisher (#46). Downstream No action required. Nothing about the installed package changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/modern-python/semvertag">https://github.com/modern-python/semvertag</a></strong> to version <strong>0.8.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/semvertag">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="semvertag-082--release-pipeline-on-pypi-trusted-publishing">semvertag 0.8.2 — release pipeline on PyPI Trusted Publishing</h1>
<p>No library changes. The package is identical to 0.8.1; this release exercises the new publish path end-to-end.</p>
<h2 id="ci">CI</h2>
<ul>
<li>Releases now authenticate to PyPI via <strong>Trusted Publishing (OIDC)</strong> instead of a long-lived <code>PYPI_TOKEN</code> secret. <code>uv publish</code> auto-detects the GitHub Actions id-token; the release job runs under a <code>pypi</code> environment that scopes the trusted publisher (#46).</li>
</ul>
<h2 id="downstream">Downstream</h2>
<p>No action required. Nothing about the installed package changes.</p>
]]></content:encoded></item><item><title>Run AER Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/run-aer-tests/</link><pubDate>Thu, 02 Jul 2026 06:43:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/run-aer-tests/</guid><description>Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.5.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Version v1.2.5
Support DataWeave reduce With A Default Accumulator</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/octoberswimmer/aer-dist">https://github.com/octoberswimmer/aer-dist</a></strong> to version <strong>v1.2.5</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-aer-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Version v1.2.5</p>
<ul>
<li>Support DataWeave reduce With A Default Accumulator</li>
</ul>
]]></content:encoded></item><item><title>PatchFlow Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/patchflow-security-scan/</link><pubDate>Thu, 02 Jul 2026 06:42:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/patchflow-security-scan/</guid><description>Version updated for https://github.com/Patchflow-security/patchflow-cli to version v0.1.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed PatchFlow CLI v0.1.2 Benchmark Results (v1.0) 18 intentionally vulnerable repos: 100% recall, 918K LOC, 19 CWE categories 5 historical CVE repos: 100% recall, 387K LOC 10 clean repos: 0.094 HC/KLOC, 720K LOC See Benchmark Report v1.0 for details.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Patchflow-security/patchflow-cli">https://github.com/Patchflow-security/patchflow-cli</a></strong> to version <strong>v0.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/patchflow-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="patchflow-cli-v012">PatchFlow CLI v0.1.2</h2>
<h3 id="benchmark-results-v10">Benchmark Results (v1.0)</h3>
<ul>
<li>18 intentionally vulnerable repos: 100% recall, 918K LOC, 19 CWE categories</li>
<li>5 historical CVE repos: 100% recall, 387K LOC</li>
<li>10 clean repos: 0.094 HC/KLOC, 720K LOC</li>
</ul>
<p>See <a href="https://github.com/Patchflow-security/patchflow-benchmarks/blob/main/reports/BENCHMARK_REPORT_v1.0.md">Benchmark Report v1.0</a> for details.</p>
<h2 id="changelog">Changelog</h2>
<h3 id="other-changes">Other Changes</h3>
<ul>
<li>a071d0ab0a8732c375c1c99e4abed4ec5a984855: PatchFlow CLI v0.1.2 — security scanner with update notification (Ghertil Abdelmalek <a href="mailto:ghertilabdelmalek@outlook.fr">ghertilabdelmalek@outlook.fr</a>)</li>
</ul>
]]></content:encoded></item><item><title>Remyx Outrider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/remyx-outrider/</link><pubDate>Thu, 02 Jul 2026 06:41:27 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/remyx-outrider/</guid><description>Version updated for https://github.com/remyxai/outrider to version v1.7.4.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed HF Hub checkpoint preflight for architecture-add Issues (REMYX-178) (8a70186) arxiv HTML retry: title-overlap threshold + project-page one-hop + README verification (c6c021f) README: add lerobot #9 (ECoT reasoning supervision) to Examples (85fa29b) Coding-agent prompt: guidance on auto-format scope (be8720d) README: drop the “Recommended” ENVIRONMENTS.md section (82b9549) Recommend ENVIRONMENTS.md + cocoindex as the default setup (9ca24e1) License detection: retry via arxiv HTML on unfavorable buckets (615af84) README: restore smellslikeml/peft #5 as the primary Outrider artifact (e8fb3a0) README: swap smellslikeml/peft #5 for the upstream draft huggingface/peft #3382 (28cfc14) README: add huggingface/peft #3382 (upstream draft) to Examples (bc70d94)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remyxai/outrider">https://github.com/remyxai/outrider</a></strong> to version <strong>v1.7.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/remyx-outrider">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>HF Hub checkpoint preflight for architecture-add Issues (REMYX-178) (8a70186)</li>
<li>arxiv HTML retry: title-overlap threshold + project-page one-hop + README verification (c6c021f)</li>
<li>README: add lerobot #9 (ECoT reasoning supervision) to Examples (85fa29b)</li>
<li>Coding-agent prompt: guidance on auto-format scope (be8720d)</li>
<li>README: drop the &ldquo;Recommended&rdquo; ENVIRONMENTS.md section (82b9549)</li>
<li>Recommend ENVIRONMENTS.md + cocoindex as the default setup (9ca24e1)</li>
<li>License detection: retry via arxiv HTML on unfavorable buckets (615af84)</li>
<li>README: restore smellslikeml/peft #5 as the primary Outrider artifact (e8fb3a0)</li>
<li>README: swap smellslikeml/peft #5 for the upstream draft huggingface/peft #3382 (28cfc14)</li>
<li>README: add huggingface/peft #3382 (upstream draft) to Examples (bc70d94)</li>
</ul>
]]></content:encoded></item><item><title>nix init</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/nix-init/</link><pubDate>Thu, 02 Jul 2026 06:40:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/nix-init/</guid><description>Version updated for https://github.com/spotdemo4/nix-init to version v1.55.0.
This action is used across all versions by 4 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed feat: Update spotdemo4/better-checkout action to v0.13.0 (#154) (3fc7f0af893590575d0d65b8a2e3fbbdff95fdec) bump: v1.54.1 -&amp;gt; v1.55.0 (d2afabdda2558d6cf558962bbc7dce09ff5e9950) chore(deps): update github actions to v1.54.1 (#153) (4e0f684fbdfd7f3a0f78fe5cfe6702ef984c3370)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spotdemo4/nix-init">https://github.com/spotdemo4/nix-init</a></strong> to version <strong>v1.55.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>4</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/nix-init">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: Update spotdemo4/better-checkout action to v0.13.0 (#154) (3fc7f0af893590575d0d65b8a2e3fbbdff95fdec)</li>
<li>bump: v1.54.1 -&gt; v1.55.0 (d2afabdda2558d6cf558962bbc7dce09ff5e9950)</li>
<li>chore(deps): update github actions to v1.54.1 (#153) (4e0f684fbdfd7f3a0f78fe5cfe6702ef984c3370)</li>
</ul>
]]></content:encoded></item><item><title>Repository Create</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/repository-create/</link><pubDate>Thu, 02 Jul 2026 06:40:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/repository-create/</guid><description>Version updated for https://github.com/stairwaytowonderland/repository-create to version v1.72.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed chore(release): 1.72.0
1.72.0 (2026-07-02) ✨ Features updates (da42214) 📚 Documentation update .github/index.md (b643fff)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/stairwaytowonderland/repository-create">https://github.com/stairwaytowonderland/repository-create</a></strong> to version <strong>v1.72.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/repository-create">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>chore(release): 1.72.0</p>
<h2 id="1720-2026-07-02"><a href="https://github.com/stairwaytowonderland/repository-create/compare/v1.71.0...v1.72.0">1.72.0</a> (2026-07-02)</h2>
<h3 id="-features">✨ Features</h3>
<ul>
<li>updates (<a href="https://github.com/stairwaytowonderland/repository-create/commit/da422148562e64d9021965f8b79e0ff95e007668">da42214</a>)</li>
</ul>
<h3 id="-documentation">📚 Documentation</h3>
<ul>
<li>update .github/index.md (<a href="https://github.com/stairwaytowonderland/repository-create/commit/b643fff8d866570e23cc6d48bc367f96dfa2a3f0">b643fff</a>)</li>
</ul>
]]></content:encoded></item><item><title>Update Uclusion</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/update-uclusion/</link><pubDate>Thu, 02 Jul 2026 06:39:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/update-uclusion/</guid><description>Version updated for https://github.com/Uclusion/update-job to version v1.1.3.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed J-all-329 Only mark job complete when it has no open tasks (bd99322) T-all-2240 Make testPush a no-op smoke test (fixed no-code message) (deabf19) T-all-2238 Reconcile job deploy state on push; configurable pending label (de092bb) fix: Only extract job ids. (340d9bb) fix: move to node 24.x (a19c034) fix: move to node 24.x (ab6d493) fix: link doc (c83286a) fix: space in view name (ff4ac90) fix: space in view name (d0c570f) fix: urlencode (f66608d)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Uclusion/update-job">https://github.com/Uclusion/update-job</a></strong> to version <strong>v1.1.3</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-uclusion">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>J-all-329 Only mark job complete when it has no open tasks (bd99322)</li>
<li>T-all-2240 Make testPush a no-op smoke test (fixed no-code message) (deabf19)</li>
<li>T-all-2238 Reconcile job deploy state on push; configurable pending label (de092bb)</li>
<li>fix: Only extract job ids. (340d9bb)</li>
<li>fix: move to node 24.x (a19c034)</li>
<li>fix: move to node 24.x (ab6d493)</li>
<li>fix: link doc (c83286a)</li>
<li>fix: space in view name (ff4ac90)</li>
<li>fix: space in view name (d0c570f)</li>
<li>fix: urlencode (f66608d)</li>
</ul>
]]></content:encoded></item><item><title>Velda Run job</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/velda-run-job/</link><pubDate>Thu, 02 Jul 2026 06:39:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/velda-run-job/</guid><description>Version updated for https://github.com/velda-io/action to version v0.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial release</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/velda-io/action">https://github.com/velda-io/action</a></strong> to version <strong>v0.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/velda-run-job">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial release</p>
]]></content:encoded></item><item><title>install spaces</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/install-spaces/</link><pubDate>Thu, 02 Jul 2026 06:38:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/install-spaces/</guid><description>Version updated for https://github.com/work-spaces/install-spaces to version v0.17.1.
This action is used across all versions by 5 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump version to v0.17.1 by @tyler-gilbert in https://github.com/work-spaces/install-spaces/pull/32 Full Changelog: https://github.com/work-spaces/install-spaces/compare/v0.16.0...v0.17.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/work-spaces/install-spaces">https://github.com/work-spaces/install-spaces</a></strong> to version <strong>v0.17.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>5</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/install-spaces">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump version to v0.17.1 by @tyler-gilbert in <a href="https://github.com/work-spaces/install-spaces/pull/32">https://github.com/work-spaces/install-spaces/pull/32</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/work-spaces/install-spaces/compare/v0.16.0...v0.17.1">https://github.com/work-spaces/install-spaces/compare/v0.16.0...v0.17.1</a></p>
]]></content:encoded></item><item><title>Run PHP Scoper</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/run-php-scoper/</link><pubDate>Thu, 02 Jul 2026 06:38:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/02/run-php-scoper/</guid><description>Version updated for https://github.com/WPTechnix/run-php-scoper to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v1.0.0 Initial release of the PHP-Scoper Action, a composite GitHub Action for scoping PHP project dependencies using humbug/php-scoper.
What’s Included PHP version selection: Choose any PHP version using php-version (default: 8.2).
Flexible PHP-Scoper versions: Use a specific release tag, version constraint, or branch with scoper-version.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/WPTechnix/run-php-scoper">https://github.com/WPTechnix/run-php-scoper</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-php-scoper">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v100">v1.0.0</h1>
<p>Initial release of the PHP-Scoper Action, a composite GitHub Action for scoping PHP project dependencies using <code>humbug/php-scoper</code>.</p>
<h2 id="whats-included">What&rsquo;s Included</h2>
<ul>
<li>
<p><strong>PHP version selection</strong>: Choose any PHP version using <code>php-version</code> (default: <code>8.2</code>).</p>
</li>
<li>
<p><strong>Flexible PHP-Scoper versions</strong>: Use a specific release tag, version constraint, or branch with <code>scoper-version</code>.</p>
</li>
<li>
<p><strong>Custom working directory</strong>: Run the action from any subdirectory within your repository.</p>
</li>
<li>
<p><strong>Configurable PHP-Scoper configuration</strong>: Specify the path to <code>scoper.inc.php</code> using a relative or absolute path.</p>
</li>
<li>
<p><strong>Optional Composer installation</strong>: Skip <code>composer install</code> when the <code>vendor/</code> directory already exists.</p>
</li>
<li>
<p><strong>Custom Composer arguments</strong>: Pass additional Composer options through <code>composer-args</code>.</p>
</li>
<li>
<p><strong>Early validation</strong>: Validate the working directory, configuration file, and PHP version before installing dependencies.</p>
</li>
<li>
<p><strong>Action outputs</strong>:</p>
<ul>
<li><code>output-path</code>: Absolute path to the generated scoped build.</li>
<li><code>scoped-files</code>: Total number of scoped PHP files.</li>
</ul>
</li>
</ul>
]]></content:encoded></item><item><title>ansede-static</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/ansede-static/</link><pubDate>Wed, 01 Jul 2026 22:44:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/ansede-static/</guid><description>Version updated for https://github.com/mattybellx/Ansede to version v5.2.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed [5.0.0] — 2026-06-27 Added Rust Pattern Engine — Native regex matching via PyO3 (ansede_rust_core), 3.6x faster on large files with graceful Python fallback Java Tree-Sitter AST Analyzer (java_ast_analyzer.py) — Replaces regex heuristics with accurate AST parsing. 9 checkers: CWE-89, CWE-78, CWE-328, CWE-918, CWE-601, CWE-79, CWE-798, CWE-22, CWE-862 4 New Detectors: CWE-942 (CORS wildcard), CWE-94 (Jinja2 SSTI), CWE-362 (TOCTOU), CWE-862 (Spring Actuator) Precision Benchmark Harness (benchmarks/precision_benchmark.py) — Multi-language, multi-repo precision tracking with per-CWE heatmaps is_framework_internal() context filter — Suppresses findings in framework/library internals (Flask src/, Express lib/) 21-repo scale proof — Validated across 7 languages with 99%+ precision on clean code Changed — Precision (99.4% FP Reduction) Calibration: Removed bare method names (exec, query, execute, raw) from callee sets to prevent Mongoose/ORM false positives Calibration: JS-023 regex anchored with (?&amp;lt;!\.) to prevent Browserify .require() false positives Calibration: Extended ambiguous callee guard to resolve/join for path traversal Calibration: JS-018 __proto__:null now recognized as defensive pattern, not prototype pollution Calibration: Java write() XSS check requires HTTP response receiver, not JSON writer Calibration: 9 CVE benchmark severity thresholds corrected (MEDIUM→MEDIUM, not HIGH) Calibration: CWE-295, CWE-502, CWE-532 added to test-file noise filter Changed — Performance (96% Faster) AST walk cache: Pre-computed per-function node lists shared across all 49 Python rules _rule_24 fix: Module-level AST walk moved outside per-function loop (20x → 1x) Lazy symbolic guards: Skip when no findings or conditionals present Lazy datascience rules: Skip for files without DS imports Java regex→AST: Always uses tree-sitter when available, eliminating regex overhead Fixed Windows path handling: \tests\, \examples\, \docs\ backslash patterns in triage filters Empty CWE display: PY-003 assigned CWE-252, PY-044 assigned CWE-1120 Test-file CWE-98 suppression: Dynamic require in test files correctly filtered CVE Recall: 92.7%→100% (164/164 across 5 languages) What’s New Since v4.1.0 100% CVE recall (164/164) — every known vulnerability detected 99.4% FP reduction on 5 clean repos (535→3 findings) 86% FP reduction on 21 repos across 7 languages 96% faster Python scanning (2,600→5,100 LOC/s) 3.6x faster JavaScript pattern matching via Rust engine Java AST analyzer replaces regex, PetClinic: 38→0 findings</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mattybellx/Ansede">https://github.com/mattybellx/Ansede</a></strong> to version <strong>v5.2.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ansede-static">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="500--2026-06-27">[5.0.0] — 2026-06-27</h2>
<h3 id="added">Added</h3>
<ul>
<li><strong>Rust Pattern Engine</strong> — Native regex matching via PyO3 (<code>ansede_rust_core</code>), 3.6x faster on large files with graceful Python fallback</li>
<li><strong>Java Tree-Sitter AST Analyzer</strong> (<code>java_ast_analyzer.py</code>) — Replaces regex heuristics with accurate AST parsing. 9 checkers: CWE-89, CWE-78, CWE-328, CWE-918, CWE-601, CWE-79, CWE-798, CWE-22, CWE-862</li>
<li><strong>4 New Detectors</strong>: CWE-942 (CORS wildcard), CWE-94 (Jinja2 SSTI), CWE-362 (TOCTOU), CWE-862 (Spring Actuator)</li>
<li><strong>Precision Benchmark Harness</strong> (<code>benchmarks/precision_benchmark.py</code>) — Multi-language, multi-repo precision tracking with per-CWE heatmaps</li>
<li><strong><code>is_framework_internal()</code> context filter</strong> — Suppresses findings in framework/library internals (Flask src/, Express lib/)</li>
<li><strong>21-repo scale proof</strong> — Validated across 7 languages with 99%+ precision on clean code</li>
</ul>
<h3 id="changed--precision-994-fp-reduction">Changed — Precision (99.4% FP Reduction)</h3>
<ul>
<li><strong>Calibration</strong>: Removed bare method names (<code>exec</code>, <code>query</code>, <code>execute</code>, <code>raw</code>) from callee sets to prevent Mongoose/ORM false positives</li>
<li><strong>Calibration</strong>: <code>JS-023</code> regex anchored with <code>(?&lt;!\.)</code> to prevent Browserify <code>.require()</code> false positives</li>
<li><strong>Calibration</strong>: Extended ambiguous callee guard to <code>resolve</code>/<code>join</code> for path traversal</li>
<li><strong>Calibration</strong>: <code>JS-018</code> <code>__proto__:null</code> now recognized as defensive pattern, not prototype pollution</li>
<li><strong>Calibration</strong>: Java <code>write()</code> XSS check requires HTTP response receiver, not JSON writer</li>
<li><strong>Calibration</strong>: 9 CVE benchmark severity thresholds corrected (MEDIUM→MEDIUM, not HIGH)</li>
<li><strong>Calibration</strong>: <code>CWE-295</code>, <code>CWE-502</code>, <code>CWE-532</code> added to test-file noise filter</li>
</ul>
<h3 id="changed--performance-96-faster">Changed — Performance (96% Faster)</h3>
<ul>
<li><strong>AST walk cache</strong>: Pre-computed per-function node lists shared across all 49 Python rules</li>
<li><strong><code>_rule_24</code> fix</strong>: Module-level AST walk moved outside per-function loop (20x → 1x)</li>
<li><strong>Lazy symbolic guards</strong>: Skip when no findings or conditionals present</li>
<li><strong>Lazy datascience rules</strong>: Skip for files without DS imports</li>
<li><strong>Java regex→AST</strong>: Always uses tree-sitter when available, eliminating regex overhead</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>Windows path handling</strong>: <code>\tests\</code>, <code>\examples\</code>, <code>\docs\</code> backslash patterns in triage filters</li>
<li><strong>Empty CWE display</strong>: <code>PY-003</code> assigned <code>CWE-252</code>, <code>PY-044</code> assigned <code>CWE-1120</code></li>
<li><strong>Test-file CWE-98 suppression</strong>: Dynamic require in test files correctly filtered</li>
<li><strong>CVE Recall</strong>: 92.7%→100% (164/164 across 5 languages)</li>
</ul>
<h3 id="whats-new-since-v410">What&rsquo;s New Since v4.1.0</h3>
<ul>
<li><strong>100% CVE recall</strong> (164/164) — every known vulnerability detected</li>
<li><strong>99.4% FP reduction</strong> on 5 clean repos (535→3 findings)</li>
<li><strong>86% FP reduction</strong> on 21 repos across 7 languages</li>
<li><strong>96% faster</strong> Python scanning (2,600→5,100 LOC/s)</li>
<li><strong>3.6x faster</strong> JavaScript pattern matching via Rust engine</li>
<li><strong>Java AST analyzer</strong> replaces regex, PetClinic: 38→0 findings</li>
</ul>
]]></content:encoded></item><item><title>Claude Ralph Loop</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/claude-ralph-loop/</link><pubDate>Wed, 01 Jul 2026 22:43:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/claude-ralph-loop/</guid><description>Version updated for https://github.com/mdelapenya/claude-ralph-github-action to version v0.8.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changes feat: wrap claude execution in Docker sbx sandbox @mdelapenya (#95) Contributors @mdelapenya</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mdelapenya/claude-ralph-github-action">https://github.com/mdelapenya/claude-ralph-github-action</a></strong> to version <strong>v0.8.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/claude-ralph-loop">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changes">Changes</h2>
<ul>
<li>feat: wrap claude execution in Docker sbx sandbox @mdelapenya (#95)</li>
</ul>
<h2 id="contributors">Contributors</h2>
<p>@mdelapenya</p>
]]></content:encoded></item><item><title>FHIR Validator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/fhir-validator/</link><pubDate>Wed, 01 Jul 2026 22:43:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/fhir-validator/</guid><description>Version updated for https://github.com/medvertical/records-fhir-validator to version validator-v0.4.1.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed npm tarball release for @records-fhir/validator@0.4.1. Synced from medvertical/records monorepo.
Install npm install @records-fhir/validator@0.4.1 What’s new in 0.4.1 Patch release for the standalone validator evidence lanes and MII reference workflow. Released with @records-fhir/validation-types 0.1.5.
Added Added validator claim summary generation for publishing the current HL7, MII reference, and FHIR Schema dual-path evidence in one machine-readable artifact. Added FHIR Schema dual-path action reporting so unconfirmed graph/reference buckets remain explicit follow-up work instead of hidden parity debt. Added package-backed terminology diagnostics and local terminology server helpers for deterministic MII/FHIR Schema quality lanes. Changed Hardened the MII reference triangulation workflow with reference-health probes, policy-rule extraction, skip taxonomy, and failed-profile prewarm details. Refreshed the public validator documentation around the 2026-07-01 evidence: 496/496 HL7 executable JSON comparisons, 231/231 measured MII reference parity, and 555-fixture FHIR Schema dual-path coverage. Tightened FHIR Schema graph slicing, reference-target extraction, and pattern diagnostics while keeping the graph path in parallel evidence mode. Fixed Fixed MII package relevance detection so package names containing substrings such as isik are not misclassified as Gematik ISiK packages. Fixed nested profile slice scoping and choice/FHIRPath edge cases uncovered by the MII and FHIR Schema dual-path lanes. Verification Verified with repository lint, stable tests, targeted validator Vitest suites, full affected conformance, MII reference gate, HL7 parity gate, and FHIR Schema dual-path report generation. Matched npm tarballs @records-fhir/validator@0.4.1 — also tagged validator-v0.4.1 @records-fhir/validation-types@0.1.5 The matching GitHub Action release (if any) is published separately under tag v0.4.1 and is not auto-synced; this release covers the npm package only.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/medvertical/records-fhir-validator">https://github.com/medvertical/records-fhir-validator</a></strong> to version <strong>validator-v0.4.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/fhir-validator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>npm tarball release for <code>@records-fhir/validator@0.4.1</code>. Synced from medvertical/records monorepo.</p>
<h2 id="install">Install</h2>
<pre tabindex="0"><code>npm install @records-fhir/validator@0.4.1
</code></pre><h2 id="whats-new-in-041">What&rsquo;s new in 0.4.1</h2>
<p>Patch release for the standalone validator evidence lanes and MII reference
workflow. Released with <code>@records-fhir/validation-types</code> 0.1.5.</p>
<h3 id="added">Added</h3>
<ul>
<li>Added validator claim summary generation for publishing the current HL7,
MII reference, and FHIR Schema dual-path evidence in one machine-readable
artifact.</li>
<li>Added FHIR Schema dual-path action reporting so unconfirmed graph/reference
buckets remain explicit follow-up work instead of hidden parity debt.</li>
<li>Added package-backed terminology diagnostics and local terminology server
helpers for deterministic MII/FHIR Schema quality lanes.</li>
</ul>
<h3 id="changed">Changed</h3>
<ul>
<li>Hardened the MII reference triangulation workflow with reference-health
probes, policy-rule extraction, skip taxonomy, and failed-profile prewarm
details.</li>
<li>Refreshed the public validator documentation around the 2026-07-01 evidence:
496/496 HL7 executable JSON comparisons, 231/231 measured MII reference
parity, and 555-fixture FHIR Schema dual-path coverage.</li>
<li>Tightened FHIR Schema graph slicing, reference-target extraction, and pattern
diagnostics while keeping the graph path in parallel evidence mode.</li>
</ul>
<h3 id="fixed">Fixed</h3>
<ul>
<li>Fixed MII package relevance detection so package names containing substrings
such as <code>isik</code> are not misclassified as Gematik ISiK packages.</li>
<li>Fixed nested profile slice scoping and choice/FHIRPath edge cases uncovered
by the MII and FHIR Schema dual-path lanes.</li>
</ul>
<h3 id="verification">Verification</h3>
<ul>
<li>Verified with repository lint, stable tests, targeted validator Vitest
suites, full affected conformance, MII reference gate, HL7 parity gate, and
FHIR Schema dual-path report generation.</li>
</ul>
<h2 id="matched-npm-tarballs">Matched npm tarballs</h2>
<ul>
<li><code>@records-fhir/validator@0.4.1</code> — also tagged <code>validator-v0.4.1</code></li>
<li><code>@records-fhir/validation-types@0.1.5</code></li>
</ul>
<p>The matching GitHub Action release (if any) is published separately under tag <code>v0.4.1</code> and is not auto-synced; this release covers the npm package only.</p>
]]></content:encoded></item><item><title>Agent Security Harness</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/agent-security-harness/</link><pubDate>Wed, 01 Jul 2026 22:42:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/agent-security-harness/</guid><description>Version updated for https://github.com/msaleme/red-team-blue-team-agent-fabric to version v4.7.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed The harness now tests all four layers of the agentic-payments stack. Since the last PyPI release (v4.5.0), two conformance layers landed — this release ships both.
Highlights (v4.5.0 → v4.7.0: 474 → 520 tests, 33 → 36 modules) Merchant-journey layer — NEW (UCP/ACP), #228 ucp_acp_harness.py — 12 tests, stdlib-only, fail-closed reference verifier.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/msaleme/red-team-blue-team-agent-fabric">https://github.com/msaleme/red-team-blue-team-agent-fabric</a></strong> to version <strong>v4.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-security-harness">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>The harness now tests all four layers of the agentic-payments stack.</strong> Since the last PyPI release (v4.5.0), two conformance layers landed — this release ships both.</p>
<h2 id="highlights-v450--v470-474--520-tests-33--36-modules">Highlights (v4.5.0 → v4.7.0: 474 → 520 tests, 33 → 36 modules)</h2>
<h3 id="merchant-journey-layer--new-ucpacp-228">Merchant-journey layer — NEW (UCP/ACP), #228</h3>
<p><code>ucp_acp_harness.py</code> — 12 tests, stdlib-only, fail-closed reference verifier.</p>
<ul>
<li><strong>UCP</strong> (Shopify Universal Cart): profile owner-key binding, cross-merchant line-item injection, journey step-order / skip-consent, quote integrity, cart-scope-vs-stated-intent, profile takeover.</li>
<li><strong>ACP</strong> (OpenAI/Stripe): checkout-session binding, SharedPaymentToken merchant + amount scope, order idempotency, product-feed authenticity, session expiry.</li>
</ul>
<h3 id="authorization--hardening-layer-ap2--fireblocks-x402-227">Authorization + hardening layer (AP2 + Fireblocks x402), #227</h3>
<p><code>ap2_harness.py</code> (17) + <code>x402_fireblocks_harness.py</code> (17) — AP2 mandate-chain authorization (FIDO-governed) and the Fireblocks x402 request-integrity / spend-governance / batch-settlement extension. Includes fixes to three fail-open verifier gaps (credential-release flag-trust, scope fail-open, SSRF range gap) surfaced by Bugbot, now guarded by negative tests.</p>
<h2 id="coverage-now-spans">Coverage now spans</h2>
<p>comms (MCP/A2A) → <strong>merchant journey (UCP/ACP)</strong> → authorization/trust (AP2/TAP) → settlement (x402/MPP/L402).</p>
<p>Full inventory: <code>docs/TEST-INVENTORY.md</code>. Verified by <code>scripts/count_tests.py</code> (definitive: 520).</p>
]]></content:encoded></item><item><title>PatchFlow Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/patchflow-security-scan/</link><pubDate>Wed, 01 Jul 2026 22:42:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/patchflow-security-scan/</guid><description>Version updated for https://github.com/Patchflow-security/patchflow-cli to version v0.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Patchflow-security/patchflow-cli">https://github.com/Patchflow-security/patchflow-cli</a></strong> to version <strong>v0.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/patchflow-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
]]></content:encoded></item><item><title>Create and Configure Repository</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/create-and-configure-repository/</link><pubDate>Wed, 01 Jul 2026 22:41:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/create-and-configure-repository/</guid><description>Version updated for https://github.com/pdrodavi-group/create-configured-repo to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/pdrodavi-group/create-configured-repo/commits/v1.0.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pdrodavi-group/create-configured-repo">https://github.com/pdrodavi-group/create-configured-repo</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/create-and-configure-repository">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/pdrodavi-group/create-configured-repo/commits/v1.0.0">https://github.com/pdrodavi-group/create-configured-repo/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>SkillTotal AI Component Security Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/skilltotal-ai-component-security-scan/</link><pubDate>Wed, 01 Jul 2026 22:41:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/skilltotal-ai-component-security-scan/</guid><description>Version updated for https://github.com/pezhik/skilltotal to version v0.24.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changed Prompt-injection/secret precision (ruleset 25): two more FPs on defensive/security content closed, recall-preserving. (1) A -----BEGIN PRIVATE KEY----- format marker held as a string constant (auth code building a PEM, e.g. @ai-sdk/google-vertex) no longer flags ST-SECRET-EMBEDDED — the pattern now requires actual base64 key material after the marker; a real multi-line key still fires. (2) A credential path cited inside a markdown inline-code span in a security guide (`write to ~/.ssh`, e.g. claude-blog) is routed to needs_review instead of ST-SENS-PATH — scoped to markdown, so a JS template literal in code and a bare path in prose still fire. Both removed spurious ST-COMBO-EXFIL escalations. New unit tests + negative corpus samples; FP floor and benign corpus stay at zero.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/pezhik/skilltotal">https://github.com/pezhik/skilltotal</a></strong> to version <strong>v0.24.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skilltotal-ai-component-security-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="changed">Changed</h3>
<ul>
<li><strong>Prompt-injection/secret precision (ruleset 25): two more FPs on defensive/security content
closed, recall-preserving.</strong> (1) A <code>-----BEGIN PRIVATE KEY-----</code> format marker held as a string
constant (auth code building a PEM, e.g. <code>@ai-sdk/google-vertex</code>) no longer flags
<code>ST-SECRET-EMBEDDED</code> — the pattern now requires actual base64 key material after the marker; a real
multi-line key still fires. (2) A credential path cited inside a markdown inline-code span in a
security guide (<code>`write to ~/.ssh`</code>, e.g. <code>claude-blog</code>) is routed to <code>needs_review</code> instead of
<code>ST-SENS-PATH</code> — scoped to markdown, so a JS template literal in code and a bare path in prose still
fire. Both removed spurious <code>ST-COMBO-EXFIL</code> escalations. New unit tests + negative corpus samples;
FP floor and benign corpus stay at zero.</li>
</ul>
]]></content:encoded></item><item><title>Sensez - Code Quality Feedback</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/sensez-code-quality-feedback/</link><pubDate>Wed, 01 Jul 2026 22:40:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/sensez-code-quality-feedback/</guid><description>Version updated for https://github.com/popov95s/sensez to version 0.1.6-alpha.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial release of the Sensez GitHub Action for pull request analysis.
What It Does Posts annotations and optional review comments on duplicated code blocks found in PR diffs. Fail-on-new thresholds let you gate merges on detected duplication. Language Support Python only in this initial release. JavaScript, TypeScript, and Rust support exist in the full CLI but are not yet shipped in the PyPI build used by the action. What Is Sensez? A structural maintainability tool that complements linters and type-checkers. It builds a graph representation of your code to detect structural duplication, dead code and code smell.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/popov95s/sensez">https://github.com/popov95s/sensez</a></strong> to version <strong>0.1.6-alpha</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/sensez-code-quality-feedback">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial release of the Sensez GitHub Action for pull request analysis.</p>
<h3 id="what-it-does">What It Does</h3>
<ul>
<li>Posts annotations and optional review comments on duplicated code blocks found in PR diffs. Fail-on-new thresholds let you gate merges on detected duplication.</li>
</ul>
<h3 id="language-support">Language Support</h3>
<ul>
<li>Python only in this initial release. JavaScript, TypeScript, and Rust support exist in the full CLI but are not yet shipped in the PyPI build used by the action.</li>
</ul>
<h3 id="what-is-sensez">What Is Sensez?</h3>
<p>A structural maintainability tool that complements linters and type-checkers. It builds a graph representation of your code to detect structural duplication, dead code and code smell.</p>
<h3 id="using-sensez-standalone-mcp--cli">Using Sensez Standalone (MCP / CLI)</h3>
<pre tabindex="0"><code>uv tool install sensez          # or: pip install sensez
sensez noze .                   # scan the current directory
</code></pre><p>For JS/TS:</p>
<pre tabindex="0"><code>npm install --dev sensez
npx sensez noze .
</code></pre><p>To use the MCP server (IDE integration):</p>
<pre tabindex="0"><code>sensez init
</code></pre><p>or</p>
<pre tabindex="0"><code>npx sensez init
</code></pre>]]></content:encoded></item><item><title>Postman Onboarding Workspace Bootstrap</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/postman-onboarding-workspace-bootstrap/</link><pubDate>Wed, 01 Jul 2026 22:39:59 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/postman-onboarding-workspace-bootstrap/</guid><description>Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.1.2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/postman-cs/postman-bootstrap-action/compare/v2.1.1...v2.1.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-bootstrap-action">https://github.com/postman-cs/postman-bootstrap-action</a></strong> to version <strong>v2.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-workspace-bootstrap">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-bootstrap-action/compare/v2.1.1...v2.1.2">https://github.com/postman-cs/postman-bootstrap-action/compare/v2.1.1...v2.1.2</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Repo Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/postman-onboarding-repo-sync/</link><pubDate>Wed, 01 Jul 2026 22:39:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/postman-onboarding-repo-sync/</guid><description>Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.0.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/postman-cs/postman-repo-sync-action/compare/v2.0.0...v2.0.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-repo-sync-action">https://github.com/postman-cs/postman-repo-sync-action</a></strong> to version <strong>v2.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-repo-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v2.0.0...v2.0.1">https://github.com/postman-cs/postman-repo-sync-action/compare/v2.0.0...v2.0.1</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Smoke Flow</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/postman-onboarding-smoke-flow/</link><pubDate>Wed, 01 Jul 2026 22:38:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/postman-onboarding-smoke-flow/</guid><description>Version updated for https://github.com/postman-cs/postman-smoke-flow-action to version v2.0.1.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/postman-cs/postman-smoke-flow-action/compare/v2.0.0...v2.0.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-smoke-flow-action">https://github.com/postman-cs/postman-smoke-flow-action</a></strong> to version <strong>v2.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-smoke-flow">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-smoke-flow-action/compare/v2.0.0...v2.0.1">https://github.com/postman-cs/postman-smoke-flow-action/compare/v2.0.0...v2.0.1</a></p>
]]></content:encoded></item><item><title>Rearm Build And Submit Release metadata action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/rearm-build-and-submit-release-metadata-action/</link><pubDate>Wed, 01 Jul 2026 22:38:19 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/rearm-build-and-submit-release-metadata-action/</guid><description>Version updated for https://github.com/relizaio/rearm-docker-action to version 1.13.4.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Address zizmor findings Bump rearm-actions to v1.7.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/relizaio/rearm-docker-action">https://github.com/relizaio/rearm-docker-action</a></strong> to version <strong>1.13.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rearm-build-and-submit-release-metadata-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Address zizmor findings</li>
<li>Bump rearm-actions to v1.7.0</li>
</ul>
]]></content:encoded></item><item><title>ReARM Version and Publish Helm Chart Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/rearm-version-and-publish-helm-chart-action/</link><pubDate>Wed, 01 Jul 2026 22:37:46 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/rearm-version-and-publish-helm-chart-action/</guid><description>Version updated for https://github.com/relizaio/rearm-helm-action to version 1.10.2.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Address zizmor findings Bump rearm-actions to v1.7.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/relizaio/rearm-helm-action">https://github.com/relizaio/rearm-helm-action</a></strong> to version <strong>1.10.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rearm-version-and-publish-helm-chart-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Address zizmor findings</li>
<li>Bump rearm-actions to v1.7.0</li>
</ul>
]]></content:encoded></item><item><title>Remyx Outrider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/remyx-outrider/</link><pubDate>Wed, 01 Jul 2026 22:37:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/remyx-outrider/</guid><description>Version updated for https://github.com/remyxai/outrider to version v1.7.0.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Behavior changes that replace categorical shape-label guards with measurement-based decisions, and give the selection stage access to workflow-attached tooling (ENVIRONMENTS.md).
Behavior changes Substitution guard removed. shape in (&amp;#34;replacement&amp;#34;, &amp;#34;simplification&amp;#34;) → auto-Issue short-circuit no longer fires before implementation. Replacement/simplification runs proceed; the path allowlist + check_integration() catch broken diffs on measured evidence. ENVIRONMENTS.md at selection. Loader runs early and threads the body into select_recommendation’s prompt, so the selection agent has workflow-attached tooling (AST-search skills, MCP servers) while verifying candidates. Empty ENVIRONMENTS.md = unchanged behavior. Self-review orphan surfaced, not vetoed. When is_orphan=true, the PR ships with a prominent warning in the body instead of being downgraded to Issue. Upstream measurement-based gates already catch scaffold-shaped diffs. Confabulation check. Extracts path-like tokens from selection_reasoning and verifies each against the workdir. Step-summary shows N of M verified; a 0 of N verified line surfaces confidently-wrong reasoning. Compatibility Backwards-compatible for runs without an ENVIRONMENTS.md file (loader no-ops). No config changes needed.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remyxai/outrider">https://github.com/remyxai/outrider</a></strong> to version <strong>v1.7.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/remyx-outrider">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Behavior changes that replace categorical shape-label guards with measurement-based decisions, and give the selection stage access to workflow-attached tooling (ENVIRONMENTS.md).</p>
<h2 id="behavior-changes">Behavior changes</h2>
<ul>
<li><strong>Substitution guard removed.</strong> <code>shape in (&quot;replacement&quot;, &quot;simplification&quot;) → auto-Issue</code> short-circuit no longer fires before implementation. Replacement/simplification runs proceed; the path allowlist + <code>check_integration()</code> catch broken diffs on measured evidence.</li>
<li><strong>ENVIRONMENTS.md at selection.</strong> Loader runs early and threads the body into <code>select_recommendation</code>&rsquo;s prompt, so the selection agent has workflow-attached tooling (AST-search skills, MCP servers) while verifying candidates. Empty ENVIRONMENTS.md = unchanged behavior.</li>
<li><strong>Self-review orphan surfaced, not vetoed.</strong> When <code>is_orphan=true</code>, the PR ships with a prominent warning in the body instead of being downgraded to Issue. Upstream measurement-based gates already catch scaffold-shaped diffs.</li>
<li><strong>Confabulation check.</strong> Extracts path-like tokens from <code>selection_reasoning</code> and verifies each against the workdir. Step-summary shows <code>N of M verified</code>; a <code>0 of N verified</code> line surfaces confidently-wrong reasoning.</li>
</ul>
<h2 id="compatibility">Compatibility</h2>
<p>Backwards-compatible for runs without an ENVIRONMENTS.md file (loader no-ops). No config changes needed.</p>
<h2 id="motivating-cases">Motivating cases</h2>
<ul>
<li>opik SAFARI (this release, validated live) — full-chain reach-PR</li>
<li>agents Entity Binding — full-chain reach-PR</li>
<li>Prior misfires (unsloth-retry confabulation, opik LettuceDetect library-shape downgrade, unsloth+TokenPilot substitution-guard downgrade) — all catchable / preventable with this release</li>
</ul>
]]></content:encoded></item><item><title>Jira Sprint CalVer</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/jira-sprint-calver/</link><pubDate>Wed, 01 Jul 2026 22:36:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/jira-sprint-calver/</guid><description>Version updated for https://github.com/RuBAN-GT/jira-sprint-calver-action to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.0.2 (2026-07-01) Bug Fixes Minor update (7402e43)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/RuBAN-GT/jira-sprint-calver-action">https://github.com/RuBAN-GT/jira-sprint-calver-action</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/jira-sprint-calver">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="102-2026-07-01"><a href="https://github.com/RuBAN-GT/jira-sprint-calver-action/compare/v1.0.1...v1.0.2">1.0.2</a> (2026-07-01)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>Minor update (<a href="https://github.com/RuBAN-GT/jira-sprint-calver-action/commit/7402e43549192938192dc8f83b81f7a0bd9b6d3b">7402e43</a>)</li>
</ul>
]]></content:encoded></item><item><title>Skyhook Cloud Login</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/skyhook-cloud-login/</link><pubDate>Wed, 01 Jul 2026 22:36:07 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/skyhook-cloud-login/</guid><description>Version updated for https://github.com/skyhook-io/cloud-login to version v1.11.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.11.1 (2026-07-01) Bug Fixes upgrade GitHub Actions dependencies (#2) (d64734d)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/skyhook-io/cloud-login">https://github.com/skyhook-io/cloud-login</a></strong> to version <strong>v1.11.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skyhook-cloud-login">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="1111-2026-07-01"><a href="https://github.com/skyhook-io/cloud-login/compare/v1.11.0...v1.11.1">1.11.1</a> (2026-07-01)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>upgrade GitHub Actions dependencies (<a href="https://github.com/skyhook-io/cloud-login/issues/2">#2</a>) (<a href="https://github.com/skyhook-io/cloud-login/commit/d64734dd2148b8f34f77853c34498b2c5fd3e830">d64734d</a>)</li>
</ul>
]]></content:encoded></item><item><title>Skyhook Docker Multi-Registry Build Push</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/skyhook-docker-multi-registry-build-push/</link><pubDate>Wed, 01 Jul 2026 22:35:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/skyhook-docker-multi-registry-build-push/</guid><description>Version updated for https://github.com/skyhook-io/docker-build-push-action to version v2.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 2.0.0 (2026-07-01) feat!: upgrade Docker actions and drop buildx_install input (#7) (09a68f8) BREAKING CHANGES removed the buildx_install input. docker/setup-buildx-action v4 removed its install input, so the composite no longer exposes buildx_install; the docker build -&amp;gt; docker buildx build alias it enabled is gone. Use the BUILDX_BUILDER env var if that behavior is needed. Claude-Session: https://claude.ai/code/session_011T9ASy4VmRoYrnuTsLd9oU</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/skyhook-io/docker-build-push-action">https://github.com/skyhook-io/docker-build-push-action</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skyhook-docker-multi-registry-build-push">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="200-2026-07-01"><a href="https://github.com/skyhook-io/docker-build-push-action/compare/v1.5.2...v2.0.0">2.0.0</a> (2026-07-01)</h1>
<ul>
<li>feat!: upgrade Docker actions and drop buildx_install input (<a href="https://github.com/skyhook-io/docker-build-push-action/issues/7">#7</a>) (<a href="https://github.com/skyhook-io/docker-build-push-action/commit/09a68f83b7508e143b63dc823259a2192bcc6d33">09a68f8</a>)</li>
</ul>
<h3 id="breaking-changes">BREAKING CHANGES</h3>
<ul>
<li>removed the buildx_install input. docker/setup-buildx-action v4 removed its install input, so the composite no longer exposes buildx_install; the docker build -&gt; docker buildx build alias it enabled is gone. Use the BUILDX_BUILDER env var if that behavior is needed.</li>
</ul>
<p>Claude-Session: <a href="https://claude.ai/code/session_011T9ASy4VmRoYrnuTsLd9oU">https://claude.ai/code/session_011T9ASy4VmRoYrnuTsLd9oU</a></p>
<ul>
<li>ci: add Dependabot for GitHub Actions</li>
</ul>
]]></content:encoded></item><item><title>Skyhook GitHub Auth Token</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/skyhook-github-auth-token/</link><pubDate>Wed, 01 Jul 2026 22:35:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/skyhook-github-auth-token/</guid><description>Version updated for https://github.com/skyhook-io/github-auth-token to version v1.1.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.1.1 (2026-07-01) Bug Fixes upgrade GitHub Actions dependencies (#1) (4d92bbc)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/skyhook-io/github-auth-token">https://github.com/skyhook-io/github-auth-token</a></strong> to version <strong>v1.1.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skyhook-github-auth-token">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="111-2026-07-01"><a href="https://github.com/skyhook-io/github-auth-token/compare/v1.1.0...v1.1.1">1.1.1</a> (2026-07-01)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>upgrade GitHub Actions dependencies (<a href="https://github.com/skyhook-io/github-auth-token/issues/1">#1</a>) (<a href="https://github.com/skyhook-io/github-auth-token/commit/4d92bbcfb92d7c074c4876d6321f86cd3746a2aa">4d92bbc</a>)</li>
</ul>
]]></content:encoded></item><item><title>Skyhook Login to AWS</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/skyhook-login-to-aws/</link><pubDate>Wed, 01 Jul 2026 22:34:26 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/skyhook-login-to-aws/</guid><description>Version updated for https://github.com/skyhook-io/login-aws to version v1.7.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.7.2 (2026-07-01) Bug Fixes upgrade GitHub Actions dependencies (#1) (d7837a6)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/skyhook-io/login-aws">https://github.com/skyhook-io/login-aws</a></strong> to version <strong>v1.7.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skyhook-login-to-aws">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="172-2026-07-01"><a href="https://github.com/skyhook-io/login-aws/compare/v1.7.1...v1.7.2">1.7.2</a> (2026-07-01)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>upgrade GitHub Actions dependencies (<a href="https://github.com/skyhook-io/login-aws/issues/1">#1</a>) (<a href="https://github.com/skyhook-io/login-aws/commit/d7837a673c237b66874c4a94abf965bf7380b45c">d7837a6</a>)</li>
</ul>
]]></content:encoded></item><item><title>Skyhook Login to Azure AKS</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/skyhook-login-to-azure-aks/</link><pubDate>Wed, 01 Jul 2026 22:33:53 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/skyhook-login-to-azure-aks/</guid><description>Version updated for https://github.com/skyhook-io/login-azure-aks to version v1.0.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.0.1 (2026-07-01) Bug Fixes update author from KoalaOps to Skyhook (92c7dc0) upgrade GitHub Actions dependencies (#1) (65c0a96)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/skyhook-io/login-azure-aks">https://github.com/skyhook-io/login-azure-aks</a></strong> to version <strong>v1.0.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skyhook-login-to-azure-aks">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="101-2026-07-01"><a href="https://github.com/skyhook-io/login-azure-aks/compare/v1.0.0...v1.0.1">1.0.1</a> (2026-07-01)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>update author from KoalaOps to Skyhook (<a href="https://github.com/skyhook-io/login-azure-aks/commit/92c7dc09169d27f1ed98f3395dde3bb9f0d6648e">92c7dc0</a>)</li>
<li>upgrade GitHub Actions dependencies (<a href="https://github.com/skyhook-io/login-azure-aks/issues/1">#1</a>) (<a href="https://github.com/skyhook-io/login-azure-aks/commit/65c0a96ab3580dd3840b90872c3b378c251f2678">65c0a96</a>)</li>
</ul>
]]></content:encoded></item><item><title>Skyhook Login to GCP GKE</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/skyhook-login-to-gcp-gke/</link><pubDate>Wed, 01 Jul 2026 22:33:20 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/skyhook-login-to-gcp-gke/</guid><description>Version updated for https://github.com/skyhook-io/login-gcp-gke to version v1.2.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.2.2 (2026-07-01) Bug Fixes upgrade GitHub Actions dependencies (#2) (70f56db)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/skyhook-io/login-gcp-gke">https://github.com/skyhook-io/login-gcp-gke</a></strong> to version <strong>v1.2.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/skyhook-login-to-gcp-gke">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="122-2026-07-01"><a href="https://github.com/skyhook-io/login-gcp-gke/compare/v1.2.1...v1.2.2">1.2.2</a> (2026-07-01)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li>upgrade GitHub Actions dependencies (<a href="https://github.com/skyhook-io/login-gcp-gke/issues/2">#2</a>) (<a href="https://github.com/skyhook-io/login-gcp-gke/commit/70f56db3163c38b9cb412f11dd70fe785348fd9b">70f56db</a>)</li>
</ul>
]]></content:encoded></item><item><title>rsync action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/rsync-action/</link><pubDate>Wed, 01 Jul 2026 22:32:47 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/rsync-action/</guid><description>Version updated for https://github.com/spotdemo4/rsync-action to version v0.0.2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed bump: v0.0.1 -&amp;gt; v0.0.2 (48fa2b3) ci(release): replace flake-release and npm publish with gh/forgejo cli (f595fd4) chore(deps): update dependency rolldown to ^1.1.4 (#1) (aa20caf) ci(workflows): add rsync tag and release automation (d0abd20) fix(action): parse rsync TLS port with fallback and range checks (e825732) refactor(action): use static rsync releases for tool setup (7739f63) fix(flake): use pkgs.rsync instead of pkgs.pkgsStatic in overlay (9e2dc66) ci: run checks on amd64 and arm64 runner matrix (7eb0273) ci(check): pass rsync auth inputs to workflow step (3398413) build(flake): update inputs and skip rsync itemize test (0ba1338)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/spotdemo4/rsync-action">https://github.com/spotdemo4/rsync-action</a></strong> to version <strong>v0.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rsync-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>bump: v0.0.1 -&gt; v0.0.2 (48fa2b3)</li>
<li>ci(release): replace flake-release and npm publish with gh/forgejo cli (f595fd4)</li>
<li>chore(deps): update dependency rolldown to ^1.1.4 (#1) (aa20caf)</li>
<li>ci(workflows): add rsync tag and release automation (d0abd20)</li>
<li>fix(action): parse rsync TLS port with fallback and range checks (e825732)</li>
<li>refactor(action): use static rsync releases for tool setup (7739f63)</li>
<li>fix(flake): use pkgs.rsync instead of pkgs.pkgsStatic in overlay (9e2dc66)</li>
<li>ci: run checks on amd64 and arm64 runner matrix (7eb0273)</li>
<li>ci(check): pass rsync auth inputs to workflow step (3398413)</li>
<li>build(flake): update inputs and skip rsync itemize test (0ba1338)</li>
</ul>
]]></content:encoded></item><item><title>Setup Tombi</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/setup-tombi/</link><pubDate>Wed, 01 Jul 2026 22:32:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/setup-tombi/</guid><description>Version updated for https://github.com/tombi-toml/setup-tombi to version v1.1.7.
This action is used across all versions by 130 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed This setup-tombi release matches tombi v1.1.7.
Full Changelog: https://github.com/tombi-toml/setup-tombi/compare/v1...v1.1.7</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tombi-toml/setup-tombi">https://github.com/tombi-toml/setup-tombi</a></strong> to version <strong>v1.1.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>130</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-tombi">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>This setup-tombi release matches <a href="https://github.com/tombi-toml/tombi/releases/tag/v1.1.7">tombi v1.1.7</a>.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/tombi-toml/setup-tombi/compare/v1...v1.1.7">https://github.com/tombi-toml/setup-tombi/compare/v1...v1.1.7</a></p>
]]></content:encoded></item><item><title>Cloudflare Email Sending</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/cloudflare-email-sending/</link><pubDate>Wed, 01 Jul 2026 22:31:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/cloudflare-email-sending/</guid><description>Version updated for https://github.com/tourcoder/cloudflare-email-sending to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/tourcoder/cloudflare-email-sending/commits/v1.0.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tourcoder/cloudflare-email-sending">https://github.com/tourcoder/cloudflare-email-sending</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/cloudflare-email-sending">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/tourcoder/cloudflare-email-sending/commits/v1.0.0">https://github.com/tourcoder/cloudflare-email-sending/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>spaces checkout run</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/spaces-checkout-run/</link><pubDate>Wed, 01 Jul 2026 22:31:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/spaces-checkout-run/</guid><description>Version updated for https://github.com/work-spaces/spaces-checkout-run to version v0.17.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Bump version to v0.17.1 by @tyler-gilbert in https://github.com/work-spaces/spaces-checkout-run/pull/26 Full Changelog: https://github.com/work-spaces/spaces-checkout-run/compare/v0.16.0...v0.17.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/work-spaces/spaces-checkout-run">https://github.com/work-spaces/spaces-checkout-run</a></strong> to version <strong>v0.17.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/spaces-checkout-run">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Bump version to v0.17.1 by @tyler-gilbert in <a href="https://github.com/work-spaces/spaces-checkout-run/pull/26">https://github.com/work-spaces/spaces-checkout-run/pull/26</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/work-spaces/spaces-checkout-run/compare/v0.16.0...v0.17.1">https://github.com/work-spaces/spaces-checkout-run/compare/v0.16.0...v0.17.1</a></p>
]]></content:encoded></item><item><title>RepoScope Security scanning + AI-code provenance</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/reposcope-security-scanning--ai-code-provenance/</link><pubDate>Wed, 01 Jul 2026 22:30:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/reposcope-security-scanning--ai-code-provenance/</guid><description>Version updated for https://github.com/xdun1698/reposcope-action to version v1.0.4.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Scan your codebase for security vulnerabilities and AI-code provenance on every push and pull request — inline PR comments, a build-gating security score, and a shareable HTML report.
New in 1.0.4 Listing name updated to “RepoScope Security scanning + AI-code provenance”. What it does 30 security detectors across 14 languages — secrets, SQL injection, XSS, command injection, TLS misconfigurations, permissive CORS, and weak crypto. AI-code provenance — flags which scanned files are attributed to AI coding tools (Copilot, Cursor, Claude, Codeium, Windsurf, Aider, Devin) in git history, and writes a machine-readable provenance.json record. Local and deterministic — no network, no LLM. Inline PR review comments — one per finding: file, line, severity badge, CWE ID, and a fix hint. GitHub Check run — PASS/FAIL against your score threshold, with annotations. HTML report artifact + build gating (fail-on, threshold) + # reposcope-ignore: suppression. Quickstart - uses: actions/checkout@v4 with: fetch-depth: 0 - uses: xdun1698/reposcope-action@v1 with: token: ${{ secrets.GITHUB_TOKEN }} Source: https://github.com/xdun1698/reposcope-action · Website: https://reposcope.app</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/xdun1698/reposcope-action">https://github.com/xdun1698/reposcope-action</a></strong> to version <strong>v1.0.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/reposcope-security-scanning-ai-code-provenance">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Scan your codebase for security vulnerabilities <strong>and AI-code provenance</strong> on every push and pull request — inline PR comments, a build-gating security score, and a shareable HTML report.</p>
<h2 id="new-in-104">New in 1.0.4</h2>
<ul>
<li>Listing name updated to &ldquo;RepoScope Security scanning + AI-code provenance&rdquo;.</li>
</ul>
<h2 id="what-it-does">What it does</h2>
<ul>
<li><strong>30 security detectors across 14 languages</strong> — secrets, SQL injection, XSS, command injection, TLS misconfigurations, permissive CORS, and weak crypto.</li>
<li><strong>AI-code provenance</strong> — flags which scanned files are attributed to AI coding tools (Copilot, Cursor, Claude, Codeium, Windsurf, Aider, Devin) in git history, and writes a machine-readable <code>provenance.json</code> record. Local and deterministic — no network, no LLM.</li>
<li><strong>Inline PR review comments</strong> — one per finding: file, line, severity badge, CWE ID, and a fix hint.</li>
<li><strong>GitHub Check run</strong> — PASS/FAIL against your score threshold, with annotations.</li>
<li><strong>HTML report artifact</strong> + build gating (<code>fail-on</code>, <code>threshold</code>) + <code># reposcope-ignore:</code> suppression.</li>
</ul>
<h2 id="quickstart">Quickstart</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v4</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">fetch-depth</span>: <span style="color:#ae81ff">0</span>
</span></span><span style="display:flex;"><span>- <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">xdun1698/reposcope-action@v1</span>
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">token</span>: <span style="color:#ae81ff">${{ secrets.GITHUB_TOKEN }}</span>
</span></span></code></pre></div><p><strong>Source:</strong> <a href="https://github.com/xdun1698/reposcope-action">https://github.com/xdun1698/reposcope-action</a> · <strong>Website:</strong> <a href="https://reposcope.app">https://reposcope.app</a></p>
]]></content:encoded></item><item><title>Setup poly CLI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/setup-poly-cli/</link><pubDate>Wed, 01 Jul 2026 15:03:30 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/setup-poly-cli/</guid><description>Version updated for https://github.com/Goldziher/polylint to version v0.1.7.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Release v0.1.7</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Goldziher/polylint">https://github.com/Goldziher/polylint</a></strong> to version <strong>v0.1.7</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-poly-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Release v0.1.7</p>
]]></content:encoded></item><item><title>ReleaseKit – Automated Versioning &amp; Release</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/releasekit-automated-versioning-release/</link><pubDate>Wed, 01 Jul 2026 15:02:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/releasekit-automated-versioning-release/</guid><description>Version updated for https://github.com/goosewobbler/releasekit to version v0.38.1.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed: Fixed independent-group members to be labeled as “bundled” instead of “coupled” in the release summary. (#513, #509) Fixed standing-PR changelog sections to use #### headings instead of bold text, restoring proper spacing within blockquotes. (#511, #508) Fixed bare #N issue references in changelog entry descriptions to be neutralized and deduplicated with appended ref labels. (#510, #507) Full Changelog: https://github.com/goosewobbler/releasekit/compare/0.38.0...0.38.1</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/goosewobbler/releasekit">https://github.com/goosewobbler/releasekit</a></strong> to version <strong>v0.38.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/releasekit-automated-versioning-release">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed:</h3>
<ul>
<li>Fixed independent-group members to be labeled as &ldquo;bundled&rdquo; instead of &ldquo;coupled&rdquo; in the release summary. (#513, #509)</li>
<li>Fixed standing-PR changelog sections to use #### headings instead of bold text, restoring proper spacing within blockquotes. (#511, #508)</li>
<li>Fixed bare #N issue references in changelog entry descriptions to be neutralized and deduplicated with appended ref labels. (#510, #507)</li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/goosewobbler/releasekit/compare/0.38.0...0.38.1">https://github.com/goosewobbler/releasekit/compare/0.38.0...0.38.1</a></p>
]]></content:encoded></item><item><title>Vizb Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/vizb-action/</link><pubDate>Wed, 01 Jul 2026 15:02:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/vizb-action/</guid><description>Version updated for https://github.com/goptics/vizb to version v0.14.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix(action): preserve scatter settings on merge-deploy by @fahimfaisaal in https://github.com/goptics/vizb/pull/155 feat: add terminal logo banner to install scripts by @fahimfaisaal in https://github.com/goptics/vizb/pull/156 feat: green arrow logs, simplify messages by @fahimfaisaal in https://github.com/goptics/vizb/pull/158 fix(charts): tooltip legend layout and sigma math by @fahimfaisaal in https://github.com/goptics/vizb/pull/159 fix(stats): correct CI formula, zAxis drop, and edge guards by @fahimfaisaal in https://github.com/goptics/vizb/pull/160 docs(readme): add quick example with platform-specific install commands by @fahimfaisaal in https://github.com/goptics/vizb/pull/162 chore(docs): upgrade Astro 6 to Astro 7 with Rust compiler by @fahimfaisaal in https://github.com/goptics/vizb/pull/164 fix(charts): fit y-axis to data range for line and scatter charts by @fahimfaisaal in https://github.com/goptics/vizb/pull/163 fix(charts): size value 3D grid from category counts and cap camera distance by @fahimfaisaal in https://github.com/goptics/vizb/pull/161 chore(ui): upgrade vite 8 and vitest 4 by @fahimfaisaal in https://github.com/goptics/vizb/pull/165 feat(charts): add –symbol and –symbol-size flags for line and scatter by @fahimfaisaal in https://github.com/goptics/vizb/pull/166 feat(scatter): add –visualmap for 2D scatter gradient coloring by @fahimfaisaal in https://github.com/goptics/vizb/pull/169 feat: applicability-rule pipeline + config/ → internal/ move by @fahimfaisaal in https://github.com/goptics/vizb/pull/170 feat(dataset): add –id flag and ?id= URL dataset selection by @fahimfaisaal in https://github.com/goptics/vizb/pull/171 fix(scatter): apply visualMap on large datasets and add house-price example by @fahimfaisaal in https://github.com/goptics/vizb/pull/172 feat(select): solo –select axis mode, multi-stat, and mixed by @fahimfaisaal in https://github.com/goptics/vizb/pull/173 feat(ci): local ACT example, stable id links, and parser fixes by @fahimfaisaal in https://github.com/goptics/vizb/pull/174 fix(sort): apply sort to 1-axis charts by @fahimfaisaal in https://github.com/goptics/vizb/pull/175 docs(charts): add bar and line examples with screenshots by @fahimfaisaal in https://github.com/goptics/vizb/pull/168 Full Changelog: https://github.com/goptics/vizb/compare/v0.13.0...v0.14.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/goptics/vizb">https://github.com/goptics/vizb</a></strong> to version <strong>v0.14.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/vizb-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix(action): preserve scatter settings on merge-deploy by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/155">https://github.com/goptics/vizb/pull/155</a></li>
<li>feat: add terminal logo banner to install scripts by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/156">https://github.com/goptics/vizb/pull/156</a></li>
<li>feat: green arrow logs, simplify messages by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/158">https://github.com/goptics/vizb/pull/158</a></li>
<li>fix(charts): tooltip legend layout and sigma math by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/159">https://github.com/goptics/vizb/pull/159</a></li>
<li>fix(stats): correct CI formula, zAxis drop, and edge guards by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/160">https://github.com/goptics/vizb/pull/160</a></li>
<li>docs(readme): add quick example with platform-specific install commands by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/162">https://github.com/goptics/vizb/pull/162</a></li>
<li>chore(docs): upgrade Astro 6 to Astro 7 with Rust compiler by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/164">https://github.com/goptics/vizb/pull/164</a></li>
<li>fix(charts): fit y-axis to data range for line and scatter charts by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/163">https://github.com/goptics/vizb/pull/163</a></li>
<li>fix(charts): size value 3D grid from category counts and cap camera distance by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/161">https://github.com/goptics/vizb/pull/161</a></li>
<li>chore(ui): upgrade vite 8 and vitest 4 by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/165">https://github.com/goptics/vizb/pull/165</a></li>
<li>feat(charts): add &ndash;symbol and &ndash;symbol-size flags for line and scatter by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/166">https://github.com/goptics/vizb/pull/166</a></li>
<li>feat(scatter): add &ndash;visualmap for 2D scatter gradient coloring by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/169">https://github.com/goptics/vizb/pull/169</a></li>
<li>feat: applicability-rule pipeline + config/ → internal/ move by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/170">https://github.com/goptics/vizb/pull/170</a></li>
<li>feat(dataset): add &ndash;id flag and ?id= URL dataset selection by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/171">https://github.com/goptics/vizb/pull/171</a></li>
<li>fix(scatter): apply visualMap on large datasets and add house-price example by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/172">https://github.com/goptics/vizb/pull/172</a></li>
<li>feat(select): solo &ndash;select axis mode, multi-stat, and mixed by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/173">https://github.com/goptics/vizb/pull/173</a></li>
<li>feat(ci): local ACT example, stable <code>id</code> links, and parser fixes by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/174">https://github.com/goptics/vizb/pull/174</a></li>
<li>fix(sort): apply sort to 1-axis charts by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/175">https://github.com/goptics/vizb/pull/175</a></li>
<li>docs(charts): add bar and line examples with screenshots by @fahimfaisaal in <a href="https://github.com/goptics/vizb/pull/168">https://github.com/goptics/vizb/pull/168</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/goptics/vizb/compare/v0.13.0...v0.14.0">https://github.com/goptics/vizb/compare/v0.13.0...v0.14.0</a></p>
]]></content:encoded></item><item><title>AI Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/ai-plugin-scanner/</link><pubDate>Wed, 01 Jul 2026 15:01:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/ai-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/ai-plugin-scanner-action to version v1.2.357.
This action is used across all versions by 17 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Published automatically from https://github.com/hashgraph-online/hol-guard/tree/869275bc9c3ab57804fbc0b168b6a98e91c39a3a with plugin-scanner 2.0.957.
Full Changelog: https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.356...v1.2.357</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/ai-plugin-scanner-action">https://github.com/hashgraph-online/ai-plugin-scanner-action</a></strong> to version <strong>v1.2.357</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>17</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Published automatically from <a href="https://github.com/hashgraph-online/hol-guard/tree/869275bc9c3ab57804fbc0b168b6a98e91c39a3a">https://github.com/hashgraph-online/hol-guard/tree/869275bc9c3ab57804fbc0b168b6a98e91c39a3a</a> with plugin-scanner 2.0.957.</p>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.356...v1.2.357">https://github.com/hashgraph-online/ai-plugin-scanner-action/compare/v1.2.356...v1.2.357</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/hol-codex-plugin-scanner/</link><pubDate>Wed, 01 Jul 2026 15:01:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.357.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.357</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.357</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.357">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.357</a></p>
]]></content:encoded></item><item><title>PDPL Compliance Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/pdpl-compliance-scan/</link><pubDate>Wed, 01 Jul 2026 15:00:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/pdpl-compliance-scan/</guid><description>Version updated for https://github.com/imohad/pdpl-scanner to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Builds on v1.0.0 with broader detection, fewer false positives, suppression, and a bilingual HTML report. 32 tests; CI green on Python 3.8/3.11/3.12.
New detection PDPL-CB-02 — personal data sent to a foreign third-party processor (analytics, email, CRM, AI, observability, payments: mixpanel, segment, sendgrid, twilio, openai, stripe, datadog, …). Entity-aware severity like CB-01. PDPL-SEC-02 — database/transport TLS disabled (sslmode=disable, ssl_mode=&amp;#34;disable&amp;#34;, ssl=false). Assisted controls now run in the engine as high-recall LEADs: DSR-02 (soft-delete erasure), SEN-01 (sensitive data without visible encryption), and repo-wide DSR-01 / RET-01 / LB-01. Leads never fail the gate on their own. Accuracy PDPL-SEC-03 placeholder/low-entropy triage: defaults like changeme / your_password downgrade to a medium LEAD; real-format secrets stay critical. Suppression Inline # pdpl-ignore[CONTROL,…], a .pdplignore file (gitignore-style globs), and glob support in --exclude. Reporting &amp;amp; DX Standalone bilingual HTML report (--html); SARIF partialFingerprints for stable code-scanning dedup; --show-pass + passed_controls in JSON. .pre-commit-hooks.yaml, PyPI publish workflow (OIDC), README badges, and community files. Upgrade: uses: imohad/pdpl-scanner@v1 now resolves to v1.1.0.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/imohad/pdpl-scanner">https://github.com/imohad/pdpl-scanner</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/pdpl-compliance-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Builds on v1.0.0 with broader detection, fewer false positives, suppression, and a bilingual HTML report. 32 tests; CI green on Python 3.8/3.11/3.12.</p>
<h3 id="new-detection">New detection</h3>
<ul>
<li><strong><code>PDPL-CB-02</code></strong> — personal data sent to a foreign third-party processor (analytics, email, CRM, AI, observability, payments: mixpanel, segment, sendgrid, twilio, openai, stripe, datadog, …). Entity-aware severity like <code>CB-01</code>.</li>
<li><strong><code>PDPL-SEC-02</code></strong> — database/transport TLS disabled (<code>sslmode=disable</code>, <code>ssl_mode=&quot;disable&quot;</code>, <code>ssl=false</code>).</li>
<li><strong>Assisted controls now run in the engine</strong> as high-recall <code>LEAD</code>s: <code>DSR-02</code> (soft-delete erasure), <code>SEN-01</code> (sensitive data without visible encryption), and repo-wide <code>DSR-01</code> / <code>RET-01</code> / <code>LB-01</code>. Leads never fail the gate on their own.</li>
</ul>
<h3 id="accuracy">Accuracy</h3>
<ul>
<li><code>PDPL-SEC-03</code> placeholder/low-entropy triage: defaults like <code>changeme</code> / <code>your_password</code> downgrade to a medium <code>LEAD</code>; real-format secrets stay critical.</li>
</ul>
<h3 id="suppression">Suppression</h3>
<ul>
<li>Inline <code># pdpl-ignore[CONTROL,…]</code>, a <code>.pdplignore</code> file (gitignore-style globs), and glob support in <code>--exclude</code>.</li>
</ul>
<h3 id="reporting--dx">Reporting &amp; DX</h3>
<ul>
<li>Standalone bilingual <strong>HTML report</strong> (<code>--html</code>); SARIF <code>partialFingerprints</code> for stable code-scanning dedup; <code>--show-pass</code> + <code>passed_controls</code> in JSON.</li>
<li><code>.pre-commit-hooks.yaml</code>, PyPI publish workflow (OIDC), README badges, and community files.</li>
</ul>
<p><strong>Upgrade:</strong> <code>uses: imohad/pdpl-scanner@v1</code> now resolves to v1.1.0.</p>
<p>Full notes: <a href="https://github.com/imohad/pdpl-scanner/blob/main/CHANGELOG.md">CHANGELOG.md</a></p>
]]></content:encoded></item><item><title>Agent Guard Secret Guardrails</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/agent-guard-secret-guardrails/</link><pubDate>Wed, 01 Jul 2026 15:00:12 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/agent-guard-secret-guardrails/</guid><description>Version updated for https://github.com/JeongJaeSoon/agent-guard to version v1.5.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat(detection): broaden output secret recall (JWT, bearer, more env keys) by @JeongJaeSoon in https://github.com/JeongJaeSoon/agent-guard/pull/85 feat(shell): mask ! shell-escape output via agent-guard exec + shell-init by @JeongJaeSoon in https://github.com/JeongJaeSoon/agent-guard/pull/86 release: v1.5.0 by @github-actions[bot] in https://github.com/JeongJaeSoon/agent-guard/pull/88 Full Changelog: https://github.com/JeongJaeSoon/agent-guard/compare/v1.4.0...v1.5.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/JeongJaeSoon/agent-guard">https://github.com/JeongJaeSoon/agent-guard</a></strong> to version <strong>v1.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-guard-secret-guardrails">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat(detection): broaden output secret recall (JWT, bearer, more env keys) by @JeongJaeSoon in <a href="https://github.com/JeongJaeSoon/agent-guard/pull/85">https://github.com/JeongJaeSoon/agent-guard/pull/85</a></li>
<li>feat(shell): mask ! shell-escape output via agent-guard exec + shell-init by @JeongJaeSoon in <a href="https://github.com/JeongJaeSoon/agent-guard/pull/86">https://github.com/JeongJaeSoon/agent-guard/pull/86</a></li>
<li>release: v1.5.0 by @github-actions[bot] in <a href="https://github.com/JeongJaeSoon/agent-guard/pull/88">https://github.com/JeongJaeSoon/agent-guard/pull/88</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/JeongJaeSoon/agent-guard/compare/v1.4.0...v1.5.0">https://github.com/JeongJaeSoon/agent-guard/compare/v1.4.0...v1.5.0</a></p>
]]></content:encoded></item><item><title>datamodel-code-generator</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/datamodel-code-generator/</link><pubDate>Wed, 01 Jul 2026 14:59:39 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/datamodel-code-generator/</guid><description>Version updated for https://github.com/koxudaxi/datamodel-code-generator to version 0.66.2.
This action is used across all versions by 3,234 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed Update CHANGELOG for 0.66.1 by @dcg-generated-docs[bot] in https://github.com/koxudaxi/datamodel-code-generator/pull/3507 Update release benchmark data by @dcg-generated-docs[bot] in https://github.com/koxudaxi/datamodel-code-generator/pull/3508 Add Modular to Used by list by @koxudaxi in https://github.com/koxudaxi/datamodel-code-generator/pull/3509 Add Pydantic missing sentinel option by @koxudaxi in https://github.com/koxudaxi/datamodel-code-generator/pull/3510 Full Changelog: https://github.com/koxudaxi/datamodel-code-generator/compare/0.66.1...0.66.2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/koxudaxi/datamodel-code-generator">https://github.com/koxudaxi/datamodel-code-generator</a></strong> to version <strong>0.66.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3,234</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/datamodel-code-generator">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>Update CHANGELOG for 0.66.1 by @dcg-generated-docs[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3507">https://github.com/koxudaxi/datamodel-code-generator/pull/3507</a></li>
<li>Update release benchmark data by @dcg-generated-docs[bot] in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3508">https://github.com/koxudaxi/datamodel-code-generator/pull/3508</a></li>
<li>Add Modular to Used by list by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3509">https://github.com/koxudaxi/datamodel-code-generator/pull/3509</a></li>
<li>Add Pydantic missing sentinel option by @koxudaxi in <a href="https://github.com/koxudaxi/datamodel-code-generator/pull/3510">https://github.com/koxudaxi/datamodel-code-generator/pull/3510</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/koxudaxi/datamodel-code-generator/compare/0.66.1...0.66.2">https://github.com/koxudaxi/datamodel-code-generator/compare/0.66.1...0.66.2</a></p>
]]></content:encoded></item><item><title>AI Commit Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/ai-commit-review/</link><pubDate>Wed, 01 Jul 2026 14:59:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/ai-commit-review/</guid><description>Version updated for https://github.com/leek/ai-commit-review to version v1.1.6.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Allow AI commit review to continue when at least one selected provider produces a valid review. Failed providers are still reported through provider-failures and logged as warnings; the action now fails only when no selected provider completes successfully.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/leek/ai-commit-review">https://github.com/leek/ai-commit-review</a></strong> to version <strong>v1.1.6</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-commit-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Allow AI commit review to continue when at least one selected provider produces a valid review. Failed providers are still reported through provider-failures and logged as warnings; the action now fails only when no selected provider completes successfully.</p>
]]></content:encoded></item><item><title>Git Velocity Analyser</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/git-velocity-analyser/</link><pubDate>Wed, 01 Jul 2026 14:58:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/git-velocity-analyser/</guid><description>Version updated for https://github.com/lukaszraczylo/git-velocity to version v1.0.9.
This action is used across all versions by 0 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Changelog</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/lukaszraczylo/git-velocity">https://github.com/lukaszraczylo/git-velocity</a></strong> to version <strong>v1.0.9</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/git-velocity-analyser">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="changelog">Changelog</h2>
]]></content:encoded></item><item><title>lgtmaybe</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/lgtmaybe/</link><pubDate>Wed, 01 Jul 2026 14:57:58 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/lgtmaybe/</guid><description>Version updated for https://github.com/MattJColes/lgtmaybe to version lgtmaybe-v0.9.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.9.2 (2026-07-01) Bug Fixes provider: fail fast on expired cloud credentials (#162) (c56fa7d)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MattJColes/lgtmaybe">https://github.com/MattJColes/lgtmaybe</a></strong> to version <strong>lgtmaybe-v0.9.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lgtmaybe">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="092-2026-07-01"><a href="https://github.com/MattJColes/lgtmaybe/compare/lgtmaybe-v0.9.1...lgtmaybe-v0.9.2">0.9.2</a> (2026-07-01)</h2>
<h3 id="bug-fixes">Bug Fixes</h3>
<ul>
<li><strong>provider:</strong> fail fast on expired cloud credentials (<a href="https://github.com/MattJColes/lgtmaybe/issues/162">#162</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/c56fa7d39a8468127b55c9288926befa9d5c9eb8">c56fa7d</a>)</li>
</ul>
]]></content:encoded></item><item><title>Synaptic PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/synaptic-pr-review/</link><pubDate>Wed, 01 Jul 2026 14:57:25 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/synaptic-pr-review/</guid><description>Version updated for https://github.com/minhphu102003/ai-pr-review-action to version v0.0.19.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v0.0.19 Context Files Support Auto-detect architecture docs, CLAUDE.md, AGENTS.md, SOUL.md, MEMORY.md, README as review context User can specify custom context files via context_files input (comma-separated paths) Smart budget: context files only fetched when diff &amp;lt; 70K chars (15K budget for context) LLM receives context in &amp;lt;context&amp;gt; block alongside the diff for better-informed reviews Inline Comments for OpenCode Engine OpenCode engine now posts inline resolvable review comments via post-processing step post_inline.py extracts issues JSON from OpenCode review and posts as PR review comments Summary comment updated to remove duplicate key issues section Improvements Only warn for user-specified context paths, not auto-detect Diff size check for OpenCode engine before fetching context files</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/minhphu102003/ai-pr-review-action">https://github.com/minhphu102003/ai-pr-review-action</a></strong> to version <strong>v0.0.19</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/synaptic-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="v0019">v0.0.19</h2>
<h3 id="context-files-support">Context Files Support</h3>
<ul>
<li>Auto-detect architecture docs, CLAUDE.md, AGENTS.md, SOUL.md, MEMORY.md, README as review context</li>
<li>User can specify custom context files via <code>context_files</code> input (comma-separated paths)</li>
<li>Smart budget: context files only fetched when diff &lt; 70K chars (15K budget for context)</li>
<li>LLM receives context in <code>&lt;context&gt;</code> block alongside the diff for better-informed reviews</li>
</ul>
<h3 id="inline-comments-for-opencode-engine">Inline Comments for OpenCode Engine</h3>
<ul>
<li>OpenCode engine now posts inline resolvable review comments via post-processing step</li>
<li><code>post_inline.py</code> extracts issues JSON from OpenCode review and posts as PR review comments</li>
<li>Summary comment updated to remove duplicate key issues section</li>
</ul>
<h3 id="improvements">Improvements</h3>
<ul>
<li>Only warn for user-specified context paths, not auto-detect</li>
<li>Diff size check for OpenCode engine before fetching context files</li>
</ul>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/totem-shield/</link><pubDate>Wed, 01 Jul 2026 14:56:52 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.87.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Cohort-link bump (no direct package changes). See .changeset/config.json for the fixed-cohort definition.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.87.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>Suppress Ratchet</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/suppress-ratchet/</link><pubDate>Wed, 01 Jul 2026 14:56:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/suppress-ratchet/</guid><description>Version updated for https://github.com/motchalini-llc/suppress-ratchet to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed feat: initial Suppress Ratchet action — gate linter suppressions (Python + TS) (7d9b6e0)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/motchalini-llc/suppress-ratchet">https://github.com/motchalini-llc/suppress-ratchet</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/suppress-ratchet">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>feat: initial Suppress Ratchet action — gate linter suppressions (Python + TS) (7d9b6e0)</li>
</ul>
]]></content:encoded></item><item><title>Themis PR Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/themis-pr-gate/</link><pubDate>Wed, 01 Jul 2026 14:55:44 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/themis-pr-gate/</guid><description>Version updated for https://github.com/Pheoxy/themis to version v1.0.2.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Summary Themis v1.0.2 is a patch release for GitHub Marketplace publication metadata.
Changed GitHub Action Marketplace display name changed from Themis to Themis PR Gate so it satisfies GitHub Marketplace’s global action-name uniqueness requirement. Stable GitHub Action examples now reference Pheoxy/themis@v1.0.2. Documentation now explains why the Marketplace display name differs from the project name. Verification Completed before tagging:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Pheoxy/themis">https://github.com/Pheoxy/themis</a></strong> to version <strong>v1.0.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/themis-pr-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="summary">Summary</h2>
<p>Themis v1.0.2 is a patch release for GitHub Marketplace publication metadata.</p>
<h2 id="changed">Changed</h2>
<ul>
<li>GitHub Action Marketplace display name changed from <code>Themis</code> to <code>Themis PR Gate</code> so it satisfies GitHub Marketplace&rsquo;s global action-name uniqueness requirement.</li>
<li>Stable GitHub Action examples now reference <code>Pheoxy/themis@v1.0.2</code>.</li>
<li>Documentation now explains why the Marketplace display name differs from the project name.</li>
</ul>
<h2 id="verification">Verification</h2>
<p>Completed before tagging:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>nix flake check
</span></span><span style="display:flex;"><span>nix run . -- release check
</span></span><span style="display:flex;"><span>nix run . -- release audit --history --format markdown
</span></span><span style="display:flex;"><span>nix run . -- self-check --repo . --base HEAD~1 --body-file examples/pr-body.md --evidence <span style="color:#e6db74">&#34;nix flake check passed&#34;</span> --human --run-checks
</span></span><span style="display:flex;"><span>git tag -v v1.0.2
</span></span></code></pre></div><p>Results:</p>
<ul>
<li><code>nix flake check</code>: pass</li>
<li><code>release check</code>: pass</li>
<li><code>release audit --history</code>: pass</li>
<li><code>self-check</code>: pass</li>
<li>signed tag verification: pass</li>
</ul>
<h2 id="github-action-smoke-test">GitHub Action Smoke Test</h2>
<ul>
<li>Workflow: <code>Themis Smoke</code></li>
<li>Run: <a href="https://github.com/Pheoxy/themis/actions/runs/28502185507">https://github.com/Pheoxy/themis/actions/runs/28502185507</a></li>
<li>Result: success</li>
<li>Commit tested: <code>a338cab9ca7afc7c450db79ca82e391c86f30655</code></li>
</ul>
<h2 id="tag-release-workflow">Tag Release Workflow</h2>
<ul>
<li>Workflow: <code>Release</code></li>
<li>Run: <a href="https://github.com/Pheoxy/themis/actions/runs/28502309852">https://github.com/Pheoxy/themis/actions/runs/28502309852</a></li>
<li>Result: success</li>
<li>Tag: <code>v1.0.2</code></li>
</ul>
<h2 id="upgrade-notes">Upgrade Notes</h2>
<p>Use <code>Pheoxy/themis@v1.0.2</code> in GitHub workflows for stable action pinning.</p>
<h2 id="marketplace-notes">Marketplace Notes</h2>
<p>Publish this release to the GitHub Marketplace using the display name <code>Themis PR Gate</code>.</p>
<h2 id="non-guarantees">Non-Guarantees</h2>
<p>Themis is a pre-upstream readiness gate. Passing Themis or this release&rsquo;s checks does not certify code correctness, security, licensing, legal compliance, or upstream acceptance.</p>
<h2 id="links">Links</h2>
<ul>
<li>Changelog: <a href="https://github.com/Pheoxy/themis/blob/v1.0.2/CHANGELOG.md">https://github.com/Pheoxy/themis/blob/v1.0.2/CHANGELOG.md</a></li>
<li>Documentation: <a href="https://github.com/Pheoxy/themis#readme">https://github.com/Pheoxy/themis#readme</a></li>
<li>Release tag: <a href="https://github.com/Pheoxy/themis/releases/tag/v1.0.2">https://github.com/Pheoxy/themis/releases/tag/v1.0.2</a></li>
</ul>
]]></content:encoded></item><item><title>Polygraph MCP gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/polygraph-mcp-gate/</link><pubDate>Wed, 01 Jul 2026 14:55:11 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/polygraph-mcp-gate/</guid><description>Version updated for https://github.com/polygraphso/litmus to version litmus-v0.22.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Minor release shipping two changes from a false-positive review of the harness:
#78 fix(c02) — the C-02 egress D rationale is now actionable: it names the undeclared host(s) and points authors at polygraph.egress, and the CLI itemizes them. Messaging only — every server’s letter grade is byte-identical. #79 feat(sandbox) — pypi/uvx MCP servers are now gradeable under the Docker sandbox. They stage wheels-only into a venv (no target code runs during staging; fails closed on sdist), resolve offline, and launch with the venv python. Both the connect and C-02 egress paths support pypi; gVisor runtime parity preserved. methodologyVersion is unchanged (litmus-v10) — a pypi server is graded by the same rubric as an npm one.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/polygraphso/litmus">https://github.com/polygraphso/litmus</a></strong> to version <strong>litmus-v0.22.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/polygraph-mcp-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Minor release shipping two changes from a false-positive review of the harness:</p>
<ul>
<li><strong>#78 <code>fix(c02)</code></strong> — the C-02 egress <strong>D</strong> rationale is now actionable: it names the undeclared host(s) and points authors at <code>polygraph.egress</code>, and the CLI itemizes them. Messaging only — every server&rsquo;s letter grade is byte-identical.</li>
<li><strong>#79 <code>feat(sandbox)</code></strong> — <strong>pypi/uvx MCP servers are now gradeable under the Docker sandbox</strong>. They stage wheels-only into a venv (no target code runs during staging; fails closed on sdist), resolve offline, and launch with the venv python. Both the connect and C-02 egress paths support pypi; gVisor runtime parity preserved.</li>
</ul>
<p><code>methodologyVersion</code> is unchanged (<code>litmus-v10</code>) — a pypi server is graded by the same rubric as an npm one.</p>
]]></content:encoded></item><item><title>Remyx Outrider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/remyx-outrider/</link><pubDate>Wed, 01 Jul 2026 14:54:38 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/remyx-outrider/</guid><description>Version updated for https://github.com/remyxai/outrider to version v1.6.34.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed When the agentic selection call fails (429, timeout, unparseable output), Outrider’s fallback picks the highest-relevance candidate. Ties on relevance were previously broken by list position — Python’s max() returns the first element at the max value.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remyxai/outrider">https://github.com/remyxai/outrider</a></strong> to version <strong>v1.6.34</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/remyx-outrider">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>When the agentic selection call fails (429, timeout, unparseable output), Outrider&rsquo;s fallback picks the highest-relevance candidate. Ties on relevance were previously broken by list position — Python&rsquo;s <code>max()</code> returns the first element at the max value.</p>
<h2 id="fix">Fix</h2>
<p>Ties now break by <code>license_compat</code>. A permissive candidate with a code link (compat=1.00) beats a no-code-link candidate (compat=0.30) at the same relevance.</p>
<h2 id="motivating-case">Motivating case</h2>
<p>GLM C-arm study batch, 2026-06-30: unsloth run hit a selection 429 and the fallback picked a no-code-link candidate over a permissive alternative at the same relevance. Fires exactly when we least want it — the fallback path is where the primary reasoning is unavailable and the safer default matters most.</p>
<p>Fixes REMYX-169.</p>
]]></content:encoded></item><item><title>MaintainerOps AI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/maintainerops-ai/</link><pubDate>Wed, 01 Jul 2026 14:54:05 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/maintainerops-ai/</guid><description>Version updated for https://github.com/rtonf/maintainerops-ai to version v0.1.11.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed v0.1.11 npm Provenance Metadata Repair MaintainerOps AI v0.1.11 is a publishing metadata repair release after v0.1.10 reached npm Trusted Publishing but failed provenance validation.
Fix Adds package.json repository.url with https://github.com/rtonf/maintainerops-ai. Keeps the npm Trusted Publishing workflow tokenless and provenance-backed. Preserves the v0.1.10 model-backed eval, label normalization, and release workflow changes. Verification Plan npm run verify GitHub PR checks and post-merge CodeQL Publish GitHub Release v0.1.11 Confirm the npm Trusted Publishing workflow publishes maintainerops-ai@0.1.11 Verify: npm view maintainerops-ai version dist-tags time --json npm exec --yes --package maintainerops-ai@latest -- maintainerops --help</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rtonf/maintainerops-ai">https://github.com/rtonf/maintainerops-ai</a></strong> to version <strong>v0.1.11</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/maintainerops-ai">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h1 id="v0111-npm-provenance-metadata-repair">v0.1.11 npm Provenance Metadata Repair</h1>
<p>MaintainerOps AI <code>v0.1.11</code> is a publishing metadata repair release after <code>v0.1.10</code> reached npm Trusted Publishing but failed provenance validation.</p>
<h2 id="fix">Fix</h2>
<ul>
<li>Adds <code>package.json</code> <code>repository.url</code> with <code>https://github.com/rtonf/maintainerops-ai</code>.</li>
<li>Keeps the npm Trusted Publishing workflow tokenless and provenance-backed.</li>
<li>Preserves the <code>v0.1.10</code> model-backed eval, label normalization, and release workflow changes.</li>
</ul>
<h2 id="verification-plan">Verification Plan</h2>
<ul>
<li><code>npm run verify</code></li>
<li>GitHub PR checks and post-merge CodeQL</li>
<li>Publish GitHub Release <code>v0.1.11</code></li>
<li>Confirm the npm Trusted Publishing workflow publishes <code>maintainerops-ai@0.1.11</code></li>
<li>Verify:</li>
</ul>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>npm view maintainerops-ai version dist-tags time --json
</span></span><span style="display:flex;"><span>npm exec --yes --package maintainerops-ai@latest -- maintainerops --help
</span></span></code></pre></div>]]></content:encoded></item><item><title>RsMetaCheck</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/rsmetacheck/</link><pubDate>Wed, 01 Jul 2026 14:53:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/rsmetacheck/</guid><description>Version updated for https://github.com/SoftwareUnderstanding/rs-metacheck-action to version 0.3.4.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed entry point typo to use the latest RSMetaCheck version by @francoto</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/SoftwareUnderstanding/rs-metacheck-action">https://github.com/SoftwareUnderstanding/rs-metacheck-action</a></strong> to version <strong>0.3.4</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rsmetacheck">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>Fixed entry point typo to use the latest RSMetaCheck version by @francoto</li>
</ul>
]]></content:encoded></item><item><title>danger-ruby-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/danger-ruby-action/</link><pubDate>Wed, 01 Jul 2026 14:52:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/danger-ruby-action/</guid><description>Version updated for https://github.com/tdrk18/danger-action to version v1.1.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed New Inputs Added 6 new inputs to expose missing Danger CLI options:
fail-on-errors — Always fail the build when Danger reports errors (--fail-on-errors) fail-if-no-pr — Fail the build if no PR is found (--fail-if-no-pr) new-comment — Post a new comment instead of editing the previous one (--new-comment) remove-previous-comments — Remove all previous comments and post a new one (--remove-previous-comments) base — Branch/tag/commit to use as the base of the diff (--base) head — Branch/tag/commit to use as the head of the diff (--head) All new inputs are optional and default to their Danger defaults, so existing workflows are unaffected.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tdrk18/danger-action">https://github.com/tdrk18/danger-action</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/danger-ruby-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<h3 id="new-inputs">New Inputs</h3>
<p>Added 6 new inputs to expose missing Danger CLI options:</p>
<ul>
<li><code>fail-on-errors</code> — Always fail the build when Danger reports errors (<code>--fail-on-errors</code>)</li>
<li><code>fail-if-no-pr</code> — Fail the build if no PR is found (<code>--fail-if-no-pr</code>)</li>
<li><code>new-comment</code> — Post a new comment instead of editing the previous one (<code>--new-comment</code>)</li>
<li><code>remove-previous-comments</code> — Remove all previous comments and post a new one (<code>--remove-previous-comments</code>)</li>
<li><code>base</code> — Branch/tag/commit to use as the base of the diff (<code>--base</code>)</li>
<li><code>head</code> — Branch/tag/commit to use as the head of the diff (<code>--head</code>)</li>
</ul>
<p>All new inputs are optional and default to their Danger defaults, so existing workflows are unaffected.</p>
]]></content:encoded></item><item><title>Crosspost Action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/crosspost-action/</link><pubDate>Wed, 01 Jul 2026 14:52:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/crosspost-action/</guid><description>Version updated for https://github.com/tgagor/action-crosspost to version v1.6.5.
This action is used across all versions by 3 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 1.6.5 (2026-07-01)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/tgagor/action-crosspost">https://github.com/tgagor/action-crosspost</a></strong> to version <strong>v1.6.5</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>3</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/crosspost-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="165-2026-07-01"><a href="https://github.com/tgagor/action-crosspost/compare/v1.6.4...v1.6.5">1.6.5</a> (2026-07-01)</h3>
]]></content:encoded></item><item><title>Polder Drift — Design System Drift Alerts</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/polder-drift-design-system-drift-alerts/</link><pubDate>Wed, 01 Jul 2026 14:51:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/polder-drift-design-system-drift-alerts/</guid><description>Version updated for https://github.com/usepolder/drift to version v1.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed fix: review findings — shallow-checkout false-new (#8) + hardening by @jongjesse in https://github.com/usepolder/drift/pull/2 test: re-home Carbon/MUI integration tests (vendored fixtures + DS devDeps) by @jongjesse in https://github.com/usepolder/drift/pull/3 chore: repo polish (CodeRabbit config, CONTRIBUTING, badges) by @jongjesse in https://github.com/usepolder/drift/pull/1 Fix glob translation: leading/embedded **/ matches zero or more dirs by @jongjesse in https://github.com/usepolder/drift/pull/4 Fix unit-inconsistent adoption metric: count drifted components, not findings by @jongjesse in https://github.com/usepolder/drift/pull/5 fix: surface comment-post failures instead of swallowing them by @jongjesse in https://github.com/usepolder/drift/pull/6 chore: prep v1 for GitHub Marketplace publish by @jongjesse in https://github.com/usepolder/drift/pull/8 fix: paginate GitHub issue-comment lookup to avoid duplicate comments by @jongjesse in https://github.com/usepolder/drift/pull/7 New Contributors @jongjesse made their first contribution in https://github.com/usepolder/drift/pull/2 Full Changelog: https://github.com/usepolder/drift/commits/v1.0.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/usepolder/drift">https://github.com/usepolder/drift</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/polder-drift-design-system-drift-alerts">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>fix: review findings — shallow-checkout false-new (#8) + hardening by @jongjesse in <a href="https://github.com/usepolder/drift/pull/2">https://github.com/usepolder/drift/pull/2</a></li>
<li>test: re-home Carbon/MUI integration tests (vendored fixtures + DS devDeps) by @jongjesse in <a href="https://github.com/usepolder/drift/pull/3">https://github.com/usepolder/drift/pull/3</a></li>
<li>chore: repo polish (CodeRabbit config, CONTRIBUTING, badges) by @jongjesse in <a href="https://github.com/usepolder/drift/pull/1">https://github.com/usepolder/drift/pull/1</a></li>
<li>Fix glob translation: leading/embedded <code>**/</code> matches zero or more dirs by @jongjesse in <a href="https://github.com/usepolder/drift/pull/4">https://github.com/usepolder/drift/pull/4</a></li>
<li>Fix unit-inconsistent adoption metric: count drifted components, not findings by @jongjesse in <a href="https://github.com/usepolder/drift/pull/5">https://github.com/usepolder/drift/pull/5</a></li>
<li>fix: surface comment-post failures instead of swallowing them by @jongjesse in <a href="https://github.com/usepolder/drift/pull/6">https://github.com/usepolder/drift/pull/6</a></li>
<li>chore: prep v1 for GitHub Marketplace publish by @jongjesse in <a href="https://github.com/usepolder/drift/pull/8">https://github.com/usepolder/drift/pull/8</a></li>
<li>fix: paginate GitHub issue-comment lookup to avoid duplicate comments by @jongjesse in <a href="https://github.com/usepolder/drift/pull/7">https://github.com/usepolder/drift/pull/7</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@jongjesse made their first contribution in <a href="https://github.com/usepolder/drift/pull/2">https://github.com/usepolder/drift/pull/2</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/usepolder/drift/commits/v1.0.0">https://github.com/usepolder/drift/commits/v1.0.0</a></p>
]]></content:encoded></item><item><title>RepoScope Security &amp; Compliance Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/reposcope-security-compliance-scanner/</link><pubDate>Wed, 01 Jul 2026 14:51:16 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/reposcope-security-compliance-scanner/</guid><description>Version updated for https://github.com/xdun1698/reposcope-action to version v1.0.0.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed RepoScope Security &amp;amp; Compliance Scanner v1.0.0 First public release — run RepoScope’s scanner in CI to catch security issues and generate audit-ready compliance evidence on every push and pull request.
What’s included 44 security detectors across 14 languages — hardcoded secrets, SQL injection, XSS, command injection, TLS misconfigs, weak crypto, permissive CORS Inline PR review comments — one per finding with file, line, severity, CWE ID, and fix hint GitHub Check run — PASS/FAIL with a configurable score threshold and annotations on high/critical findings Compliance report artifact — HTML report mapping findings to OWASP Top 10, SOC 2 Type II, PCI-DSS v4.0, EU AI Act Article 12, and ISO/IEC 42001 Configurable build gate — fail-on severity and score threshold Inline suppression via reposcope-ignore comments Setup instructions and all inputs/outputs are in the README.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/xdun1698/reposcope-action">https://github.com/xdun1698/reposcope-action</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/reposcope-security-compliance-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="reposcope-security--compliance-scanner-v100">RepoScope Security &amp; Compliance Scanner v1.0.0</h2>
<p>First public release — run RepoScope&rsquo;s scanner in CI to catch security issues and generate audit-ready compliance evidence on every push and pull request.</p>
<h3 id="whats-included">What&rsquo;s included</h3>
<ul>
<li><strong>44 security detectors across 14 languages</strong> — hardcoded secrets, SQL injection, XSS, command injection, TLS misconfigs, weak crypto, permissive CORS</li>
<li><strong>Inline PR review comments</strong> — one per finding with file, line, severity, CWE ID, and fix hint</li>
<li><strong>GitHub Check run</strong> — PASS/FAIL with a configurable score threshold and annotations on high/critical findings</li>
<li><strong>Compliance report artifact</strong> — HTML report mapping findings to OWASP Top 10, SOC 2 Type II, PCI-DSS v4.0, EU AI Act Article 12, and ISO/IEC 42001</li>
<li><strong>Configurable build gate</strong> — <code>fail-on</code> severity and score <code>threshold</code></li>
<li><strong>Inline suppression</strong> via <code>reposcope-ignore</code> comments</li>
</ul>
<p>Setup instructions and all inputs/outputs are in the <a href="https://github.com/xdun1698/reposcope-action#readme">README</a>.</p>
<hr>
<p><em>By <a href="https://reposcope.app">NxGen Tech Solutions</a>. Code-level controls only — a development aid, not a certification tool.</em></p>
]]></content:encoded></item><item><title>gmc — Google Merchant Center CLI</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/gmc-google-merchant-center-cli/</link><pubDate>Wed, 01 Jul 2026 14:50:10 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/gmc-google-merchant-center-cli/</guid><description>Version updated for https://github.com/yasserstudio/gmc to version v1.0.16.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed gmc ordertracking — Order Tracking sub-API (ordertracking/v1) Adds gmc ordertracking — the Order Tracking sub-API (accounts.orderTrackingSignals). This was the last remaining GA (v1) Merchant API sub-API, so the stable v1 surface is now fully covered (12 GA sub-APIs).</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yasserstudio/gmc">https://github.com/yasserstudio/gmc</a></strong> to version <strong>v1.0.16</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/gmc-google-merchant-center-cli">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="gmc-ordertracking--order-tracking-sub-api-ordertrackingv1"><code>gmc ordertracking</code> — Order Tracking sub-API (<code>ordertracking/v1</code>)</h2>
<p>Adds <code>gmc ordertracking</code> — the <strong>Order Tracking</strong> sub-API (<code>accounts.orderTrackingSignals</code>). This was the last remaining GA (<code>v1</code>) Merchant API sub-API, so <strong>the stable v1 surface is now fully covered (12 GA sub-APIs).</strong></p>
<p>Order tracking signals report completed shipments so Google can show accurate delivery estimates. The sub-API is <strong>write-only</strong> — a signal is immutable once created (no get/list/update/delete).</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>gmc ordertracking create --file signal.json
</span></span><span style="display:flex;"><span>cat signal.json | gmc ordertracking create        <span style="color:#75715e"># or via stdin</span>
</span></span><span style="display:flex;"><span>gmc ordertracking create --file signal.json --merchant-id <span style="color:#ae81ff">555</span>
</span></span></code></pre></div><ul>
<li>Reads the <code>OrderTrackingSignal</code> from <code>--file</code>/stdin, validates the required fields (<code>orderId</code>, non-empty <code>shippingInfo</code>, non-empty <code>lineItems</code>) <strong>offline by shape</strong> so malformed input fails fast instead of as an opaque 400.</li>
<li>Strips the output-only <code>orderTrackingSignalId</code>; supports <code>--merchant-id</code> to attribute a signal on behalf of another business.</li>
<li>Wire shape verified against the <code>ordertracking/v1</code> proto (<code>POST .../orderTrackingSignals</code>, signal as the body, no <code>dataSource</code>).</li>
</ul>
<p><code>reviews</code>, <code>productstudio</code>, and <code>youtube</code> remain pre-GA (<code>v1beta</code>/<code>v1alpha</code>) and are deferred until they graduate to <code>v1</code>.</p>
<p><strong>Packages:</strong> <code>@gmc-cli/cli</code> 1.0.16 · <code>@gmc-cli/api</code> 0.9.21 · <code>@gmc-cli/auth</code> 0.7.3</p>
]]></content:encoded></item><item><title>EcoTrace Carbon Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/ecotrace-carbon-gate/</link><pubDate>Wed, 01 Jul 2026 14:49:37 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/ecotrace-carbon-gate/</guid><description>Version updated for https://github.com/Zwony/ecotrace to version v1.4.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed EcoTrace v1.4.0 Released: 2026-07-01 Type: Feature Release — 6 new features, 4 bug fixes, zero breaking changes
New Features Pausable Tracking API (pause() / esume()) Pause and resume carbon tracking to isolate your code’s emissions from setup/teardown overhead.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Zwony/ecotrace">https://github.com/Zwony/ecotrace</a></strong> to version <strong>v1.4.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ecotrace-carbon-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="ecotrace-v140">EcoTrace v1.4.0</h2>
<p><strong>Released:</strong> 2026-07-01
<strong>Type:</strong> Feature Release — 6 new features, 4 bug fixes, zero breaking changes</p>
<hr>
<h2 id="new-features">New Features</h2>
<h3 id="pausable-tracking-api-pause-">Pausable Tracking API (pause() /</h3>
<p>esume())
Pause and resume carbon tracking to isolate your code&rsquo;s emissions from setup/teardown overhead.</p>
<p>\\python
eco.pause()
expensive_setup_io()
eco.resume()
\\</p>
<h3 id="side-by-side-run-comparisons-ecotrace-diff">Side-by-Side Run Comparisons (ecotrace diff)</h3>
<p>Compare any two tracking runs directly from the terminal.</p>
<p>\\ash
ecotrace diff abc123def456 789012abc345
ecotrace diff &ndash;latest
\\</p>
<h3 id="webhook-observability-exporter-webhookexporter">Webhook Observability Exporter (WebhookExporter)</h3>
<p>Stream carbon data to Slack, MS Teams, Discord, or any custom API in real-time.</p>
<p>\\python
from ecotrace.exporters.webhook import WebhookExporter
WebhookExporter(eco, url=&lsquo;<a href="https://hooks.slack.com/services/...'">https://hooks.slack.com/services/...'</a>)
\\</p>
<h3 id="filtered-csv-exporting">Filtered CSV Exporting</h3>
<p>Extended \ecotrace export\ with --csv\ format and --run/--func\ filters.</p>
<p>\\ash
ecotrace export &ndash;csv -o filtered.csv &ndash;run abc123
\\</p>
<h3 id="log-maintenance-ecotrace-clean--ecotrace-reset">Log Maintenance (ecotrace clean &amp; ecotrace reset)</h3>
<p>\\ash
ecotrace clean &ndash;keep-runs 10
ecotrace clean &ndash;before 2026-06-01
ecotrace reset &ndash;yes
\\</p>
<hr>
<h2 id="bug-fixes">Bug Fixes</h2>
<ul>
<li><strong>ML Callbacks Carbon Calculation:</strong> Fixed duplicate carbon calculation in Keras and PyTorch callbacks</li>
<li><strong>Empty GPU monitoring crash:</strong> Guarded \EcoTraceML\ shutdown against empty GPU monitor histories</li>
<li><strong>Async Hotspots:</strong> Restored file path and line number tracking in \measure_async()\</li>
<li><strong>CPU caching performance:</strong> Eliminated duplicate \cpuinfo\ calls in \get_cpu_info\</li>
</ul>
<hr>
<h2 id="install--upgrade">Install / Upgrade</h2>
<p>\\ash
pip install &ndash;upgrade ecotrace
\\</p>
<p>Full documentation: <a href="https://github.com/Zwony/ecotrace">https://github.com/Zwony/ecotrace</a></p>
]]></content:encoded></item><item><title>HOL Codex Plugin Scanner</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/hol-codex-plugin-scanner/</link><pubDate>Wed, 01 Jul 2026 07:02:48 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/hol-codex-plugin-scanner/</guid><description>Version updated for https://github.com/hashgraph-online/hol-codex-plugin-scanner-action to version v1.2.355.
This action is used across all versions by 10 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.355</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action</a></strong> to version <strong>v1.2.355</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>10</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/hol-codex-plugin-scanner">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.355">https://github.com/hashgraph-online/hol-codex-plugin-scanner-action/compare/v1...v1.2.355</a></p>
]]></content:encoded></item><item><title>Holon Solve</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/holon-solve/</link><pubDate>Wed, 01 Jul 2026 07:02:15 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/holon-solve/</guid><description>Version updated for https://github.com/holon-run/holon to version v0.25.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Runtime line Holon v0.25.0 is part of the Rust runtime line. The Rust runtime is now the main holon binary.
This release adds a Bing Web Search provider with managed WebSearch tool kept alongside native search, an external trigger token-only storage model with reset-callback API, and trigger revocation on agent stop. It also fixes max_turns counting, coerce_string JSON-string parsing for tool arguments, callback_base_url/advertise_url decoupling, and skill install for non-flat catalog layouts. The memory indexer is redesigned as a single daemon with outbox cleanup, and SQLite connection init gains PRAGMA tuning for better performance.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/holon-run/holon">https://github.com/holon-run/holon</a></strong> to version <strong>v0.25.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/holon-solve">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="runtime-line">Runtime line</h2>
<p>Holon v0.25.0 is part of the Rust runtime line. The Rust runtime is now the main <code>holon</code> binary.</p>
<p>This release adds a Bing Web Search provider with managed WebSearch tool kept alongside native search, an external trigger token-only storage model with reset-callback API, and trigger revocation on agent stop. It also fixes max_turns counting, coerce_string JSON-string parsing for tool arguments, callback_base_url/advertise_url decoupling, and skill install for non-flat catalog layouts. The memory indexer is redesigned as a single daemon with outbox cleanup, and SQLite connection init gains PRAGMA tuning for better performance.</p>
<p>Supported binary assets for this release are Linux amd64, macOS amd64, and macOS arm64.</p>
<h2 id="changes">Changes</h2>
<ul>
<li>Add Bing Web Search provider and keep managed WebSearch alongside native search (<a href="https://github.com/holon-run/holon/pull/2075">#2075</a>).</li>
<li>Store external trigger token only, add reset-callback API (<a href="https://github.com/holon-run/holon/pull/2072">#2072</a>).</li>
<li>Revoke external triggers when agent is stopped (<a href="https://github.com/holon-run/holon/pull/2074">#2074</a>).</li>
<li>Parse JSON-string arrays/objects in coerce_string for tool arguments (<a href="https://github.com/holon-run/holon/pull/2073">#2073</a>).</li>
<li>Fix max_turns counter to use turn_index instead of total_model_rounds (<a href="https://github.com/holon-run/holon/pull/2070">#2070</a>).</li>
<li>Emit first-run intro when provider is configured (<a href="https://github.com/holon-run/holon/pull/2069">#2069</a>).</li>
<li>Decouple callback_base_url from advertise_url (<a href="https://github.com/holon-run/holon/pull/2068">#2068</a>).</li>
<li>Support non-flat catalog layouts and non-main default branches in skill install (<a href="https://github.com/holon-run/holon/pull/2067">#2067</a>).</li>
<li>Redesign memory indexer to single daemon with outbox cleanup (<a href="https://github.com/holon-run/holon/pull/2061">#2061</a>).</li>
<li>Add SQLite PRAGMA tuning to connection init for performance (<a href="https://github.com/holon-run/holon/pull/2063">#2063</a>).</li>
</ul>
<h2 id="install">Install</h2>
<p>Homebrew:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>brew tap holon-run/tap
</span></span><span style="display:flex;"><span>brew install holon
</span></span></code></pre></div><p>Direct binary:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>curl -L <span style="color:#e6db74">&#34;https://github.com/holon-run/holon/releases/download/v0.25.0/holon-linux-amd64.tar.gz&#34;</span> | tar -xz
</span></span><span style="display:flex;"><span>chmod +x holon
</span></span><span style="display:flex;"><span>./holon --help
</span></span></code></pre></div><p>Replace <code>holon-linux-amd64.tar.gz</code> with <code>holon-darwin-amd64.tar.gz</code> or <code>holon-darwin-arm64.tar.gz</code> on macOS.</p>
]]></content:encoded></item><item><title>lgtmaybe</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/lgtmaybe/</link><pubDate>Wed, 01 Jul 2026 07:01:43 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/lgtmaybe/</guid><description>Version updated for https://github.com/MattJColes/lgtmaybe to version lgtmaybe-v0.9.1.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed 0.9.1 (2026-07-01) Documentation streamline install + local-model guides (#160) (6425ad3)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/MattJColes/lgtmaybe">https://github.com/MattJColes/lgtmaybe</a></strong> to version <strong>lgtmaybe-v0.9.1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/lgtmaybe">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="091-2026-07-01"><a href="https://github.com/MattJColes/lgtmaybe/compare/lgtmaybe-v0.9.0...lgtmaybe-v0.9.1">0.9.1</a> (2026-07-01)</h2>
<h3 id="documentation">Documentation</h3>
<ul>
<li>streamline install + local-model guides (<a href="https://github.com/MattJColes/lgtmaybe/issues/160">#160</a>) (<a href="https://github.com/MattJColes/lgtmaybe/commit/6425ad30e2adc866fb5001d4a8a0c3ae791ecea4">6425ad3</a>)</li>
</ul>
]]></content:encoded></item><item><title>Totem Shield</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/totem-shield/</link><pubDate>Wed, 01 Jul 2026 07:01:09 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/totem-shield/</guid><description>Version updated for https://github.com/mmnto-ai/totem to version @mmnto/pack-rust-architecture@1.86.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Cohort-link bump (no direct package changes). See .changeset/config.json for the fixed-cohort definition.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/mmnto-ai/totem">https://github.com/mmnto-ai/totem</a></strong> to version <strong>@mmnto/pack-rust-architecture@1.86.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/totem-shield">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><em>Cohort-link bump (no direct package changes). See <code>.changeset/config.json</code> for the fixed-cohort definition.</em></p>
]]></content:encoded></item><item><title>agent-bom Scan</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/agent-bom-scan/</link><pubDate>Wed, 01 Jul 2026 07:00:36 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/agent-bom-scan/</guid><description>Version updated for https://github.com/msaad00/agent-bom to version v0.91.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed docs(release): 0.90.1 hygiene — soften SCA framing, fix stale pins, README callouts by @msaad00 in https://github.com/msaad00/agent-bom/pull/3314 fix(sca): honor NVD CPE inclusive/exclusive version bounds exactly by @msaad00 in https://github.com/msaad00/agent-bom/pull/3315 fix(output): surface match_confidence_tier across SARIF, JSON, HTML by @msaad00 in https://github.com/msaad00/agent-bom/pull/3317 fix(release): harden post-0.90 audit findings by @msaad00 in https://github.com/msaad00/agent-bom/pull/3316 fix(output): carry match_confidence_tier on the JSON blast_radius rollup by @msaad00 in https://github.com/msaad00/agent-bom/pull/3319 fix(ui): fail fast offline and polish README how-it-works diagram by @msaad00 in https://github.com/msaad00/agent-bom/pull/3318 fix(sca): make NVD capped sync ingest its unsynced tail across runs by @msaad00 in https://github.com/msaad00/agent-bom/pull/3320 fix(version): correct post-release regex and prerelease ordering in version compare by @msaad00 in https://github.com/msaad00/agent-bom/pull/3330 fix(graph): keep cross-page attack paths in filtered /graph by @msaad00 in https://github.com/msaad00/agent-bom/pull/3321 fix(cli): fail-close –fail-on-severity on unknown/none findings by @msaad00 in https://github.com/msaad00/agent-bom/pull/3322 fix(mcp): emit canonical OWASP codes from tool-abuse rules by @msaad00 in https://github.com/msaad00/agent-bom/pull/3323 fix(sarif): de-duplicate cloud CIS failures in SARIF output by @msaad00 in https://github.com/msaad00/agent-bom/pull/3324 fix(inventory): keep distinct MCP servers distinct across identity, enrichment, and Cortex audit by @msaad00 in https://github.com/msaad00/agent-bom/pull/3325 chore(deps): combine UI dependency updates by @msaad00 in https://github.com/msaad00/agent-bom/pull/3337 fix(model-scan): close pickle-scan size gate and memo evasion by @msaad00 in https://github.com/msaad00/agent-bom/pull/3326 fix(version): honor tagged bounds for Go pseudo-versions by @msaad00 in https://github.com/msaad00/agent-bom/pull/3327 fix(image): warn on legacy rpmdb instead of silent zero coverage by @msaad00 in https://github.com/msaad00/agent-bom/pull/3328 fix(mcp): block SSRF in repo scan and offload clone off the event loop by @msaad00 in https://github.com/msaad00/agent-bom/pull/3329 feat(ui): design-system foundation — Collapsible, Card/Section, entity icons, vendor logos, state primitives by @msaad00 in https://github.com/msaad00/agent-bom/pull/3338 fix(sca): harden OSV/NVD/KEV/GHSA sync + SQLite concurrency (availability) by @msaad00 in https://github.com/msaad00/agent-bom/pull/3339 feat(ui): real connections experience — vendor logos + connector cards wired to backend by @msaad00 in https://github.com/msaad00/agent-bom/pull/3340 fix(api): bind audit tenant server-side, harden rate-limit identity + global ceiling by @msaad00 in https://github.com/msaad00/agent-bom/pull/3341 fix(output): dedup CycloneDX components + scope finding id by package by @msaad00 in https://github.com/msaad00/agent-bom/pull/3342 fix(ui): align connections screenshot spec with redesigned headings by @msaad00 in https://github.com/msaad00/agent-bom/pull/3344 feat: capability-depth — reachability→CVE, perf, identity owner-binding, FinOps rates, SBOM attestation/SPDX2 by @msaad00 in https://github.com/msaad00/agent-bom/pull/3346 feat(ui): declutter, capability-driven IA, interaction-state fixes, real trust stack by @msaad00 in https://github.com/msaad00/agent-bom/pull/3347 feat(gateway): OAuth 2.1 AS conformance + inline A2A mutual-auth enforcement + per-tool-call scope/DLP by @msaad00 in https://github.com/msaad00/agent-bom/pull/3348 chore(release): v0.91.0 by @msaad00 in https://github.com/msaad00/agent-bom/pull/3349 Full Changelog: https://github.com/msaad00/agent-bom/compare/v0.90.0...v0.91.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/msaad00/agent-bom">https://github.com/msaad00/agent-bom</a></strong> to version <strong>v0.91.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/agent-bom-scan">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>docs(release): 0.90.1 hygiene — soften SCA framing, fix stale pins, README callouts by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3314">https://github.com/msaad00/agent-bom/pull/3314</a></li>
<li>fix(sca): honor NVD CPE inclusive/exclusive version bounds exactly by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3315">https://github.com/msaad00/agent-bom/pull/3315</a></li>
<li>fix(output): surface match_confidence_tier across SARIF, JSON, HTML by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3317">https://github.com/msaad00/agent-bom/pull/3317</a></li>
<li>fix(release): harden post-0.90 audit findings by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3316">https://github.com/msaad00/agent-bom/pull/3316</a></li>
<li>fix(output): carry match_confidence_tier on the JSON blast_radius rollup by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3319">https://github.com/msaad00/agent-bom/pull/3319</a></li>
<li>fix(ui): fail fast offline and polish README how-it-works diagram by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3318">https://github.com/msaad00/agent-bom/pull/3318</a></li>
<li>fix(sca): make NVD capped sync ingest its unsynced tail across runs by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3320">https://github.com/msaad00/agent-bom/pull/3320</a></li>
<li>fix(version): correct post-release regex and prerelease ordering in version compare by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3330">https://github.com/msaad00/agent-bom/pull/3330</a></li>
<li>fix(graph): keep cross-page attack paths in filtered /graph by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3321">https://github.com/msaad00/agent-bom/pull/3321</a></li>
<li>fix(cli): fail-close &ndash;fail-on-severity on unknown/none findings by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3322">https://github.com/msaad00/agent-bom/pull/3322</a></li>
<li>fix(mcp): emit canonical OWASP codes from tool-abuse rules by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3323">https://github.com/msaad00/agent-bom/pull/3323</a></li>
<li>fix(sarif): de-duplicate cloud CIS failures in SARIF output by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3324">https://github.com/msaad00/agent-bom/pull/3324</a></li>
<li>fix(inventory): keep distinct MCP servers distinct across identity, enrichment, and Cortex audit by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3325">https://github.com/msaad00/agent-bom/pull/3325</a></li>
<li>chore(deps): combine UI dependency updates by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3337">https://github.com/msaad00/agent-bom/pull/3337</a></li>
<li>fix(model-scan): close pickle-scan size gate and memo evasion by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3326">https://github.com/msaad00/agent-bom/pull/3326</a></li>
<li>fix(version): honor tagged bounds for Go pseudo-versions by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3327">https://github.com/msaad00/agent-bom/pull/3327</a></li>
<li>fix(image): warn on legacy rpmdb instead of silent zero coverage by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3328">https://github.com/msaad00/agent-bom/pull/3328</a></li>
<li>fix(mcp): block SSRF in repo scan and offload clone off the event loop by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3329">https://github.com/msaad00/agent-bom/pull/3329</a></li>
<li>feat(ui): design-system foundation — Collapsible, Card/Section, entity icons, vendor logos, state primitives by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3338">https://github.com/msaad00/agent-bom/pull/3338</a></li>
<li>fix(sca): harden OSV/NVD/KEV/GHSA sync + SQLite concurrency (availability) by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3339">https://github.com/msaad00/agent-bom/pull/3339</a></li>
<li>feat(ui): real connections experience — vendor logos + connector cards wired to backend by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3340">https://github.com/msaad00/agent-bom/pull/3340</a></li>
<li>fix(api): bind audit tenant server-side, harden rate-limit identity + global ceiling by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3341">https://github.com/msaad00/agent-bom/pull/3341</a></li>
<li>fix(output): dedup CycloneDX components + scope finding id by package by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3342">https://github.com/msaad00/agent-bom/pull/3342</a></li>
<li>fix(ui): align connections screenshot spec with redesigned headings by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3344">https://github.com/msaad00/agent-bom/pull/3344</a></li>
<li>feat: capability-depth — reachability→CVE, perf, identity owner-binding, FinOps rates, SBOM attestation/SPDX2 by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3346">https://github.com/msaad00/agent-bom/pull/3346</a></li>
<li>feat(ui): declutter, capability-driven IA, interaction-state fixes, real trust stack by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3347">https://github.com/msaad00/agent-bom/pull/3347</a></li>
<li>feat(gateway): OAuth 2.1 AS conformance + inline A2A mutual-auth enforcement + per-tool-call scope/DLP by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3348">https://github.com/msaad00/agent-bom/pull/3348</a></li>
<li>chore(release): v0.91.0 by @msaad00 in <a href="https://github.com/msaad00/agent-bom/pull/3349">https://github.com/msaad00/agent-bom/pull/3349</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/msaad00/agent-bom/compare/v0.90.0...v0.91.0">https://github.com/msaad00/agent-bom/compare/v0.90.0...v0.91.0</a></p>
]]></content:encoded></item><item><title>Codeowners Plus</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/codeowners-plus/</link><pubDate>Wed, 01 Jul 2026 07:00:04 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/codeowners-plus/</guid><description>Version updated for https://github.com/multimediallc/codeowners-plus to version v1.10.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed v1.9.1 by @BakerNet in https://github.com/multimediallc/codeowners-plus/pull/133 Add gomodUpdateImportPaths to renovate config by @BakerNet in https://github.com/multimediallc/codeowners-plus/pull/135 dev: Update module github.com/google/go-github/v85 to v86 by @mm-renovate-bot[bot] in https://github.com/multimediallc/codeowners-plus/pull/125 Fully support sha pinning + remove docker from runtime. by @Icantjuddle in https://github.com/multimediallc/codeowners-plus/pull/143 Fix goreleaser trigger by @BakerNet in https://github.com/multimediallc/codeowners-plus/pull/146 ci: trigger goreleaser on tag push, create draft release by @BakerNet in https://github.com/multimediallc/codeowners-plus/pull/148 fix: action path has infixed ./ for local action runs by @BakerNet in https://github.com/multimediallc/codeowners-plus/pull/149 Bump the gomod group across 1 directory with 2 updates by @dependabot[bot] in https://github.com/multimediallc/codeowners-plus/pull/151 dev: Update actions/checkout action to v7 by @mm-renovate-bot[bot] in https://github.com/multimediallc/codeowners-plus/pull/153 dev: Update golangci/golangci-lint-action action to v9.2.1 by @mm-renovate-bot[bot] in https://github.com/multimediallc/codeowners-plus/pull/140 Example workflow fixes by @kolayne in https://github.com/multimediallc/codeowners-plus/pull/150 Add the config.disable_review_status_comments config option by @kolayne in https://github.com/multimediallc/codeowners-plus/pull/160 Bump the github-actions group with 2 updates by @dependabot[bot] in https://github.com/multimediallc/codeowners-plus/pull/156 Bump the gomod group with 2 updates by @dependabot[bot] in https://github.com/multimediallc/codeowners-plus/pull/157 fix: Make sort order deterministic by @BakerNet in https://github.com/multimediallc/codeowners-plus/pull/162 New Contributors @kolayne made their first contribution in https://github.com/multimediallc/codeowners-plus/pull/150 Full Changelog: https://github.com/multimediallc/codeowners-plus/compare/v1.9.1...v1.10.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/multimediallc/codeowners-plus">https://github.com/multimediallc/codeowners-plus</a></strong> to version <strong>v1.10.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/codeowners-plus">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>v1.9.1 by @BakerNet in <a href="https://github.com/multimediallc/codeowners-plus/pull/133">https://github.com/multimediallc/codeowners-plus/pull/133</a></li>
<li>Add gomodUpdateImportPaths to renovate config by @BakerNet in <a href="https://github.com/multimediallc/codeowners-plus/pull/135">https://github.com/multimediallc/codeowners-plus/pull/135</a></li>
<li>dev: Update module github.com/google/go-github/v85 to v86 by @mm-renovate-bot[bot] in <a href="https://github.com/multimediallc/codeowners-plus/pull/125">https://github.com/multimediallc/codeowners-plus/pull/125</a></li>
<li>Fully support sha pinning + remove docker from runtime.  by @Icantjuddle in <a href="https://github.com/multimediallc/codeowners-plus/pull/143">https://github.com/multimediallc/codeowners-plus/pull/143</a></li>
<li>Fix goreleaser trigger by @BakerNet in <a href="https://github.com/multimediallc/codeowners-plus/pull/146">https://github.com/multimediallc/codeowners-plus/pull/146</a></li>
<li>ci: trigger goreleaser on tag push, create draft release by @BakerNet in <a href="https://github.com/multimediallc/codeowners-plus/pull/148">https://github.com/multimediallc/codeowners-plus/pull/148</a></li>
<li>fix: action path has infixed <code>./</code> for local action runs by @BakerNet in <a href="https://github.com/multimediallc/codeowners-plus/pull/149">https://github.com/multimediallc/codeowners-plus/pull/149</a></li>
<li>Bump the gomod group across 1 directory with 2 updates by @dependabot[bot] in <a href="https://github.com/multimediallc/codeowners-plus/pull/151">https://github.com/multimediallc/codeowners-plus/pull/151</a></li>
<li>dev: Update actions/checkout action to v7 by @mm-renovate-bot[bot] in <a href="https://github.com/multimediallc/codeowners-plus/pull/153">https://github.com/multimediallc/codeowners-plus/pull/153</a></li>
<li>dev: Update golangci/golangci-lint-action action to v9.2.1 by @mm-renovate-bot[bot] in <a href="https://github.com/multimediallc/codeowners-plus/pull/140">https://github.com/multimediallc/codeowners-plus/pull/140</a></li>
<li>Example workflow fixes by @kolayne in <a href="https://github.com/multimediallc/codeowners-plus/pull/150">https://github.com/multimediallc/codeowners-plus/pull/150</a></li>
<li>Add the <code>config.disable_review_status_comments</code> config option by @kolayne in <a href="https://github.com/multimediallc/codeowners-plus/pull/160">https://github.com/multimediallc/codeowners-plus/pull/160</a></li>
<li>Bump the github-actions group with 2 updates by @dependabot[bot] in <a href="https://github.com/multimediallc/codeowners-plus/pull/156">https://github.com/multimediallc/codeowners-plus/pull/156</a></li>
<li>Bump the gomod group with 2 updates by @dependabot[bot] in <a href="https://github.com/multimediallc/codeowners-plus/pull/157">https://github.com/multimediallc/codeowners-plus/pull/157</a></li>
<li>fix: Make sort order deterministic by @BakerNet in <a href="https://github.com/multimediallc/codeowners-plus/pull/162">https://github.com/multimediallc/codeowners-plus/pull/162</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@kolayne made their first contribution in <a href="https://github.com/multimediallc/codeowners-plus/pull/150">https://github.com/multimediallc/codeowners-plus/pull/150</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/multimediallc/codeowners-plus/compare/v1.9.1...v1.10.0">https://github.com/multimediallc/codeowners-plus/compare/v1.9.1...v1.10.0</a></p>
]]></content:encoded></item><item><title>AI Cost Receipt</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/ai-cost-receipt/</link><pubDate>Wed, 01 Jul 2026 06:59:31 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/ai-cost-receipt/</guid><description>Version updated for https://github.com/noah-thing/receipt to version v0.5.0.
This action is used across all versions by ? repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Builds on 0.4.0’s session health with automation, history, and a reviewer-facing note.
receipt guard — a Claude Code hook entrypoint. Stays silent until a session crosses your gate, then prints the single most important move where the agent sees it. With --notify it exits 2 so Claude Code feeds the nudge back to the model — strongest on the PreCompact hook, right before lossy auto-compaction. receipt health --json / --quiet --gate — machine-readable output and severity exit codes (0 / 10 watch / 20 degrading / 30 critical) for hooks and CI. receipt health --all — scores every past session and learns your personal pattern (“you tend to drift around turn ~12; X% of sessions compacted too late”). Context tax — shows how much of a session is just re-sending itself (the quadratic cost behind both rising spend and fading quality). PR-comment health note — a collapsed, reviewer-facing &amp;lt;details&amp;gt; block when the work ran under degrading conditions; silent otherwise; opt out with &amp;#34;health&amp;#34;: false. It never claims the code is wrong — only points to where to look. Honest constraint: the token-only ledger cannot detect redundant file reads, identical-command loops, or semantic issues (hallucinations, drift) — those need data Receipt deliberately never stores. Features only ever flag “conditions correlated with drift,” documented in docs/SESSION-HEALTH.md.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/noah-thing/receipt">https://github.com/noah-thing/receipt</a></strong> to version <strong>v0.5.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/ai-cost-receipt">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Builds on 0.4.0&rsquo;s session health with automation, history, and a reviewer-facing note.</p>
<ul>
<li><strong><code>receipt guard</code></strong> — a Claude Code hook entrypoint. Stays silent until a session crosses your gate, then prints the single most important move where the agent sees it. With <code>--notify</code> it exits 2 so Claude Code feeds the nudge back to the model — strongest on the <code>PreCompact</code> hook, right before lossy auto-compaction.</li>
<li><strong><code>receipt health --json</code> / <code>--quiet --gate</code></strong> — machine-readable output and severity exit codes (0 / 10 watch / 20 degrading / 30 critical) for hooks and CI.</li>
<li><strong><code>receipt health --all</code></strong> — scores every past session and learns your personal pattern (&ldquo;you tend to drift around turn ~12; X% of sessions compacted too late&rdquo;).</li>
<li><strong>Context tax</strong> — shows how much of a session is just re-sending itself (the quadratic cost behind both rising spend and fading quality).</li>
<li><strong>PR-comment health note</strong> — a collapsed, reviewer-facing <code>&lt;details&gt;</code> block when the work ran under degrading conditions; silent otherwise; opt out with <code>&quot;health&quot;: false</code>. It never claims the code is wrong — only points to where to look.</li>
</ul>
<p><strong>Honest constraint:</strong> the token-only ledger cannot detect redundant file reads, identical-command loops, or semantic issues (hallucinations, drift) — those need data Receipt deliberately never stores. Features only ever flag &ldquo;conditions correlated with drift,&rdquo; documented in docs/SESSION-HEALTH.md.</p>
<p>Still deterministic and local. 104 tests, typecheck clean. MIT.</p>
]]></content:encoded></item><item><title>Run AER Tests</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/run-aer-tests/</link><pubDate>Wed, 01 Jul 2026 06:58:57 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/run-aer-tests/</guid><description>Version updated for https://github.com/octoberswimmer/aer-dist to version v1.2.3.
This publisher is shown as ‘verified’ by GitHub.
This action is used across all versions by 0 repositories.
Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Version v1.2.3
Add Downloaded aer To Integrated Terminal PATH
Publish Platform Events Created By Flows And Stamp Generated-Code Line Numbers
Fix Flow Line-Info Backfill And Skip Time-Based Scheduled Paths In Tests</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/octoberswimmer/aer-dist">https://github.com/octoberswimmer/aer-dist</a></strong> to version <strong>v1.2.3</strong>.</p>
<ul>
<li>
<p>This publisher is shown as &lsquo;verified&rsquo; by GitHub.</p>
</li>
<li>
<p>This action is used across all versions by <strong>0</strong> repositories.</p>
</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/run-aer-tests">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Version v1.2.3</p>
<ul>
<li>
<p>Add Downloaded aer To Integrated Terminal PATH</p>
</li>
<li>
<p>Publish Platform Events Created By Flows And Stamp Generated-Code Line Numbers</p>
</li>
<li>
<p>Fix Flow Line-Info Backfill And Skip Time-Based Scheduled Paths In Tests</p>
</li>
</ul>
]]></content:encoded></item><item><title>Postman API Onboarding</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/postman-api-onboarding/</link><pubDate>Wed, 01 Jul 2026 06:58:24 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/postman-api-onboarding/</guid><description>Version updated for https://github.com/postman-cs/postman-api-onboarding-action to version v2.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed feat: skip+warn built-in tests without api key + access-token-primary docs by @jaredboynton in https://github.com/postman-cs/postman-api-onboarding-action/pull/56 Full Changelog: https://github.com/postman-cs/postman-api-onboarding-action/compare/v1...v2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-api-onboarding-action">https://github.com/postman-cs/postman-api-onboarding-action</a></strong> to version <strong>v2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-api-onboarding">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>feat: skip+warn built-in tests without api key + access-token-primary docs by @jaredboynton in <a href="https://github.com/postman-cs/postman-api-onboarding-action/pull/56">https://github.com/postman-cs/postman-api-onboarding-action/pull/56</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-api-onboarding-action/compare/v1...v2">https://github.com/postman-cs/postman-api-onboarding-action/compare/v1...v2</a></p>
]]></content:encoded></item><item><title>Postman Onboarding AWS Spec Discovery</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/postman-onboarding-aws-spec-discovery/</link><pubDate>Wed, 01 Jul 2026 06:57:51 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/postman-onboarding-aws-spec-discovery/</guid><description>Version updated for https://github.com/postman-cs/postman-aws-spec-discovery-action to version v2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps-dev): bump @commitlint/config-conventional from 20.5.3 to 21.0.2 by @dependabot[bot] in https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/13 chore(deps): bump the npm-minor-patch group across 1 directory with 21 updates by @dependabot[bot] in https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/10 chore(deps): bump the actions group across 1 directory with 3 updates by @dependabot[bot] in https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/9 chore(deps-dev): bump @commitlint/cli from 20.5.3 to 21.0.2 by @dependabot[bot] in https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/12 feat: optional access-token telemetry account_type by @jaredboynton in https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/23 New Contributors @dependabot[bot] made their first contribution in https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/13 Full Changelog: https://github.com/postman-cs/postman-aws-spec-discovery-action/compare/v1...v2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-aws-spec-discovery-action">https://github.com/postman-cs/postman-aws-spec-discovery-action</a></strong> to version <strong>v2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-aws-spec-discovery">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps-dev): bump @commitlint/config-conventional from 20.5.3 to 21.0.2 by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/13">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/13</a></li>
<li>chore(deps): bump the npm-minor-patch group across 1 directory with 21 updates by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/10">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/10</a></li>
<li>chore(deps): bump the actions group across 1 directory with 3 updates by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/9">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/9</a></li>
<li>chore(deps-dev): bump @commitlint/cli from 20.5.3 to 21.0.2 by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/12">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/12</a></li>
<li>feat: optional access-token telemetry account_type by @jaredboynton in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/23">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/23</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/13">https://github.com/postman-cs/postman-aws-spec-discovery-action/pull/13</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-aws-spec-discovery-action/compare/v1...v2">https://github.com/postman-cs/postman-aws-spec-discovery-action/compare/v1...v2</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Workspace Bootstrap</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/postman-onboarding-workspace-bootstrap/</link><pubDate>Wed, 01 Jul 2026 06:57:18 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/postman-onboarding-workspace-bootstrap/</guid><description>Version updated for https://github.com/postman-cs/postman-bootstrap-action to version v2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps-dev): bump @commitlint/cli from 20.5.3 to 21.0.2 by @dependabot[bot] in https://github.com/postman-cs/postman-bootstrap-action/pull/48 chore(deps): bump the actions group across 1 directory with 3 updates by @dependabot[bot] in https://github.com/postman-cs/postman-bootstrap-action/pull/44 chore(deps-dev): bump @commitlint/config-conventional from 20.5.3 to 21.0.2 by @dependabot[bot] in https://github.com/postman-cs/postman-bootstrap-action/pull/46 chore: add workflow_dispatch trigger to CI workflow by @andrewpostymt in https://github.com/postman-cs/postman-bootstrap-action/pull/36 ci: harden e2e gate waiter against transient GitHub API failures by @jaredboynton in https://github.com/postman-cs/postman-bootstrap-action/pull/59 feat: sync additional local collections by @andrewpostymt in https://github.com/postman-cs/postman-bootstrap-action/pull/61 feat: access-token gateway migration + EC v3 multiprotocol collections by @jaredboynton in https://github.com/postman-cs/postman-bootstrap-action/pull/64 Full Changelog: https://github.com/postman-cs/postman-bootstrap-action/compare/v1...v2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-bootstrap-action">https://github.com/postman-cs/postman-bootstrap-action</a></strong> to version <strong>v2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-workspace-bootstrap">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps-dev): bump @commitlint/cli from 20.5.3 to 21.0.2 by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/48">https://github.com/postman-cs/postman-bootstrap-action/pull/48</a></li>
<li>chore(deps): bump the actions group across 1 directory with 3 updates by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/44">https://github.com/postman-cs/postman-bootstrap-action/pull/44</a></li>
<li>chore(deps-dev): bump @commitlint/config-conventional from 20.5.3 to 21.0.2 by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/46">https://github.com/postman-cs/postman-bootstrap-action/pull/46</a></li>
<li>chore: add workflow_dispatch trigger to CI workflow by @andrewpostymt in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/36">https://github.com/postman-cs/postman-bootstrap-action/pull/36</a></li>
<li>ci: harden e2e gate waiter against transient GitHub API failures by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/59">https://github.com/postman-cs/postman-bootstrap-action/pull/59</a></li>
<li>feat: sync additional local collections by @andrewpostymt in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/61">https://github.com/postman-cs/postman-bootstrap-action/pull/61</a></li>
<li>feat: access-token gateway migration + EC v3 multiprotocol collections by @jaredboynton in <a href="https://github.com/postman-cs/postman-bootstrap-action/pull/64">https://github.com/postman-cs/postman-bootstrap-action/pull/64</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-bootstrap-action/compare/v1...v2">https://github.com/postman-cs/postman-bootstrap-action/compare/v1...v2</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Insights Linking</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/postman-onboarding-insights-linking/</link><pubDate>Wed, 01 Jul 2026 06:56:45 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/postman-onboarding-insights-linking/</guid><description>Version updated for https://github.com/postman-cs/postman-insights-onboarding-action to version v2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps-dev): bump @commitlint/config-conventional from 20.5.3 to 21.0.2 by @dependabot[bot] in https://github.com/postman-cs/postman-insights-onboarding-action/pull/26 chore(deps-dev): bump the npm-minor-patch group across 1 directory with 2 updates by @dependabot[bot] in https://github.com/postman-cs/postman-insights-onboarding-action/pull/24 chore(deps): bump the actions group with 3 updates by @dependabot[bot] in https://github.com/postman-cs/postman-insights-onboarding-action/pull/23 chore(deps-dev): bump @commitlint/cli from 20.5.3 to 21.0.2 by @dependabot[bot] in https://github.com/postman-cs/postman-insights-onboarding-action/pull/25 fix: implement support for xray key matching by @hiqbal-postman in https://github.com/postman-cs/postman-insights-onboarding-action/pull/10 feat: thread access-token re-mint through Bifrost catalog client by @jaredboynton in https://github.com/postman-cs/postman-insights-onboarding-action/pull/36 New Contributors @dependabot[bot] made their first contribution in https://github.com/postman-cs/postman-insights-onboarding-action/pull/26 @hiqbal-postman made their first contribution in https://github.com/postman-cs/postman-insights-onboarding-action/pull/10 Full Changelog: https://github.com/postman-cs/postman-insights-onboarding-action/compare/v1...v2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-insights-onboarding-action">https://github.com/postman-cs/postman-insights-onboarding-action</a></strong> to version <strong>v2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-insights-linking">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps-dev): bump @commitlint/config-conventional from 20.5.3 to 21.0.2 by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/26">https://github.com/postman-cs/postman-insights-onboarding-action/pull/26</a></li>
<li>chore(deps-dev): bump the npm-minor-patch group across 1 directory with 2 updates by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/24">https://github.com/postman-cs/postman-insights-onboarding-action/pull/24</a></li>
<li>chore(deps): bump the actions group with 3 updates by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/23">https://github.com/postman-cs/postman-insights-onboarding-action/pull/23</a></li>
<li>chore(deps-dev): bump @commitlint/cli from 20.5.3 to 21.0.2 by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/25">https://github.com/postman-cs/postman-insights-onboarding-action/pull/25</a></li>
<li>fix: implement support for xray key matching by @hiqbal-postman in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/10">https://github.com/postman-cs/postman-insights-onboarding-action/pull/10</a></li>
<li>feat: thread access-token re-mint through Bifrost catalog client by @jaredboynton in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/36">https://github.com/postman-cs/postman-insights-onboarding-action/pull/36</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/26">https://github.com/postman-cs/postman-insights-onboarding-action/pull/26</a></li>
<li>@hiqbal-postman made their first contribution in <a href="https://github.com/postman-cs/postman-insights-onboarding-action/pull/10">https://github.com/postman-cs/postman-insights-onboarding-action/pull/10</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-insights-onboarding-action/compare/v1...v2">https://github.com/postman-cs/postman-insights-onboarding-action/compare/v1...v2</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Repo Sync</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/postman-onboarding-repo-sync/</link><pubDate>Wed, 01 Jul 2026 06:56:08 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/postman-onboarding-repo-sync/</guid><description>Version updated for https://github.com/postman-cs/postman-repo-sync-action to version v2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps-dev): bump @commitlint/config-conventional from 20.5.3 to 21.0.2 by @dependabot[bot] in https://github.com/postman-cs/postman-repo-sync-action/pull/40 chore(deps-dev): bump @commitlint/cli from 20.5.3 to 21.0.2 by @dependabot[bot] in https://github.com/postman-cs/postman-repo-sync-action/pull/39 fix: pass CI_ENVIRONMENT key to postman collection run env-var flag by @jaredboynton in https://github.com/postman-cs/postman-repo-sync-action/pull/49 ci: harden e2e gate waiter against transient GitHub API failures by @jaredboynton in https://github.com/postman-cs/postman-repo-sync-action/pull/54 feat: add Azure DevOps repo sync support by @andrewpostymt in https://github.com/postman-cs/postman-repo-sync-action/pull/58 feat: access-token gateway routing + @postman v3 converter cutover by @jaredboynton in https://github.com/postman-cs/postman-repo-sync-action/pull/61 New Contributors @andrewpostymt made their first contribution in https://github.com/postman-cs/postman-repo-sync-action/pull/58 Full Changelog: https://github.com/postman-cs/postman-repo-sync-action/compare/v1...v2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-repo-sync-action">https://github.com/postman-cs/postman-repo-sync-action</a></strong> to version <strong>v2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-repo-sync">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps-dev): bump @commitlint/config-conventional from 20.5.3 to 21.0.2 by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/40">https://github.com/postman-cs/postman-repo-sync-action/pull/40</a></li>
<li>chore(deps-dev): bump @commitlint/cli from 20.5.3 to 21.0.2 by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/39">https://github.com/postman-cs/postman-repo-sync-action/pull/39</a></li>
<li>fix: pass CI_ENVIRONMENT key to postman collection run env-var flag by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/49">https://github.com/postman-cs/postman-repo-sync-action/pull/49</a></li>
<li>ci: harden e2e gate waiter against transient GitHub API failures by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/54">https://github.com/postman-cs/postman-repo-sync-action/pull/54</a></li>
<li>feat: add Azure DevOps repo sync support by @andrewpostymt in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/58">https://github.com/postman-cs/postman-repo-sync-action/pull/58</a></li>
<li>feat: access-token gateway routing + @postman v3 converter cutover by @jaredboynton in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/61">https://github.com/postman-cs/postman-repo-sync-action/pull/61</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@andrewpostymt made their first contribution in <a href="https://github.com/postman-cs/postman-repo-sync-action/pull/58">https://github.com/postman-cs/postman-repo-sync-action/pull/58</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-repo-sync-action/compare/v1...v2">https://github.com/postman-cs/postman-repo-sync-action/compare/v1...v2</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Service Token</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/postman-onboarding-service-token/</link><pubDate>Wed, 01 Jul 2026 06:55:35 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/postman-onboarding-service-token/</guid><description>Version updated for https://github.com/postman-cs/postman-resolve-service-token-action to version v2.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps-dev): bump the npm-minor-patch group across 1 directory with 2 updates by @dependabot[bot] in https://github.com/postman-cs/postman-resolve-service-token-action/pull/10 chore(deps): bump the actions group with 3 updates by @dependabot[bot] in https://github.com/postman-cs/postman-resolve-service-token-action/pull/9 ci: harden e2e gate waiter against transient GitHub API failures by @jaredboynton in https://github.com/postman-cs/postman-resolve-service-token-action/pull/17 New Contributors @dependabot[bot] made their first contribution in https://github.com/postman-cs/postman-resolve-service-token-action/pull/10 Full Changelog: https://github.com/postman-cs/postman-resolve-service-token-action/compare/v1...v2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-resolve-service-token-action">https://github.com/postman-cs/postman-resolve-service-token-action</a></strong> to version <strong>v2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-service-token">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps-dev): bump the npm-minor-patch group across 1 directory with 2 updates by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/10">https://github.com/postman-cs/postman-resolve-service-token-action/pull/10</a></li>
<li>chore(deps): bump the actions group with 3 updates by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/9">https://github.com/postman-cs/postman-resolve-service-token-action/pull/9</a></li>
<li>ci: harden e2e gate waiter against transient GitHub API failures by @jaredboynton in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/17">https://github.com/postman-cs/postman-resolve-service-token-action/pull/17</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/postman-cs/postman-resolve-service-token-action/pull/10">https://github.com/postman-cs/postman-resolve-service-token-action/pull/10</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-resolve-service-token-action/compare/v1...v2">https://github.com/postman-cs/postman-resolve-service-token-action/compare/v1...v2</a></p>
]]></content:encoded></item><item><title>Postman Onboarding Smoke Flow</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/postman-onboarding-smoke-flow/</link><pubDate>Wed, 01 Jul 2026 06:55:02 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/postman-onboarding-smoke-flow/</guid><description>Version updated for https://github.com/postman-cs/postman-smoke-flow-action to version v2.0.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed build(deps-dev): bump the npm-minor-patch group across 1 directory with 2 updates by @dependabot[bot] in https://github.com/postman-cs/postman-smoke-flow-action/pull/16 build(deps): bump the actions group with 3 updates by @dependabot[bot] in https://github.com/postman-cs/postman-smoke-flow-action/pull/15 ci: harden e2e gate waiter against transient GitHub API failures by @jaredboynton in https://github.com/postman-cs/postman-smoke-flow-action/pull/23 feat: access-token-only Smoke reshape via v3 gateway by @jaredboynton in https://github.com/postman-cs/postman-smoke-flow-action/pull/28 New Contributors @dependabot[bot] made their first contribution in https://github.com/postman-cs/postman-smoke-flow-action/pull/16 Full Changelog: https://github.com/postman-cs/postman-smoke-flow-action/compare/v1...v2.0.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/postman-cs/postman-smoke-flow-action">https://github.com/postman-cs/postman-smoke-flow-action</a></strong> to version <strong>v2.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/postman-onboarding-smoke-flow">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>build(deps-dev): bump the npm-minor-patch group across 1 directory with 2 updates by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/16">https://github.com/postman-cs/postman-smoke-flow-action/pull/16</a></li>
<li>build(deps): bump the actions group with 3 updates by @dependabot[bot] in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/15">https://github.com/postman-cs/postman-smoke-flow-action/pull/15</a></li>
<li>ci: harden e2e gate waiter against transient GitHub API failures by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/23">https://github.com/postman-cs/postman-smoke-flow-action/pull/23</a></li>
<li>feat: access-token-only Smoke reshape via v3 gateway by @jaredboynton in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/28">https://github.com/postman-cs/postman-smoke-flow-action/pull/28</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@dependabot[bot] made their first contribution in <a href="https://github.com/postman-cs/postman-smoke-flow-action/pull/16">https://github.com/postman-cs/postman-smoke-flow-action/pull/16</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/postman-cs/postman-smoke-flow-action/compare/v1...v2.0.0">https://github.com/postman-cs/postman-smoke-flow-action/compare/v1...v2.0.0</a></p>
]]></content:encoded></item><item><title>Remyx Outrider</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/remyx-outrider/</link><pubDate>Wed, 01 Jul 2026 06:54:29 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/remyx-outrider/</guid><description>Version updated for https://github.com/remyxai/outrider to version v1.6.31.
This action is used across all versions by 2 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed The self-review call now honors the claude-timeout workflow input — completing the per-stage timeout consolidation begun in v1.6.28 (preflight), v1.6.29 (audit), v1.6.30 (selection). After this release, claude-timeout is the single budget knob across every Claude-Code stage in the chain.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/remyxai/outrider">https://github.com/remyxai/outrider</a></strong> to version <strong>v1.6.31</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>2</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/remyx-outrider">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>The self-review call now honors the <code>claude-timeout</code> workflow input — completing the per-stage timeout consolidation begun in v1.6.28 (preflight), v1.6.29 (audit), v1.6.30 (selection). After this release, <code>claude-timeout</code> is the single budget knob across every Claude-Code stage in the chain.</p>
<p><strong>What changed</strong></p>
<ul>
<li><code>self_review_diff</code> production call site in <code>process_target</code> now passes <code>target.claude_timeout_s</code> (was hardcoded 180s default).</li>
<li>Direct callers (tests, ad-hoc invocations) that don&rsquo;t pass an explicit <code>timeout_s</code> keep the 180s default for backwards compatibility.</li>
</ul>
<p><strong>Why it matters</strong></p>
<p>Self-review detects orphan code (new code not reachable from any production path) and downgrades a drafted PR back to Issue. On heavy diffs in large monorepos or on slower non-Anthropic backends, the previous 180s ceiling caused the pass to time out — and the chain would ship the PR without the safety-net check.</p>
<p>PR: <a href="https://github.com/remyxai/outrider/pull/79">#79</a></p>
]]></content:encoded></item><item><title>rumdl-action</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/rumdl-action/</link><pubDate>Wed, 01 Jul 2026 06:53:56 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/rumdl-action/</guid><description>Version updated for https://github.com/rvben/rumdl to version v0.2.27.
This action is used across all versions by 6 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Fixed MD077: detect latent list markers past an unstable heading (05d273e) MD013: keep reference-style links atomic when reflowing (a991a71) Downloads File Platform Checksum rumdl-v0.2.27-x86_64-unknown-linux-gnu.tar.gz Linux x86_64 checksum rumdl-v0.2.27-x86_64-unknown-linux-musl.tar.gz Linux x86_64 (musl) checksum rumdl-v0.2.27-aarch64-unknown-linux-gnu.tar.gz Linux ARM64 checksum rumdl-v0.2.27-aarch64-unknown-linux-musl.tar.gz Linux ARM64 (musl) checksum rumdl-v0.2.27-x86_64-apple-darwin.tar.gz macOS x86_64 checksum rumdl-v0.2.27-aarch64-apple-darwin.tar.gz macOS ARM64 (Apple Silicon) checksum rumdl-v0.2.27-x86_64-pc-windows-msvc.zip Windows x86_64 checksum Installation Using uv (Recommended) uv tool install rumdl Using pip pip install rumdl Using pipx pipx install rumdl Direct Download Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/rvben/rumdl">https://github.com/rvben/rumdl</a></strong> to version <strong>v0.2.27</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>6</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/rumdl-action">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h3 id="fixed">Fixed</h3>
<ul>
<li><strong>MD077</strong>: detect latent list markers past an unstable heading (<a href="https://github.com/rvben/rumdl/commit/05d273eae5636d400f97f7186eb6cabda140ecd3">05d273e</a>)</li>
<li><strong>MD013</strong>: keep reference-style links atomic when reflowing (<a href="https://github.com/rvben/rumdl/commit/a991a71c2b05a1f83cb95de95e4b96cf3c4227e8">a991a71</a>)</li>
</ul>
<h2 id="downloads">Downloads</h2>
<table>
  <thead>
      <tr>
          <th>File</th>
          <th>Platform</th>
          <th>Checksum</th>
      </tr>
  </thead>
  <tbody>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.27/rumdl-v0.2.27-x86_64-unknown-linux-gnu.tar.gz">rumdl-v0.2.27-x86_64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.27/rumdl-v0.2.27-x86_64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.27/rumdl-v0.2.27-x86_64-unknown-linux-musl.tar.gz">rumdl-v0.2.27-x86_64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux x86_64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.27/rumdl-v0.2.27-x86_64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.27/rumdl-v0.2.27-aarch64-unknown-linux-gnu.tar.gz">rumdl-v0.2.27-aarch64-unknown-linux-gnu.tar.gz</a></td>
          <td>Linux ARM64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.27/rumdl-v0.2.27-aarch64-unknown-linux-gnu.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.27/rumdl-v0.2.27-aarch64-unknown-linux-musl.tar.gz">rumdl-v0.2.27-aarch64-unknown-linux-musl.tar.gz</a></td>
          <td>Linux ARM64 (musl)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.27/rumdl-v0.2.27-aarch64-unknown-linux-musl.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.27/rumdl-v0.2.27-x86_64-apple-darwin.tar.gz">rumdl-v0.2.27-x86_64-apple-darwin.tar.gz</a></td>
          <td>macOS x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.27/rumdl-v0.2.27-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.27/rumdl-v0.2.27-aarch64-apple-darwin.tar.gz">rumdl-v0.2.27-aarch64-apple-darwin.tar.gz</a></td>
          <td>macOS ARM64 (Apple Silicon)</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.27/rumdl-v0.2.27-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td>
      </tr>
      <tr>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.27/rumdl-v0.2.27-x86_64-pc-windows-msvc.zip">rumdl-v0.2.27-x86_64-pc-windows-msvc.zip</a></td>
          <td>Windows x86_64</td>
          <td><a href="https://github.com/rvben/rumdl/releases/download/v0.2.27/rumdl-v0.2.27-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td>
      </tr>
  </tbody>
</table>
<h2 id="installation">Installation</h2>
<h3 id="using-uv-recommended">Using uv (Recommended)</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>uv tool install rumdl
</span></span></code></pre></div><h3 id="using-pip">Using pip</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pip install rumdl
</span></span></code></pre></div><h3 id="using-pipx">Using pipx</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-bash" data-lang="bash"><span style="display:flex;"><span>pipx install rumdl
</span></span></code></pre></div><h3 id="direct-download">Direct Download</h3>
<p>Download the appropriate binary for your platform from the table above, extract it, and add it to your PATH.</p>
]]></content:encoded></item><item><title>Docker Compose Cache</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/docker-compose-cache/</link><pubDate>Wed, 01 Jul 2026 06:53:23 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/docker-compose-cache/</guid><description>Version updated for https://github.com/seijikohara/docker-compose-cache-action to version v1.8.15.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed ci: fail summary jobs when upstream jobs do not succeed by @seijikohara in https://github.com/seijikohara/docker-compose-cache-action/pull/301 chore(deps): update actions/checkout action to v7 by @renovate[bot] in https://github.com/seijikohara/docker-compose-cache-action/pull/297 chore(deps): lock file maintenance by @renovate[bot] in https://github.com/seijikohara/docker-compose-cache-action/pull/302 Full Changelog: https://github.com/seijikohara/docker-compose-cache-action/compare/v1.8.14...v1.8.15</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/seijikohara/docker-compose-cache-action">https://github.com/seijikohara/docker-compose-cache-action</a></strong> to version <strong>v1.8.15</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/docker-compose-cache">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>ci: fail summary jobs when upstream jobs do not succeed by @seijikohara in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/301">https://github.com/seijikohara/docker-compose-cache-action/pull/301</a></li>
<li>chore(deps): update actions/checkout action to v7 by @renovate[bot] in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/297">https://github.com/seijikohara/docker-compose-cache-action/pull/297</a></li>
<li>chore(deps): lock file maintenance by @renovate[bot] in <a href="https://github.com/seijikohara/docker-compose-cache-action/pull/302">https://github.com/seijikohara/docker-compose-cache-action/pull/302</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/seijikohara/docker-compose-cache-action/compare/v1.8.14...v1.8.15">https://github.com/seijikohara/docker-compose-cache-action/compare/v1.8.14...v1.8.15</a></p>
]]></content:encoded></item><item><title>Satellite Deploy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/satellite-deploy/</link><pubDate>Wed, 01 Jul 2026 06:52:50 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/satellite-deploy/</guid><description>Version updated for https://github.com/snakenet-org/satellite-deploy to version v1.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 20.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Initial first release of GitHub action for the Satellite Auto-Deployment feature</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/snakenet-org/satellite-deploy">https://github.com/snakenet-org/satellite-deploy</a></strong> to version <strong>v1</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>20</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/satellite-deploy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>Initial first release of GitHub action for the Satellite Auto-Deployment feature</p>
]]></content:encoded></item><item><title>Difftron Delta Coverage Gate</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/difftron-delta-coverage-gate/</link><pubDate>Wed, 01 Jul 2026 06:52:17 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/difftron-delta-coverage-gate/</guid><description>Version updated for https://github.com/swantron/difftron to version v1.0.0.
This action is used across all versions by 1 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed First public release.
Fail a pull request when newly changed lines aren’t tested — language-agnostic delta/patch coverage for LCOV, Cobertura, and Go coverage, in a few lines of YAML.
Composite Action, builds from source — no external binary to trust</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/swantron/difftron">https://github.com/swantron/difftron</a></strong> to version <strong>v1.0.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/difftron-delta-coverage-gate">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p>First public release.</p>
<p>Fail a pull request when newly changed lines aren&rsquo;t tested — language-agnostic delta/patch coverage for LCOV, Cobertura, and Go coverage, in a few lines of YAML.</p>
<ul>
<li>
<p>Composite Action, builds from source — no external binary to trust</p>
</li>
<li>
<p>Auto-detects the PR/push diff range</p>
</li>
<li>
<p>Posts a sticky delta-coverage comment on the PR</p>
</li>
<li>
<p>Files with no coverage data (docs/config) are skipped, not failed</p>
<p>Quickstart: see examples/quickstart.yml</p>
</li>
</ul>
]]></content:encoded></item><item><title>Release Uclusion</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/release-uclusion/</link><pubDate>Wed, 01 Jul 2026 06:51:13 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/release-uclusion/</guid><description>Version updated for https://github.com/Uclusion/release-job to version v1.1.0.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed T-all-2238 Mark a job deployed only when its latest commits are on the env (ce28b48) fix: move to node 24.x (497b508) fix: link doc (92f76e8) Merge remote-tracking branch ‘origin/main’ (bcadebe) fix: space in view name (3677e82) Update README.md (e9f6d6c) feat: label releases (80fdfc6) feat: label releases (24faaeb) feat: label releases (1274acb) feat: label releases - untested (bed25f2)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Uclusion/release-job">https://github.com/Uclusion/release-job</a></strong> to version <strong>v1.1.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/release-uclusion">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>T-all-2238 Mark a job deployed only when its latest commits are on the env (ce28b48)</li>
<li>fix: move to node 24.x (497b508)</li>
<li>fix: link doc (92f76e8)</li>
<li>Merge remote-tracking branch &lsquo;origin/main&rsquo; (bcadebe)</li>
<li>fix: space in view name (3677e82)</li>
<li>Update README.md (e9f6d6c)</li>
<li>feat: label releases (80fdfc6)</li>
<li>feat: label releases (24faaeb)</li>
<li>feat: label releases (1274acb)</li>
<li>feat: label releases - untested (bed25f2)</li>
</ul>
]]></content:encoded></item><item><title>Update Uclusion</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/update-uclusion/</link><pubDate>Wed, 01 Jul 2026 06:50:40 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/update-uclusion/</guid><description>Version updated for https://github.com/Uclusion/update-job to version v1.1.2.
This action is used across all versions by 1 repositories. Action Type This is a Docker action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed T-all-2240 Make testPush a no-op smoke test (fixed no-code message) (deabf19) T-all-2238 Reconcile job deploy state on push; configurable pending label (de092bb) fix: Only extract job ids. (340d9bb) fix: move to node 24.x (a19c034) fix: move to node 24.x (ab6d493) fix: link doc (c83286a) fix: space in view name (ff4ac90) fix: space in view name (d0c570f) fix: urlencode (f66608d) fix: cleanup (93a64c0)</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/Uclusion/update-job">https://github.com/Uclusion/update-job</a></strong> to version <strong>v1.1.2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>1</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Docker</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/update-uclusion">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<ul>
<li>T-all-2240 Make testPush a no-op smoke test (fixed no-code message) (deabf19)</li>
<li>T-all-2238 Reconcile job deploy state on push; configurable pending label (de092bb)</li>
<li>fix: Only extract job ids. (340d9bb)</li>
<li>fix: move to node 24.x (a19c034)</li>
<li>fix: move to node 24.x (ab6d493)</li>
<li>fix: link doc (c83286a)</li>
<li>fix: space in view name (ff4ac90)</li>
<li>fix: space in view name (d0c570f)</li>
<li>fix: urlencode (f66608d)</li>
<li>fix: cleanup (93a64c0)</li>
</ul>
]]></content:encoded></item><item><title>MIU PR Review</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/miu-pr-review/</link><pubDate>Wed, 01 Jul 2026 06:50:06 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/miu-pr-review/</guid><description>Version updated for https://github.com/vanducng/miu-cr to version v0.81.0.
This action is used across all versions by 0 repositories. Action Type This is a Composite action.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed miu-cr v0.81.0 AI code review for local changes and GitHub pull requests. Use it as a CLI, CI gate, or GitHub Action with your own LLM key.
Install curl -fsSL https://cr.miu.sh/install.sh | sh -s -- v0.81.0 brew install vanducng/tap/miucr go install github.com/vanducng/miu-cr/cmd/miucr@v0.81.0 GitHub Action:</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/vanducng/miu-cr">https://github.com/vanducng/miu-cr</a></strong> to version <strong>v0.81.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Composite</strong> action.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/miu-pr-review">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="miu-cr-v0810">miu-cr v0.81.0</h2>
<p>AI code review for local changes and GitHub pull requests. Use it as a CLI, CI gate, or GitHub Action with your own LLM key.</p>
<h3 id="install">Install</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>curl -fsSL https://cr.miu.sh/install.sh | sh -s -- v0.81.0
</span></span><span style="display:flex;"><span>brew install vanducng/tap/miucr
</span></span><span style="display:flex;"><span>go install github.com/vanducng/miu-cr/cmd/miucr@v0.81.0
</span></span></code></pre></div><p>GitHub Action:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-yaml" data-lang="yaml"><span style="display:flex;"><span><span style="color:#f92672">permissions</span>:
</span></span><span style="display:flex;"><span>  <span style="color:#f92672">pull-requests</span>: <span style="color:#ae81ff">write</span>
</span></span><span style="display:flex;"><span>
</span></span><span style="display:flex;"><span><span style="color:#f92672">steps</span>:
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">actions/checkout@v6</span>
</span></span><span style="display:flex;"><span>  - <span style="color:#f92672">uses</span>: <span style="color:#ae81ff">vanducng/miu-cr@v0.81.0</span>
</span></span><span style="display:flex;"><span>    <span style="color:#f92672">with</span>:
</span></span><span style="display:flex;"><span>      <span style="color:#f92672">api-key</span>: <span style="color:#ae81ff">${{ secrets.ANTHROPIC_API_KEY }}</span>
</span></span></code></pre></div><h3 id="common-commands">Common commands</h3>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-sh" data-lang="sh"><span style="display:flex;"><span>miucr login --provider openai
</span></span><span style="display:flex;"><span>miucr review --staged
</span></span><span style="display:flex;"><span>miucr review --from main --to HEAD --gate high
</span></span><span style="display:flex;"><span>miucr review --pr owner/repo#123 --post
</span></span><span style="display:flex;"><span>miucr upgrade
</span></span></code></pre></div><p>Docs: <a href="https://cr.miu.sh">https://cr.miu.sh</a></p>
]]></content:encoded></item><item><title>Setup vp</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/setup-vp/</link><pubDate>Wed, 01 Jul 2026 06:49:33 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/setup-vp/</guid><description>Version updated for https://github.com/voidzero-dev/setup-vp to version v1.13.0.
This action is used across all versions by 0 repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed What’s Changed chore(deps): update dependency vite-plus to v0.1.24 by @renovate[bot] in https://github.com/voidzero-dev/setup-vp/pull/78 chore(deps): update vite+ to v0.1.24 by @renovate[bot] in https://github.com/voidzero-dev/setup-vp/pull/79 chore(deps): update github actions to v3.24 by @renovate[bot] in https://github.com/voidzero-dev/setup-vp/pull/80 test: add Node 20 to node-version matrix (expected red until Vite+ supports it) by @fengmk2 in https://github.com/voidzero-dev/setup-vp/pull/84 chore(deps): upgrade vite-plus to 0.2.1 by @fengmk2 in https://github.com/voidzero-dev/setup-vp/pull/85 docs: update shared agent guidance by @jong-kyung in https://github.com/voidzero-dev/setup-vp/pull/89 chore: switch input schemas to zod mini by @jong-kyung in https://github.com/voidzero-dev/setup-vp/pull/98 chore(deps): update dependency @actions/cache to v6.1.0 by @renovate[bot] in https://github.com/voidzero-dev/setup-vp/pull/86 chore(deps): update pnpm to v11.9.0 by @renovate[bot] in https://github.com/voidzero-dev/setup-vp/pull/99 fix: install pkg.pr.new preview builds via VP_PR_VERSION by @fengmk2 in https://github.com/voidzero-dev/setup-vp/pull/100 New Contributors @jong-kyung made their first contribution in https://github.com/voidzero-dev/setup-vp/pull/89 Full Changelog: https://github.com/voidzero-dev/setup-vp/compare/v1.12.0...v1.13.0</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/voidzero-dev/setup-vp">https://github.com/voidzero-dev/setup-vp</a></strong> to version <strong>v1.13.0</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>0</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/setup-vp">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<h2 id="whats-changed-1">What&rsquo;s Changed</h2>
<ul>
<li>chore(deps): update dependency vite-plus to v0.1.24 by @renovate[bot] in <a href="https://github.com/voidzero-dev/setup-vp/pull/78">https://github.com/voidzero-dev/setup-vp/pull/78</a></li>
<li>chore(deps): update vite+ to v0.1.24 by @renovate[bot] in <a href="https://github.com/voidzero-dev/setup-vp/pull/79">https://github.com/voidzero-dev/setup-vp/pull/79</a></li>
<li>chore(deps): update github actions to v3.24 by @renovate[bot] in <a href="https://github.com/voidzero-dev/setup-vp/pull/80">https://github.com/voidzero-dev/setup-vp/pull/80</a></li>
<li>test: add Node 20 to node-version matrix (expected red until Vite+ supports it) by @fengmk2 in <a href="https://github.com/voidzero-dev/setup-vp/pull/84">https://github.com/voidzero-dev/setup-vp/pull/84</a></li>
<li>chore(deps): upgrade vite-plus to 0.2.1 by @fengmk2 in <a href="https://github.com/voidzero-dev/setup-vp/pull/85">https://github.com/voidzero-dev/setup-vp/pull/85</a></li>
<li>docs: update shared agent guidance by @jong-kyung in <a href="https://github.com/voidzero-dev/setup-vp/pull/89">https://github.com/voidzero-dev/setup-vp/pull/89</a></li>
<li>chore: switch input schemas to zod mini by @jong-kyung in <a href="https://github.com/voidzero-dev/setup-vp/pull/98">https://github.com/voidzero-dev/setup-vp/pull/98</a></li>
<li>chore(deps): update dependency @actions/cache to v6.1.0 by @renovate[bot] in <a href="https://github.com/voidzero-dev/setup-vp/pull/86">https://github.com/voidzero-dev/setup-vp/pull/86</a></li>
<li>chore(deps): update pnpm to v11.9.0 by @renovate[bot] in <a href="https://github.com/voidzero-dev/setup-vp/pull/99">https://github.com/voidzero-dev/setup-vp/pull/99</a></li>
<li>fix: install pkg.pr.new preview builds via VP_PR_VERSION by @fengmk2 in <a href="https://github.com/voidzero-dev/setup-vp/pull/100">https://github.com/voidzero-dev/setup-vp/pull/100</a></li>
</ul>
<h2 id="new-contributors">New Contributors</h2>
<ul>
<li>@jong-kyung made their first contribution in <a href="https://github.com/voidzero-dev/setup-vp/pull/89">https://github.com/voidzero-dev/setup-vp/pull/89</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a href="https://github.com/voidzero-dev/setup-vp/compare/v1.12.0...v1.13.0">https://github.com/voidzero-dev/setup-vp/compare/v1.12.0...v1.13.0</a></p>
]]></content:encoded></item><item><title>docs-version-deploy</title><link>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/docs-version-deploy/</link><pubDate>Wed, 01 Jul 2026 06:49:00 +0000</pubDate><guid>https://devops-actions.github.io/github-actions-marketplace-news/blog/2026/07/01/docs-version-deploy/</guid><description>Version updated for https://github.com/yukiakai212/docs-version-deploy to version v2.
This action is used across all versions by ? repositories. Action Type This is a Node action using Node version 24.
Go to the GitHub Marketplace to find the latest changes.
What’s Changed Full Changelog: https://github.com/yukiakai212/docs-version-deploy/compare/v1...v2</description><content:encoded><![CDATA[<p>Version updated for <strong><a href="https://github.com/yukiakai212/docs-version-deploy">https://github.com/yukiakai212/docs-version-deploy</a></strong> to version <strong>v2</strong>.</p>
<ul>
<li>This action is used across all versions by <strong>?</strong> repositories.</li>
</ul>
<h2 id="action-type">Action Type</h2>
<p>This is a <strong>Node</strong> action using Node version <strong>24</strong>.</p>
<p>Go to the <a href="https://github.com/marketplace/actions/docs-version-deploy">GitHub Marketplace</a> to find the latest changes.</p>
<h2 id="whats-changed">What&rsquo;s Changed</h2>
<p><strong>Full Changelog</strong>: <a href="https://github.com/yukiakai212/docs-version-deploy/compare/v1...v2">https://github.com/yukiakai212/docs-version-deploy/compare/v1...v2</a></p>
]]></content:encoded></item></channel></rss>